2017 © Pedro Peláez
 

contao-bundle contao-security-checker-bundle

This check works by comparing the composer.lock against an open vulnerability database. A clean check does not mean there are absolutely no security problems whatsoever.

image

oneup/contao-security-checker-bundle

This check works by comparing the composer.lock against an open vulnerability database. A clean check does not mean there are absolutely no security problems whatsoever.

  • Tuesday, July 10, 2018
  • by bytehead
  • Repository
  • 3 Watchers
  • 5 Stars
  • 2,554 Installations
  • PHP
  • 0 Dependents
  • 0 Suggesters
  • 1 Forks
  • 3 Open issues
  • 14 Versions
  • 8 % Grown

The README.md

Don't use this piece of software anymore as the underlying web service will stop working at the end of January 2021. Instead, use the Open-Source CLI tool that does the same locally, or use the [Symfony CLI][2] tool., (*1)


Contao Security Checker Bundle

This extension provides a way to automatically or manually check your installed vendor extensions and the Contao core against the open vulnerability database at FriendsOfPHP/security-advisories., (*2)

Author Software License Total Downloads, (*3)

--, (*4)

Features included: * Perform the check regularly. * Get an E-Mail if the audit failed in any way. (Or always get an email if a check was performed. Your choice.) * Start the check manually. * Suppress notifications for manually started checks., (*5)

--, (*6)

Screenshot, (*7)

Note: A clean check does not imply that there are no security problems present, it just means that the test against the underlying database reveiled nothing., (*8)

Documentation

Installation

Perform the following steps to install and use the basic functionality of the OneupUploaderBundle:, (*9)

  • Download the ContaoSecurityCheckerBundle using Composer
  • Enable the bundle
  • Configure the bundle

Step 1: Download the ContaoSecurityCheckerBundle

Add OneupUploaderBundle to your composer.json using the following construct:, (*10)

$ composer require oneup/contao-security-checker-bundle "^0.4"

Composer will install the bundle to your project's vendor/oneup/contao-security-checker-bundle directory., (*11)

Step 2: Enable the bundle

Enable the bundle in the kernel:, (*12)

``` php <?php // app/AppKernel.php, (*13)

public function registerBundles() { $bundles = [ // ... new Oneup\Bundle\ContaoSecurityCheckerBundle\OneupContaoSecurityCheckerBundle(), ]; }, (*14)


Enable the bundles api route: ``` yml # app/config/routing.yml oneup_contao_security_checker: prefix: /security-advisories resource: "@OneupContaoSecurityCheckerBundle/Resources/config/routing.yml" # ...

Step 3: Configure the bundle

Add this little configuration to your app/config/config.yml and adjust it to your needs., (*15)

# app/config/config.yml

# OneupContaoSecurityChecker configuration
oneup_contao_security_checker:
    enable_notifications: true
    suppress_manual_audits: false
    notify_only_failed_audits: true
    notification_email: your@email.here
    cron_cycle: daily
    enable_cron: true
    enable_api: false
    api_key: ~

Upgrade Notes

  • Version 0.4.0 Added an API endpoint, per default disabled (see #7)
  • Version 0.3.0 Added Contao Manager Plugin
  • Version 0.2.0 Renamed Bundle (update/check your app/config/config.yml)
  • Version 0.1.0 Initial release

License

This bundle is under the MIT license. See the complete license in the bundle., (*16)

Reporting an issue or a feature request

Issues and feature requests are tracked in the Github issue tracker., (*17)

When reporting a bug, it may be a good idea to reproduce it in a basic project built using the Contao Standard Edition to allow developers of the bundle to reproduce the issue by simply cloning it and following some steps., (*18)

The Versions

10/07 2018

dev-master

9999999-dev http://1up.io

This check works by comparing the composer.lock against an open vulnerability database. A clean check does not mean there are absolutely no security problems whatsoever.

  Sources   Download

MIT

The Requires

 

The Development Requires

extensions security bundle check modules contao

10/07 2018

0.4.3

0.4.3.0 http://1up.io

This check works by comparing the composer.lock against an open vulnerability database. A clean check does not mean there are absolutely no security problems whatsoever.

  Sources   Download

MIT

The Requires

 

The Development Requires

extensions security bundle check modules contao

10/07 2018

0.4.2

0.4.2.0 http://1up.io

This check works by comparing the composer.lock against an open vulnerability database. A clean check does not mean there are absolutely no security problems whatsoever.

  Sources   Download

MIT

The Requires

 

The Development Requires

extensions security bundle check modules contao

10/07 2018

0.4.1

0.4.1.0 http://1up.io

This check works by comparing the composer.lock against an open vulnerability database. A clean check does not mean there are absolutely no security problems whatsoever.

  Sources   Download

MIT

The Requires

 

The Development Requires

extensions security bundle check modules contao

30/01 2018

0.4.0

0.4.0.0 http://1up.io

This check works by comparing the composer.lock against an open vulnerability database. A clean check does not mean there are absolutely no security problems whatsoever.

  Sources   Download

MIT

The Requires

 

The Development Requires

extensions security bundle check modules contao

15/02 2017

0.3.1

0.3.1.0 http://1up.io

This check works by comparing the composer.lock against an open vulnerability database. A clean check does not mean there are absolutely no security problems whatsoever.

  Sources   Download

MIT

The Requires

 

The Development Requires

extensions security bundle check modules contao

15/02 2017

0.3.0

0.3.0.0 http://1up.io

This check works by comparing the composer.lock against an open vulnerability database. A clean check does not mean there are absolutely no security problems whatsoever.

  Sources   Download

MIT

The Requires

 

The Development Requires

extensions security bundle check modules contao

15/02 2017

0.2.0

0.2.0.0 http://1up.io

This check works by comparing the composer.lock against an open vulnerability database. A clean check does not mean there are absolutely no security problems whatsoever.

  Sources   Download

MIT

The Requires

 

The Development Requires

extensions security bundle check modules contao

15/02 2017

0.1.5

0.1.5.0 http://1up.io

This check works by comparing the composer.lock against an open vulnerability database. A clean check does not mean there are absolutely no security problems whatsoever.

  Sources   Download

MIT

The Requires

 

The Development Requires

extensions security bundle check modules contao

05/11 2016

0.1.4

0.1.4.0 http://1up.io

This check works by comparing the composer.lock against an open vulnerability database. A clean check does not mean there are absolutely no security problems whatsoever.

  Sources   Download

MIT

The Requires

 

The Development Requires

extensions security bundle check modules contao

23/05 2016

0.1.3

0.1.3.0 http://1up.io

This check works by comparing the composer.lock against an open vulnerability database. A clean check does not mean there are absolutely no security problems whatsoever.

  Sources   Download

MIT

The Requires

 

The Development Requires

extensions security bundle check modules contao

23/05 2016

0.1.2

0.1.2.0 http://1up.io

This check works by comparing the composer.lock against an open vulnerability database. A clean check does not mean there are absolutely no security problems whatsoever.

  Sources   Download

MIT

The Requires

 

The Development Requires

extensions security bundle check modules contao

20/05 2016

0.1.1

0.1.1.0 http://1up.io

This check works by comparing the composer.lock against an open vulnerability database. A clean check does not mean there are absolutely no security problems whatsoever.

  Sources   Download

MIT

The Requires

 

The Development Requires

extensions security bundle check modules contao

20/05 2016

0.1.0

0.1.0.0 http://1up.io

This check works by comparing the composer.lock against an open vulnerability database. A clean check does not mean there are absolutely no security problems whatsoever.

  Sources   Download

MIT

The Requires

 

The Development Requires

extensions security bundle check modules contao