Skip to content

fix: Simplify PHP framework suppression for Composer#7693

Merged
jeremylong merged 1 commit intodependency-check:mainfrom
sigv:follow-up-7444
May 31, 2025
Merged

fix: Simplify PHP framework suppression for Composer#7693
jeremylong merged 1 commit intodependency-check:mainfrom
sigv:follow-up-7444

Conversation

@sigv
Copy link
Contributor

@sigv sigv commented May 30, 2025

Description of Change

The base suppression that is bundled for suppressing php in packages names should be expanded, as mentioned in comment by @georgschoelly on #7444.

All matches of PHP in Composer packages are safe to consider not being part of PHP framework cpe:/a:php:php because Composer is the package manager next level down.

This change removes three distinct suppressions, which are now covered by the extended regular expression.

Related issues

Have test cases been added to cover the new functionality?

no

@sigv
Copy link
Contributor Author

sigv commented May 30, 2025

This is intentionally filed against main and not generatedSuppressions so that the existing three rules are merged together.

Copy link
Collaborator

@jeremylong jeremylong left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@jeremylong jeremylong added this to the 12.1.2 milestone May 31, 2025
@jeremylong jeremylong merged commit 4ff0e58 into dependency-check:main May 31, 2025
8 checks passed
@sigv sigv deleted the follow-up-7444 branch June 1, 2025 07:58
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Jul 2, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

core changes to core

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants