Skip to content

birke/rememberme is abandoned #308

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
Rotzbua opened this issue Mar 18, 2025 · 0 comments
Open

birke/rememberme is abandoned #308

Rotzbua opened this issue Mar 18, 2025 · 0 comments

Comments

@Rotzbua
Copy link
Contributor

Rotzbua commented Mar 18, 2025

Problem

Used release 1.0.5 is 8 years old 2017-02-12 12:43 UTC

https://packagist.org/packages/birke/rememberme#1.0.5

This package is abandoned and no longer maintained. The author suggests using the mober/rememberme package instead.

Cause composer audit output due peer dependency:

Found 1 security vulnerability advisory affecting 1 package:
+-------------------+----------------------------------------------------------------------------------+
| Package           | paragonie/random_compat                                                          |
| Severity          | low                                                                              |
| CVE               | NO CVE                                                                           |
| Title             | Uses insecure CSPRNG (openssl_random_pseudo_bytes())                             |
| URL               | https://github.com/paragonie/random_compat/issues/96                             |
| Affected versions | <2.0                                                                             |
| Reported at       | 2016-03-16T00:00:00+00:00                                                        |
| Advisory ID       | PKSA-cncr-q695-v65g                                                              |
+-------------------+----------------------------------------------------------------------------------+
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant