Skip to content

Security updates for phpunit/phpunit and symfony/process#7

Merged
glaubinix merged 1 commit intomainfrom
resolve-security-notices
Feb 23, 2026
Merged

Security updates for phpunit/phpunit and symfony/process#7
glaubinix merged 1 commit intomainfrom
resolve-security-notices

Conversation

@stevenrombauts
Copy link
Contributor

@stevenrombauts stevenrombauts commented Feb 23, 2026

This PR upgrades phpunit/phpunit and symfony/process to versions that do not have a known security issue. It also updates various other packages to get rid of deprecations, both in the output and when running the tests.

@stevenrombauts stevenrombauts self-assigned this Feb 23, 2026
@private-packagist
Copy link

composer.lock

Click to show 75 changes in this composer.lock file

Package changes

Package Operation From To About
private-packagist/oidc-identities add - 1.0.1 view code - License: MIT License
psr/log add - 3.0.2 view code - License: MIT License
clue/stream-filter upgrade v1.6.0 v1.7.0 diff
guzzlehttp/guzzle upgrade 7.4.5 7.10.0 diff
guzzlehttp/promises upgrade 1.5.1 2.3.0 diff
guzzlehttp/psr7 upgrade 2.5.0 2.8.0 diff
league/csv upgrade 9.8.0 9.28.0 diff
php-http/client-common upgrade 2.5.0 2.7.3 diff
php-http/discovery upgrade 1.14.3 1.20.0 diff
php-http/guzzle7-adapter upgrade 1.0.0 1.1.0 diff
php-http/httplug upgrade 2.3.0 2.4.1 diff
php-http/message upgrade 1.13.0 1.16.2 diff
php-http/message-factory upgrade v1.0.2 1.1.0 diff
php-http/promise upgrade 1.1.0 1.3.1 diff
private-packagist/api-client upgrade 1.29.0 1.40.1 diff
psr/http-client upgrade 1.0.1 1.0.3 diff
psr/http-factory upgrade 1.0.1 1.1.0 diff
psr/http-message upgrade 1.1 2.0 diff
symfony/console upgrade v6.4.15 v6.4.32 diff
symfony/deprecation-contracts upgrade v3.5.0 v3.6.0 diff
symfony/options-resolver upgrade v6.4.13 v8.0.0 diff
symfony/polyfill-ctype upgrade v1.31.0 v1.33.0 diff
symfony/polyfill-intl-grapheme upgrade v1.31.0 v1.33.0 diff
symfony/polyfill-intl-normalizer upgrade v1.31.0 v1.33.0 diff
symfony/polyfill-mbstring upgrade v1.31.0 v1.33.0 diff
symfony/polyfill-php80 upgrade v1.31.0 v1.33.0 diff
symfony/service-contracts upgrade v3.5.0 v3.6.1 diff
symfony/string upgrade v6.4.15 v6.4.30 diff

Dev Package changes

Package Operation From To About
clue/ndjson-react add - v1.3.0 view code - License: MIT License
evenement/evenement add - v3.0.2 view code - License: MIT License
fidry/cpu-core-counter add - 1.3.0 view code - License: MIT License
react/cache add - v1.2.0 view code - License: MIT License
react/child-process add - v0.6.7 view code - License: MIT License
react/dns add - v1.14.0 view code - License: MIT License
react/event-loop add - v1.6.0 view code - License: MIT License
react/promise add - v3.3.0 view code - License: MIT License
react/socket add - v1.17.0 view code - License: MIT License
react/stream add - v1.4.0 view code - License: MIT License
symfony/polyfill-php84 add - v1.33.0 view code - License: MIT License
composer/pcre upgrade 3.0.0 3.1.4 diff
composer/semver upgrade 3.3.2 3.4.4 diff
composer/xdebug-handler upgrade 3.0.3 3.0.5 diff
doctrine/instantiator upgrade 1.4.1 2.1.0 diff
friendsofphp/php-cs-fixer upgrade v3.10.0 v3.94.2 diff
myclabs/deep-copy upgrade 1.11.0 1.13.4 diff
nikic/php-parser upgrade v4.14.0 v5.7.0 diff
phar-io/manifest upgrade 2.0.3 2.0.4 diff
php-http/mock-client upgrade 1.5.0 1.6.1 diff
phpunit/php-code-coverage upgrade 9.2.16 9.2.32 diff
phpunit/phpunit upgrade 9.5.23 ⚠️ 9.6.34 ✅ diff
sebastian/cli-parser upgrade 1.0.1 1.0.2 diff
sebastian/comparator upgrade 4.0.6 4.0.10 diff
sebastian/complexity upgrade 2.0.2 2.0.3 diff
sebastian/diff upgrade 4.0.4 4.0.6 diff
sebastian/environment upgrade 5.1.4 5.1.5 diff
sebastian/exporter upgrade 4.0.4 4.0.8 diff
sebastian/global-state upgrade 5.0.5 5.0.8 diff
sebastian/lines-of-code upgrade 1.0.3 1.0.4 diff
sebastian/recursion-context upgrade 4.0.4 4.0.6 diff
sebastian/resource-operations upgrade 3.0.3 3.0.4 diff
sebastian/type upgrade 3.0.0 3.2.1 diff
symfony/event-dispatcher upgrade v6.4.13 v8.0.4 diff
symfony/event-dispatcher-contracts upgrade v3.5.0 v3.6.0 diff
symfony/filesystem upgrade v6.4.13 v8.0.1 diff
symfony/finder upgrade v6.4.13 v8.0.5 diff
symfony/polyfill-php81 upgrade v1.31.0 v1.33.0 diff
symfony/process upgrade v6.4.15 ⚠️ v8.0.5 ✅ diff
symfony/stopwatch upgrade v6.4.13 v8.0.0 diff
theseer/tokenizer upgrade 1.2.1 1.3.1 diff
doctrine/annotations remove 1.13.3 - -
doctrine/lexer remove 1.2.3 - -
psr/cache remove 3.0.0 - -
psr/log remove 3.0.0 - -

Important Metadata Changes

Package Version Metadata From To
friendsofphp/php-cs-fixer v3.94.2 dist url https://api.github.com/repos/FriendsOfPHP/PHP-CS-Fixer/zipball/76d7da666e66d83a1dc27a9d1c625c80cc4ac1fe https://api.github.com/repos/PHP-CS-Fixer/PHP-CS-Fixer/zipball/7787ceff91365ba7d623ec410b8f429cdebb4f63
friendsofphp/php-cs-fixer v3.94.2 source url https://github.com/FriendsOfPHP/PHP-CS-Fixer.git https://github.com/PHP-CS-Fixer/PHP-CS-Fixer.git

Settings · Docs · Powered by Private Packagist

@stevenrombauts stevenrombauts marked this pull request as ready for review February 23, 2026 12:24
@stevenrombauts stevenrombauts requested a review from a team February 23, 2026 12:25
@glaubinix glaubinix merged commit 040fc2b into main Feb 23, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants