Skip to content

[Renovate] Pin shivammathur/setup-php action to f3e473d [SECURITY] - autoclosed - #10

Closed
appsec-renovate-bot[bot] wants to merge 1 commit into
mainfrom
renovate/github-tags-shivammathur-setup-php-vulnerability
Closed

[Renovate] Pin shivammathur/setup-php action to f3e473d [SECURITY] - autoclosed#10
appsec-renovate-bot[bot] wants to merge 1 commit into
mainfrom
renovate/github-tags-shivammathur-setup-php-vulnerability

Conversation

@appsec-renovate-bot

Copy link
Copy Markdown

This PR contains the following updates:

Package Type Update Change
shivammathur/setup-php action pinDigest f3e473d

Setup PHP: GitHub tokens configured by setup-php may be exposed through pinned affected Composer versions

GHSA-5wxr-w449-57cm

More information

Details

Impact

This affects only workflows that pin an exact affected Composer semver version through setup-php, for example tools: composer:2.9.7.

Workflows using the default Composer version, composer:v2, or no pinned Composer version are not affected through setup-php, because those Composer URLs have been updated to patched Composer releases for all setup-php versions.

setup-php does not directly print the token. The token may be exposed through Composer when Composer validates github-oauth auth and rejects GitHub's newer hyphen-containing token format.

Public repository logs may expose the token. GitHub-hosted runner GITHUB_TOKEN values expire after the job, but exposure may still matter during the token lifetime and for longer-lived GitHub App or user tokens.

Patches

setup-php 2.37.1 skips generated GitHub OAuth auth for pinned Composer versions affected by Composer GHSA-f9f8-rm49-7jv2 while preserving other Composer auth, including Packagist auth.

Workarounds

Upgrade to setup-php 2.37.1 or newer. You can also avoid the affected path by using a patched Composer version: 2.9.8, 2.2.28, 1.10.28, or newer supported Composer releases.

It is recommended to avoid pinning affected Composer versions such as composer:2.9.7, unless you have automations to do timely updates in your workflows.

Severity

  • CVSS Score: 5.9 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@appsec-renovate-bot appsec-renovate-bot Bot changed the title [Renovate] Pin shivammathur/setup-php action to f3e473d [SECURITY] [Renovate] Pin shivammathur/setup-php action to f3e473d [SECURITY] - autoclosed Aug 13, 2026
@appsec-renovate-bot
appsec-renovate-bot Bot deleted the renovate/github-tags-shivammathur-setup-php-vulnerability branch August 13, 2026 07:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants