twig/twig in drupal/recommended-settings is at it again

Created on 29 January 2025, 1 day ago

I can never remember where to put drupal/recommended-settings issues because the github repo is locked to issue creation and search does not provide a page for the project on drupal.org, so here we are.

Problem/Motivation

+-------------------+----------------------------------------------------------------------------------+
Package twig/twig
Severity medium
CVE CVE-2025-24374
Title Twig security issue where escaping was missing when using null coalesce operator
URL https://github.com/advisories/GHSA-3xg3-cgvq-2xwr
Affected versions >=3.16.0,<3.19.0
Reported at 2025-01-29T18:41:43+00:00
+-------------------+----------------------------------------------------------------------------------+

Your requirements could not be resolved to an installable set of packages.

  Problem 1
    - Root composer.json requires drupal/core-recommended ^10.4.1 -> satisfiable by drupal/core-recommended[10.4.1, 10.4.x-dev, 10.5.x-dev].
    - drupal/core-recommended[10.4.1, ..., 10.5.x-dev] require twig/twig ~v3.16.0 -> found twig/twig[v3.16.0] but it conflicts with your root composer.json require (^3.19.0).
πŸ› Bug report
Status

Active

Version

10.4 ✨

Component

other

Created by

πŸ‡ΊπŸ‡ΈUnited States loopy1492

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Merge Requests

Comments & Activities

Production build 0.71.5 2024