<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🚨 Security advisory: Composer 2.9.8 and 2.2.28 (LTS) fix a vulnerability that lead Composer to leak GitHub Actions GITHUB_TOKENs and GitHub App installation tokens into job logs]]></title><description><![CDATA[<p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f6a8.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--rotating_light" style="height:23px;width:auto;vertical-align:middle" title="🚨" alt="🚨" /> Security advisory: Composer 2.9.8 and 2.2.28 (LTS) fix a vulnerability that lead Composer to leak GitHub Actions GITHUB_TOKENs and GitHub App installation tokens into job logs.<br />GitHub's new ghs_&lt;id&gt;_&lt;JWT&gt; token format fails Composer's validation regex; the rejected token is printed into the error message and secret masking does not reliably catch it.<br />Update now or disable affected Actions workflows.<br /><a href="https://blog.packagist.com/composer-2-9-8-and-2-2-28-fix-github-actions-token-disclosure-in-error-messages/" rel="nofollow noopener"><span>https://</span><span>blog.packagist.com/composer-2-</span><span>9-8-and-2-2-28-fix-github-actions-token-disclosure-in-error-messages/</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/3ea71b08-a4a5-4181-bd2b-0ecbb08c5944/security-advisory-composer-2.9.8-and-2.2.28-lts-fix-a-vulnerability-that-lead-composer-to-leak-github-actions-github_tokens-and-github-app-installation-tokens-into-job-logs</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 04:00:19 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/3ea71b08-a4a5-4181-bd2b-0ecbb08c5944.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 13 May 2026 10:43:32 GMT</pubDate><ttl>60</ttl></channel></rss>