microsoftgraph/msgraph-sdk-php

Security vulnerabilities in specific guzzlehttp/guzzle versions affecting 1.x

Closed this issue · 1 comments

Thanks for this project. Due to these vulnerabilities:

The minimum version for guzzlehttp/guzzle should be 6.5.8. This means the entry in composer.json should be:

    "guzzlehttp/guzzle": "^6.5.8 || ^7.4.4",

Is this something you are likely to change and issue a new 1.x release for?

Thanks for raising this @gravelld! Making the changes.