baserCMS の5系最新版がリリースされました!
今回 5.2.8 はバグフィックスのためのリリースです。
詳しくはリリース記事をご確認ください。
最新バージョンへのアップデートをお願いします。
■ リリース情報
5.2.8 : baserCMS 5.2.8 がリリースされました
baserCMS の5系最新版がリリースされました!
今回 5.2.8 はバグフィックスのためのリリースです。
詳しくはリリース記事をご確認ください。
最新バージョンへのアップデートをお願いします。
■ リリース情報
5.2.8 : baserCMS 5.2.8 がリリースされました
リリースのアナウンスが、めちゃくちゃですね。
インストールパッケージは、5.2.8になってますよ?
この手のケアレスミスは、結構多いように思いますので、リリース前にチェックされるような仕組みをつくられてはいかがでしょうか?
ある意味、プロダクト自体の信用度が下がってしまうのではないかと、懸念します。
ご指摘、ありがとうございます。
ご連絡・対応が遅くなり、申し訳ありません。
現在、baserCMSの最新バージョンは5.2.8が最新版となっており、このスレッド・公式サイトの表記等、共に修正しております。
開発チームと共にリリース時の仕組みを一度見直し、チェック体制などの強化につとめていければと考えております。
今後ともどうぞよろしくお願いいたします。
アップデートでエラーが出ました。
調べてみると、脆弱性が報告されているパッケージに対して、Composerが拒否している、とのことでした。
composer.json ファイルを開き、config の項目内に audit の設定を追記して、ブロック機能をオフにします。
とのやり方が提示されましたが、公式としては強制アップデートと脆弱性が解消されたバージョンを待つのとどちらが推奨されますか?
調べると行ってもエラーをGeminiに聞いた内容ですので、見当外れでしたらご指摘ください。
2026-07-18 15:35:59 error: Composer によるアップデートが失敗しました。update ログを確認してください。
2026-07-18 15:35:59 error: PHP Deprecated: PHP Startup: Use of mbstring.http_input is deprecated in Unknown on line 0
PHP Deprecated: PHP Startup: Use of mbstring.http_output is deprecated in Unknown on line 0
PHP Deprecated: PHP Startup: Use of mbstring.internal_encoding is deprecated in Unknown on line 0
./composer.json has been updated
Running composer update baserproject/baser-core --with-all-dependencies
Loading composer repositories with package information
Updating dependencies
Your requirements could not be resolved to an installable set of packages.
Problem 1
- Root composer.json requires cakephp/authentication 3.0., found cakephp/authentication[3.0.0, 3.0.1, 3.0.2, 3.0.3] but these were not loaded, because they are affected by security advisories (“PKSA-bz6x-t8z8-r26p”). Go to Packagist.org to find advisory details. To ignore the advisories, add them to the audit “ignore” config. To turn the feature off entirely, you can set “block-insecure” to false in your “audit” config.
Problem 2
- Root composer.json requires cakephp/cakephp 5.0., found cakephp/cakephp[5.0.0, …, 5.0.11] but these were not loaded, because they are affected by security advisories (“PKSA-wx2k-k564-z67n”). Go to Packagist.org to find advisory details. To ignore the advisories, add them to the audit “ignore” config. To turn the feature off entirely, you can set “block-insecure” to false in your “audit” config.
Problem 3
- Root composer.json requires baserproject/baser-core 5.2.8 → satisfiable by baserproject/baser-core[5.2.8].
- baserproject/baser-core 5.2.8 requires cakephp/cakephp 5.0.* → found cakephp/cakephp[5.0.0, …, 5.0.11] but these were not loaded, because they are affected by security advisories (“PKSA-wx2k-k564-z67n”). Go to Packagist.org to find advisory details. To ignore the advisories, add them to the audit “ignore” config. To turn the feature off entirely, you can set “block-insecure” to false in your “audit” config.
Problem 4
- cakephp/bake is locked to version 3.1.1 and an update of this package was not requested.
- cakephp/bake 3.1.1 requires cakephp/cakephp ^5.0.3 → found cakephp/cakephp[5.0.3, …, 5.3.7] but these were not loaded, because they are affected by security advisories (“PKSA-wx2k-k564-z67n”, “PKSA-y889-wbb2-rsdf”). Go to Packagist.org to find advisory details. To ignore the advisories, add them to the audit “ignore” config. To turn the feature off entirely, you can set “block-insecure” to false in your “audit” config.
Problem 5
- cakephp/debug_kit is locked to version 5.0.6 and an update of this package was not requested.
- cakephp/debug_kit 5.0.6 requires cakephp/cakephp ^5.0 → found cakephp/cakephp[5.0.0, …, 5.3.7] but these were not loaded, because they are affected by security advisories (“PKSA-wx2k-k564-z67n”, “PKSA-y889-wbb2-rsdf”). Go to Packagist.org to find advisory details. To ignore the advisories, add them to the audit “ignore” config. To turn the feature off entirely, you can set “block-insecure” to false in your “audit” config.
Problem 6
- vierge-noire/cakephp-test-suite-light is locked to version v3.0 and an update of this package was not requested.
- vierge-noire/cakephp-test-suite-light v3.0 requires cakephp/cakephp ^5.0 → found cakephp/cakephp[5.0.0, …, 5.3.7] but these were not loaded, because they are affected by security advisories (“PKSA-wx2k-k564-z67n”, “PKSA-y889-wbb2-rsdf”). Go to Packagist.org to find advisory details. To ignore the advisories, add them to the audit “ignore” config. To turn the feature off entirely, you can set “block-insecure” to false in your “audit” config.
Problem 7
- vierge-noire/cakephp-fixture-factories is locked to version v3.0.2 and an update of this package was not requested.
- vierge-noire/cakephp-fixture-factories v3.0.2 requires vierge-noire/cakephp-test-suite-light ^3.0 → satisfiable by vierge-noire/cakephp-test-suite-light[v3.0].
- vierge-noire/cakephp-test-suite-light v3.0 requires cakephp/cakephp ^5.0 → found cakephp/cakephp[5.0.0, …, 5.3.7] but these were not loaded, because they are affected by security advisories (“PKSA-wx2k-k564-z67n”, “PKSA-y889-wbb2-rsdf”). Go to Packagist.org to find advisory details. To ignore the advisories, add them to the audit “ignore” config. To turn the feature off entirely, you can set “block-insecure” to false in your “audit” config.
Installation failed, reverting ./composer.json and ./composer.lock to their original content.