Skip to content

fix(php): bump guzzlehttp packages for Dependabot/OSV advisories - #33

Merged
proxymesh merged 1 commit into
mainfrom
cursor/fix-php-guzzle-vulns-1ac3
Jul 30, 2026
Merged

fix(php): bump guzzlehttp packages for Dependabot/OSV advisories#33
proxymesh merged 1 commit into
mainfrom
cursor/fix-php-guzzle-vulns-1ac3

Conversation

@proxymeshai

@proxymeshai proxymeshai commented Jul 30, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • Reviewed open security findings across proxy-examples ecosystems (npm, RubyGems, Packagist, PyPI via OSV/npm audit/composer audit; GitHub Dependabot alerts API is not accessible to this token).
  • Only remaining vulnerabilities were in the PHP lockfile: guzzlehttp/guzzle 7.10.0 and guzzlehttp/psr7 2.9.0.
  • Bumped guzzlehttp/guzzle7.15.2 and guzzlehttp/psr72.13.0 (plus related transitive updates: promises, deprecation-contracts, polyfill-php80).

Advisories addressed

composer audit and OSV Packagist querybatch are clean afterward. PHP integration check passed. npm/ruby had no open vulns; Python requirements had no actionable current advisories.

Slack Thread

Open in Web Open in Cursor 

Upgrade guzzlehttp/guzzle 7.10.0 → 7.15.2 and guzzlehttp/psr7
2.9.0 → 2.13.0 to clear known cookie, proxy, and URI advisories.

Co-authored-by: ProxyMesh AI <proxymeshai@users.noreply.github.com>

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved: lockfile-only security version bump for guzzlehttp packages with all status checks passing. No reviewers assigned. Auto-merge could not be enabled from this run’s available tools.

Open in Web View Automation 

Sent by Cursor Approval Agent: oss dependabot approver

@proxymesh
proxymesh merged commit 7eb051a into main Jul 30, 2026
9 checks passed
@proxymesh
proxymesh deleted the cursor/fix-php-guzzle-vulns-1ac3 branch July 30, 2026 14:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants