No results found.

Featured Open source

Open Source Contributions

Merged upstream fixes to Magento 2 core, Mage-OS and Warden: a setup route hardening, two setup:di:compile speed-ups and a Session Reaper upload bypass fix.

Source on GitHub ↗Setup route write-upSession Reaper write-up

Merged upstream PRs
29
Merged into Magento core
3
Merged into Warden
12
Repositories
16

On 30th September 2024 I reported that Magento’s sample nginx config exposed the exact Magento version through the /setup route, and opened a fix the same day. It merged into Magento core nine months later. A fix that only lives in one project’s patches/ folder helps one project, so where maintainers will take it, it goes upstream.

As of 9th October 2026 that is 29 merged pull requests across 16 third-party open source repositories, from May 2020 onwards. Client and employer repositories are not counted.

What has been merged into Magento core?

Three pull requests in magento/magento2: one closes a version leak in the default web server config, two speed up setup:di:compile.

#39228, merged 26th June 2025. Closes my own issue #39227. The web setup wizard answered on /setup with the default nginx config, which leaked the Magento version. The fix denies it by default in nginx.conf.sample, with the same change for Apache in setup/.htaccess:

location ~* ^/setup($|/) {
    root $MAGE_ROOT;
    location ~ ^/setup/index.php {
        deny all;
        # If you want to enable the web based setup functionality, add your
        # ip address to the allow list below or comment out the deny all above.
        # allow 127.0.0.1;

#40615 and #40614, merged 8th and 23rd June 2026. The first caches ReflectionClass instantiations in the DI compiler, roughly 60,000 redundant ones per compile on a mid-size store. The second memoises interception config scope reads. Both pull requests carry before and after timings from three real projects:

ProjectArea config phase (#40615)Interception phase (#40614)
~470 modules1.9s to 1.2s1.8s to 0.6s
~390 modules3.8s to 2.1s4.1s to 1.0s
~390 modules3.9s to 2.1s4.6s to 1.7s

The trade-off is memory: about 16 MB and 10 MB more peak PHP memory respectively, which a compile run with a 2 GB limit absorbs easily.

Why did a Magento security fix land in Mage-OS?

Because Magento did not take it. I proposed the fix to Magento first, and that pull request was removed as security related and never merged.

mage-os/mageos-magento2#174, merged 8th November 2025, closes a customer file upload validation bypass: a file could be uploaded through an attribute whose input type is not a file. It was being used in the Session Reaper (CVE-2025-54236) chain to reach remote code execution.

What else has been merged?

Twelve of the other 25 are in Warden, the Docker development environment, across wardenenv/warden, wardenenv/images and wardenenv/docs.

  • Warden: PHP SPX profiling support (warden#820, with a setup guide), and the ondemand PHP-FPM process manager (images#126, 1st October 2026).
  • Deployer: Magento artifact deploys (#3601) and PHP-FPM reloads.
  • Vendor modules: fixes in Adyen’s Magento module, Sansec Shield and magento/inventory.

What has not landed?

Five of my pull requests to magento/magento2 are still open, among them critical CSS through layout files and USPS REST token cache key scoping. Twelve were closed unmerged. Several were earlier duplicates of the di:compile work, and three were env.php module override changes closed on 20th September 2026.