Skip to content

[FP]: Spatie Laravel packages are matched as Laravel framework #7602

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
sigv opened this issue Apr 15, 2025 · 0 comments
Closed

[FP]: Spatie Laravel packages are matched as Laravel framework #7602

sigv opened this issue Apr 15, 2025 · 0 comments

Comments

@sigv
Copy link
Contributor

sigv commented Apr 15, 2025

Package URl

pkg:composer/spatie/[email protected]

CPE

cpe:2.3:a:laravel:laravel:3.7.3:*:*:*:*:*:*:*

CVE

CVE-2018-15133

ODC Integration

{"label" => "CLI"}

ODC Version

12.1.1

Description

Spatie provides various Laravel (PHP) packages. Quoting their website:

[Spatie has] created more than 500 packages for Laravel and PHP. These packages have been downloaded a whopping 1.58 billion times!

Their naming scheme follows spatie/laravel-project-name format, where all project names are prefixed with laravel. This however results in a match for laravel/framework project, even if it's really spatie/laravel-sluggable or other. There is no shared versioning scheme, as the framework has latest version at v12.8.1, while the Sluggable extension by Spatie has latest version at 3.7.4.

@sigv sigv added the FP Report label Apr 15, 2025
@sigv sigv changed the title [FP]: composer.lock (, ): (8.1) [FP]: Spatie Laravel packages are matched as Laravel framework Apr 15, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants