Skip to content

Commit a9ba028

Browse files
authored
release(v3.11.2): phpseclib security dependency update
- deps(composer): upgrade phpseclib/phpseclib to 3.0.51 to pick up the latest upstream security fix
1 parent 80d5182 commit a9ba028

3 files changed

Lines changed: 28 additions & 8 deletions

File tree

CHANGELOG.md

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,25 @@
11
# Changelog
22

3+
## Changes 04/16/2026 (v3.11.2)
4+
5+
`release(v3.11.2): phpseclib security dependency update`
6+
7+
**Commit message**
8+
9+
```text
10+
release(v3.11.2): phpseclib security dependency update
11+
12+
- deps(composer): upgrade phpseclib/phpseclib to 3.0.51 to pick up the latest upstream security fix
13+
```
14+
15+
**Changed**
16+
17+
- **Dependency security maintenance**
18+
- Updated `phpseclib/phpseclib` to `3.0.51` in Composer dependencies to pick up the current upstream security fix in the locked dependency set.
19+
- This release addresses the upstream advisory covering variable-time HMAC comparison in `SSH2::get_binary_packet()`.
20+
21+
---
22+
323
## Changes 03/24/2026 (v3.11.1)
424

525
`release(v3.11.1): shared-hosting worker fallback and deleted-user session invalidation (closes #110)`

composer.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44
"type": "project",
55
"require": {
66
"jumbojett/openid-connect-php": "^1.0.0",
7-
"phpseclib/phpseclib": "^3.0.50",
7+
"phpseclib/phpseclib": "^3.0.51",
88
"robthree/twofactorauth": "^3.0",
99
"endroid/qr-code": "^5.0",
1010
"sabre/dav": "^4.4"

composer.lock

Lines changed: 7 additions & 7 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)