mirror of
https://github.com/PHPOffice/PhpSpreadsheet.git
synced 2026-10-08 04:46:26 +00:00
Merge pull request #5000 from oleibman/securitymd
Security Policy Updates
This commit is contained in:
+5
-4
@@ -34,13 +34,14 @@ This makes it easier to see exactly what is being tested when reviewing the PR.
|
||||
|
||||
## How to release
|
||||
|
||||
1. Complete CHANGELOG.md and commit
|
||||
2. Create an annotated tag
|
||||
1. On the master branch only, run `composer sbom`, and, if needed, update release numbers on SECURITY.md.
|
||||
2. Complete CHANGELOG.md and commit
|
||||
3. Create an annotated tag
|
||||
1. `git tag -a 1.2.3`
|
||||
2. Tag subject must be the version number, eg: `1.2.3`
|
||||
3. Tag body must be a copy-paste of the changelog entries.
|
||||
3. Push the tag with `git push --tags`, GitHub Actions will create a GitHub release automatically, and the release details will automatically be sent to packagist.
|
||||
4. By default, Github removes markdown headings in the Release Notes. You can either edit to restore these, or, probably preferably, change the default comment character on your system - `git config core.commentChar ";"`.
|
||||
4. Push the tag with `git push --tags`, GitHub Actions will create a GitHub release automatically, and the release details will automatically be sent to packagist.
|
||||
5. By default, Github removes markdown headings in the Release Notes. You can either edit to restore these, or, probably preferably, change the default comment character on your system - `git config core.commentChar ";"`.
|
||||
|
||||
> **Note:** Tagged releases are made from the `master` branch. Only in an emergency should a tagged release be made from the `release` branch. (i.e. cherry-picked hot-fixes.) However, there are 4 branches which have been updated to apply security patches, and those may be tagged if future security updates are needed.
|
||||
- 1.30.x (no further updates aside from security patches, including code changes needed for Php 8.5 compatibility)
|
||||
|
||||
+32
@@ -0,0 +1,32 @@
|
||||
# Security Policy
|
||||
|
||||
## Reporting a Vulnerability
|
||||
|
||||
If you discover a security vulnerability within this project, please report it via [Private Vulnerability Reporting](https://github.com/PHPOffice/PhpSpreadsheet/security/advisories/new).
|
||||
|
||||
Please do not report security vulnerabilities through public GitHub issues.
|
||||
|
||||
### What to Include
|
||||
* Type of issue (e.g., buffer overflow, SQL injection, cross-site scripting).
|
||||
* Full paths of source file(s) related to the manifestation of the issue.
|
||||
* The location of the affected source code within those paths.
|
||||
* Proof of concept (step-by-step instructions to reproduce the issue).
|
||||
* Suggested remediation.
|
||||
|
||||
## Supported Versions
|
||||
|
||||
| Version | Supported |
|
||||
| -------------------- | --------- |
|
||||
| >= 5.10.0 | ✅ |
|
||||
| >= 4.0.0, < 5.10.0 | ❌ |
|
||||
| >= 3.10.8, < 4.0.0 | ✅ |
|
||||
| >= 3.0.0, < 3.10.8 | ❌ |
|
||||
| >= 2.4.8, < 3.0.0 | ✅ |
|
||||
| >= 2.2.0, < 2.4.8 | ❌ |
|
||||
| >= 2.1.19, < 2.2.0 | ✅ |
|
||||
| >= 2.0.0, < 2.1.19 | ❌ |
|
||||
| >= 1.30.6, < 2.0.0 | ✅ |
|
||||
| < 1.30.6 | ❌ |
|
||||
|
||||
## Disclosure Policy
|
||||
We follow a coordinated vulnerability disclosure approach. We ask that you give us reasonable time to address the issue before making any public disclosures.
|
||||
@@ -18,6 +18,7 @@
|
||||
"process-timeout": 600,
|
||||
"sort-packages": true,
|
||||
"allow-plugins": {
|
||||
"cyclonedx/cyclonedx-php-composer": true,
|
||||
"dealerdirect/phpcodesniffer-composer-installer": true
|
||||
}
|
||||
},
|
||||
@@ -64,6 +65,9 @@
|
||||
"phpcbf samples/ src/ tests/ --report=checkstyle",
|
||||
"php-cs-fixer fix"
|
||||
],
|
||||
"sbom": [
|
||||
"composer CycloneDX:make-sbom --omit=dev --output-file=./sbom.xml"
|
||||
],
|
||||
"versions": [
|
||||
"phpcs samples/ src/ tests/ --standard=PHPCompatibility --runtime-set testVersion 8.0- --exclude=PHPCompatibility.Variables.ForbiddenThisUseContexts -n"
|
||||
]
|
||||
@@ -93,6 +97,7 @@
|
||||
"require-dev": {
|
||||
"ext-intl": "*",
|
||||
"ext-openssl": "*",
|
||||
"cyclonedx/cyclonedx-php-composer": "^6.2",
|
||||
"dealerdirect/phpcodesniffer-composer-installer": "dev-main",
|
||||
"dompdf/dompdf": "^2.0 || ^3.0",
|
||||
"friendsofphp/php-cs-fixer": "^3.2",
|
||||
|
||||
Generated
+506
-1
@@ -4,7 +4,7 @@
|
||||
"Read more about it at https://getcomposer.org/doc/01-basic-usage.md#installing-dependencies",
|
||||
"This file is @generated automatically"
|
||||
],
|
||||
"content-hash": "60d332b917eb81ff1fac85d62cecffcd",
|
||||
"content-hash": "856c467bd80051944d384538ca6fda5f",
|
||||
"packages": [
|
||||
{
|
||||
"name": "composer/pcre",
|
||||
@@ -461,6 +461,82 @@
|
||||
],
|
||||
"time": "2025-08-20T19:15:30+00:00"
|
||||
},
|
||||
{
|
||||
"name": "composer/spdx-licenses",
|
||||
"version": "1.6.0",
|
||||
"source": {
|
||||
"type": "git",
|
||||
"url": "https://github.com/composer/spdx-licenses.git",
|
||||
"reference": "5ecd0cb4177696f9fd48f1605dda81db3dee7889"
|
||||
},
|
||||
"dist": {
|
||||
"type": "zip",
|
||||
"url": "https://api.github.com/repos/composer/spdx-licenses/zipball/5ecd0cb4177696f9fd48f1605dda81db3dee7889",
|
||||
"reference": "5ecd0cb4177696f9fd48f1605dda81db3dee7889",
|
||||
"shasum": ""
|
||||
},
|
||||
"require": {
|
||||
"php": "^7.2 || ^8.0"
|
||||
},
|
||||
"require-dev": {
|
||||
"phpstan/phpstan": "^1.11",
|
||||
"symfony/phpunit-bridge": "^6.4.25 || ^7.3.3 || ^8.0"
|
||||
},
|
||||
"type": "library",
|
||||
"extra": {
|
||||
"branch-alias": {
|
||||
"dev-main": "1.x-dev"
|
||||
}
|
||||
},
|
||||
"autoload": {
|
||||
"psr-4": {
|
||||
"Composer\\Spdx\\": "src"
|
||||
}
|
||||
},
|
||||
"notification-url": "https://packagist.org/downloads/",
|
||||
"license": [
|
||||
"MIT"
|
||||
],
|
||||
"authors": [
|
||||
{
|
||||
"name": "Nils Adermann",
|
||||
"email": "naderman@naderman.de",
|
||||
"homepage": "http://www.naderman.de"
|
||||
},
|
||||
{
|
||||
"name": "Jordi Boggiano",
|
||||
"email": "j.boggiano@seld.be",
|
||||
"homepage": "http://seld.be"
|
||||
},
|
||||
{
|
||||
"name": "Rob Bast",
|
||||
"email": "rob.bast@gmail.com",
|
||||
"homepage": "http://robbast.nl"
|
||||
}
|
||||
],
|
||||
"description": "SPDX licenses list and validation library.",
|
||||
"keywords": [
|
||||
"license",
|
||||
"spdx",
|
||||
"validator"
|
||||
],
|
||||
"support": {
|
||||
"irc": "ircs://irc.libera.chat:6697/composer",
|
||||
"issues": "https://github.com/composer/spdx-licenses/issues",
|
||||
"source": "https://github.com/composer/spdx-licenses/tree/1.6.0"
|
||||
},
|
||||
"funding": [
|
||||
{
|
||||
"url": "https://packagist.com",
|
||||
"type": "custom"
|
||||
},
|
||||
{
|
||||
"url": "https://github.com/composer",
|
||||
"type": "github"
|
||||
}
|
||||
],
|
||||
"time": "2026-04-08T20:18:39+00:00"
|
||||
},
|
||||
{
|
||||
"name": "composer/xdebug-handler",
|
||||
"version": "3.0.5",
|
||||
@@ -527,6 +603,179 @@
|
||||
],
|
||||
"time": "2024-05-06T16:37:16+00:00"
|
||||
},
|
||||
{
|
||||
"name": "cyclonedx/cyclonedx-library",
|
||||
"version": "v4.2.0",
|
||||
"source": {
|
||||
"type": "git",
|
||||
"url": "https://github.com/CycloneDX/cyclonedx-php-library.git",
|
||||
"reference": "a99d940fad1b091fe48f41b6ef1b5960bbb0fbd4"
|
||||
},
|
||||
"dist": {
|
||||
"type": "zip",
|
||||
"url": "https://api.github.com/repos/CycloneDX/cyclonedx-php-library/zipball/a99d940fad1b091fe48f41b6ef1b5960bbb0fbd4",
|
||||
"reference": "a99d940fad1b091fe48f41b6ef1b5960bbb0fbd4",
|
||||
"shasum": ""
|
||||
},
|
||||
"require": {
|
||||
"ext-dom": "*",
|
||||
"ext-json": "*",
|
||||
"ext-libxml": "*",
|
||||
"opis/json-schema": "^2.0",
|
||||
"php": "^8.1"
|
||||
},
|
||||
"conflict": {
|
||||
"composer/spdx-licenses": "<1.5"
|
||||
},
|
||||
"require-dev": {
|
||||
"composer/spdx-licenses": "^1.5",
|
||||
"ext-simplexml": "*",
|
||||
"roave/security-advisories": "dev-latest"
|
||||
},
|
||||
"suggest": {
|
||||
"composer/spdx-licenses": "used in license factory",
|
||||
"package-url/packageurl-php": "for parsing and crafting PackageURL strings"
|
||||
},
|
||||
"type": "library",
|
||||
"extra": {
|
||||
"branch-alias": {
|
||||
"dev-master": "4.x-dev"
|
||||
},
|
||||
"composer-normalize": {
|
||||
"indent-size": 4,
|
||||
"indent-style": "space"
|
||||
}
|
||||
},
|
||||
"autoload": {
|
||||
"psr-4": {
|
||||
"CycloneDX\\Core\\": "src/Core/",
|
||||
"CycloneDX\\Contrib\\": "src/Contrib/"
|
||||
}
|
||||
},
|
||||
"notification-url": "https://packagist.org/downloads/",
|
||||
"license": [
|
||||
"Apache-2.0"
|
||||
],
|
||||
"authors": [
|
||||
{
|
||||
"name": "Jan Kowalleck",
|
||||
"email": "jan.kowalleck@gmail.com",
|
||||
"homepage": "https://github.com/jkowalleck"
|
||||
}
|
||||
],
|
||||
"description": "Work with CycloneDX documents.",
|
||||
"homepage": "https://github.com/CycloneDX/cyclonedx-php-library/#readme",
|
||||
"keywords": [
|
||||
"CycloneDX",
|
||||
"HBOM",
|
||||
"OBOM",
|
||||
"SBOM",
|
||||
"SaaSBOM",
|
||||
"bill-of-materials",
|
||||
"bom",
|
||||
"models",
|
||||
"normalizer",
|
||||
"owasp",
|
||||
"package-url",
|
||||
"purl",
|
||||
"serializer",
|
||||
"software-bill-of-materials",
|
||||
"spdx",
|
||||
"validator",
|
||||
"vdr",
|
||||
"vex"
|
||||
],
|
||||
"support": {
|
||||
"docs": "https://cyclonedx-php-library.readthedocs.io",
|
||||
"issues": "https://github.com/CycloneDX/cyclonedx-php-library/issues",
|
||||
"source": "https://github.com/CycloneDX/cyclonedx-php-library/"
|
||||
},
|
||||
"funding": [
|
||||
{
|
||||
"url": "https://owasp.org/donate/?reponame=www-project-cyclonedx&title=OWASP+CycloneDX",
|
||||
"type": "other"
|
||||
}
|
||||
],
|
||||
"time": "2026-09-17T17:38:29+00:00"
|
||||
},
|
||||
{
|
||||
"name": "cyclonedx/cyclonedx-php-composer",
|
||||
"version": "v6.2.0",
|
||||
"source": {
|
||||
"type": "git",
|
||||
"url": "https://github.com/CycloneDX/cyclonedx-php-composer.git",
|
||||
"reference": "934440a5ef7c3c3cdb58c3c3d389d412630ccbf6"
|
||||
},
|
||||
"dist": {
|
||||
"type": "zip",
|
||||
"url": "https://api.github.com/repos/CycloneDX/cyclonedx-php-composer/zipball/934440a5ef7c3c3cdb58c3c3d389d412630ccbf6",
|
||||
"reference": "934440a5ef7c3c3cdb58c3c3d389d412630ccbf6",
|
||||
"shasum": ""
|
||||
},
|
||||
"require": {
|
||||
"composer-plugin-api": "^2.3",
|
||||
"composer/spdx-licenses": "^1.5.7",
|
||||
"cyclonedx/cyclonedx-library": "^4.0",
|
||||
"package-url/packageurl-php": "^1.0",
|
||||
"php": "^8.1"
|
||||
},
|
||||
"require-dev": {
|
||||
"composer/composer": "^2.3.0",
|
||||
"marc-mabe/php-enum": "^4.6",
|
||||
"roave/security-advisories": "dev-latest"
|
||||
},
|
||||
"type": "composer-plugin",
|
||||
"extra": {
|
||||
"class": "CycloneDX\\Composer\\Plugin",
|
||||
"branch-alias": {
|
||||
"dev-master": "6.x-dev"
|
||||
},
|
||||
"composer-normalize": {
|
||||
"indent-size": 4,
|
||||
"indent-style": "space"
|
||||
}
|
||||
},
|
||||
"autoload": {
|
||||
"psr-4": {
|
||||
"CycloneDX\\Composer\\": "src/"
|
||||
}
|
||||
},
|
||||
"notification-url": "https://packagist.org/downloads/",
|
||||
"license": [
|
||||
"Apache-2.0"
|
||||
],
|
||||
"authors": [
|
||||
{
|
||||
"name": "Jan Kowalleck",
|
||||
"email": "jan.kowalleck@gmail.com",
|
||||
"homepage": "https://github.com/jkowalleck"
|
||||
}
|
||||
],
|
||||
"description": "Creates CycloneDX Software Bill-of-Materials (SBOM) from PHP Composer projects",
|
||||
"homepage": "https://github.com/CycloneDX/cyclonedx-php-composer/#readme",
|
||||
"keywords": [
|
||||
"CycloneDX",
|
||||
"SBOM",
|
||||
"bill-of-materials",
|
||||
"bom",
|
||||
"composer",
|
||||
"package-url",
|
||||
"purl",
|
||||
"software-bill-of-materials",
|
||||
"spdx"
|
||||
],
|
||||
"support": {
|
||||
"issues": "https://github.com/CycloneDX/cyclonedx-php-composer/issues",
|
||||
"source": "https://github.com/CycloneDX/cyclonedx-php-composer/"
|
||||
},
|
||||
"funding": [
|
||||
{
|
||||
"url": "https://owasp.org/donate/?reponame=www-project-cyclonedx&title=OWASP+CycloneDX",
|
||||
"type": "other"
|
||||
}
|
||||
],
|
||||
"time": "2026-02-17T13:23:10+00:00"
|
||||
},
|
||||
{
|
||||
"name": "dealerdirect/phpcodesniffer-composer-installer",
|
||||
"version": "dev-main",
|
||||
@@ -1474,6 +1723,262 @@
|
||||
},
|
||||
"time": "2025-12-06T11:56:16+00:00"
|
||||
},
|
||||
{
|
||||
"name": "opis/json-schema",
|
||||
"version": "2.6.0",
|
||||
"source": {
|
||||
"type": "git",
|
||||
"url": "https://github.com/opis/json-schema.git",
|
||||
"reference": "8458763e0dd0b6baa310e04f1829fc73da4e8c8a"
|
||||
},
|
||||
"dist": {
|
||||
"type": "zip",
|
||||
"url": "https://api.github.com/repos/opis/json-schema/zipball/8458763e0dd0b6baa310e04f1829fc73da4e8c8a",
|
||||
"reference": "8458763e0dd0b6baa310e04f1829fc73da4e8c8a",
|
||||
"shasum": ""
|
||||
},
|
||||
"require": {
|
||||
"ext-json": "*",
|
||||
"opis/string": "^2.1",
|
||||
"opis/uri": "^1.0",
|
||||
"php": "^7.4 || ^8.0"
|
||||
},
|
||||
"require-dev": {
|
||||
"ext-bcmath": "*",
|
||||
"ext-intl": "*",
|
||||
"phpunit/phpunit": "^9.0"
|
||||
},
|
||||
"type": "library",
|
||||
"extra": {
|
||||
"branch-alias": {
|
||||
"dev-master": "2.x-dev"
|
||||
}
|
||||
},
|
||||
"autoload": {
|
||||
"psr-4": {
|
||||
"Opis\\JsonSchema\\": "src/"
|
||||
}
|
||||
},
|
||||
"notification-url": "https://packagist.org/downloads/",
|
||||
"license": [
|
||||
"Apache-2.0"
|
||||
],
|
||||
"authors": [
|
||||
{
|
||||
"name": "Sorin Sarca",
|
||||
"email": "sarca_sorin@hotmail.com"
|
||||
},
|
||||
{
|
||||
"name": "Marius Sarca",
|
||||
"email": "marius.sarca@gmail.com"
|
||||
}
|
||||
],
|
||||
"description": "Json Schema Validator for PHP",
|
||||
"homepage": "https://opis.io/json-schema",
|
||||
"keywords": [
|
||||
"json",
|
||||
"json-schema",
|
||||
"schema",
|
||||
"validation",
|
||||
"validator"
|
||||
],
|
||||
"support": {
|
||||
"issues": "https://github.com/opis/json-schema/issues",
|
||||
"source": "https://github.com/opis/json-schema/tree/2.6.0"
|
||||
},
|
||||
"time": "2025-10-17T12:46:48+00:00"
|
||||
},
|
||||
{
|
||||
"name": "opis/string",
|
||||
"version": "2.1.0",
|
||||
"source": {
|
||||
"type": "git",
|
||||
"url": "https://github.com/opis/string.git",
|
||||
"reference": "3e4d2aaff518ac518530b89bb26ed40f4503635e"
|
||||
},
|
||||
"dist": {
|
||||
"type": "zip",
|
||||
"url": "https://api.github.com/repos/opis/string/zipball/3e4d2aaff518ac518530b89bb26ed40f4503635e",
|
||||
"reference": "3e4d2aaff518ac518530b89bb26ed40f4503635e",
|
||||
"shasum": ""
|
||||
},
|
||||
"require": {
|
||||
"ext-iconv": "*",
|
||||
"ext-json": "*",
|
||||
"php": "^7.4 || ^8.0"
|
||||
},
|
||||
"require-dev": {
|
||||
"phpunit/phpunit": "^9.0"
|
||||
},
|
||||
"type": "library",
|
||||
"extra": {
|
||||
"branch-alias": {
|
||||
"dev-master": "2.x-dev"
|
||||
}
|
||||
},
|
||||
"autoload": {
|
||||
"psr-4": {
|
||||
"Opis\\String\\": "src/"
|
||||
}
|
||||
},
|
||||
"notification-url": "https://packagist.org/downloads/",
|
||||
"license": [
|
||||
"Apache-2.0"
|
||||
],
|
||||
"authors": [
|
||||
{
|
||||
"name": "Marius Sarca",
|
||||
"email": "marius.sarca@gmail.com"
|
||||
},
|
||||
{
|
||||
"name": "Sorin Sarca",
|
||||
"email": "sarca_sorin@hotmail.com"
|
||||
}
|
||||
],
|
||||
"description": "Multibyte strings as objects",
|
||||
"homepage": "https://opis.io/string",
|
||||
"keywords": [
|
||||
"multi-byte",
|
||||
"opis",
|
||||
"string",
|
||||
"string manipulation",
|
||||
"utf-8"
|
||||
],
|
||||
"support": {
|
||||
"issues": "https://github.com/opis/string/issues",
|
||||
"source": "https://github.com/opis/string/tree/2.1.0"
|
||||
},
|
||||
"time": "2025-10-17T12:38:41+00:00"
|
||||
},
|
||||
{
|
||||
"name": "opis/uri",
|
||||
"version": "1.1.0",
|
||||
"source": {
|
||||
"type": "git",
|
||||
"url": "https://github.com/opis/uri.git",
|
||||
"reference": "0f3ca49ab1a5e4a6681c286e0b2cc081b93a7d5a"
|
||||
},
|
||||
"dist": {
|
||||
"type": "zip",
|
||||
"url": "https://api.github.com/repos/opis/uri/zipball/0f3ca49ab1a5e4a6681c286e0b2cc081b93a7d5a",
|
||||
"reference": "0f3ca49ab1a5e4a6681c286e0b2cc081b93a7d5a",
|
||||
"shasum": ""
|
||||
},
|
||||
"require": {
|
||||
"opis/string": "^2.0",
|
||||
"php": "^7.4 || ^8.0"
|
||||
},
|
||||
"require-dev": {
|
||||
"phpunit/phpunit": "^9"
|
||||
},
|
||||
"type": "library",
|
||||
"extra": {
|
||||
"branch-alias": {
|
||||
"dev-master": "1.x-dev"
|
||||
}
|
||||
},
|
||||
"autoload": {
|
||||
"psr-4": {
|
||||
"Opis\\Uri\\": "src/"
|
||||
}
|
||||
},
|
||||
"notification-url": "https://packagist.org/downloads/",
|
||||
"license": [
|
||||
"Apache-2.0"
|
||||
],
|
||||
"authors": [
|
||||
{
|
||||
"name": "Marius Sarca",
|
||||
"email": "marius.sarca@gmail.com"
|
||||
},
|
||||
{
|
||||
"name": "Sorin Sarca",
|
||||
"email": "sarca_sorin@hotmail.com"
|
||||
}
|
||||
],
|
||||
"description": "Build, parse and validate URIs and URI-templates",
|
||||
"homepage": "https://opis.io",
|
||||
"keywords": [
|
||||
"URI Template",
|
||||
"parse url",
|
||||
"punycode",
|
||||
"uri",
|
||||
"uri components",
|
||||
"url",
|
||||
"validate uri"
|
||||
],
|
||||
"support": {
|
||||
"issues": "https://github.com/opis/uri/issues",
|
||||
"source": "https://github.com/opis/uri/tree/1.1.0"
|
||||
},
|
||||
"time": "2021-05-22T15:57:08+00:00"
|
||||
},
|
||||
{
|
||||
"name": "package-url/packageurl-php",
|
||||
"version": "1.1.2",
|
||||
"source": {
|
||||
"type": "git",
|
||||
"url": "https://github.com/package-url/packageurl-php.git",
|
||||
"reference": "32058ad61f0d8b457fa26e7860bbd8b903196d3f"
|
||||
},
|
||||
"dist": {
|
||||
"type": "zip",
|
||||
"url": "https://api.github.com/repos/package-url/packageurl-php/zipball/32058ad61f0d8b457fa26e7860bbd8b903196d3f",
|
||||
"reference": "32058ad61f0d8b457fa26e7860bbd8b903196d3f",
|
||||
"shasum": ""
|
||||
},
|
||||
"require": {
|
||||
"php": "^7.3 || ^8.0"
|
||||
},
|
||||
"require-dev": {
|
||||
"ext-json": "*",
|
||||
"phpunit/phpunit": "9.6.16",
|
||||
"roave/security-advisories": "dev-latest"
|
||||
},
|
||||
"type": "library",
|
||||
"extra": {
|
||||
"composer-normalize": {
|
||||
"indent-size": 4,
|
||||
"indent-style": "space"
|
||||
}
|
||||
},
|
||||
"autoload": {
|
||||
"psr-4": {
|
||||
"PackageUrl\\": "src"
|
||||
}
|
||||
},
|
||||
"notification-url": "https://packagist.org/downloads/",
|
||||
"license": [
|
||||
"MIT"
|
||||
],
|
||||
"authors": [
|
||||
{
|
||||
"name": "Jan Kowalleck",
|
||||
"email": "jan.kowalleck@gmail.com",
|
||||
"homepage": "https://github.com/jkowalleck"
|
||||
}
|
||||
],
|
||||
"description": "Builder and parser based on the package URL (purl) specification.",
|
||||
"homepage": "https://github.com/package-url/packageurl-php#readme",
|
||||
"keywords": [
|
||||
"package",
|
||||
"package-url",
|
||||
"packageurl",
|
||||
"purl",
|
||||
"url"
|
||||
],
|
||||
"support": {
|
||||
"issues": "https://github.com/package-url/packageurl-php/issues",
|
||||
"source": "https://github.com/package-url/packageurl-php/tree/1.1.2"
|
||||
},
|
||||
"funding": [
|
||||
{
|
||||
"url": "https://github.com/sponsors/jkowalleck",
|
||||
"type": "github"
|
||||
}
|
||||
],
|
||||
"time": "2024-02-05T11:20:07+00:00"
|
||||
},
|
||||
{
|
||||
"name": "paragonie/random_compat",
|
||||
"version": "v9.99.100",
|
||||
|
||||
@@ -0,0 +1,294 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<bom xmlns="http://cyclonedx.org/schema/bom/1.5" version="1" serialNumber="urn:uuid:5cb7f33c-bb22-4c26-bf95-13e7cee3802d">
|
||||
<metadata>
|
||||
<timestamp><![CDATA[2026-10-01T13:50:19Z]]></timestamp>
|
||||
<tools>
|
||||
<tool>
|
||||
<name><![CDATA[composer]]></name>
|
||||
<version><![CDATA[2.8.11]]></version>
|
||||
</tool>
|
||||
<tool>
|
||||
<vendor><![CDATA[cyclonedx]]></vendor>
|
||||
<name><![CDATA[cyclonedx-php-composer]]></name>
|
||||
<version><![CDATA[v6.2.0]]></version>
|
||||
<externalReferences>
|
||||
<reference type="distribution">
|
||||
<url><![CDATA[https://api.github.com/repos/CycloneDX/cyclonedx-php-composer/zipball/934440a5ef7c3c3cdb58c3c3d389d412630ccbf6]]></url>
|
||||
<comment><![CDATA[dist reference: 934440a5ef7c3c3cdb58c3c3d389d412630ccbf6]]></comment>
|
||||
</reference>
|
||||
<reference type="vcs">
|
||||
<url><![CDATA[https://github.com/CycloneDX/cyclonedx-php-composer.git]]></url>
|
||||
<comment><![CDATA[source reference: 934440a5ef7c3c3cdb58c3c3d389d412630ccbf6]]></comment>
|
||||
</reference>
|
||||
<reference type="website">
|
||||
<url><![CDATA[https://github.com/CycloneDX/cyclonedx-php-composer/#readme]]></url>
|
||||
<comment><![CDATA[as detected from Composer manifest 'homepage']]></comment>
|
||||
</reference>
|
||||
<reference type="issue-tracker">
|
||||
<url><![CDATA[https://github.com/CycloneDX/cyclonedx-php-composer/issues]]></url>
|
||||
<comment><![CDATA[as detected from Composer manifest 'support.issues']]></comment>
|
||||
</reference>
|
||||
<reference type="vcs">
|
||||
<url><![CDATA[https://github.com/CycloneDX/cyclonedx-php-composer/]]></url>
|
||||
<comment><![CDATA[as detected from Composer manifest 'support.source']]></comment>
|
||||
</reference>
|
||||
</externalReferences>
|
||||
</tool>
|
||||
<tool>
|
||||
<vendor><![CDATA[cyclonedx]]></vendor>
|
||||
<name><![CDATA[cyclonedx-library]]></name>
|
||||
<version><![CDATA[v4.2.0]]></version>
|
||||
<externalReferences>
|
||||
<reference type="distribution">
|
||||
<url><![CDATA[https://api.github.com/repos/CycloneDX/cyclonedx-php-library/zipball/a99d940fad1b091fe48f41b6ef1b5960bbb0fbd4]]></url>
|
||||
<comment><![CDATA[dist reference: a99d940fad1b091fe48f41b6ef1b5960bbb0fbd4]]></comment>
|
||||
</reference>
|
||||
<reference type="vcs">
|
||||
<url><![CDATA[https://github.com/CycloneDX/cyclonedx-php-library.git]]></url>
|
||||
<comment><![CDATA[source reference: a99d940fad1b091fe48f41b6ef1b5960bbb0fbd4]]></comment>
|
||||
</reference>
|
||||
<reference type="website">
|
||||
<url><![CDATA[https://github.com/CycloneDX/cyclonedx-php-library/#readme]]></url>
|
||||
<comment><![CDATA[as detected from Composer manifest 'homepage']]></comment>
|
||||
</reference>
|
||||
<reference type="documentation">
|
||||
<url><![CDATA[https://cyclonedx-php-library.readthedocs.io]]></url>
|
||||
<comment><![CDATA[as detected from Composer manifest 'support.docs']]></comment>
|
||||
</reference>
|
||||
<reference type="issue-tracker">
|
||||
<url><![CDATA[https://github.com/CycloneDX/cyclonedx-php-library/issues]]></url>
|
||||
<comment><![CDATA[as detected from Composer manifest 'support.issues']]></comment>
|
||||
</reference>
|
||||
<reference type="vcs">
|
||||
<url><![CDATA[https://github.com/CycloneDX/cyclonedx-php-library/]]></url>
|
||||
<comment><![CDATA[as detected from Composer manifest 'support.source']]></comment>
|
||||
</reference>
|
||||
</externalReferences>
|
||||
</tool>
|
||||
</tools>
|
||||
<component type="application" bom-ref="phpoffice/phpspreadsheet-dev-master">
|
||||
<author><![CDATA[Maarten Balliauw, Mark Baker, Franck Lefevre, Erik Tilt, Adrien Crivelli, Owen Leibman]]></author>
|
||||
<group><![CDATA[phpoffice]]></group>
|
||||
<name><![CDATA[phpspreadsheet]]></name>
|
||||
<version><![CDATA[dev-master]]></version>
|
||||
<description><![CDATA[PHPSpreadsheet - Read, Create and Write Spreadsheet documents in PHP - Spreadsheet engine]]></description>
|
||||
<licenses>
|
||||
<license>
|
||||
<id><![CDATA[MIT]]></id>
|
||||
</license>
|
||||
</licenses>
|
||||
<purl><![CDATA[pkg:composer/phpoffice/phpspreadsheet@dev-master]]></purl>
|
||||
<externalReferences>
|
||||
<reference type="website">
|
||||
<url><![CDATA[https://github.com/PHPOffice/PhpSpreadsheet]]></url>
|
||||
<comment><![CDATA[as detected from Composer manifest 'homepage']]></comment>
|
||||
</reference>
|
||||
</externalReferences>
|
||||
<properties>
|
||||
<property name="cdx:composer:package:distReference"><![CDATA[b03f7f3371e1dd1adafa41e4d0e47335f2d782f9]]></property>
|
||||
<property name="cdx:composer:package:sourceReference"><![CDATA[b03f7f3371e1dd1adafa41e4d0e47335f2d782f9]]></property>
|
||||
<property name="cdx:composer:package:type"><![CDATA[library]]></property>
|
||||
</properties>
|
||||
</component>
|
||||
</metadata>
|
||||
<components>
|
||||
<component type="library" bom-ref="composer/pcre-3.4.0.0">
|
||||
<author><![CDATA[Jordi Boggiano]]></author>
|
||||
<group><![CDATA[composer]]></group>
|
||||
<name><![CDATA[pcre]]></name>
|
||||
<version><![CDATA[3.4.0]]></version>
|
||||
<description><![CDATA[PCRE wrapping library that offers type-safe preg_* replacements.]]></description>
|
||||
<licenses>
|
||||
<license>
|
||||
<id><![CDATA[MIT]]></id>
|
||||
</license>
|
||||
</licenses>
|
||||
<purl><![CDATA[pkg:composer/composer/pcre@3.4.0]]></purl>
|
||||
<externalReferences>
|
||||
<reference type="distribution">
|
||||
<url><![CDATA[https://api.github.com/repos/composer/pcre/zipball/d5a341b3fb61f3001970940afb1d332968a183ed]]></url>
|
||||
<comment><![CDATA[dist reference: d5a341b3fb61f3001970940afb1d332968a183ed]]></comment>
|
||||
</reference>
|
||||
<reference type="vcs">
|
||||
<url><![CDATA[https://github.com/composer/pcre.git]]></url>
|
||||
<comment><![CDATA[source reference: d5a341b3fb61f3001970940afb1d332968a183ed]]></comment>
|
||||
</reference>
|
||||
<reference type="issue-tracker">
|
||||
<url><![CDATA[https://github.com/composer/pcre/issues]]></url>
|
||||
<comment><![CDATA[as detected from Composer manifest 'support.issues']]></comment>
|
||||
</reference>
|
||||
<reference type="vcs">
|
||||
<url><![CDATA[https://github.com/composer/pcre/tree/3.4.0]]></url>
|
||||
<comment><![CDATA[as detected from Composer manifest 'support.source']]></comment>
|
||||
</reference>
|
||||
</externalReferences>
|
||||
<properties>
|
||||
<property name="cdx:composer:package:distReference"><![CDATA[d5a341b3fb61f3001970940afb1d332968a183ed]]></property>
|
||||
<property name="cdx:composer:package:sourceReference"><![CDATA[d5a341b3fb61f3001970940afb1d332968a183ed]]></property>
|
||||
<property name="cdx:composer:package:type"><![CDATA[library]]></property>
|
||||
</properties>
|
||||
</component>
|
||||
<component type="library" bom-ref="maennchen/zipstream-php-3.1.2.0">
|
||||
<author><![CDATA[Paul Duncan, Jonatan Männchen, Jesse Donat, András Kolesár]]></author>
|
||||
<group><![CDATA[maennchen]]></group>
|
||||
<name><![CDATA[zipstream-php]]></name>
|
||||
<version><![CDATA[3.1.2]]></version>
|
||||
<description><![CDATA[ZipStream is a library for dynamically streaming dynamic zip files from PHP without writing to the disk at all on the server.]]></description>
|
||||
<licenses>
|
||||
<license>
|
||||
<id><![CDATA[MIT]]></id>
|
||||
</license>
|
||||
</licenses>
|
||||
<purl><![CDATA[pkg:composer/maennchen/zipstream-php@3.1.2]]></purl>
|
||||
<externalReferences>
|
||||
<reference type="distribution">
|
||||
<url><![CDATA[https://api.github.com/repos/maennchen/ZipStream-PHP/zipball/aeadcf5c412332eb426c0f9b4485f6accba2a99f]]></url>
|
||||
<comment><![CDATA[dist reference: aeadcf5c412332eb426c0f9b4485f6accba2a99f]]></comment>
|
||||
</reference>
|
||||
<reference type="vcs">
|
||||
<url><![CDATA[https://github.com/maennchen/ZipStream-PHP.git]]></url>
|
||||
<comment><![CDATA[source reference: aeadcf5c412332eb426c0f9b4485f6accba2a99f]]></comment>
|
||||
</reference>
|
||||
<reference type="issue-tracker">
|
||||
<url><![CDATA[https://github.com/maennchen/ZipStream-PHP/issues]]></url>
|
||||
<comment><![CDATA[as detected from Composer manifest 'support.issues']]></comment>
|
||||
</reference>
|
||||
<reference type="vcs">
|
||||
<url><![CDATA[https://github.com/maennchen/ZipStream-PHP/tree/3.1.2]]></url>
|
||||
<comment><![CDATA[as detected from Composer manifest 'support.source']]></comment>
|
||||
</reference>
|
||||
</externalReferences>
|
||||
<properties>
|
||||
<property name="cdx:composer:package:distReference"><![CDATA[aeadcf5c412332eb426c0f9b4485f6accba2a99f]]></property>
|
||||
<property name="cdx:composer:package:sourceReference"><![CDATA[aeadcf5c412332eb426c0f9b4485f6accba2a99f]]></property>
|
||||
<property name="cdx:composer:package:type"><![CDATA[library]]></property>
|
||||
</properties>
|
||||
</component>
|
||||
<component type="library" bom-ref="markbaker/complex-3.0.2.0">
|
||||
<author><![CDATA[Mark Baker]]></author>
|
||||
<group><![CDATA[markbaker]]></group>
|
||||
<name><![CDATA[complex]]></name>
|
||||
<version><![CDATA[3.0.2]]></version>
|
||||
<description><![CDATA[PHP Class for working with complex numbers]]></description>
|
||||
<licenses>
|
||||
<license>
|
||||
<id><![CDATA[MIT]]></id>
|
||||
</license>
|
||||
</licenses>
|
||||
<purl><![CDATA[pkg:composer/markbaker/complex@3.0.2]]></purl>
|
||||
<externalReferences>
|
||||
<reference type="distribution">
|
||||
<url><![CDATA[https://api.github.com/repos/MarkBaker/PHPComplex/zipball/95c56caa1cf5c766ad6d65b6344b807c1e8405b9]]></url>
|
||||
<comment><![CDATA[dist reference: 95c56caa1cf5c766ad6d65b6344b807c1e8405b9]]></comment>
|
||||
</reference>
|
||||
<reference type="vcs">
|
||||
<url><![CDATA[https://github.com/MarkBaker/PHPComplex.git]]></url>
|
||||
<comment><![CDATA[source reference: 95c56caa1cf5c766ad6d65b6344b807c1e8405b9]]></comment>
|
||||
</reference>
|
||||
<reference type="website">
|
||||
<url><![CDATA[https://github.com/MarkBaker/PHPComplex]]></url>
|
||||
<comment><![CDATA[as detected from Composer manifest 'homepage']]></comment>
|
||||
</reference>
|
||||
<reference type="issue-tracker">
|
||||
<url><![CDATA[https://github.com/MarkBaker/PHPComplex/issues]]></url>
|
||||
<comment><![CDATA[as detected from Composer manifest 'support.issues']]></comment>
|
||||
</reference>
|
||||
<reference type="vcs">
|
||||
<url><![CDATA[https://github.com/MarkBaker/PHPComplex/tree/3.0.2]]></url>
|
||||
<comment><![CDATA[as detected from Composer manifest 'support.source']]></comment>
|
||||
</reference>
|
||||
</externalReferences>
|
||||
<properties>
|
||||
<property name="cdx:composer:package:distReference"><![CDATA[95c56caa1cf5c766ad6d65b6344b807c1e8405b9]]></property>
|
||||
<property name="cdx:composer:package:sourceReference"><![CDATA[95c56caa1cf5c766ad6d65b6344b807c1e8405b9]]></property>
|
||||
<property name="cdx:composer:package:type"><![CDATA[library]]></property>
|
||||
</properties>
|
||||
</component>
|
||||
<component type="library" bom-ref="markbaker/matrix-3.0.1.0">
|
||||
<author><![CDATA[Mark Baker]]></author>
|
||||
<group><![CDATA[markbaker]]></group>
|
||||
<name><![CDATA[matrix]]></name>
|
||||
<version><![CDATA[3.0.1]]></version>
|
||||
<description><![CDATA[PHP Class for working with matrices]]></description>
|
||||
<licenses>
|
||||
<license>
|
||||
<id><![CDATA[MIT]]></id>
|
||||
</license>
|
||||
</licenses>
|
||||
<purl><![CDATA[pkg:composer/markbaker/matrix@3.0.1]]></purl>
|
||||
<externalReferences>
|
||||
<reference type="distribution">
|
||||
<url><![CDATA[https://api.github.com/repos/MarkBaker/PHPMatrix/zipball/728434227fe21be27ff6d86621a1b13107a2562c]]></url>
|
||||
<comment><![CDATA[dist reference: 728434227fe21be27ff6d86621a1b13107a2562c]]></comment>
|
||||
</reference>
|
||||
<reference type="vcs">
|
||||
<url><![CDATA[https://github.com/MarkBaker/PHPMatrix.git]]></url>
|
||||
<comment><![CDATA[source reference: 728434227fe21be27ff6d86621a1b13107a2562c]]></comment>
|
||||
</reference>
|
||||
<reference type="website">
|
||||
<url><![CDATA[https://github.com/MarkBaker/PHPMatrix]]></url>
|
||||
<comment><![CDATA[as detected from Composer manifest 'homepage']]></comment>
|
||||
</reference>
|
||||
<reference type="issue-tracker">
|
||||
<url><![CDATA[https://github.com/MarkBaker/PHPMatrix/issues]]></url>
|
||||
<comment><![CDATA[as detected from Composer manifest 'support.issues']]></comment>
|
||||
</reference>
|
||||
<reference type="vcs">
|
||||
<url><![CDATA[https://github.com/MarkBaker/PHPMatrix/tree/3.0.1]]></url>
|
||||
<comment><![CDATA[as detected from Composer manifest 'support.source']]></comment>
|
||||
</reference>
|
||||
</externalReferences>
|
||||
<properties>
|
||||
<property name="cdx:composer:package:distReference"><![CDATA[728434227fe21be27ff6d86621a1b13107a2562c]]></property>
|
||||
<property name="cdx:composer:package:sourceReference"><![CDATA[728434227fe21be27ff6d86621a1b13107a2562c]]></property>
|
||||
<property name="cdx:composer:package:type"><![CDATA[library]]></property>
|
||||
</properties>
|
||||
</component>
|
||||
<component type="library" bom-ref="psr/simple-cache-3.0.0.0">
|
||||
<author><![CDATA[PHP-FIG]]></author>
|
||||
<group><![CDATA[psr]]></group>
|
||||
<name><![CDATA[simple-cache]]></name>
|
||||
<version><![CDATA[3.0.0]]></version>
|
||||
<description><![CDATA[Common interfaces for simple caching]]></description>
|
||||
<licenses>
|
||||
<license>
|
||||
<id><![CDATA[MIT]]></id>
|
||||
</license>
|
||||
</licenses>
|
||||
<purl><![CDATA[pkg:composer/psr/simple-cache@3.0.0]]></purl>
|
||||
<externalReferences>
|
||||
<reference type="distribution">
|
||||
<url><![CDATA[https://api.github.com/repos/php-fig/simple-cache/zipball/764e0b3939f5ca87cb904f570ef9be2d78a07865]]></url>
|
||||
<comment><![CDATA[dist reference: 764e0b3939f5ca87cb904f570ef9be2d78a07865]]></comment>
|
||||
</reference>
|
||||
<reference type="vcs">
|
||||
<url><![CDATA[https://github.com/php-fig/simple-cache.git]]></url>
|
||||
<comment><![CDATA[source reference: 764e0b3939f5ca87cb904f570ef9be2d78a07865]]></comment>
|
||||
</reference>
|
||||
<reference type="vcs">
|
||||
<url><![CDATA[https://github.com/php-fig/simple-cache/tree/3.0.0]]></url>
|
||||
<comment><![CDATA[as detected from Composer manifest 'support.source']]></comment>
|
||||
</reference>
|
||||
</externalReferences>
|
||||
<properties>
|
||||
<property name="cdx:composer:package:distReference"><![CDATA[764e0b3939f5ca87cb904f570ef9be2d78a07865]]></property>
|
||||
<property name="cdx:composer:package:sourceReference"><![CDATA[764e0b3939f5ca87cb904f570ef9be2d78a07865]]></property>
|
||||
<property name="cdx:composer:package:type"><![CDATA[library]]></property>
|
||||
</properties>
|
||||
</component>
|
||||
</components>
|
||||
<dependencies>
|
||||
<dependency ref="composer/pcre-3.4.0.0"/>
|
||||
<dependency ref="maennchen/zipstream-php-3.1.2.0"/>
|
||||
<dependency ref="markbaker/complex-3.0.2.0"/>
|
||||
<dependency ref="markbaker/matrix-3.0.1.0"/>
|
||||
<dependency ref="psr/simple-cache-3.0.0.0"/>
|
||||
<dependency ref="phpoffice/phpspreadsheet-dev-master">
|
||||
<dependency ref="composer/pcre-3.4.0.0"/>
|
||||
<dependency ref="maennchen/zipstream-php-3.1.2.0"/>
|
||||
<dependency ref="markbaker/complex-3.0.2.0"/>
|
||||
<dependency ref="markbaker/matrix-3.0.1.0"/>
|
||||
<dependency ref="psr/simple-cache-3.0.0.0"/>
|
||||
</dependency>
|
||||
</dependencies>
|
||||
</bom>
|
||||
Reference in New Issue
Block a user