• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

hyperwallet / php-sdk / 36933886920
98%

Build:
DEFAULT BRANCH: master
Ran 01 Oct 2026 10:18PM UTC
Jobs 1
Files 45
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

01 Oct 2026 10:14PM UTC coverage: 97.816% (+0.007%) from 97.809%
36933886920

push

github

web-flow
LI-197450 - Pin JWE alg/enc headers before decryption (#137)

* LI-197450 - Pin JWE alg/enc headers before decryption

Prevents an algorithm-confusion/downgrade attack (CWE-347): decrypt()
previously called $jwe->decrypt($privateJweKey) without validating the
untrusted alg/enc header fields, so an attacker intercepting a response
could flip alg to legacy RSA1_5 and force the private key to be used
with PKCS#1 v1.5 padding, vulnerable to Bleichenbacher-style attacks.
Mirrors the algorithm pinning already applied on the JWS side.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* Fix CI: allow installing dev dependencies with security advisories

Composer's dependency resolver now excludes package versions with
known security advisories from the pool by default. phpunit/phpunit's
^5.7/^7.0.0 branches (needed for the PHP 5.6/7.1/7.2 CI jobs) carry
advisories, so the resolver was left only with phpunit 9.6.x, which
requires PHP >=7.3 and breaks composer install on those older PHP
versions in CI.

phpunit is a require-dev-only testing dependency; consumers of this
SDK never install it (composer install --no-dev skips it), so this
has no effect on production dependency security. Verified via
`composer audit --no-dev` that the production dependency tree has
zero advisories. Add --no-blocking to the CI composer install
commands so the resolver can still pick a PHP-compatible phpunit
version for each matrix entry.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* Fix CI: use COMPOSER_NO_BLOCKING env var instead of CLI flag

The --no-blocking CLI flag doesn't exist in the older Composer version
bundled for the PHP 7.1 CI job, causing a hard
"option does not exist" error there. Composer also supports this via
the COMPOSER_NO_BLOCKING=1 environment variable, which older Composer
versions simply ignore rather than erroring on, so it works across
the entire PHP version matrix.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* Bump versi... (continued)

6 of 6 new or added lines in 1 file covered. (100.0%)

2015 of 2060 relevant lines covered (97.82%)

19.04 hits per line

Jobs
ID Job ID Ran Files Coverage
1 36933886920.1 01 Oct 2026 10:17PM UTC 45
97.82
GitHub Action Run
Source Files on build 36933886920
  • Tree
  • List 45
  • Changed 45
  • Source Changed 41
  • Coverage Changed 45
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • 699fbfb0 on github
  • Prev Build on master (#20037754762)
  • Next Build on master (#36952316329)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc