This is a security release and all users are advised to update their install(s) as soon as possible.
Changed
- Various housekeeping, including improvements to the tests and documentation.
- Thanks to Sergei Morozov and Juliette Reinders Folmer for their contributions.
Fixed
- SECURITY FIX: Running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Gitblame,HgblameorSvnblamereport(s) would process a file whose name contains shell metacharacters. #1473- Users using the default
Fullreport, or any of the other non-*blame reports, are not affected. - For more details, see the security advisory.
- Thanks go to Faze-up and Volker Dusch for responsibly disclosing the vulnerability.
- Additionally, thanks go to Volker Dusch, Rodrigo Primo, Dan Wallis and Juliette Reinders Folmer for creating and testing the fix.
- Users using the default
Other
- The GPG signature for the PHAR files has been rotated. The new fingerprint is: 5CB4F778BF9BC4FB67AE511D96E91A992CF22FF4.
Statistics
Closed: 0 issues
Merged: 46 pull requests
Follow @phpcs on Mastodon or @PHP_CodeSniffer on X to stay informed.
Please consider funding the PHP_CodeSniffer project. If you already do so: thank you!