Skip to content

Update Smarty to 5.8.2 - #36442

Open
eileenmcnaughton wants to merge 1 commit into
civicrm:6.18from
eileenmcnaughton:6.18
Open

Update Smarty to 5.8.2#36442
eileenmcnaughton wants to merge 1 commit into
civicrm:6.18from
eileenmcnaughton:6.18

Conversation

@eileenmcnaughton

Copy link
Copy Markdown
Contributor

Overview

Update Smarty to 5.8.2
This is a security hardening update

Before

5.7.0

After

5.8.4, restriction set to 5.8.2 plus (that version being the earliest one with all security patches)

Technical Details

Per policy we apply all security updates to the rc (regardless of whether it is known to have any application) - we do a security update if shown to be relevant to Civi.

Note that I don't think there is a reason not to have a composer requirement that allows updates within the 5.x series - in this case I think it's why dependabot didn't kick in

Comments

This is a security hardening update
@civibot

civibot Bot commented Aug 7, 2026

Copy link
Copy Markdown

🤖 Thank you for contributing to CiviCRM! ❤️ We will need to test and review this PR. 👷

Introduction for new contributors...
  • If this is your first PR, an admin will greenlight automated testing with the command ok to test or add to whitelist.
  • A series of tests will automatically run. You can see the results at the bottom of this page (if there are any problems, it will include a link to see what went wrong).
  • A demo site will be built where anyone can try out a version of CiviCRM that includes your changes.
  • If this process needs to be repeated, an admin will issue the command test this please to rerun tests and build a new demo site.
  • Before this PR can be merged, it needs to be reviewed. Please keep in mind that reviewers are volunteers, and their response time can vary from a few hours to a few weeks depending on their availability and their knowledge of this particular part of CiviCRM.
  • A great way to speed up this process is to "trade reviews" with someone - find an open PR that you feel able to review, and leave a comment like "I'm reviewing this now, could you please review mine?" (include a link to yours). You don't have to wait for a response to get started (and you don't have to stop at one!) the more you review, the faster this process goes for everyone 😄
  • To ensure that you are credited properly in the final release notes, please add yourself to contributor-key.yml
  • For more information about contributing, see CONTRIBUTING.md.
PR commands & links...
  • /rebase <branch-name> will rebase your branch and change the base of the PR.
  • /squash will combine all commits (keeping only the first commit messsage).
  • /port <branch-name> will create a copy of this PR against a different branch.
  • /lintroll will automatically fix linting errors, amending commits as needed.
  • retest this please will rerun the tests and rebuild the demo site.
  • 📖 Review standards
  • 🗒️ Review template (brief or verbose)

➡️ Online demo of this PR 🔗

@civibot civibot Bot added the 6.18 label Aug 7, 2026
@larssandergreen

Copy link
Copy Markdown
Contributor

There are two security advisories, one is fixed in 5.8.2 and the other in 5.8.4, so I think we need 5.8.4.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants