Bump the composer group across 1 directory with 6 updates - #15
Merged
Merged
Conversation
Bumps the composer group with 6 updates in the / directory: | Package | From | To | | --- | --- | --- | | [symfony/runtime](https://github.com/symfony/runtime) | `5.4.46` | `5.4.52` | | [symfony/yaml](https://github.com/symfony/yaml) | `5.4.23` | `5.4.52` | | [twig/twig](https://github.com/twigphp/Twig) | `3.19.0` | `3.27.0` | | [symfony/cache](https://github.com/symfony/cache) | `5.4.25` | `6.4.43` | | [symfony/process](https://github.com/symfony/process) | `6.4.15` | `6.4.41` | | [symfony/routing](https://github.com/symfony/routing) | `5.4.25` | `5.4.53` | Updates `symfony/runtime` from 5.4.46 to 5.4.52 - [Release notes](https://github.com/symfony/runtime/releases) - [Changelog](https://github.com/symfony/runtime/blob/8.2/CHANGELOG.md) - [Commits](symfony/runtime@v5.4.46...v5.4.52) Updates `symfony/yaml` from 5.4.23 to 5.4.52 - [Release notes](https://github.com/symfony/yaml/releases) - [Changelog](https://github.com/symfony/yaml/blob/8.2/CHANGELOG.md) - [Commits](symfony/yaml@v5.4.23...v5.4.52) Updates `twig/twig` from 3.19.0 to 3.27.0 - [Release notes](https://github.com/twigphp/Twig/releases) - [Changelog](https://github.com/twigphp/Twig/blob/3.x/CHANGELOG) - [Commits](twigphp/Twig@v3.19.0...v3.27.0) Updates `symfony/cache` from 5.4.25 to 6.4.43 - [Release notes](https://github.com/symfony/cache/releases) - [Changelog](https://github.com/symfony/cache/blob/8.2/CHANGELOG.md) - [Commits](symfony/cache@v5.4.25...v6.4.43) Updates `symfony/process` from 6.4.15 to 6.4.41 - [Release notes](https://github.com/symfony/process/releases) - [Changelog](https://github.com/symfony/process/blob/8.2/CHANGELOG.md) - [Commits](symfony/process@v6.4.15...v6.4.41) Updates `symfony/routing` from 5.4.25 to 5.4.53 - [Release notes](https://github.com/symfony/routing/releases) - [Changelog](https://github.com/symfony/routing/blob/8.2/CHANGELOG.md) - [Commits](symfony/routing@v5.4.25...v5.4.53) --- updated-dependencies: - dependency-name: symfony/runtime dependency-version: 5.4.52 dependency-type: direct:production dependency-group: composer - dependency-name: symfony/yaml dependency-version: 5.4.52 dependency-type: direct:production dependency-group: composer - dependency-name: twig/twig dependency-version: 3.27.0 dependency-type: direct:production dependency-group: composer - dependency-name: symfony/cache dependency-version: 6.4.43 dependency-type: indirect dependency-group: composer - dependency-name: symfony/process dependency-version: 6.4.41 dependency-type: indirect dependency-group: composer - dependency-name: symfony/routing dependency-version: 5.4.53 dependency-type: indirect dependency-group: composer ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the composer group with 6 updates in the / directory:
5.4.465.4.525.4.235.4.523.19.03.27.05.4.256.4.436.4.156.4.415.4.255.4.53Updates
symfony/runtimefrom 5.4.46 to 5.4.52Release notes
Sourced from symfony/runtime's releases.
Commits
b1ee708[Runtime] Fix CVE-2024-50340 patch bypass by gating argv on $_SERVER['QUERY_S...a101e88Update CHANGELOG for 5.4.50Updates
symfony/yamlfrom 5.4.23 to 5.4.52Release notes
Sourced from symfony/yaml's releases.
Commits
b0b2705[Yaml] Harden the Parser::cleanup() regexes against catastrophic backtracking5a351ff[Yaml] Bound collection-alias resolution in the parserb02ba66[Yaml] Bound recursion depth in the parsera454d47Add PR template and auto-close PR on subtree split repositories7025b96parse empty sequence elements as null62f96e1🐛 throw ParseException on invalid date81cad0cRevert "minor #54653 Auto-close PRs on subtree-splits (nicolas-grekas)"bc780e1call substr() with integer offsetsa38ba0bAuto-close PRs on subtree-splitse78db7fApply php-cs-fixer fix --rules nullable_type_declaration_for_default_null_valueUpdates
twig/twigfrom 3.19.0 to 3.27.0Release notes
Sourced from twig/twig's releases.
... (truncated)
Changelog
Sourced from twig/twig's changelog.
... (truncated)
Commits
04ae1bfPrepare the 3.27.0 release99a1038security #558 Fix sandbox filter/tag/function allow-list bypass when sandbox ...23eb6ebFix sandbox filter/tag/function allow-list bypass when sandbox state changes ...7d55aa8security #cve-2026-48805 Fix sandbox bypass in deprecated internal wrappers (...9fcf690security #552 Fix sandbox __toString policy bypass via dynamic mapping keys (...635cea4Document new support for any expression as a dynamic mapping key9ff4101Fix sandbox __toString policy bypass via dynamic mapping keysbaebc46security #535 Fix sandbox__toStringbypasses viaTraversableinjoin/`...e3f6665Fix deprecation notices in tests475fb69Guard sandbox__toStringwalker against self-referencing iterablesUpdates
symfony/cachefrom 5.4.25 to 6.4.43Release notes
Sourced from symfony/cache's releases.
... (truncated)
Changelog
Sourced from symfony/cache's changelog.
... (truncated)
Commits
8f0b5de[Cache] Add support for relay 0.4091df731[Cache] Fix "Class Relay\Relay not found" for RedisCluster/RedisArray with tc...e2ae0cf[Cache] Initialize PhpArrayAdapter before classifying keys in deleteItems()0b72083Remove obsoletereturninstruction from classes constructorsde42a53[Cache] Remove always-true method_exists() check in FilesystemCommonTrait::__...704edf2[Cache] Ensure RelayProxy compatibility with Relay extension 0.30.082698beRestore compat with DBAL v4.x654e10fUnsafe unserialize phpstan rule2a639adDrop PR warning and auto-closing on subtree splits5490a57Merge branch '5.4' into 6.4Updates
symfony/processfrom 6.4.15 to 6.4.41Release notes
Sourced from symfony/process's releases.
Commits
c8fc09b[Process] Stop leaking CGI/FastCGI request-context vars to subprocesses6c93071[Process] Ignore array env values before proc_open7b8e6e8More CS fixes5731331CS fixes - native_function_invocation & static_lambda736ed52[CS] Back config from 8.1 and apply heredoc_indentation rulec46e854[Process] Fix escaping for MSYS on Windowsc593135[Process] Adjust Process mustRun method phpdoce579464[Process] Ignore invalid env var names8541b73[Process] Fix dealing with broken stdin pipes48bad91Replace __sleep/wakeup() by __(un)serialize() for throwing and internal usagesUpdates
symfony/routingfrom 5.4.25 to 5.4.53Release notes
Sourced from symfony/routing's releases.
... (truncated)
Commits
f4ca0c5[Routing] Fix dot-segment encoding for chained "../" and "./" in generated URLs275b313[Routing] Fix regex alternation anchoring in UrlGenerator requirement validationdd08c19[Routing] Fix: lost priority when defining hosts in configuration986597bdo not use TestCase::getName() when possible7289d3cAdd PR template and auto-close PR on subtree split repositoriesb6f7178Fix typosf8dd6f8use more entropy with uniqid()c99c74bbug #57645 [Routing] Discard in-memory cache of routes when writing the file-...7bec6df[Router] Discard in-memory cache of routes when writing the file-based cache6df1dd8Revert "minor #54653 Auto-close PRs on subtree-splits (nicolas-grekas)"Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.