Skip to content

build(deps): bump the theme-composer group in /wp-content/themes/wp-starter with 6 updates - #268

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/composer/wp-content/themes/wp-starter/theme-composer-d77419bc1d
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/composer/wp-content/themes/wp-starter/theme-composer-d77419bc1d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 18, 2026

Copy link
Copy Markdown

Bumps the theme-composer group in /wp-content/themes/wp-starter with 6 updates:

Package From To
timber/timber 2.4.0 2.5.1
wpackagist-plugin/accessibility-checker 1.42.1 1.49.0
wpackagist-plugin/safe-svg 2.4.0 2.5.0
wpackagist-plugin/seo-by-rank-math 1.0.260 1.0.278
wp-coding-standards/wpcs 3.2.0 3.4.1
wpackagist-plugin/create-block-theme 2.9.0 2.10.1

Updates timber/timber from 2.4.0 to 2.5.1

Release notes

Sourced from timber/timber's releases.

v2.5.1

2.5.1 (2026-05-29)

Bug Fixes

Miscellaneous Chores

  • Update .gitattributes to exclude phpstan.neon.dist and typos.toml from dist (3a226cf)

v2.5.0

2.5.0 (2026-05-29)

Features

Bug Fixes

  • Bump twig/twig to ^3.27 for sandbox security fixes (112d369)
  • Fix indentation in core.php (b8e0e77)
  • Switch version property to constant and mark old property as deprecated (971a38b)

Code Refactoring

  • admin: Extract MINIMUM_WP_VERSION constant and simplify notice (79c4813)

Tests

  • cache: Drop vestigial sleep(1) in twig cache tests (bbe859a)
  • cache: Replace sleep() with manual transient expiry (03d6a6e)
  • helper: Use usleep(50ms) instead of sleep(1) in testTimers (95949ff)
  • main: Trim testGetPostsInLoop fixture to loop length (bc023c1)
  • pagination: Reduce fixture sizes via WithOption posts_per_page=2 (1d49c5b)
  • pagination: Reduce testPaginationEndLimits fixture cost (34631bc)
  • post-query: Cut fixture sizes via method-level WithOption (0894595)
  • Stop custom-upload-dir tests leaking into random-order runs (c62f138)

Continuous Integration

  • Harden GitHub Actions workflows (43d0b89)
  • Update composer PHP versions action to v2.1.0 (dadab84)

... (truncated)

Changelog

Sourced from timber/timber's changelog.

2.5.1 (2026-05-29)

Bug Fixes

Miscellaneous Chores

  • update .gitattributes to exclude phpstan.neon.dist and typos.toml from dist (3a226cf)

2.5.0 (2026-05-29)

Features

Bug Fixes

  • bump twig/twig to ^3.27 for sandbox security fixes (112d369)
  • correct indentation in core.php (b8e0e77)
  • switch version property to constant and mark old property as deprecated (971a38b)

Code Refactoring

  • admin: extract MINIMUM_WP_VERSION constant and simplify notice (79c4813)

Tests

  • cache: drop vestigial sleep(1) in twig cache tests (bbe859a)
  • cache: replace sleep() with manual transient expiry (03d6a6e)
  • helper: use usleep(50ms) instead of sleep(1) in testTimers (95949ff)
  • main: trim testGetPostsInLoop fixture to loop length (bc023c1)
  • pagination: reduce fixture sizes via WithOption posts_per_page=2 (1d49c5b)
  • pagination: reduce testPaginationEndLimits fixture cost (34631bc)
  • post-query: cut fixture sizes via method-level WithOption (0894595)
  • stop custom-upload-dir tests leaking into random-order runs (c62f138)

Continuous Integration

  • harden GitHub Actions workflows (43d0b89)
  • update composer PHP versions action to v2.1.0 (dadab84)

... (truncated)

Commits
  • b91d24b chore(2.x): release 2.5.1 (#3263)
  • 5a26a21 fix: Fix bug with WP version notice in admin (#3264)
  • 3a226cf chore: update .gitattributes to exclude phpstan.neon.dist and typos.toml from...
  • 537e59c chore(2.x): release 2.5.0 (#3251)
  • a8aa17e feat: Add post excerpt content filter (#3247)
  • b24cf4c chore: update method references to use class name directly (#3262)
  • b8e0e77 fix: correct indentation in core.php
  • fe9e33e chore: update deprecation notice version
  • 112d369 fix: bump twig/twig to ^3.27 for sandbox security fixes
  • 767d0b4 chore: remove phpcs.xml configuration file
  • Additional commits viewable in compare view

Updates wpackagist-plugin/accessibility-checker from 1.42.1 to 1.49.0

Updates wpackagist-plugin/safe-svg from 2.4.0 to 2.5.0

Updates wpackagist-plugin/seo-by-rank-math from 1.0.260 to 1.0.278

Updates wp-coding-standards/wpcs from 3.2.0 to 3.4.1

Release notes

Sourced from wp-coding-standards/wpcs's releases.

3.4.1 - 2026-07-27

This is a security release and all users are advised to update their WordPressCS install as soon as possible.

Changed

  • The minimum required PHPCSUtils version to 1.2.3 (was 1.2.2). #2770
  • The minimum required PHPCSExtra version to 1.5.1 (was 1.5.0). #2770
  • Various housekeeping, including documentation improvements.

Fixed

  • SECURITY FIX: Running the WordPress.WP.EnqueuedResourceParameters sniff over untrusted PHP code, for example, in a CI pipeline that lints pull requests, or on a developer machine reviewing third-party code, could lead to arbitrary command execution on the scanning host. #2771 This affects users of the WordPress and WordPress-Extra rulesets. The WordPress-Core ruleset and the WordPress-Docs ruleset are not affected. For more details, see the security advisory Thanks to @​FORIMOC for responsibly disclosing the vulnerability.

3.4.0

We're happy to welcome @​rodrigoprimo as co-maintainer of WordPressCS as of this release.

Added

Changed

  • The minimum required PHP_CodeSniffer version to 3.13.5 (was 3.13.4). #2761
  • The minimum required PHPCSUtils version to 1.2.2 (was 1.1.0). #2761
  • The default value for minimum_wp_version, as used by a number of sniffs detecting usage of deprecated WP features, has been updated to 6.7. #2757
  • WordPress.NamingConventions.PrefixAllGlobals has been updated to recognize pluggable functions introduced in WP up to WP 7.0.0. #2747
  • WordPress.WP.ClassNameCase has been updated to recognize classes introduced in WP up to WP 7.0.0. #2747
  • WordPress.WP.DeprecatedFunctions now detects functions deprecated in WordPress up to WP 7.0.0. #2747
  • The ConstantsHelper::is_use_of_global_constant() method will no longer flag a constant alias created via an import use statement as it were the use of a global constant. #2579
  • The ConstantsHelper::is_in_function_call() method will now act fully case-agnostic for the function names being checked. #2706 Previously, the $valid_functions parameter would need to be passed with the function names as keys in lowercase.
  • WordPress.PHP.NoSilencedErrors: error silencing is no longer accepted for the parse_url() function. #2701
  • Improved the wording of the error message for WordPress.Arrays.ArrayDeclarationSpacing.AssociativeArrayFound. #2688
  • Improved the wording of the error message for WordPress.PHP.RestrictedPHPFunctions. #2702
  • Various housekeeping, including documentation and test improvements. Includes a contribution by @​dd32.

Deprecated

  • WordPress.Arrays.ArrayDeclarationSpacing: the allow_single_item_single_line_associative_arrays property has been deprecated in favor of the new allow_single_item_single_line_explicit_key_arrays property. #2696 This is a name change only. The functionality of these properties is the same.

Fixed

  • WordPress.DB.PreparedSQL and WordPress.DB.PreparedSQLPlaceholders: false positive for static method calls to a non-global class named wpdb. #2753
  • WordPress.Security.EscapeOutput: false positive for get_search_query() when the $escaped parameter was passed as fully qualified or non-lowercase true. #2618
  • WordPress.Security.EscapeOutput: false negative for _deprecated_file() calls when the basename( __FILE__ ) pattern used non-standard casing for either basename() and/or __FILE__. #2729
  • WordPress.WP.AlternativeFunctions: false negative when class functions/constants/properties use the same name as select global WP constants/functions. #2617
  • WordPress.WP.AlternativeFunctions: false positive for fully qualified references to the global PHP stream constants \STDIN, \STDOUT, and \STDERR. #2617
  • WordPress.WP.CronInterval: false positive when the callback function reference used a different case than the function declaration, even though they are in the same file. #2730

3.3.0

... (truncated)

Changelog

Sourced from wp-coding-standards/wpcs's changelog.

[3.4.1] - 2026-07-27

This is a security release and all users are advised to update their WordPressCS install as soon as possible.

Changed

  • The minimum required PHPCSUtils version to 1.2.3 (was 1.2.2). #2770
  • The minimum required PHPCSExtra version to 1.5.1 (was 1.5.0). #2770
  • Various housekeeping, including documentation improvements.

Fixed

  • SECURITY FIX: Running the WordPress.WP.EnqueuedResourceParameters sniff over untrusted PHP code, for example, in a CI pipeline that lints pull requests, or on a developer machine reviewing third-party code, could lead to arbitrary command execution on the scanning host. #2771 This affects users of the WordPress and WordPress-Extra rulesets. The WordPress-Core ruleset and the WordPress-Docs ruleset are not affected. For more details, see the security advisory. Thanks to [@​FORIMOC] for responsibly disclosing the vulnerability.

#2770: WordPress/WordPress-Coding-Standards#2770 #2771: WordPress/WordPress-Coding-Standards#2771

[3.4.0] - 2026-07-16

We're happy to welcome [@​rodrigoprimo] as co-maintainer of WordPressCS as of this release.

Added

Changed

  • The minimum required PHP_CodeSniffer version to 3.13.5 (was 3.13.4). #2761
  • The minimum required PHPCSUtils version to 1.2.2 (was 1.1.0). #2761
  • The default value for minimum_wp_version, as used by a number of sniffs detecting usage of deprecated WP features, has been updated to 6.7. #2757
  • WordPress.NamingConventions.PrefixAllGlobals has been updated to recognize pluggable functions introduced in WP up to WP 7.0.0. #2747
  • WordPress.WP.ClassNameCase has been updated to recognize classes introduced in WP up to WP 7.0.0. #2747
  • WordPress.WP.DeprecatedFunctions now detects functions deprecated in WordPress up to WP 7.0.0. #2747
  • The ConstantsHelper::is_use_of_global_constant() method will no longer flag a constant alias created via an import use statement as it were the use of a global constant. #2579
  • The ConstantsHelper::is_in_function_call() method will now act fully case-agnostic for the function names being checked. #2706 Previously, the $valid_functions parameter would need to be passed with the function names as keys in lowercase.
  • WordPress.PHP.NoSilencedErrors: error silencing is no longer accepted for the parse_url() function. #2701
  • Improved the wording of the error message for WordPress.Arrays.ArrayDeclarationSpacing.AssociativeArrayFound. #2688
  • Improved the wording of the error message for WordPress.PHP.RestrictedPHPFunctions. #2702
  • Various housekeeping, including documentation and test improvements. Includes a contribution by [@​dd32].

Deprecated

  • WordPress.Arrays.ArrayDeclarationSpacing: the allow_single_item_single_line_associative_arrays property has been deprecated in favor of the new allow_single_item_single_line_explicit_key_arrays property. #2696 This is a name change only. The functionality of these properties is the same.

Fixed

... (truncated)

Commits
  • ec2ff94 Merge pull request #2773 from WordPress/develop
  • b558639 Merge pull request #2772 from WordPress/feature/changelog-3.4.1
  • 1696dc8 Changelog for the release of WordPressCS 3.4.1
  • a29048d Merge pull request #2771 from WordPress/security/enqueuedresourceparams-fix-i...
  • 7262444 WP/EnqueuedResourceParameters: remove eval() from is_falsy()
  • 54719c0 Merge pull request #2770 from WordPress/feature/composer-update-versions
  • 267d84e Composer: update minimum version PHPCSUtils + PHPCSExtra
  • e8064a6 Add SECURITY.md file (#2766)
  • 7ac8973 Merge pull request #2768 from WordPress/dependabot/github_actions/action-runn...
  • 9466b4b GH Actions: Bump actions/checkout in the action-runners group
  • Additional commits viewable in compare view

Updates wpackagist-plugin/create-block-theme from 2.9.0 to 2.10.1

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the theme-composer group in /wp-content/themes/wp-starter with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [timber/timber](https://github.com/timber/timber) | `2.4.0` | `2.5.1` |
| wpackagist-plugin/accessibility-checker | `1.42.1` | `1.49.0` |
| wpackagist-plugin/safe-svg | `2.4.0` | `2.5.0` |
| wpackagist-plugin/seo-by-rank-math | `1.0.260` | `1.0.278` |
| [wp-coding-standards/wpcs](https://github.com/WordPress/WordPress-Coding-Standards) | `3.2.0` | `3.4.1` |
| wpackagist-plugin/create-block-theme | `2.9.0` | `2.10.1` |


Updates `timber/timber` from 2.4.0 to 2.5.1
- [Release notes](https://github.com/timber/timber/releases)
- [Changelog](https://github.com/timber/timber/blob/2.x/CHANGELOG.md)
- [Commits](timber/timber@v2.4.0...v2.5.1)

Updates `wpackagist-plugin/accessibility-checker` from 1.42.1 to 1.49.0

Updates `wpackagist-plugin/safe-svg` from 2.4.0 to 2.5.0

Updates `wpackagist-plugin/seo-by-rank-math` from 1.0.260 to 1.0.278

Updates `wp-coding-standards/wpcs` from 3.2.0 to 3.4.1
- [Release notes](https://github.com/WordPress/WordPress-Coding-Standards/releases)
- [Changelog](https://github.com/WordPress/WordPress-Coding-Standards/blob/develop/CHANGELOG.md)
- [Commits](WordPress/WordPress-Coding-Standards@3.2.0...3.4.1)

Updates `wpackagist-plugin/create-block-theme` from 2.9.0 to 2.10.1

---
updated-dependencies:
- dependency-name: timber/timber
  dependency-version: 2.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: theme-composer
- dependency-name: wpackagist-plugin/accessibility-checker
  dependency-version: 1.49.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: theme-composer
- dependency-name: wpackagist-plugin/safe-svg
  dependency-version: 2.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: theme-composer
- dependency-name: wpackagist-plugin/seo-by-rank-math
  dependency-version: 1.0.278
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: theme-composer
- dependency-name: wp-coding-standards/wpcs
  dependency-version: 3.4.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: theme-composer
- dependency-name: wpackagist-plugin/create-block-theme
  dependency-version: 2.10.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: theme-composer
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update php code labels Sep 18, 2026
bd-viget added a commit that referenced this pull request Sep 18, 2026
Closes #267, #269, #272, #274. #268, #270, #271 and #273 were already
covered by the dependency refresh on this branch.

actions/checkout v4 -> v7, setup-node v4 -> v7, cache v4 -> v6.
symfony/console ^7.4 -> ^8.1 at the root. cssnano 7 -> 9.

idleberg/wordpress-vite-assets is removed rather than taken to 2.0.
Nothing references it - the theme reads dist/.vite/manifest.json through
its own inc/class-vite.php, so the package and its idleberg/vite-manifest
dependency have been dead weight.

Two things this turned up that are not fixed here:

cssnano only runs when NODE_ENV=prod, which nothing sets - not the
workflows, not ddev, not vite.config.js. So it is configured but never
invoked.

Setting NODE_ENV=prod fails the build outright. postcss-prefix-selector
emits ":is(.block-editor-block-list__block)div" for the video player
scoped styles, which is not valid CSS, and lightningcss rejects it on the
minify pass. It only warns on the default build. Confirmed this fails the
same way on cssnano 7, so it predates the bump.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01627bWvzFL2gjxJLTxYCjoZ
@bd-viget

Copy link
Copy Markdown
Contributor

Superseded by #266, which carries this along with the rest of the dependency refresh for v1.1.0.

@bd-viget bd-viget closed this Sep 20, 2026
@bd-viget
bd-viget deleted the dependabot/composer/wp-content/themes/wp-starter/theme-composer-d77419bc1d branch September 20, 2026 15:18
@dependabot @github

dependabot Bot commented on behalf of github Sep 20, 2026

Copy link
Copy Markdown
Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant