WeSearch

Composer-cve-gate – pre-install gate for Composer, built after Laravel-Lang

·5 min read · 0 reactions · 0 comments · 16 views
#security#software#composer
Composer-cve-gate – pre-install gate for Composer, built after Laravel-Lang
⚡ TL;DR · AI summary

Composer-cve-gate is a pre-install gate designed to enhance security for Composer by blocking potentially vulnerable packages before installation. It checks packages against multiple vulnerability signals, ensuring that malicious code does not run on the user's machine. This tool is particularly useful in preventing issues that can arise from Composer's post-install scripts, which can execute arbitrary code immediately after download.

Key facts
Original article
GitHub
Read full at GitHub →
Opening excerpt (first ~120 words) tap to expand

composer-cve-gate Pre-install / pre-upgrade CVE gate for Composer. Blocks before post-install scripts run. Most of the time composer require is fine. Sometimes it isn't — and when it isn't, the damage is usually done by the time composer audit flags it, because audit runs after post-install scripts. composer-cve-gate adds two subcommands that resolve the full transitive tree, check every package against multiple vulnerability signals, and block the install before any code touches your machine. What it checks OSV.dev — Google's aggregated vulnerability feed, native Packagist coverage. GitHub Advisory Database — composer ecosystem, version-range filtered. NIST NVD — keyword + CPE-version match for upstream CVEs. Packagist freshness hold — packages published less than 3 days ago are held.

Excerpt limited to ~120 words for fair-use compliance. The full article is at GitHub.

Anonymous · no account needed
Share 𝕏 Facebook Reddit LinkedIn Threads WhatsApp Bluesky Mastodon Email

Discussion

0 comments

More from GitHub