-
-
Notifications
You must be signed in to change notification settings - Fork 824
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[REF] Upgrade DomPDF to v0.8.6 #18688
Conversation
(Standard links)
|
f46e3c5
to
328fbd2
Compare
@seamuslee001 given we have just cut the rc I'm OK merging this - since we do generally try to keep this up to date - any thoughts? |
I had tested this on a firefox page and worked so lets merge it tbqh |
@seamuslee001 ok - I'm fine with merging if you fix up the PR template - we should link to the changelog changes in that |
Updated now @eileenmcnaughton |
Cool - just noting this requires php7.1 so any ESR backport is out |
This might require some action? Note on resource references: Because of the changes in resource security, some resources (images, external stylesheets) that would previously load with the default settings may not longer load. To ensure compatibility with this release ensure the remote resources can be loaded and that any local filesystem resources are within the directory specified by the chroot setting. By default, chroot is set to the Dompdf directory. Information on how to change these settings can be found in the readme section on setting options. This update addresses the following announced vulnerabilities: |
@seamuslee001 I don't really understand how Composer works, but why is the |
@colemanw checking this suggests that https://stackoverflow.com/questions/46185777/is-content-hash-a-mandatory-part-of-composer-lock it is only when things change in composer.json that the hash gets updated |
[REF] Upgrade DomPDF to v0.8.6
Overview
Upgrades DomPDF version to v0.8.6
Before
DomPDF Version 0.8.5 used
After
DomPDF version 0.8.6 used
Technical Details
Fixes a minor security issue and also fixes a few other issues https://github.com/dompdf/dompdf/releases/tag/v0.8.6