Skip to content

Releases: php/pie

1.4.7

25 Jun 10:52
Immutable release. Only release title and notes can be modified.
1.4.7
b6fe5f2

Choose a tag to compare

1.4.7

  • Total issues resolved: 0
  • Total pull requests resolved: 1
  • Total contributors: 1

bug

1.4.6

17 Jun 11:28
Immutable release. Only release title and notes can be modified.
1.4.6
3301920

Choose a tag to compare

1.4.6

  • Total issues resolved: 0
  • Total pull requests resolved: 1
  • Total contributors: 1

bug

1.4.5

26 May 15:11
Immutable release. Only release title and notes can be modified.
1.4.5
5d1485c

Choose a tag to compare

This release contains vulnerability fixes for the following security advisories:

  • GHSA-h842-vjwg-pxxx - Sudo-elevated arbitrary file deletion via extra.pie-installed-binary metadata in UninstallUsingUnlink
  • GHSA-pm6p-666q-hvj5 - Sudo-elevated root code execution via TOCTOU between self-update verify and write
  • GHSA-f67f-c344-cqqr - PIE self-update accepts any historically-attested pie.phar (rollback gap)
  • GHSA-vcv4-gmjc-mxvq - php-ext.build-path traversal escapes PIE's vendor extract directory
  • GHSA-8xmh-xrvp-hwrf - WindowsInstall::copyExtraFile lacks destination containment check (Windows-only path traversal)
  • GHSA-p4j8-36rr-gjfq - Self-update attestation verification is scoped to --owner=php, not --repo=php/pie

1.3.13

26 May 15:11
Immutable release. Only release title and notes can be modified.
1.3.13
f5203dc

Choose a tag to compare

This release contains vulnerability fixes for the following security advisories:

  • GHSA-h842-vjwg-pxxx - Sudo-elevated arbitrary file deletion via extra.pie-installed-binary metadata in UninstallUsingUnlink
  • GHSA-pm6p-666q-hvj5 - Sudo-elevated root code execution via TOCTOU between self-update verify and write
  • GHSA-f67f-c344-cqqr - PIE self-update accepts any historically-attested pie.phar (rollback gap)
  • GHSA-vcv4-gmjc-mxvq - php-ext.build-path traversal escapes PIE's vendor extract directory
  • GHSA-8xmh-xrvp-hwrf - WindowsInstall::copyExtraFile lacks destination containment check (Windows-only path traversal)
  • GHSA-p4j8-36rr-gjfq - Self-update attestation verification is scoped to --owner=php, not --repo=php/pie

1.4.4

13 May 13:51
Immutable release. Only release title and notes can be modified.
1.4.4
a6873a3

Choose a tag to compare

1.4.4

  • Total issues resolved: 0
  • Total pull requests resolved: 1
  • Total contributors: 1

dependencies

1.3.12

13 May 12:57
Immutable release. Only release title and notes can be modified.
1.3.12
5e861db

Choose a tag to compare

1.3.12

  • Total issues resolved: 0
  • Total pull requests resolved: 1
  • Total contributors: 1

dependencies

1.4.3

12 May 09:45
Immutable release. Only release title and notes can be modified.
1.4.3
b601d8d

Choose a tag to compare

1.4.3

  • Total issues resolved: 2
  • Total pull requests resolved: 3
  • Total contributors: 2

bug

1.4.2

24 Apr 09:06
Immutable release. Only release title and notes can be modified.
1.4.2
b197d28

Choose a tag to compare

1.4.2

  • Total issues resolved: 0
  • Total pull requests resolved: 1
  • Total contributors: 1

bug

1.4.1

14 Apr 12:51
Immutable release. Only release title and notes can be modified.
1.4.1
bc4c1af

Choose a tag to compare

1.4.1

  • Total issues resolved: 0
  • Total pull requests resolved: 1
  • Total contributors: 1

dependencies,php

1.3.11

14 Apr 12:08
Immutable release. Only release title and notes can be modified.
1.3.11
a5c8b24

Choose a tag to compare

1.3.11

  • Total issues resolved: 0
  • Total pull requests resolved: 1
  • Total contributors: 1

dependencies,php