Bump the composer group across 1 directory with 9 updates#648
Open
dependabot[bot] wants to merge 1 commit intolivefrom
Open
Bump the composer group across 1 directory with 9 updates#648dependabot[bot] wants to merge 1 commit intolivefrom
dependabot[bot] wants to merge 1 commit intolivefrom
Conversation
Bumps the composer group with 7 updates in the / directory: | Package | From | To | | --- | --- | --- | | [symfony/http-foundation](https://github.com/symfony/http-foundation) | `4.4.42` | `5.4.50` | | [symfony/http-kernel](https://github.com/symfony/http-kernel) | `4.4.42` | `4.4.50` | | [symfony/process](https://github.com/symfony/process) | `4.4.41` | `5.4.46` | | [spipu/html2pdf](https://github.com/spipu/html2pdf) | `5.2.5` | `5.2.8` | | [twig/twig](https://github.com/twigphp/Twig) | `3.4.1` | `3.11.2` | | [symfony/twig-bridge](https://github.com/symfony/twig-bridge) | `4.4.42` | `4.4.51` | | [guzzlehttp/guzzle](https://github.com/guzzle/guzzle) | `7.4.4` | `7.10.0` | Updates `symfony/http-foundation` from 4.4.42 to 5.4.50 - [Release notes](https://github.com/symfony/http-foundation/releases) - [Changelog](https://github.com/symfony/http-foundation/blob/7.3/CHANGELOG.md) - [Commits](symfony/http-foundation@v4.4.42...v5.4.50) Updates `symfony/http-kernel` from 4.4.42 to 4.4.50 - [Release notes](https://github.com/symfony/http-kernel/releases) - [Changelog](https://github.com/symfony/http-kernel/blob/7.3/CHANGELOG.md) - [Commits](symfony/http-kernel@v4.4.42...v4.4.50) Updates `symfony/process` from 4.4.41 to 5.4.46 - [Release notes](https://github.com/symfony/process/releases) - [Changelog](https://github.com/symfony/process/blob/7.3/CHANGELOG.md) - [Commits](symfony/process@v4.4.41...v5.4.46) Updates `spipu/html2pdf` from 5.2.5 to 5.2.8 - [Release notes](https://github.com/spipu/html2pdf/releases) - [Changelog](https://github.com/spipu/html2pdf/blob/master/CHANGELOG.md) - [Commits](spipu/html2pdf@v5.2.5...v5.2.8) Updates `twig/twig` from 3.4.1 to 3.11.2 - [Changelog](https://github.com/twigphp/Twig/blob/3.x/CHANGELOG) - [Commits](twigphp/Twig@v3.4.1...v3.11.2) Updates `symfony/twig-bridge` from 4.4.42 to 4.4.51 - [Release notes](https://github.com/symfony/twig-bridge/releases) - [Changelog](https://github.com/symfony/twig-bridge/blob/7.3/CHANGELOG.md) - [Commits](symfony/twig-bridge@v4.4.42...v4.4.51) Updates `guzzlehttp/guzzle` from 7.4.4 to 7.10.0 - [Release notes](https://github.com/guzzle/guzzle/releases) - [Changelog](https://github.com/guzzle/guzzle/blob/7.10/CHANGELOG.md) - [Commits](guzzle/guzzle@7.4.4...7.10.0) Updates `guzzlehttp/psr7` from 2.2.1 to 2.8.0 - [Release notes](https://github.com/guzzle/psr7/releases) - [Changelog](https://github.com/guzzle/psr7/blob/2.8/CHANGELOG.md) - [Commits](guzzle/psr7@2.2.1...2.8.0) Updates `tecnickcom/tcpdf` from 6.4.4 to 6.10.0 - [Changelog](https://github.com/tecnickcom/TCPDF/blob/main/CHANGELOG.TXT) - [Commits](tecnickcom/TCPDF@6.4.4...6.10.0) --- updated-dependencies: - dependency-name: symfony/http-foundation dependency-version: 5.4.50 dependency-type: direct:production dependency-group: composer - dependency-name: symfony/http-kernel dependency-version: 4.4.50 dependency-type: direct:production dependency-group: composer - dependency-name: symfony/process dependency-version: 5.4.46 dependency-type: direct:production dependency-group: composer - dependency-name: spipu/html2pdf dependency-version: 5.2.8 dependency-type: direct:production dependency-group: composer - dependency-name: twig/twig dependency-version: 3.11.2 dependency-type: direct:production dependency-group: composer - dependency-name: symfony/twig-bridge dependency-version: 4.4.51 dependency-type: direct:production dependency-group: composer - dependency-name: guzzlehttp/guzzle dependency-version: 7.10.0 dependency-type: indirect dependency-group: composer - dependency-name: guzzlehttp/psr7 dependency-version: 2.8.0 dependency-type: indirect dependency-group: composer - dependency-name: tecnickcom/tcpdf dependency-version: 6.10.0 dependency-type: indirect dependency-group: composer ... Signed-off-by: dependabot[bot] <support@github.com>
This was referenced Nov 12, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the composer group with 7 updates in the / directory:
4.4.425.4.504.4.424.4.504.4.415.4.465.2.55.2.83.4.13.11.24.4.424.4.517.4.47.10.0Updates
symfony/http-foundationfrom 4.4.42 to 5.4.50Release notes
Sourced from symfony/http-foundation's releases.
... (truncated)
Changelog
Sourced from symfony/http-foundation's changelog.
... (truncated)
Commits
1a0706e[HttpFoundation] Fix parsing pathinfo with no leading slash3f38b8a[HttpFoundation] Fix test897e8a2[HttpFoundation] Revert risk change3280c9dWork around parse_url() bug (bis)168b77csecurity #cve-2024-50345 [HttpFoundation] Reject URIs that contain invalid ch...32310ff[HttpFoundation] Reject URIs that contain invalid characters38bd9bc[HttpFoundation] Remove invalid HTTP method from exception message3f38426Ensure compatibility with mongodb v235f7b4csession names must not be emptye641eddensure session storages are opened in tests before destroying themUpdates
symfony/http-kernelfrom 4.4.42 to 4.4.50Commits
aa6df6cUpdate VERSION for 4.4.50f7822a7security #cve-2022-24894 [HttpKernel] Remove private headers before storing r...4e36db8Update VERSION for 4.4.49bc62d95[HttpKernel] Fix message for unresovable arguments of invokable controllers0924172Bump Symfony version to 4.4.49a6d5229Update VERSION for 4.4.4826989b2bug #47857 [HttpKernel] Fix empty request stack when terminating with excepti...3f61170[HttpKernel] Fix empty request stack when terminating with exception9a34f1abug #47878 [HttpKernel] Remove EOL when using error_log() in HttpKernel Logge...abc1357[HttpKernel] Remove EOL when using error_log() in HttpKernel LoggerUpdates
symfony/processfrom 4.4.41 to 5.4.46Release notes
Sourced from symfony/process's releases.
... (truncated)
Changelog
Sourced from symfony/process's changelog.
... (truncated)
Commits
0190687[Process] Fix testee75984security #cve-2024-51736 [Process] Use %PATH% before %CD% to load the shell o...05c2ccc[Process] Use %PATH% before %CD% to load the shell on Windowsd94dda5[Process] Fix escaping /X arguments on Windows72baf6bfix the constant being used81e1a0cfix the path separator being usedd67303eminor #58747 [Process] fix the directory separator being used (xabbuh)5cdd400minor #58746 [Process] Improve test cleanup by unlinking in afinallyblock...7be8366fix the directory separator being useda56fe7bignore case of built-in cmd.exe commandsUpdates
spipu/html2pdffrom 5.2.5 to 5.2.8Release notes
Sourced from spipu/html2pdf's releases.
Changelog
Sourced from spipu/html2pdf's changelog.
Commits
6c94dcdupdate copyright dates92afd81fix XSS vulnerabilities in examples0a75590fix docb0f4777better unit tests9718fd4better unit tests17f53d1update changelog9de65b7Merge pull request #733 from jausions/phpunit-9-compatibilitye258a36add support of PHP 8.1 and PHP 8.22a26c9e- Added compatibility with PHPUnit 9.0Updates
twig/twigfrom 3.4.1 to 3.11.2Changelog
Sourced from twig/twig's changelog.
... (truncated)
Commits
5b580ecFix code94612e7Prepare the 3.11.2 release8b52782Update CHANGELOGec39a9dSandbox ArrayAccess and do sandbox checks before isset() checkscafc608Fix sandbox handling for __toString()ff063afPrepare the 3.11.1 release41103dcFix a security issue when an included sandboxed template has been loaded befo...e80fb8ePrepare the 3.11.0 releasefe32121Update CHANGELOG0d524d3feature #4182 Add the possibility to deprecate attributes and nodes on Node (...Updates
symfony/twig-bridgefrom 4.4.42 to 4.4.51Release notes
Sourced from symfony/twig-bridge's releases.
Commits
83b021c[TwigBridge] Add integration tests on twig code helpers7654da4[TwigBridge] Ensure CodeExtension's filters properly escape their inputd6b0fbfFix the notification email theme for asynchronously dispatched emails7d6e6dbsuggest to install the Twig bundle when the required component is already ins...53e4f5eFix CS5192cb6CS fixesUpdates
guzzlehttp/guzzlefrom 7.4.4 to 7.10.0Release notes
Sourced from guzzlehttp/guzzle's releases.
... (truncated)
Changelog
Sourced from guzzlehttp/guzzle's changelog.
... (truncated)
Commits
b51ac70Release 7.10.0af24c69Use thehttp_get_last_response_headersfunction (#3301)2be2ee8Remove obsolete reference capturing of$http_response_header(#3294)c6420f2Add PHP 8.5 support (#3300)7b2f29fRelease 7.9.38f68d9fImprove compatibility with bad servers for boolean cookie values (#3281)234747fRemove explicit content-length header for GET requests (#3278)d28a072testHandlesGarbageHttpServerGracefully: Split test between PHP <= 8.1 and >...41f5ce7CS fixes0811cfdSA upgradesUpdates
guzzlehttp/psr7from 2.2.1 to 2.8.0Release notes
Sourced from guzzlehttp/psr7's releases.
... (truncated)
Changelog
Sourced from guzzlehttp/psr7's changelog.
... (truncated)
Commits
21dc724Release 2.8.0d54eefeUpdate README.md893e271[2.8] Allow empty lists as header values (#625)b0b99b8[2.8] Add PHP 8.5 support (#628)c2270caRelease 2.7.10cfd892Support uppercase IPv6 addresses in URI (#620)a2474ad[2.7] Improve uploaded file error message (#621)ca06f23SA upgradesa70f5c9Release 2.7.0 (#615)5a1f771Add ability to encode bools and ints (#614)Updates
tecnickcom/tcpdffrom 6.4.4 to 6.10.0Changelog
Sourced from tecnickcom/tcpdf's changelog.
... (truncated)
Commits
ca5b6deMerge pull request #812 from tecnickcom/factur383714cBump versionf0495bdMerge branch 'embedded-files' into factur76debf1Merge pull request #811 from tecnickcom/multimerge50717ebUpdate changeloge2d94afMerge branch 'tmbenhura'8fb02a5Merge branch 'imglfix'05e42a9Merge branch 'issue-806'0f91dceMerge branch 'htmldestinations'151859eBump versionYou can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.