Fix version ranges for GHSA-xvmh-25jw-gmmm #6712
Merged
+78
−2
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Ranges taken from https://moodle.org/mod/forum/discuss.php?d=471297#p1892199
Note that I tried to submit this improvement via https://github.com/advisories/GHSA-xvmh-25jw-gmmm/improve
But I got "We were not able to process your request because some field values were not properly filled: vulnerable version ranges is invalid. Please revisit the form and submit it again with the values corrected." while trying to submit this as version range:
<4.1.22 || >=4.2.0,<4.4.12 || >=4.5.0,<4.5.8 || >=5.0.0,<5.0.4 || 5.1.0This is a valid range for Composer
So I reverted to the good ol' editing json, and I hope I did it correctly. But it'd be great if the form was fixed.