Alerts This Week
Warning Icon 1 409
Alerts This Week
Warning Icon 1 409

Fedora 44 Composer 2.9.8 Security GitHub Token Fix Advisory 2026-bd05cb6c4d

fedora
Calendar Grey May 23, 2026
Dist Fedora Esm H88
Fixed GitHub token validation and disclosure issues in Composer version 2.9.8 for Fedora 44. Update recommended.
Version 2.9.8 - 2026-05-13 Security: Fixed GitHub token validation and disclosure (GHSA-f9f8-rm49-7jv2)

Summary

Composer helps you declare, manage and install dependencies of PHP projects,

ensuring you have the right stack everywhere.

Documentation: https://getcomposer.org/doc/

Update Information:

Version 2.9.8 - 2026-05-13 Security: Fixed GitHub token validation and disclosure (GHSA-f9f8-rm49-7jv2)

Change Log

* Wed May 13 2026 Remi Collet - 2.9.8-1 - update to 2.9.8

References

Fedora Update Notification FEDORA-2026-bd05cb6c4d 2026-05-23 00:56:16.173256+00:00 Name : composer Product : Fedora 44 Version : 2.9.8 Release : 1.fc44 URL : https://getcomposer.org/ Summary : Dependency Manager for PHP Description : Composer helps you declare, manage and install dependencies of PHP projects, ensuring you have the right stack everywhere. Documentation: https://getcomposer.org/doc/

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-bd05cb6c4d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: composer
Product: Fedora 44
Version: 2.9.8
Release: 1.fc44
Summary: Dependency Manager for PHP

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here