On 30th September 2024 I reported that Magento’s sample nginx config exposed the exact Magento version through the /setup route, and opened a fix the same day. It merged into Magento core nine months later. A fix that only lives in one project’s patches/ folder helps one project, so where maintainers will take it, it goes upstream.
As of 9th October 2026 that is 29 merged pull requests across 16 third-party open source repositories, from May 2020 onwards. Client and employer repositories are not counted.
What has been merged into Magento core?
Three pull requests in magento/magento2: one closes a version leak in the default web server config, two speed up setup:di:compile.
#39228, merged 26th June 2025. Closes my own issue #39227. The web setup wizard answered on /setup with the default nginx config, which leaked the Magento version. The fix denies it by default in nginx.conf.sample, with the same change for Apache in setup/.htaccess:
location ~* ^/setup($|/) {
root $MAGE_ROOT;
location ~ ^/setup/index.php {
deny all;
# If you want to enable the web based setup functionality, add your
# ip address to the allow list below or comment out the deny all above.
# allow 127.0.0.1;
#40615 and #40614, merged 8th and 23rd June 2026. The first caches ReflectionClass instantiations in the DI compiler, roughly 60,000 redundant ones per compile on a mid-size store. The second memoises interception config scope reads. Both pull requests carry before and after timings from three real projects:
| Project | Area config phase (#40615) | Interception phase (#40614) |
|---|---|---|
| ~470 modules | 1.9s to 1.2s | 1.8s to 0.6s |
| ~390 modules | 3.8s to 2.1s | 4.1s to 1.0s |
| ~390 modules | 3.9s to 2.1s | 4.6s to 1.7s |
The trade-off is memory: about 16 MB and 10 MB more peak PHP memory respectively, which a compile run with a 2 GB limit absorbs easily.
Why did a Magento security fix land in Mage-OS?
Because Magento did not take it. I proposed the fix to Magento first, and that pull request was removed as security related and never merged.
mage-os/mageos-magento2#174, merged 8th November 2025, closes a customer file upload validation bypass: a file could be uploaded through an attribute whose input type is not a file. It was being used in the Session Reaper (CVE-2025-54236) chain to reach remote code execution.
What else has been merged?
Twelve of the other 25 are in Warden, the Docker development environment, across wardenenv/warden, wardenenv/images and wardenenv/docs.
- Warden: PHP SPX profiling support (warden#820, with a setup guide), and the
ondemandPHP-FPM process manager (images#126, 1st October 2026). - Deployer: Magento artifact deploys (#3601) and PHP-FPM reloads.
- Vendor modules: fixes in Adyen’s Magento module, Sansec Shield and magento/inventory.
What has not landed?
Five of my pull requests to magento/magento2 are still open, among them critical CSS through layout files and USPS REST token cache key scoping. Twelve were closed unmerged. Several were earlier duplicates of the di:compile work, and three were env.php module override changes closed on 20th September 2026.