Composer security advisories

In Tools wird wieder einmal security advisories (mcp/sdk) angezeigt.
Man kann aber nicht aktualisieren!

Your requirements could not be resolved to an installable set of packages.

Problem 1

  • Root composer.json requires shopware/core 6.7.13.0 → satisfiable by shopware/core[v6.7.13.0].
  • shopware/core v6.7.13.0 requires mcp/sdk ^0.6.0 → found mcp/sdk[v0.6.0] but these were not loaded, because they are affected by security advisories („PKSA-p9gd-j6gr-6f9t“). Go to Packagist.org to find advisory details. To ignore the advisories, add their IDs to the „policy.advisories.ignore-id“ config or add the package to „policy.advisories.ignore“. To turn the feature off entirely, you can set „policy.advisories.block“ to false.
    Problem 2
  • Root composer.json requires shopware/storefront 6.7.13.0 → satisfiable by shopware/storefront[v6.7.13.0].
  • shopware/storefront v6.7.13.0 requires mcp/sdk ^0.6.0 → found mcp/sdk[v0.6.0] but these were not loaded, because they are affected by security advisories („PKSA-p9gd-j6gr-6f9t“). Go to Packagist.org to find advisory details. To ignore the advisories, add their IDs to the „policy.advisories.ignore-id“ config or add the package to „policy.advisories.ignore“. To turn the feature off entirely, you can set „policy.advisories.block“ to false.
    Problem 3
  • Root composer.json requires swag/paypal 10.8.0 → satisfiable by swag/paypal[10.8.0].
  • shopware/core v6.7.13.0 requires mcp/sdk ^0.6.0 → found mcp/sdk[v0.6.0] but these were not loaded, because they are affected by security advisories („PKSA-p9gd-j6gr-6f9t“). Go to Packagist.org to find advisory details. To ignore the advisories, add their IDs to the „policy.advisories.ignore-id“ config or add the package to „policy.advisories.ignore“. To turn the feature off entirely, you can set „policy.advisories.block“ to false.
  • swag/paypal 10.8.0 requires shopware/core ~6.7.0@dev → satisfiable by shopware/core[v6.7.13.0].

Steffen Winde

Das Security Advisory wurde heute Morgen, um 2026-08-14 06:19:00, gemeldet.

Shopware benötigt Zeit, um die Kompatibilität mit der neuen Version einer Drittanbieter-Software sicher zu stellen. In den nächsten Tagen wird sicherlich ein Update von Shopware bzw. des Plugins bereitgestellt, falls dieses Paket durch Shopware oder ein Shopware-Plugin geladen wird.

Der Hinweis, wie betroffenen Pakete per composer aktualisiert werden können, wird in Frosh Tools immer sofort angezeigt, unabhängig davon ob es mit Shopware kompatibel ist oder nicht.

Bei uns sieht das in den Frosh Tools auch übel aus. Aber bald aktualisieren wir Shopware und dann ist hoffentlich dieses und natürlich die anderen behoben.