test(deps): update dependency composer to v2.9.4#20
Open
mend-developer-platform-dev[bot] wants to merge 1 commit intomainfrom
Open
test(deps): update dependency composer to v2.9.4#20mend-developer-platform-dev[bot] wants to merge 1 commit intomainfrom
mend-developer-platform-dev[bot] wants to merge 1 commit intomainfrom
Conversation
e48204b to
398bf9c
Compare
398bf9c to
fb49c44
Compare
fb49c44 to
8b73569
Compare
8b73569 to
d480bcc
Compare
d480bcc to
c61acda
Compare
c61acda to
612bb46
Compare
612bb46 to
3c88302
Compare
3c88302 to
1c6d582
Compare
1c6d582 to
2125b57
Compare
2125b57 to
1f06a7c
Compare
1f06a7c to
57402ab
Compare
57402ab to
2972db1
Compare
2972db1 to
8b5c399
Compare
8b5c399 to
407cfde
Compare
407cfde to
e7f0b66
Compare
453e3d3 to
81b6854
Compare
81b6854 to
ef0bc94
Compare
ef0bc94 to
3066292
Compare
3066292 to
9a6c188
Compare
9a6c188 to
8bbf6e1
Compare
8bbf6e1 to
ef790e0
Compare
ef790e0 to
4da71ac
Compare
4da71ac to
a362647
Compare
a362647 to
3f1a21a
Compare
3f1a21a to
349e9e4
Compare
349e9e4 to
9a87187
Compare
9a87187 to
e8ae640
Compare
e8ae640 to
f6a1b81
Compare
f6a1b81 to
60e99bf
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.5.8→2.9.4Release Notes
composer/composer (composer)
v2.9.4Compare Source
HTTP/3causing issues with proxies (#12699)showcommand regression with long descriptions containing unicode characters (#12704)git rev-listusages to support older pre-2.33 git versions (#12705)=in them on Windows (#12726)v2.9.3Compare Source
COMPOSER_NO_SECURITY_BLOCKINGenv var not being respected forupdatesdone via theinstallcommand, and added--no-security-blockingflag toinstallas well (#12677)update --lock/update mirrorsnot working when locked packages contain vulnerabilities (#12645)client-certificateauthentication implementation (#12667)php-extschema not being validated in ValidatingArrayLoader (#12694)--bump-after-updateis used and the lock file is disabled (#12660)v2.9.2Compare Source
--no-security-blockingflag to disable/configure security blocking (#12617)audit > ignoreto act only on audits or only on security blocking (#12618, #12612)configcommand not being able to set the new audit settings (#12609)v2.9.1Compare Source
v2.9.0Compare Source
v2.8.12Compare Source
config --globalpath resolution issue (#12537)v2.8.11Compare Source
bumpcommand handling of 0.x versions (#12468)auditcommand failing hard if any advisory constraint was invalid (#12507)v2.8.10Compare Source
v2.8.9Compare Source
bump-after-updatetriggering after anupdate --lock, which makes no sense (#12371)ZipArchive(#12409)composer <script-name>(#12383)v2.8.8Compare Source
v2.8.7Compare Source
COMPOSER_MAX_PARALLEL_PROCESSenv var to control max amount of parallel processes Composer will start (#12356)diagnosecommand output--with ...constraints to make them apply to packages replaced a package with a different name (#12353)v2.8.6Compare Source
COMPOSER_WITH_DEPENDENCIESandCOMPOSER_WITH_ALL_DEPENDENCIESenv vars to enable the--with[-all]-dependenciesflags (#12289)COMPOSER_SKIP_SCRIPTSenv var to tell Composer to skip certain script handlers by script names (comma separated) (#12290)v2.8.5Compare Source
Added build provenance attestation so you can also now download and verify phar files from GitHub releases:
fundingvalues causing parse errors in packages (#12247)reload()is used (#12269)vendor/composer/autoload*.php(#12263)v2.8.4Compare Source
auditcommand not being meaningful (now 1 for vulnerabilities and 2 for abandoned, 3 for both) (#12203)bump-after-updatefailing when using inline constraints (#12223)create-projectcommand to now disable symlinking when used with a path repo as argument (#12222)validate --no-check-publishto hide publish errors entirely as they are irrelevant (#12196)auditcommand returning a failing code when composer audit fails as this should not trigger build failures, but running audit as standard part of your build is probably a terrible idea anyway (#12196)v2.8.3Compare Source
v2.8.2Compare Source
create-projectregression in 2.8.1 when using path repos with relative paths (#12150)v2.8.1Compare Source
config --globalpath resolution issue (#12537)v2.8.0Compare Source
https_proxyenv var falling back tohttp_proxy's value. The fallback and warning have now been removed per the 2.7.3 release notes (#11938, #11915)--patch-onlyflag to theupdatecommand to restrict updates to patch versions and make an update of all deps safer (#12122)--abandonedflag to theauditcommand to configure how abandoned packages should be treated, overriding theaudit.abandonedconfig setting (#12091)--ignore-severityflag to theauditcommand to ignore one or more advisory severities (#12132)--bump-after-updateflag to theupdatecommand to run bump after the update is done (#11942)scriptsreceive additional CLI arguments and where they appear in the command, see the docs (#12086)allow-missing-requirementsconfig setting to skip the error when the lock file is not fulfilling the composer.json's dependencies (#11966)--typeflag to filter packages by type(s) in thereinstallcommand (#12114)--strict-ambiguousflag to thedump-autoloadcommand to make it return with an error code if duplicate classes are found (#12119)dump-autoloadwhen vendor files have been deleted (#12139)create-projectto avoid having to run it again and again (#12120)sort-packagesis enabled (#11348)E_STRICT(#12116)initcommand to validate the given license identifier (#12115)v2.7.9Compare Source
completioncommand (#12015)v2.7.8Compare Source
release-age,release-dateandlatest-release-datein the JSON output ofoutdated(#12053)#signs (#12042)bumpcommand not handling some~constraints correctly (#12038)relative: truesometimes not being respected in path repo symlinks (#12092)archivecommand crashing when a path cannot be realpath'd on windows (#11544)685add7)v2.7.7Compare Source
fa3b958)3c37a67)3773f77)de5f7e3)3130a74,04a63b3)configcommand to remove autoload keys (#11967)typesupport ininitcommand (#11999)safe.bareRepositoryis set tostrictin the git config (#11969)v2.7.6Compare Source
v2.7.5Compare Source
uninstallalias toremovecommand (#11951)100as code (#11954)v2.7.4Compare Source
Call to undefined method ProxyManager::needsTransitionWarning()) with projects requiring composer/composer in an pre-2.7.3 version (#11943, #11940)v2.7.3Compare Source
Call to undefined method ProxyManager::needsTransitionWarning()) with projects requiring composer/composer in an pre-2.7.3 version (#11943, #11940)v2.7.2Compare Source
composer --version(#11866)c3efff9)outdated --ignore ...still attempting to load the latest version of the ignored packages (#11863)update --lockstill incorrectly updating some metadata (#11850, #11787)v2.7.1Compare Source
diagnoseauditing of Composer dependencies failing when running from the pharv2.7.0Compare Source
audit.abandonedconfig setting tofail, set it toreportorignoreif you do not want this, or set it viaCOMPOSER_AUDIT_ABANDONEDenv var (#11643)update/require/removecommands to perform partial update with --with-dependencies while changing only what is absolutely necessary in transitive dependencies (#11665)outdated/showcommands to allow sorting by and displaying the release date (most outdated first) (#11762)--selfcombined with--installedor--lockedinshowcommand, to add the root package to the package list being output (#11785)auditcommand output (#11702)scripts-aliasestop level key in composer.json to define aliases for custom scripts you defined (#11666)COMPOSER_IPRESOLVEenv var to force IPv4 or IPv6, set it to4or6(#11791)outdated's --ignore arg (#11831)bumpcommand bumping*to>=current version(#11694)validatecommand (#11829)installwhen running in very verbose (-vv) mode (#11763)diagnosecommand (#11761)diagnosecommand output (#11688)show --direct <package>with an indirect/transitive dependency (#11728)COMPOSER_FUND=0env var to hide calls for funding (#11779)bumpcommand not bumping packages required with avprefix (#11764)update --locknot keeping the dist reference/url/checksum pinned (#11787)requirecommand crashing at the end if no lock file is present (#11814)requirecommand (#11716)requirecommand (#11747)v2.6.6Compare Source
v2.6.5Compare Source
cb363b0)v2.6.4Compare Source
show -a <packagename>(#11659)v2.6.3Compare Source
ignore,report(current default) orfail(future default in 2.7) to make the audit command report abandoned packages as a security problem (#11639)filesautoload rules are detected (#11109)archivecommand not producing the correct output if the temp dir is a symlink (#11636)v2.6.2Compare Source
$_SERVER['SCRIPT_NAME']to detect them, they are now more transparent (#11562)" which caused a regression (#11617)install --auditruns and not implicit audits withrequire,create-projectorupdatecommands (#11616)create-projectinfinite post-install loop in some circumstances (#11613)v2.6.1Compare Source
v2.6.0Compare Source
rmalias to theremovecommand (#11367)--dry-runtodump-autoloadcommand to allow running --strict-psr checks without modifying the filesystem (#11608)bumping patch level in~1.2.3constraints (#11590)requireif the package name is not found but similar ones exist (#11284)~in repository paths for vcs and artifact repositories (#11453)composer(#11526)why/why-notcommand output (#11308)securitykey to thesupportkey of composer.json to set the URL to the vulnerability disclosure policy (#11271)installexit code to be non-zero (5) if a requested security audit failed (#11362)Fixed binary proxies causing scripts inspecting(Reverted in 2.6.2)$_SERVER['SCRIPT_NAME']to detect them, they are now more transparent (#11562)Fixed executability of non-php binaries which are not marked executable (#11557)(Reverted in 2.6.1)mtimemodification of the vendor dir to only happen when packages are modified, and not require lock file modification to happen (#11593)create-projectusing the wrong composer.json file if one was set via theCOMPOSERenv var (#11493)Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.