aleblanc/security-checker

一个针对您的 composer.lock 的 PHP 安全检查器,使用 github/advisory-database

v7.0.3 2022-03-15 10:15 UTC

README

使用 Github 咨询数据库 进行 Symfony 安全检查。

安装/使用

composer require aleblanc/security-checker --dev
php vendor/aleblanc/security-checker/security-checker security:check

使用 Github Actions / Github CI 从 Github 咨询数据库执行安全扫描

  api_security_checker_github:
    name: Github Advisory Security checker (PHP ${{ matrix.php }})
    runs-on: ubuntu-latest
    timeout-minutes: 20
    strategy:
      matrix:
        php:
          - '8.1'
      fail-fast: false
    steps:
      - name: Checkout
        uses: actions/checkout@v3
        with:
          token: "${{ secrets.GITHUB_TOKEN }}"
      - name: Setup PHP
        uses: shivammathur/setup-php@v2
        with:
          php-version: ${{ matrix.php }}
          extensions: intl, bcmath, curl, openssl, mbstring, zip
          ini-values: memory_limit=-1
          tools: pecl, composer
          coverage: none
      - run: composer require aleblanc/security-checker --dev
      - run: php vendor/aleblanc/security-checker/security-checker security:check

https://github.com/sensiolabs/security-checker 分支而来