Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
PRODUCT FAMILYAPPLICATIONMANUAL

Composer Project

Composer

Composer is tracked by BlackTree as an end-user software application. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Lifecycle status

No support or retirement date is shown unless BlackTree can link it to a registered publisher source. A missing date means that a boundary is not publicly stated, has not yet been extracted, or still needs source routing. It does not mean the product is supported indefinitely.

Product overview

Composer is tracked by BlackTree as an end-user software application. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • User-facing application functions
  • Local or managed application deployment
  • Vendor-maintained feature and security updates

Typical use

Used by individuals or organizations for the product-specific tasks described by its publisher.

Deployment

Installed on supported endpoints or supplied through a vendor-managed service, depending on the edition.

Lifecycle records

No verified lifecycle boundary is currently published for this product family.

Official sources

MANUAL

Composer official lifecycle source

Registered for manual verification because unattended extraction is unavailable or inappropriate.

Open publisher source

Package vulnerability advisories

Composer has a command injection via malicious perforce reference

Fixed: 2.9.6, 2.2.27

Composer has a command injection via malicious perforce repository

Fixed: 2.9.6, 2.2.27

Composer has multiple command injections via malicious git/hg branch names

Fixed: 2.2.24, 2.7.7

Composer code execution and possible privilege escalation via compromised InstalledVersions.php or installed.php

Fixed: 2.2.23, 2.7.0

Composer has a command injection via malicious git branch name

Fixed: 2.2.24, 2.7.7

Composer arbitrary command execution via a malicious package's Perforce source URL

Fixed: 2.10.3, 2.2.30

Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)

Fixed: 2.10.2, 2.2.29

Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files

Fixed: 2.10.2, 2.2.29