Skip to content

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Nov 6, 2024

Bumps the composer group with 3 updates in the / directory: guzzlehttp/psr7, twig/twig and aws/aws-sdk-php.

Updates guzzlehttp/psr7 from 1.8.5 to 1.9.1

Release notes

Sourced from guzzlehttp/psr7's releases.

1.9.1

See change log for changes.

1.9.0

See change log for changes.

Changelog

Sourced from guzzlehttp/psr7's changelog.

1.9.1 - 2023-04-17

Fixed

  • Fixed header validation issue

1.9.0 - 2022-06-20

Added

  • Added UriComparator::isCrossOrigin method
Commits

Updates twig/twig from 2.15.1 to 3.11.2

Changelog

Sourced from twig/twig's changelog.

3.11.2 (2024-11-06)

  • [BC BREAK] Fix a security issue in the sandbox mode allowing an attacker to call attributes on Array-like objects They are now checked via the property policy
  • Fix a security issue in the sandbox mode allowing an attacker to be able to call toString() under some circumstances on an object even if the __toString() method is not allowed by the security policy

3.11.1 (2024-09-10)

  • Fix a security issue when an included sandboxed template has been loaded before without the sandbox context

3.11.0 (2024-08-08)

  • Add Twig\Cache\ChainCache and Twig\Cache\ReadOnlyFilesystemCache
  • Add the possibility to deprecate attributes and nodes on Node
  • Add the possibility to add a package and a version to the deprecated tag
  • Add the possibility to add a package for filter/function/test deprecations
  • Mark ConstantExpression as being @final
  • Add the find filter
  • Fix optimizer mode validation in OptimizerNodeVisitor
  • Add the possibility to yield from a generator in PrintNode
  • Add the shuffle filter
  • Add the singular and plural filters in StringExtension
  • Deprecate the second argument of Twig\Node\Expression\CallExpression::compileArguments()
  • Deprecate Twig\ExpressionParser\parseHashExpression() in favor of Twig\ExpressionParser::parseMappingExpression()
  • Deprecate Twig\ExpressionParser\parseArrayExpression() in favor of Twig\ExpressionParser::parseSequenceExpression()
  • Add sequence and mapping tests
  • Deprecate Twig\Node\Expression\NameExpression::isSimple() and Twig\Node\Expression\NameExpression::isSpecial()

3.10.3 (2024-05-16)

  • Fix missing ; in generated code

3.10.2 (2024-05-14)

  • Fix support for the deprecated escaper signature

3.10.1 (2024-05-12)

  • Fix BC break on escaper extension
  • Fix constant return type

3.10.0 (2024-05-11)

  • Make CoreExtension::formatDate, CoreExtension::convertDate, and CoreExtension::formatNumber part of the public API
  • Add needs_charset option for filters and functions

... (truncated)

Commits
  • 5b580ec Fix code
  • 94612e7 Prepare the 3.11.2 release
  • 8b52782 Update CHANGELOG
  • ec39a9d Sandbox ArrayAccess and do sandbox checks before isset() checks
  • cafc608 Fix sandbox handling for __toString()
  • ff063af Prepare the 3.11.1 release
  • 41103dc Fix a security issue when an included sandboxed template has been loaded befo...
  • e80fb8e Prepare the 3.11.0 release
  • fe32121 Update CHANGELOG
  • 0d524d3 feature #4182 Add the possibility to deprecate attributes and nodes on Node (...
  • Additional commits viewable in compare view

Updates aws/aws-sdk-php from 3.227.0 to 3.325.3

Release notes

Sourced from aws/aws-sdk-php's releases.

Version 3.325.3

  • Aws\GuardDuty - GuardDuty RDS Protection expands support for Amazon Aurora PostgreSQL Limitless Databases.
  • Aws\S3Control - Fix ListStorageLensConfigurations and ListStorageLensGroups deserialization for Smithy SDKs.
  • Aws\LakeFormation - API changes for new named tag expressions feature.
  • Aws\CodeBuild - AWS CodeBuild now adds additional compute types for reserved capacity fleet.
  • Aws\VerifiedPermissions - Adding BatchGetPolicy API which supports the retrieval of multiple policies across multiple policy stores within a single request.
  • Aws\QApps - Introduces category apis in AmazonQApps. Web experience users use Categories to tag and filter library items.

Version 3.325.2

  • Aws\DocDBElastic - Amazon DocumentDB Elastic Clusters adds support for pending maintenance actions feature with APIs GetPendingMaintenanceAction, ListPendingMaintenanceActions and ApplyPendingMaintenanceAction
  • Aws\BedrockAgent - Amazon Bedrock Knowledge Bases now supports using application inference profiles to increase throughput and improve resilience.
  • Aws\CloudWatchLogs - This release introduces an improvement in PutLogEvents
  • Aws\TaxSettings - Add support for supplemental tax registrations via these new APIs: PutSupplementalTaxRegistration, ListSupplementalTaxRegistrations, and DeleteSupplementalTaxRegistration.

Version 3.325.1

  • Aws\PrometheusService - Added support for UpdateScraper API, to enable updating collector configuration in-place
  • Aws\SageMaker - SageMaker HyperPod adds scale-down at instance level via BatchDeleteClusterNodes API and group level via UpdateCluster API. SageMaker Training exposes secondary job status in TrainingJobSummary from ListTrainingJobs API. SageMaker now supports G6, G6e, P5e instances for HyperPod and Training.
  • Aws\SESv2 - This release enables customers to provide the email template content in the SESv2 SendEmail and SendBulkEmail APIs instead of the name or the ARN of a stored email template.
  • Aws\AutoScaling - Adds bake time for Auto Scaling group Instance Refresh
  • Aws\ElasticLoadBalancingv2 - Add UDP support for AWS PrivateLink and dual-stack Network Load Balancers
  • Aws\Batch - Add podNamespace to EksAttemptDetail and containerID to EksAttemptContainerDetail.
  • Aws\Glue - Add schedule support for AWS Glue column statistics

Version 3.325.0

  • Aws\Keyspaces - Adds support for interacting with user-defined types (UDTs) through the following new operations: Create-Type, Delete-Type, List-Types, Get-Type.
  • Aws\GeoPlaces - Release of Amazon Location Places API. Places enables you to quickly search, display, and filter places, businesses, and locations based on proximity, category, and name
  • Aws\Route53 - This release adds support for TLSA, SSHFP, SVCB, and HTTPS record types.
  • Aws\EC2 - This release adds two new capabilities to VPC Security Groups: Security Group VPC Associations and Shared Security Groups.
  • Aws\ECS - This release supports service deployments and service revisions which provide a comprehensive view of your Amazon ECS service history.
  • Aws\DataSync - AWS DataSync now supports Enhanced mode tasks. This task mode supports transfer of virtually unlimited numbers of objects with enhanced metrics, more detailed logs, and higher performance than Basic mode. This mode currently supports transfers between Amazon S3 locations.
  • Aws\Redshift - This release launches S3 event integrations to create and manage integrations from an Amazon S3 source into an Amazon Redshift database.
  • Aws\GeoMaps - Release of Amazon Location Maps API. Maps enables you to build digital maps that showcase your locations, visualize your data, and unlock insights to drive your business
  • Aws\AppSync - This release adds support for AppSync Event APIs.
  • Aws\OpenSearchService - This release introduces the new OpenSearch user interface (Dashboards), a new web-based application that can be associated with multiple data sources across OpenSearch managed clusters, serverless collections, and Amazon S3, so that users can gain a comprehensive insights in an unified interface.
  • Aws\WorkMail - This release adds support for Multi-Factor Authentication (MFA) and Personal Access Tokens through integration with AWS IAM Identity Center.
  • Aws\Connect - Updated the public documentation for the UserIdentityInfo object to accurately reflect the character limits for the FirstName and LastName fields, which were previously listed as 1-100 characters.
  • Aws\OpenSearchServerless - Neo Integration via IAM Identity Center (IdC)
  • Aws\GeoRoutes - Release of Amazon Location Routes API. Routes enables you to plan efficient routes and streamline deliveries by leveraging real-time traffic, vehicle restrictions, and turn-by-turn directions.
  • Aws\SageMaker - Added support for Model Registry Staging construct. Users can define series of stages that models can progress through for model workflows and lifecycle. This simplifies tracking and managing models as they transition through development, testing, and production stages.
  • Aws\RedshiftServerless - Adds and updates API members for the Redshift Serverless AI-driven scaling and optimization feature using the price-performance target setting.
  • Aws\NetworkFirewall - AWS Network Firewall now supports configuring TCP idle timeout

Version 3.324.13

  • Aws\BedrockRuntime - Update Application Inference Profile
  • Aws\CleanRooms - This release adds the option for customers to configure analytics engine when creating a collaboration, and introduces the new SPARK analytics engine type in addition to maintaining the legacy CLEAN_ROOMS_SQL engine type.
  • Aws\RedshiftDataAPIService - Adding a new API GetStatementResultV2 that supports CSV formatted results from ExecuteStatement and BatchExecuteStatement calls.
  • Aws\SageMaker - Adding notebook-al2-v3 as allowed value to SageMaker NotebookInstance PlatformIdentifier attribute
  • Aws\IoTFleetWise - Updated BatchCreateVehicle and BatchUpdateVehicle APIs: LimitExceededException has been added and the maximum number of vehicles in a batch has been set to 10 explicitly
  • Aws\Bedrock - Update Application Inference Profile
  • Aws\CloudWatchLogs - Added support for new optional baseline parameter in the UpdateAnomaly API. For UpdateAnomaly requests with baseline set to True, The anomaly behavior is then treated as baseline behavior. However, more severe occurrences of this behavior will still be reported as anomalies.

... (truncated)

Commits

Updates guzzlehttp/guzzle from 7.4.4 to 7.8.2

Release notes

Sourced from guzzlehttp/guzzle's releases.

Release 7.8.2

Added

  • Support for PHP 8.4

Release 7.8.1

Changed

  • Updated links in docs to their canonical versions
  • Replaced call_user_func* with native calls

Release 7.8.0

See change log for changes.

Release 7.7.1

See change log for changes.

Release 7.7.0

See change log for changes.

Release 7.6.1

See change log for changes.

Release 7.6.0

See change log for changes.

Release 7.5.3

See change log for changes.

Release 7.5.2

See change log for changes.

Release 7.5.1

See change log for changes.

Release 7.5.0

See change log for changes.

Release 7.4.5

See change log for changes.

Changelog

Sourced from guzzlehttp/guzzle's changelog.

7.8.2 - 2024-07-18

Added

  • Support for PHP 8.4

7.8.1 - 2023-12-03

Changed

  • Updated links in docs to their canonical versions
  • Replaced call_user_func* with native calls

7.8.0 - 2023-08-27

Added

  • Support for PHP 8.3
  • Added automatic closing of handles on CurlFactory object destruction

7.7.1 - 2023-08-27

Changed

  • Remove the need for AllowDynamicProperties in CurlMultiHandler

7.7.0 - 2023-05-21

Added

  • Support guzzlehttp/promises v2

7.6.1 - 2023-05-15

Fixed

  • Fix SetCookie::fromString MaxAge deprecation warning and skip invalid MaxAge values

7.6.0 - 2023-05-14

Added

  • Support for setting the minimum TLS version in a unified way
  • Apply on request the version set in options parameters

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the composer group with 3 updates in the / directory: [guzzlehttp/psr7](https://github.com/guzzle/psr7), [twig/twig](https://github.com/twigphp/Twig) and [aws/aws-sdk-php](https://github.com/aws/aws-sdk-php).


Updates `guzzlehttp/psr7` from 1.8.5 to 1.9.1
- [Release notes](https://github.com/guzzle/psr7/releases)
- [Changelog](https://github.com/guzzle/psr7/blob/1.9.1/CHANGELOG.md)
- [Commits](guzzle/psr7@1.8.5...1.9.1)

Updates `twig/twig` from 2.15.1 to 3.11.2
- [Changelog](https://github.com/twigphp/Twig/blob/v3.11.2/CHANGELOG)
- [Commits](twigphp/Twig@v2.15.1...v3.11.2)

Updates `aws/aws-sdk-php` from 3.227.0 to 3.325.3
- [Release notes](https://github.com/aws/aws-sdk-php/releases)
- [Commits](aws/aws-sdk-php@3.227.0...3.325.3)

Updates `guzzlehttp/guzzle` from 7.4.4 to 7.8.2
- [Release notes](https://github.com/guzzle/guzzle/releases)
- [Changelog](https://github.com/guzzle/guzzle/blob/7.9/CHANGELOG.md)
- [Commits](guzzle/guzzle@7.4.4...7.8.2)

---
updated-dependencies:
- dependency-name: guzzlehttp/psr7
  dependency-type: direct:production
  dependency-group: composer
- dependency-name: twig/twig
  dependency-type: direct:production
  dependency-group: composer
- dependency-name: aws/aws-sdk-php
  dependency-type: indirect
  dependency-group: composer
- dependency-name: guzzlehttp/guzzle
  dependency-type: indirect
  dependency-group: composer
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Nov 6, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant