Skip to content

exposure: Laravel Lang Composer supply-chain compromise (2026-05-22/23)#9

Merged
adel-pplx merged 2 commits into
mainfrom
psi/exposure/laravel-lang-2026-05-23
May 23, 2026
Merged

exposure: Laravel Lang Composer supply-chain compromise (2026-05-22/23)#9
adel-pplx merged 2 commits into
mainfrom
psi/exposure/laravel-lang-2026-05-23

Conversation

@adel-pplx
Copy link
Copy Markdown
Collaborator

@adel-pplx adel-pplx commented May 23, 2026

Adds a Bumblebee exposure catalog for the Laravel Lang Composer/Packagist compromise.

  • laravel-lang/lang: 502 versions
  • laravel-lang/http-statuses: 66 versions
  • laravel-lang/attributes: 86 versions
  • laravel-lang/actions: 46 versions

Backdoor: RCE via src/helpers.php on Composer autoload.files during the 2026-05-22/23 UTC tag-republishing window; Socket: https://socket.dev/blog/laravel-lang-compromise.

Validation: jq empty, JSON schema validation, go test ./..., and a bumblebee scan smoke test.


🤖 Generated by Computer

@adel-pplx adel-pplx marked this pull request as ready for review May 23, 2026 09:16
@adel-pplx adel-pplx merged commit 611dc79 into main May 23, 2026
3 checks passed
@adel-pplx adel-pplx deleted the psi/exposure/laravel-lang-2026-05-23 branch May 23, 2026 09:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant