ugh, composer.
There are 4 composer security advisories affecting our repositories.
Server-Side Request Forgery in dompdf/dompdf
Remote file inclusion
Dompdf vulnerable to URI validation failure on SVG parsing
Key/algorithm type confusion