Bump the composer group across 1 directory with 7 updates #20
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the composer group with 6 updates in the / directory:
2.6.42.7.75.4.205.4.466.6.26.7.62.15.43.11.22.4.32.7.05.4.205.4.47Updates
composer/composerfrom 2.6.4 to 2.7.7Release notes
Sourced from composer/composer's releases.
... (truncated)
Changelog
Sourced from composer/composer's changelog.
... (truncated)
Commits
2919429Release 2.7.7e354a8dUpdate changelog04a63b3Add more characters for best fit encoding protectionad8985eUpdate changelog3130a74Fix windows parameter encoding to prevent abuse of unicode characters with be...5aa7b03Fix testee28354Merge pull request from GHSA-47f6-5gq3-vx9c6bd43dfMerge pull request from GHSA-v9qv-c7wm-wgmffa3b958Fix secure-http check to avoid bypass using emojisf3e877aUpdate depsUpdates
symfony/http-foundationfrom 5.4.20 to 5.4.46Release notes
Sourced from symfony/http-foundation's releases.
... (truncated)
Commits
168b77csecurity #cve-2024-50345 [HttpFoundation] Reject URIs that contain invalid ch...32310ff[HttpFoundation] Reject URIs that contain invalid characters38bd9bc[HttpFoundation] Remove invalid HTTP method from exception message3f38426Ensure compatibility with mongodb v235f7b4csession names must not be emptye641eddensure session storages are opened in tests before destroying thema5509aaAdd PR template and auto-close PR on subtree split repositoriesae0d217move setting deprecation session options into a legacy group testa414c5dbug #58181 [HttpFoundation] Update links forX-Accel-Redirectand fail prop...b61630eWork around parse_url() bugUpdates
symfony/processfrom 5.4.28 to 5.4.47Release notes
Sourced from symfony/process's releases.
Commits
5d1662fnormalize paths to avoid failures if a path is referenced by different names0190687[Process] Fix testee75984security #cve-2024-51736 [Process] Use %PATH% before %CD% to load the shell o...05c2ccc[Process] Use %PATH% before %CD% to load the shell on Windowsd94dda5[Process] Fix escaping /X arguments on Windows72baf6bfix the constant being used81e1a0cfix the path separator being usedd67303eminor #58747 [Process] fix the directory separator being used (xabbuh)5cdd400minor #58746 [Process] Improve test cleanup by unlinking in afinallyblock...7be8366fix the directory separator being usedUpdates
tecnickcom/tcpdffrom 6.6.2 to 6.7.6Changelog
Sourced from tecnickcom/tcpdf's changelog.
Commits
4cf1ab1fix control for all PHP versionsbfa7d2bForbid access to parent folder in HTML images951eabfBump version38b75a8Update GitHub actions820383aFix comment05f3a28fix: CSV-2024-22640 (#712)d4adef4Update GitHub workflows82fc97bSquash multiple fixes8115ff6Fix SPDX license ID (#591) and update min PHP version to 5.5.02fb1c01Update workflowUpdates
twig/twigfrom 2.15.4 to 3.11.2Changelog
Sourced from twig/twig's changelog.
... (truncated)
Commits
5b580ecFix code94612e7Prepare the 3.11.2 release8b52782Update CHANGELOGec39a9dSandbox ArrayAccess and do sandbox checks before isset() checkscafc608Fix sandbox handling for __toString()ff063afPrepare the 3.11.1 release41103dcFix a security issue when an included sandboxed template has been loaded befo...e80fb8ePrepare the 3.11.0 releasefe32121Update CHANGELOG0d524d3feature #4182 Add the possibility to deprecate attributes and nodes on Node (...Updates
guzzlehttp/psr7from 2.4.3 to 2.7.0Release notes
Sourced from guzzlehttp/psr7's releases.
... (truncated)
Changelog
Sourced from guzzlehttp/psr7's changelog.
... (truncated)
Commits
a70f5c9Release 2.7.0 (#615)5a1f771Add ability to encode bools and ints (#614)9aed204[2.7] AddUtils::redactUserInfo()method (#613)6de2986Release 2.6.3 (#612)731ee08Fix code style (#611)89eafc3Test on PHP 8.4 (#610)04e3e83MakeStreamWrapper::stream_stat()returnsfalseif inner stream's size is...5b4d5ac[2.6] Update deps (#609)a243f80Synced readme with actual definitions (#601)0423dd4Fixes for PHP 8.4 deprecation (#600)Updates
symfony/security-httpfrom 5.4.20 to 5.4.47Release notes
Sourced from symfony/security-http's releases.
... (truncated)
Commits
cde02b0[security-http] Check owner of persisted remember-me cookie7152f0e[Security] Store original token in token storage when implicitly exiting impe...8a4986dAdd PR template and auto-close PR on subtree split repositoriesc0f8159Work around parse_url() bugdc6de50Revert stateless check14d271e[HttpKernel][Security] Fix accessing session for stateless request7194820Revert "minor #54653 Auto-close PRs on subtree-splits (nicolas-grekas)"1957999minor #54785 Remove calls toTestCase::iniSet()and calls to deprecated met...49c9c6dRemove calls togetMockForAbstractClass()31d24e4Remove calls toTestCase::iniSet()and calls to deprecated methods of `Mock...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.