Skip to content

Bump guzzle, psr7, phpunit and php_codesniffer for security fixes - #568

Merged
txu-gsd merged 1 commit into
masterfrom
chore/dependency-security-bumps
Sep 15, 2026
Merged

txu-gsd merged 1 commit into
masterfrom
chore/dependency-security-bumps

Conversation

@txu-gsd

@txu-gsd txu-gsd commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

Description

Clears the assigned open Dependabot alerts:

  • guzzlehttp/guzzle 7.9.2 → 7.15.5 (HIGH + 7 medium alerts)
  • guzzlehttp/psr7 2.7.0 → 2.13.1 (4 medium alerts)
  • phpunit/phpunit 11.5.0 → 11.5.56 (HIGH, dev dep; composer.json pin widened from exact 11.5.0 to ^11.5.0)
  • squizlabs/php_codesniffer 3.11.2 → 3.13.6 (HIGH, dev dep)

Includes one test fix: psr7 >= 2.12 percent-encodes + as %2B in query values (RFC-correct; a raw + decodes as a space server-side), so the expectation in tests/Zendesk/API/UnitTests/Sell/ContactsTest.php was updated alongside its existing %20 handling.

Tests: 283 tests, 2385 assertions, OK (2 skipped, 6 pre-existing deprecations). Live suite not run — requires sandbox credentials.

Out of scope: composer audit also reports a medium for dev dep psy/psysh (CVE-2026-25129, fixed in >0.12.18) — separate follow-up.

Risks

  • Level: Low
  • Notes: Runtime behavior change is limited to psr7 query-string encoding (strictly more RFC-correct). Dev-dep bumps (phpunit, codesniffer) do not affect library consumers.

🤖 Generated with Claude Code

Update composer dependencies to clear Dependabot alerts:
- guzzlehttp/guzzle 7.9.2 -> 7.15.5
- guzzlehttp/psr7 2.7.0 -> 2.13.1
- phpunit/phpunit 11.5.0 -> 11.5.56 (widen pin to ^11.5.0)
- squizlabs/php_codesniffer 3.11.2 -> 3.13.6

psr7 >= 2.12 percent-encodes '+' in query values, so update the Sell
contacts upsert test expectation accordingly.

Co-Authored-By: Claude Code <noreply@anthropic.com>
@txu-gsd
txu-gsd merged commit 707e238 into master Sep 15, 2026
4 checks passed
@txu-gsd
txu-gsd deleted the chore/dependency-security-bumps branch September 15, 2026 01:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants