Higher matching version 1.7.0 of taxjar was found in public repository packagist.org than 1.6.5 in the Magento repository
gmarszal opened this issue · 1 comments
Description
Steps to Reproduce
- Just try to run composer install, or composer update
Expected Result
Taxjar module is installed
Actual Result
I see an error
[Exception] Higher matching version 1.7.0 of taxjar/module-taxjar was found in public repository packagist.org than 1.6.5 in private https://repo.magento.com. Public package might've been taken over by a malicious entity, please investigate and update package requirement to match the version from the private repository
Versions
- Magento 2.4
- Magento Commerce (EE)
- PHP 7.x
Hi @gmarszal,
This message that you are receiving is due to the fact that we have just released v1.7.0 to Packagist.org and the Magento marketplace, but there is a waiting period (roughly 2 weeks) before the update version is available via marketplace.
Otherwise, I can assure you that v1.7.0 is the current release!
I'm going to close this issue now since the version conflict on "latest" should resolve itself once the marketplace updates.
Edit: We have made changes to our release process to avoid these conflicts in the future! Thanks for reporting!