Roave/SecurityAdvisories

:closed_lock_with_key: Security advisories as a simple composer exclusion list, updated daily

phpsecurity-advisoriessecurity-vulnerabilitycomposerinfosecsecurity-vulnerabilities
Crecimiento de estrellas
Estrellas
2.9k
Forks
111
Crecimiento semanal
+-1
Issues
0
1k2k
ene 2023mar 2024jun 2025sept 2026
README

Roave Security Advisories

A message to Russian 🇷🇺 people

If you currently live in Russia, please read this message.

SWUbanner

Help Palestine 🇵🇸

ReadMeSupportPalestine

Purpose

Hourly build Downloads

This package ensures that your application doesn't have installed dependencies with known security vulnerabilities.

[!TIP] Safety first, my friend! Help keep your supply chain secure with this library, but if you need an extra hand with updating dependencies, application security development, or anything else, get in touch.

- The Roave Team

Installation

composer require --dev roave/security-advisories:dev-latest

Usage

This package does not provide any API or usable classes: its only purpose is to prevent installation of software with known and documented security issues. Simply add "roave/security-advisories": "dev-latest" to your composer.json "require-dev" section and you will not be able to harm yourself with software with known security vulnerabilities.

For example, try following:

composer require --dev roave/security-advisories:dev-latest
# following commands will fail:
composer require symfony/symfony:2.5.2
composer require zendframework/zendframework:2.3.1 

The checks are only executed when adding a new dependency via composer require or when running composer update: deploying an application with a valid composer.lock and via composer install won't trigger any security versions checking.

You can manually trigger a version check by using the --dry-run switch on an update while not doing anything. Running composer update --dry-run roave/security-advisories is an effective way to manually trigger a security version check.

roave/security-advisories for enterprise

Available as part of the Tidelift Subscription.

The maintainers of roave/security-advisories and thousands of other packages are working with Tidelift to deliver commercial support and maintenance for the open source dependencies you use to build your applications. Save time, reduce risk, and improve code health, while paying the maintainers of the exact dependencies you use. Learn more.

You can also contact us at team@roave.com for looking into security issues in your own project.

Stability

This package can only be required in its dev-latest version: there will never be stable/tagged versions because of the nature of the problem being targeted. Security issues are in fact a moving target, and locking your project to a specific tagged version of the package would not make any sense.

This package is therefore only suited for installation in the root of your deployable project.

Sources

This package extracts information about existing security issues in various composer projects from the FriendsOfPHP/security-advisories repository and the GitHub Advisory Database.

Repositorios relacionados
laravel/laravel

Laravel is a web application framework with expressive, elegant syntax. We’ve already laid the foundation for your next big idea — freeing you to create without sweating the small things.

Bladelibraryphpframework
laravel.com
84.9k24.9k
coollabsio/coolify

An open-source, self-hostable PaaS alternative to Vercel, Heroku & Netlify that lets you easily deploy static sites, databases, full-stack applications and 280+ one-click services on your own servers.

PHPPackagistApache License 2.0nodejsmysql
coolify.io
61.6k5.4k
LeCoupa/awesome-cheatsheets

👩‍💻👨‍💻 Awesome cheatsheets for popular programming languages, frameworks and development tools. They include everything you should know in one single file.

JavaScriptnpmawesomeMIT Licensecheatsheetsjavascript
lecoupa.github.io/awesome-cheatsheets/
46.4k6.7k
nextcloud/server

☁️ Nextcloud server, a safe home for all your data

PHPPackagistGNU Affero General Public License v3.0open-sourcefile-sharing
nextcloud.com
36.8k5.2k
laravel/framework

Laravel is a web application framework with expressive, elegant syntax.

PHPPackagistlibraryMIT Licensephpframework
laravel.com
34.9k12k
ziadoz/awesome-php

A curated list of amazingly awesome PHP libraries, resources and shiny things.

awesomeDo What The F*ck You Want To Public Licensephpphp-framework
32.7k5.1k
symfony/symfony

The Symfony PHP framework

PHPPackagistlibraryMIT Licenseframeworkphp
symfony.com
31.1k9.9k
composer/composer

Dependency Manager for PHP

PHPPackagistMIT Licensephpcomposer
getcomposer.org
29.5k4.8k
bagisto/bagisto

Open Source eCommerce & Multi-Vendor Marketplace Platform Built with Laravel for Enterprise-Scale Commerce, Supporting 10M+ SKUs

PHPPackagistappMIT Licenseecommerce-frameworklaravel
bagisto.com
28.1k3.3k
monicahq/monica

Personal CRM. Remember everything about your friends, family and business relationships.

PHPPackagistappGNU Affero General Public License v3.0laravelcrm
beta.monicahq.com
25.3k2.6k
firefly-iii/firefly-iii

Firefly III: a personal finances manager

PHPPackagistappGNU Affero General Public License v3.0phpmoney
firefly-iii.org
24.6k2.3k
krayin/laravel-crm

Krayin CRM is Free & Open Source CRM Built with Laravel for Customer, Lead, and Sales Management.

PHPPackagistMIT Licensephplaravel
krayincrm.com
23.8k1.6k