smichaelsen/no-insecure-typo3-extensions 问题修复 & 功能扩展

解决BUG、新增功能、兼容多环境部署,快速响应你的开发需求

邮箱:yvsm@zunyunkeji.com | QQ:316430983 | 微信:yvsm316

smichaelsen/no-insecure-typo3-extensions

Composer 安装命令:

composer require smichaelsen/no-insecure-typo3-extensions

包简介

This package declares conflicts to insecure TYPO3 extensions

README 文档

README

This package is inspired by roave/security-advisories. When you require this package it ensures that you can not load TYPO3 extensions in versions with known vulnerabilities (according to the rating in the TER by the TYPO3 security team).

I've built this with best intentions and to my best knowledge. Nevertheless this comes without guarantee. Do not hold me responsible in case something unexpected/undesired happens.

Usage

Option #1: Require

composer require smichaelsen/no-insecure-typo3-extensions dev-master

Require this package in your project permanently and from now on when you require a TYPO3 extension that has known security issues you will get a composer conflict on composer update.

Pro: Easy to setup and fits every (composer based) TYPO3 project.
Con: You only recognize insecure extensions when you actively perform composer update.

Option #2: Dry Run in CI

If you have a CI that can run tests on your project you can perform on every test:

composer update --dry-run smichaelsen/no-insecure-typo3-extensions dev-master

Pro: You will immediatelly be informed about insecure extensions in your project in every test run.
Con: You need a CI server or a similar setup where automatic tests are performed.

Does this make my project (more) secure?

When you are maintaining TYPO3 projects it's your responsibility to stay up to date with security advisories and best practices. This package can not take this responsibility from you. However it can be an additional security measure.

Which TYPO3 extensions are covered?

This package relies on information from the TYPO3 TER - so only extensions that are published there are covered. It also covers Extensions published via packagist, when they are available in the TER.

How (often) is it updated?

This project automatically checks the TER extension list for updated security information twice a day and updates this package when necessary.

统计信息

  • 总下载量: 59.28k
  • 月度下载量: 0
  • 日度下载量: 0
  • 收藏数: 9
  • 点击次数: 0
  • 依赖项目数: 0
  • 推荐数: 0

GitHub 信息

  • Stars: 9
  • Watchers: 1
  • Forks: 0
  • 开发语言: PHP

其他信息

  • 授权协议: Unknown
  • 更新时间: 2026-01-04

承接程序开发

PHP开发

VUE

Vue开发

前端开发

小程序开发

公众号开发

系统定制

数据库设计

云部署

网站建设

安全加固