Task #88288

Raise fluid dependency to latest minor version

Added by Benni Mack about 2 months ago. Updated about 2 months ago.

Status:
Closed
Priority:
Should have
Assignee:
Category:
Fluid
Target version:
Start date:
2019-05-07
Due date:
% Done:

100%

TYPO3 Version:
9
PHP Version:
Tags:
Complexity:
Sprint Focus:

Description

Let's use the new versions released by Claus today!

Associated revisions

Revision 3d048b30 (diff)
Added by Benni Mack about 2 months ago

[SECURITY] Raise Fluid Standalone dependency

Raise Fluid Standalone dependency to the next stable version
which fixes an important XSS issue when escaping
ternary operators.

Used composer command:
composer req typo3fluid/fluid:^2.6.1 --prefer-lowest

Resolves: #88288
Releases: master, 9.5, 8.7
Security-Bulletin: TYPO3-CORE-SA-2019-013
Change-Id: I04f32d8d01f893bc26ff21aa0c079c85e9db85b9
Reviewed-on: https://review.typo3.org/c/Packages/TYPO3.CMS/+/60693
Reviewed-by: Claus Due <>
Reviewed-by: Susanne Moog <>
Reviewed-by: Benni Mack <>
Tested-by: Susanne Moog <>
Tested-by: TYPO3com <>
Tested-by: Benni Mack <>

Revision 686d8f28 (diff)
Added by Benni Mack about 2 months ago

[SECURITY] Raise Fluid Standalone dependency

Raise Fluid Standalone dependency to the next stable version
which fixes an important XSS issue when escaping
ternary operators.

Used composer command:
composer req typo3fluid/fluid:^2.6.1 --prefer-lowest

Resolves: #88288
Releases: master, 9.5, 8.7
Security-Bulletin: TYPO3-CORE-SA-2019-013
Change-Id: I9ac20e69f88ad8369f88e3fdc32186e0d0cdd93c
Reviewed-on: https://review.typo3.org/c/Packages/TYPO3.CMS/+/60692
Tested-by: Claus Due <>
Tested-by: TYPO3com <>
Tested-by: Benni Mack <>
Reviewed-by: Claus Due <>
Reviewed-by: Benni Mack <>

Revision 2df4046f (diff)
Added by Benni Mack about 2 months ago

[SECURITY] Raise Fluid Standalone dependency

Raise Fluid Standalone dependency to the next stable version
which fixes an important XSS issue when escaping
ternary operators.

Used composer command:
composer req typo3fluid/fluid:^2.5.5 --prefer-lowest

As TYPO3 v8.7 tarballs already delivered 2.5.4, the
minimum required version is now 2.5.5.

In addition, EXT:core composer.json now explicitly
requires Fluid Standalone as it was the case for v9+master
already.

Resolves: #88288
Releases: master, 9.5, 8.7
Security-Bulletin: TYPO3-CORE-SA-2019-013
Change-Id: Ib87bd7b8e064525b2204296e9be3a0bb7ee5cc78
Reviewed-on: https://review.typo3.org/c/Packages/TYPO3.CMS/+/60691
Tested-by: TYPO3com <>
Tested-by: Benni Mack <>
Reviewed-by: Benni Mack <>

History

#1 Updated by Gerrit Code Review about 2 months ago

  • Status changed from New to Under Review

Patch set 1 for branch TYPO3_8-7 of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/c/Packages/TYPO3.CMS/+/60691

#2 Updated by Gerrit Code Review about 2 months ago

Patch set 1 for branch 9.5 of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/c/Packages/TYPO3.CMS/+/60692

#3 Updated by Gerrit Code Review about 2 months ago

Patch set 1 for branch master of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/c/Packages/TYPO3.CMS/+/60693

#4 Updated by Gerrit Code Review about 2 months ago

Patch set 2 for branch TYPO3_8-7 of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/c/Packages/TYPO3.CMS/+/60691

#5 Updated by Gerrit Code Review about 2 months ago

Patch set 2 for branch 9.5 of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/c/Packages/TYPO3.CMS/+/60692

#6 Updated by Gerrit Code Review about 2 months ago

Patch set 2 for branch master of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/c/Packages/TYPO3.CMS/+/60693

#7 Updated by Gerrit Code Review about 2 months ago

Patch set 3 for branch TYPO3_8-7 of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/c/Packages/TYPO3.CMS/+/60691

#8 Updated by Benni Mack about 2 months ago

  • Status changed from Under Review to Resolved
  • % Done changed from 0 to 100

#9 Updated by Benni Mack about 2 months ago

  • Status changed from Resolved to Closed

Also available in: Atom PDF