Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update dependency composer/composer to v2.7.6 #5719

Open
wants to merge 1 commit into
base: staging
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Feb 8, 2024

Mend Renovate

This PR contains the following updates:

Package Update Change
composer/composer minor 2.6.6 -> 2.7.6

Release Notes

composer/composer (composer/composer)

v2.7.6

Compare Source

  • Fixed regression when script handlers add an autoloader which uses a private callback (#​11960)

v2.7.5

Compare Source

  • Added uninstall alias to remove command (#​11951)
    • Added workaround for broken curl versions 8.7.0/8.7.1 causing transport exceptions (#​11913)
    • Fixed root usage warnings showing up within Podman containers (#​11946)
    • Fixed config command not handling objects correctly in some conditions (#​11945)
    • Fixed binary proxies not containing the correct path if the project dir is a symlink (#​11947)
    • Fixed Composer autoloader being overruled by project autoloaders when they are loaded by event handlers (scripts/plugins) (#​11955)
    • Fixed TransportException (http failures) not having a distinct exit code, should now exit with 100 as code (#​11954)

v2.7.4

Compare Source

  • Fixed regression (Call to undefined method ProxyManager::needsTransitionWarning()) with projects requiring composer/composer in an pre-2.7.3 version (#​11943, #​11940)

v2.7.3

Compare Source

  • BC Warning: Fixed https_proxy env var falling back to http_proxy's value, this is still in place but with a warning for now, and https_proxy can now be set empty to remove the fallback. Composer 2.8.0 will remove the fallback so make sure you heed the warnings (#​11915)
    • Fixed show and outdated commands to remove leading v in e.g. v1.2.3 when showing lists of packages (#​11925)
    • Fixed audit command not showing any id when no CVE is present, the advisory ID is now shown (#​11892)
    • Fixed the warning about a missing default version showing for packages with project type as those are typically not versioned and do not have cyclic dependencies (#​11885)
    • Fixed PHP 8.4 deprecation warnings
    • Fixed clear-cache command to respect the config.cache-dir setting from the local composer.json (#​11921)
    • Fixed status command not handling failed download/install promises correctly (#​11889)
    • Added support for buy_me_a_coffee in GitHub funding files (#​11902)
    • Added hg support for SSH urls (#​11878)
    • Fixed some env vars with an integer value causing a crash (#​11908)
    • Fixed context data not being output when using IOInterface as a PSR-3 logger (#​11882)

v2.7.2

Compare Source

  • Added info about the PHP version when running composer --version (#​11866)
    • Added warning when the root version cannot be detected (#​11858)
    • Fixed plugins still being enabled in a few contexts when running as root (c3efff9)
    • Fixed outdated --ignore ... still attempting to load the latest version of the ignored packages (#​11863)
    • Fixed handling of broken symlinks in the middle of an install path (#​11864)
    • Fixed update --lock still incorrectly updating some metadata (#​11850, #​11787)

v2.7.1

Compare Source

  • Added several warnings when plugins are disabled to hint at common problems people had with 2.7.0 (#​11842)
    • Fixed diagnose auditing of Composer dependencies failing when running from the phar

v2.7.0

Compare Source

  • Security: Fixed code execution and possible privilege escalation via compromised vendor dir contents (GHSA-7c6p-848j-wh5h / CVE-2024-24821)
    • Changed the default of the audit.abandoned config setting to fail, set it to report or ignore if you do not want this, or set it via COMPOSER_AUDIT_ABANDONED env var (#​11643)
    • Added --minimal-changes (-m) flag to update/require/remove commands to perform partial update with --with-dependencies while changing only what is absolutely necessary in transitive dependencies (#​11665)
    • Added --sort-by-age (-A) flag to outdated/show commands to allow sorting by and displaying the release date (most outdated first) (#​11762)
    • Added support for --self combined with --installed or --locked in show command, to add the root package to the package list being output (#​11785)
    • Added severity information to audit command output (#​11702)
    • Added scripts-aliases top level key in composer.json to define aliases for custom scripts you defined (#​11666)
    • Added IPv4 fallback on connection timeout, as well as a COMPOSER_IPRESOLVE env var to force IPv4 or IPv6, set it to 4 or 6 (#​11791)
    • Added support for wildcards in outdated's --ignore arg (#​11831)
    • Added support for bump command bumping * to >=current version (#​11694)
    • Added detection of constraints that cannot possibly match anything to validate command (#​11829)
    • Added package source information to the output of install when running in very verbose (-vv) mode (#​11763)
    • Added audit of Composer's own bundled dependencies in diagnose command (#​11761)
    • Added GitHub token expiration date to diagnose command output (#​11688)
    • Added non-zero status code to why/why-not commands (#​11796)
    • Added error when calling show --direct <package> with an indirect/transitive dependency (#​11728)
    • Added COMPOSER_FUND=0 env var to hide calls for funding (#​11779)
    • Fixed bump command not bumping packages required with a v prefix (#​11764)
    • Fixed automatic disabling of plugins when running non-interactive as root
    • Fixed update --lock not keeping the dist reference/url/checksum pinned (#​11787)
    • Fixed require command crashing at the end if no lock file is present (#​11814)
    • Fixed root aliases causing problems when auditing locked dependencies (#​11771)
    • Fixed handling of versions with 4 components in require command (#​11716)
    • Fixed compatibility issues with Symfony 7
    • Fixed composer.json remaining behind after a --dry-run of the require command (#​11747)
    • Fixed warnings being shown incorrectly under some circumstances (#​11786, #​11760, #​11803)

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot added the renovate label Feb 8, 2024
@renovate renovate bot changed the title chore(deps): update dependency composer/composer to v2.7.0 chore(deps): update dependency composer/composer to v2.7.1 Feb 9, 2024
@renovate renovate bot force-pushed the renovate/composer-composer-2.x branch from 2f8af62 to ca29225 Compare February 9, 2024 15:04
@renovate renovate bot changed the title chore(deps): update dependency composer/composer to v2.7.1 chore(deps): update dependency composer/composer to v2.7.2 Mar 11, 2024
@renovate renovate bot force-pushed the renovate/composer-composer-2.x branch from ca29225 to 5a0bd43 Compare March 11, 2024 20:20
@renovate renovate bot changed the title chore(deps): update dependency composer/composer to v2.7.2 Update dependency composer/composer to v2.7.2 Apr 4, 2024
@renovate renovate bot force-pushed the renovate/composer-composer-2.x branch from 5a0bd43 to 83cc37e Compare April 20, 2024 02:34
@renovate renovate bot changed the title Update dependency composer/composer to v2.7.2 Update dependency composer/composer to v2.7.3 Apr 20, 2024
@renovate renovate bot changed the title Update dependency composer/composer to v2.7.3 chore(deps): update dependency composer/composer to v2.7.3 Apr 20, 2024
@renovate renovate bot changed the title chore(deps): update dependency composer/composer to v2.7.3 chore(deps): update dependency composer/composer to v2.7.4 Apr 22, 2024
@renovate renovate bot force-pushed the renovate/composer-composer-2.x branch from 83cc37e to 210f5f7 Compare April 22, 2024 20:30
@renovate renovate bot changed the title chore(deps): update dependency composer/composer to v2.7.4 Update dependency composer/composer to v2.7.4 Apr 30, 2024
@renovate renovate bot force-pushed the renovate/composer-composer-2.x branch from 210f5f7 to 961bc28 Compare May 3, 2024 17:05
@renovate renovate bot changed the title Update dependency composer/composer to v2.7.4 Update dependency composer/composer to v2.7.5 May 3, 2024
@renovate renovate bot changed the title Update dependency composer/composer to v2.7.5 chore(deps): update dependency composer/composer to v2.7.5 May 3, 2024
@renovate renovate bot changed the title chore(deps): update dependency composer/composer to v2.7.5 chore(deps): update dependency composer/composer to v2.7.6 May 4, 2024
@renovate renovate bot force-pushed the renovate/composer-composer-2.x branch from 961bc28 to 251d0ee Compare May 4, 2024 23:11
@renovate renovate bot changed the title chore(deps): update dependency composer/composer to v2.7.6 Update dependency composer/composer to v2.7.6 May 7, 2024
@renovate renovate bot changed the title Update dependency composer/composer to v2.7.6 chore(deps): update dependency composer/composer to v2.7.6 May 22, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant