Skip to content

Conversation

@arjenschol
Copy link

@arjenschol arjenschol commented Jul 6, 2022

The security checker now has a hard dependency on guzzlehttp/guzzle, which unfortunately had a few security issues in the last weeks. So even when not using guzzlehttp in your application, this would generate a security warning.

By following https://docs.php-http.org/en/latest/httplug/library-developers.html we implemented ClientDiscovery so an existing PSR-18 compatible HTTP client (i.e. symfony/http-client) could be reused.

Unfortunately this is not possible while keeping PHP 5.6 support because psr/http-factory requires >= 7.0.

Is this acceptable for a 1.11 release or should it target a 2.0 release?
composer.json must be updated according to this choice..

- Remove last GuzzleException
- Require at least php-http/discovery 1.6.1 which is the last version with PHP 5.6 support.
@arjenschol arjenschol marked this pull request as ready for review July 6, 2022 13:12
@paras-malhotra
Copy link
Member

Let's target a 2.0 release. Thanks for this pull request!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants