PrestaOne Bridge Security Policy

Security owner: "ELEVIO", MB

The PHP 7.4 compatibility line uses firebase/php-jwt 6.x. Advisory
PKSA-y2cr-5h3j-g3ys is accepted only for the Google Firebase RS256 verification path until
PHP 7.4 support ends or an upstream-compatible fixed release is available.

Compensating controls are mandatory and tested: only RS256 is accepted, certificates must contain
an RSA public key of at least 2048 bits, issuer and audience are exact, and token time claims are
validated locally. No other algorithm or caller may use this dependency.

Risk review expires on 2027-01-31. A release must fail if these controls or the explicit Composer
advisory record are removed without replacing the dependency.
