Skip to content

Bump the "maintenance" group with 1 update across multiple ecosystems - #315

Open
dependabot[bot] wants to merge 1 commit into
19.xfrom
dependabot/maintenance-8c67783e8e
Open

dependabot[bot] wants to merge 1 commit into
19.xfrom
dependabot/maintenance-8c67783e8e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the maintenance group with 14 updates:

Package From To
lion/command 6.2.4 6.2.5
lion/database 12.1.4 12.1.5
lion/files 9.1.4 9.1.5
lion/helpers 6.1.4 6.1.5
lion/security 12.0.4 12.0.5
monolog/monolog 3.10.0 3.12.0
nesbot/carbon 3.13.1 3.14.1
predis/predis 3.5.1 3.6.1
symfony/console 8.1.2 8.1.8
symfony/process 8.1.0 8.1.7
vlucas/phpdotenv 5.6.4 5.7.0
brianium/paratest 7.23.1 7.25.0
lion/test 4.1.4 4.1.5
phpstan/phpstan 2.2.6 2.2.16

Updates lion/command from 6.2.4 to 6.2.5

Release notes

Sourced from lion/command's releases.

v6.2.5

What's Changed

Full Changelog: lion-packages/command@v6.2.4...v6.2.5

Commits
  • 9bba22b Merge pull request #71 from lion-packages/dependabot/maintenance-557ac4f2a5
  • 368f0c2 build(deps-dev): bump the maintenance group with 5 updates
  • See full diff in compare view

Updates lion/database from 12.1.4 to 12.1.5

Release notes

Sourced from lion/database's releases.

v12.1.5

What's Changed

Full Changelog: lion-packages/database@v12.1.4...v12.1.5

Commits
  • 72cea8f Merge pull request #137 from lion-packages/dependabot/maintenance-3bf13b741c
  • 1d82ebc build(deps-dev): bump the maintenance group with 4 updates
  • See full diff in compare view

Updates lion/files from 9.1.4 to 9.1.5

Release notes

Sourced from lion/files's releases.

v9.1.5

What's Changed

Full Changelog: lion-packages/files@v9.1.4...v9.1.5

Commits
  • 0237306 Merge pull request #52 from lion-packages/dependabot/maintenance-84c26f0b52
  • f722524 build(deps-dev): bump the maintenance group with 4 updates
  • See full diff in compare view

Updates lion/helpers from 6.1.4 to 6.1.5

Release notes

Sourced from lion/helpers's releases.

v6.1.5

What's Changed

Full Changelog: lion-packages/helpers@v6.1.4...v6.1.5

Commits
  • 9836b01 Merge pull request #51 from lion-packages/dependabot/maintenance-186b4b21e5
  • 422b8fc build(deps-dev): bump squizlabs/php_codesniffer from 4.0.1 to 4.0.2
  • 4292f00 Merge pull request #50 from lion-packages/dependabot/maintenance-84c26f0b52
  • 25a13c0 build(deps-dev): bump the maintenance group with 4 updates
  • See full diff in compare view

Updates lion/security from 12.0.4 to 12.0.5

Release notes

Sourced from lion/security's releases.

v12.0.5

What's Changed

Full Changelog: lion-packages/security@v12.0.4...v12.0.5

Commits
  • 70873ea Merge pull request #72 from lion-packages/dependabot/maintenance-61d85ca329
  • 950669f build(deps-dev): bump guzzlehttp/guzzle from 8.0.1 to 8.1.0
  • 5a9e247 Merge pull request #71 from lion-packages/dependabot/maintenance-186b4b21e5
  • 86a3e0d build(deps-dev): bump squizlabs/php_codesniffer from 4.0.1 to 4.0.2
  • 9f563b3 Merge pull request #69 from lion-packages/dependabot/maintenance-3530bd6321
  • 879088d build(deps-dev): bump the maintenance group with 5 updates
  • See full diff in compare view

Updates monolog/monolog from 3.10.0 to 3.12.0

Release notes

Sourced from monolog/monolog's releases.

3.12.0

  • Added support for reading the timestamp of new records from a PSR-20 clock, via a new $clock constructor param and Logger::setClock() (#2065)
  • Added support for #[WithMonologChannel] on constructor/method parameters, so a channel can be bound to a single argument instead of the whole class (#2068)
  • Fixed TelegramBotHandler breaking HTML markup when truncating or splitting long messages, open tags are now closed at the end of a chunk and reopened in the next one (#2066)
  • Fixed RedactingFormatter not redacting secrets nested inside array values of sensitive keys (#2067)

Full Changelog: Seldaek/monolog@3.11.0...3.12.0

3.11.0

  • Security: Fixed potential XSS in BrowserConsoleHandler when logging user provided content
  • Added RedactingFormatter to automatically redact sensitive data from records, based on key names, #[SensitiveParameter] constructor params and/or regex patterns (#2041)
  • Added FrankenPhpHandler to log records via FrankenPHP's frankenphp_log() function (#2056)
  • Added LogMonsterHandler which complains if the code did not log enough records before the process/request ends, like a dead man's switch for logs (#2039)
  • Added FILE_PER_HOUR rotation mode to RotatingFileHandler (#2040)
  • Added ErrorHandler::captureStackTraces() to attach the stack trace of PHP errors to the records it generates (#2060)
  • Added NormalizerFormatter::setMaxTraceLength() to limit how many stack trace frames are included when normalizing exceptions (#2015)
  • Added extension points to TelegramBotHandler to change the API URL (e.g. for a self-hosted Bot API server) and to send extra curl headers (#2029)
  • Added ability to override IntrospectionProcessor's SKIP_FUNCTIONS in subclasses (#2050)
  • Added $maxLength param to SyslogUdpHandler/UdpSocket to keep datagrams below the path MTU, as fragmented UDP packets are often dropped (#2049)
  • Fixed StreamHandler truncating writes on non-blocking streams, it now loops until the whole record is written (#2016)
  • Fixed stack trace frames without file/line being skipped, they are now reported as internal[function] entries so traces are not truncated or empty (#2061)
  • Fixed RotatingFileHandler cleanup not finding files behind stream wrappers (e.g. private://) as glob() cannot see through those (#2058)
  • Fixed RotatingFileHandler not using the configured timezone when computing the next rotation time (#2022)
  • Fixed scalars being replaced by the "Over N levels deep" message instead of being output when the max normalization depth is reached (#2042)
  • Fixed DeduplicationHandler failing with an undefined array key error when the store file is written to concurrently (#2020)
  • Fixed TelegramBotHandler swallowing errors when the API returns a non-JSON response (#2030)
  • Fixed AbstractProcessingHandler::handle() reading $bubble directly instead of calling getBubble(), so overrides of it were ignored (#2031)
  • Fixed warning on PHP 8.5 when ErrorHandler sets the HTTP response code and a status line was already registered (#2027)

Full Changelog: Seldaek/monolog@3.10.0...3.11.0

Changelog

Sourced from monolog/monolog's changelog.

3.12.0 (2026-09-09)

  • Added support for reading the timestamp of new records from a PSR-20 clock, via a new $clock constructor param and Logger::setClock() (#2065)
  • Added support for #[WithMonologChannel] on constructor/method parameters, so a channel can be bound to a single argument instead of the whole class (#2068)
  • Fixed TelegramBotHandler breaking HTML markup when truncating or splitting long messages, open tags are now closed at the end of a chunk and reopened in the next one (#2066)
  • Fixed RedactingFormatter not redacting secrets nested inside array values of sensitive keys (#2067)

3.11.0 (2026-09-02)

  • Security: Fixed potential XSS in BrowserConsoleHandler when logging user provided content
  • Added RedactingFormatter to automatically redact sensitive data from records, based on key names, #[SensitiveParameter] constructor params and/or regex patterns (#2041)
  • Added FrankenPhpHandler to log records via FrankenPHP's frankenphp_log() function (#2056)
  • Added LogMonsterHandler which complains if the code did not log enough records before the process/request ends, like a dead man's switch for logs (#2039)
  • Added FILE_PER_HOUR rotation mode to RotatingFileHandler (#2040)
  • Added ErrorHandler::captureStackTraces() to attach the stack trace of PHP errors to the records it generates (#2060)
  • Added NormalizerFormatter::setMaxTraceLength() to limit how many stack trace frames are included when normalizing exceptions (#2015)
  • Added extension points to TelegramBotHandler to change the API URL (e.g. for a self-hosted Bot API server) and to send extra curl headers (#2029)
  • Added ability to override IntrospectionProcessor's SKIP_FUNCTIONS in subclasses (#2050)
  • Added $maxLength param to SyslogUdpHandler/UdpSocket to keep datagrams below the path MTU, as fragmented UDP packets are often dropped (#2049)
  • Fixed StreamHandler truncating writes on non-blocking streams, it now loops until the whole record is written (#2016)
  • Fixed stack trace frames without file/line being skipped, they are now reported as internal[function] entries so traces are not truncated or empty (#2061)
  • Fixed RotatingFileHandler cleanup not finding files behind stream wrappers (e.g. private://) as glob() cannot see through those (#2058)
  • Fixed RotatingFileHandler not using the configured timezone when computing the next rotation time (#2022)
  • Fixed scalars being replaced by the "Over N levels deep" message instead of being output when the max normalization depth is reached (#2042)
  • Fixed DeduplicationHandler failing with an undefined array key error when the store file is written to concurrently (#2020)
  • Fixed TelegramBotHandler swallowing errors when the API returns a non-JSON response (#2030)
  • Fixed AbstractProcessingHandler::handle() reading $bubble directly instead of calling getBubble(), so overrides of it were ignored (#2031)
  • Fixed warning on PHP 8.5 when ErrorHandler sets the HTTP response code and a status line was already registered (#2027)
Commits
  • 72c534f Update changelog
  • 7f81d36 Fix baseline
  • 1ab1776 Add more mongodb version pins
  • d3d822a Fix baseline
  • c1dd221 Fix TelegramBotHandler breaking HTML tags when truncating or splitting long m...
  • ddcd2b4 Fix mongodb version in phpstan build as well
  • b8f218d Allow reading the timestamp of log records from a PSR-20 clock (#2065)
  • 9e5649c Fix couchdb install warning
  • f04a319 Pin a higher version of mongodb to avoid problems with outdated versions
  • 2313cc7 Fix RedactingFormatter missing secrets nested in array-valued sensitive keys ...
  • Additional commits viewable in compare view

Updates nesbot/carbon from 3.13.1 to 3.14.1

Release notes

Sourced from nesbot/carbon's releases.

3.14.1

What's Changed

New Contributors

Full Changelog: CarbonPHP/carbon@3.14.0...3.14.1

3.14.0

What's Changed

Full Changelog: CarbonPHP/carbon@3.13.3...3.14.0

⚠️ If you unserialize CarbonPeriod objects that may have custom filters or custom dateClass, you might experience breaking change in some specific edge cases starting with this version

3.13.3

What's Changed

New Contributors

Full Changelog: CarbonPHP/carbon@3.13.2...3.13.3

3.13.2

What's Changed

Full Changelog: CarbonPHP/carbon@3.13.1...3.13.2

Commits
  • 34e9109 Merge pull request #151 from CarbonPHP/fix/issue-148-addWeekdays-float
  • e347b25 Fix support for decimal number in addWeekdays() and subWeekdays()
  • 6da87cf Merge pull request #150 from CarbonPHP/fix/issue-147-monthly-with-native-date...
  • fd3136d Allow to use float timestamps and DateTimeInterface in monthly(), quarterly()...
  • 58512e6 Merge pull request #149 from CarbonPHP/fix/issue-146-yearly-overflow
  • d7ed6fa Select last working commit on Laravel master branch
  • 41dc25e Upgrade orchestra/testbench-core
  • bf5db16 Fix #146 use year cycle when overflow is on
  • 1c75eb5 Add test for #146
  • a82fdca Merge pull request #3359 from dualfroz/dualfroz/fix-round-numeric-precision-c...
  • Additional commits viewable in compare view

Updates predis/predis from 3.5.1 to 3.6.1

Release notes

Sourced from predis/predis's releases.

v3.6.1

Fixed

  • Fixed RESP3 double parsing returning positive INF for -inf payloads (#1716)
  • Fixed client_info connection parameter being ignored (#1722)
  • Fixed Stream::write() and read() leaving a dead connection when a host error handler throws exception (#1725)

Security

  • Deprecated CommandInterface::deserializeCommand() (CVE GHSA-w6f5-v2h6-g786)
  • Fixed CRLF command smuggling and node misrouting in AbstractAggregateConnection::write() and CommandInterface::deserializeCommand() (CVE GHSA-w6f5-v2h6-g786)

v3.6.0

Added

  • Added support for new TS commands + Indonesian language support integration test (#1695)
  • Added support for new COLLECT reducer for FT.AGGREGATE (#1699)
  • Added support for SDIFFCARD and SUNIONCARD command
  • Added support for MAXCOUNT and MAXSIZE arguments for XREAD and XREADGROUP
  • Added support for TS.READ command
  • Added support for EXCLUDEEMPTY argument for TS.MRANGE and TS.MREVRANGE commands
  • Added explicit testing for FT.SEARCH timeout policies
  • Added support for TS.QUERYLABELS command
  • Added support for LMOVEM and BLMOVEM commands
  • Added support for FT.ALIASLIST command
  • Added stream commands to ClusterStrategy
  • Added vector sets commands to ClusterStrategy
  • Added experimental support for HIMPORT bulk hash import feature (API may change in a future release)

Changed

  • Added OBJECT and hash field expiration commands to ClusterStrategy
  • Make ZMSCORE command prefixable and add to ClusterStrategy (#1692)

Fixed

  • Fixed Sentinel does not wipe servers on exception caused (#1694)
  • Fixed @method cmsincrby() annotation
Changelog

Sourced from predis/predis's changelog.

v3.6.1 (2026-09-17)

Fixed

  • Fixed RESP3 double parsing returning positive INF for -inf payloads (#1716)
  • Fixed client_info connection parameter being ignored (#1722)
  • Fixed Stream::write() and read() leaving a dead connection when a host error handler throws exception (#1725)

Security

  • Deprecated CommandInterface::deserializeCommand() (CVE GHSA-w6f5-v2h6-g786)
  • Fixed CRLF command smuggling and node misrouting in AbstractAggregateConnection::write() and CommandInterface::deserializeCommand() (CVE GHSA-w6f5-v2h6-g786)

v3.6.0 (2026-08-14)

Added

  • Added support for new TS commands + Indonesian language support integration test (#1695)
  • Added support for new COLLECT reducer for FT.AGGREGATE (#1699)
  • Added support for SDIFFCARD and SUNIONCARD command
  • Added support for MAXCOUNT and MAXSIZE arguments for XREAD and XREADGROUP
  • Added support for TS.READ command
  • Added support for EXCLUDEEMPTY argument for TS.MRANGE and TS.MREVRANGE commands
  • Added explicit testing for FT.SEARCH timeout policies
  • Added support for TS.QUERYLABELS command
  • Added support for LMOVEM and BLMOVEM commands
  • Added support for FT.ALIASLIST command
  • Added stream commands to ClusterStrategy
  • Added vector sets commands to ClusterStrategy
  • Added experimental support for HIMPORT bulk hash import feature (API may change in a future release)

Changed

  • Added OBJECT and hash field expiration commands to ClusterStrategy
  • Make ZMSCORE command prefixable and add to ClusterStrategy (#1692)

Fixed

  • Fixed Sentinel does not wipe servers on exception caused (#1694)
  • Fixed @method cmsincrby() annotation
Commits
  • e2db963 tag v3.6.1
  • 3edc442 Fixed CRLF command smuggling and node misrouting in `AbstractAggregateConnect...
  • 3749086 Fixed Stream::write()/read() leaving a dead connection when a host error hand...
  • 3a5b55e Deprecated CommandInterface::deserializeCommand() (CVE GHSA-w6f5-v2h6-g786) (...
  • 401abc4 fix changelog typo
  • e7b89c1 Fixed client_info connection parameter being ignored (#1722)
  • 3a8c350 Bump the github-actions group with 2 updates (#1720)
  • 6759513 Fix RESP3 double parsing returning positive INF for -inf (#1716)
  • 0795d69 bump dev version
  • 2ff20c0 tag v3.6.0
  • Additional commits viewable in compare view

Updates symfony/console from 8.1.2 to 8.1.8

Release notes

Sourced from symfony/console's releases.

v8.1.8

Changelog (symfony/console@v8.1.7...v8.1.8)

v8.1.7

Changelog (symfony/console@v8.1.6...v8.1.7)

v8.1.6

Changelog (symfony/console@v8.1.5...v8.1.6)

v8.1.5

Changelog (symfony/console@v8.1.4...v8.1.5)

v8.1.4

Changelog (symfony/console@v8.1.2...v8.1.4)

Commits
  • 4b81146 Merge branch '7.4' into 8.1
  • d7bca2f Merge branch '6.4' into 7.4
  • 0f758df [Console] Fix quadratic formatting of non-ASCII content
  • 29afb89 Merge branch '7.4' into 8.1
  • 3a19734 [Console] Report a validation error instead of a TypeError on numeric argumen...
  • 117a485 Merge branch '7.4' into 8.1
  • 9553be3 [Console] [FrameworkBundle] Adapt merged tests to the 7.4 APIs
  • 30dc1f2 Merge branch '6.4' into 7.4
  • 9e118dd [Console] Keep messages containing malformed UTF-8 when wrapping
  • 31de385 Merge branch '7.4' into 8.1
  • Additional commits viewable in compare view

Updates symfony/process from 8.1.0 to 8.1.7

Release notes

Sourced from symfony/process's releases.

v8.1.7

Changelog (symfony/process@v8.1.6...v8.1.7)

v8.1.6

Changelog (symfony/process@v8.1.5...v8.1.6)

v8.1.5

Changelog (symfony/process@v8.1.0...v8.1.5)

Commits
  • 10823b0 Merge branch '7.4' into 8.1
  • ed0ae09 Merge branch '6.4' into 7.4
  • b9f3d9d Merge branch '5.4' into 6.4
  • 485d7b3 [Process] Use an absolute path for the cmd.exe fallback on Windows
  • f4d0960 bug #65739 [Process] Ignore invalid env var names and non-scalar env values (...
  • adc8b34 [Process] Ignore array env values before proc_open
  • 6057c47 [Process] Ignore invalid env var names
  • f90c81d [Process] Stop leaking CGI/FastCGI request-context vars to subprocesses
  • d863f5e Merge branch '7.4' into 8.1
  • 058d17f Merge branch '6.4' into 7.4
  • Additional commits viewable in compare view

Updates vlucas/phpdotenv from 5.6.4 to 5.7.0

Release notes

Sourced from vlucas/phpdotenv's releases.

v5.7.0

What's Changed

New Contributors

Full Changelog: vlucas/phpdotenv@v5.6.4...v5.7.0

Commits
  • 301c079 Resolve the remaining static analysis baseline entries (#614)
  • 5d0bb3b Document the real parsing, nesting, comment, escape and validation rules (#609)
  • 4426075 Stop comments from starting multiline values (#615)
  • eec19ee Add regression tests for existing behaviour (#608)
  • 226b4ed Improve diagnostics and messages (#607)
  • 4f84f7e Strip a leading UTF-8 byte order mark from string content (#606)
  • 4b900c5 Resolve nested variables without re-copying the value prefix (#605)
  • dd5b391 Remove quadratic value parsing (#604)
  • 46d5ce3 Skip environment writes and reads for names or values containing a null byte ...
  • 8bf174e Fix memory-safety crash on invalid UTF-8 variable names (#602)
  • Additional commits viewable in compare view

Updates brianium/paratest from 7.23.1 to 7.25.0

Release notes

Sourced from brianium/paratest's releases.

v7.25.0

What's Changed

New Contributors

Full Changelog: paratestphp/paratest@v7.24.1...v7.25.0

v7.24.1

What's Changed

New Contributors

Full Changelog: paratestphp/paratest@v7.24.0...v7.24.1

v7.24.0

What's Changed

Full Changelog: paratestphp/paratest@v7.23.1...v7.24.0

Commits
  • 5aa46dc feat: Add PHP 8.6 Support (#1138)
  • f594887 Update dependency phpunit/phpunit to ^13.3.4
  • 67e7546 Update all non-major dependencies
  • baa15b2 Update dependency phpunit/phpunit to ^13.3.3
  • 0cf7aa0 Update dependency phpunit/php-code-coverage to ^14.3.2
  • ad3e986 Update dependency phpstan/phpstan to ^2.2.13
  • 10ca65e WrapperRunnerTest: strip undeterministic output to make test runs idempoten...
  • 7ae4ed5 Update dependency phpstan/phpstan to ^2.2.12
  • 435f812 Update dependency phpstan/phpstan to ^2.2.11
  • 80ae12a Update dependency phpstan/phpstan to ^2.2.10
  • Additional commits viewable in compare view

Updates lion/test from 4.1.4 to 4.1.5

Release notes

Sourced from lion/test's releases.

v4.1.5

What's Changed

Full Changelog: https://github.com/lion-packages/test/compare/v4.1.4...v4.1.5<...

Description has been truncated

Bumps the maintenance group with 14 updates:

| Package | From | To |
| --- | --- | --- |
| [lion/command](https://github.com/lion-packages/command) | `6.2.4` | `6.2.5` |
| [lion/database](https://github.com/lion-packages/database) | `12.1.4` | `12.1.5` |
| [lion/files](https://github.com/lion-packages/files) | `9.1.4` | `9.1.5` |
| [lion/helpers](https://github.com/lion-packages/helpers) | `6.1.4` | `6.1.5` |
| [lion/security](https://github.com/lion-packages/security) | `12.0.4` | `12.0.5` |
| [monolog/monolog](https://github.com/Seldaek/monolog) | `3.10.0` | `3.12.0` |
| [nesbot/carbon](https://github.com/CarbonPHP/carbon) | `3.13.1` | `3.14.1` |
| [predis/predis](https://github.com/predis/predis) | `3.5.1` | `3.6.1` |
| [symfony/console](https://github.com/symfony/console) | `8.1.2` | `8.1.8` |
| [symfony/process](https://github.com/symfony/process) | `8.1.0` | `8.1.7` |
| [vlucas/phpdotenv](https://github.com/vlucas/phpdotenv) | `5.6.4` | `5.7.0` |
| [brianium/paratest](https://github.com/paratestphp/paratest) | `7.23.1` | `7.25.0` |
| [lion/test](https://github.com/lion-packages/test) | `4.1.4` | `4.1.5` |
| [phpstan/phpstan](https://github.com/phpstan/phpstan-phar-composer-source) | `2.2.6` | `2.2.16` |


Updates `lion/command` from 6.2.4 to 6.2.5
- [Release notes](https://github.com/lion-packages/command/releases)
- [Commits](lion-packages/command@v6.2.4...v6.2.5)

Updates `lion/database` from 12.1.4 to 12.1.5
- [Release notes](https://github.com/lion-packages/database/releases)
- [Commits](lion-packages/database@v12.1.4...v12.1.5)

Updates `lion/files` from 9.1.4 to 9.1.5
- [Release notes](https://github.com/lion-packages/files/releases)
- [Commits](lion-packages/files@v9.1.4...v9.1.5)

Updates `lion/helpers` from 6.1.4 to 6.1.5
- [Release notes](https://github.com/lion-packages/helpers/releases)
- [Commits](lion-packages/helpers@v6.1.4...v6.1.5)

Updates `lion/security` from 12.0.4 to 12.0.5
- [Release notes](https://github.com/lion-packages/security/releases)
- [Commits](lion-packages/security@v12.0.4...v12.0.5)

Updates `monolog/monolog` from 3.10.0 to 3.12.0
- [Release notes](https://github.com/Seldaek/monolog/releases)
- [Changelog](https://github.com/Seldaek/monolog/blob/main/CHANGELOG.md)
- [Commits](Seldaek/monolog@3.10.0...3.12.0)

Updates `nesbot/carbon` from 3.13.1 to 3.14.1
- [Release notes](https://github.com/CarbonPHP/carbon/releases)
- [Commits](CarbonPHP/carbon@3.13.1...3.14.1)

Updates `predis/predis` from 3.5.1 to 3.6.1
- [Release notes](https://github.com/predis/predis/releases)
- [Changelog](https://github.com/predis/predis/blob/main/CHANGELOG.md)
- [Commits](predis/predis@v3.5.1...v3.6.1)

Updates `symfony/console` from 8.1.2 to 8.1.8
- [Release notes](https://github.com/symfony/console/releases)
- [Changelog](https://github.com/symfony/console/blob/8.2/CHANGELOG.md)
- [Commits](symfony/console@v8.1.2...v8.1.8)

Updates `symfony/process` from 8.1.0 to 8.1.7
- [Release notes](https://github.com/symfony/process/releases)
- [Changelog](https://github.com/symfony/process/blob/8.2/CHANGELOG.md)
- [Commits](symfony/process@v8.1.0...v8.1.7)

Updates `vlucas/phpdotenv` from 5.6.4 to 5.7.0
- [Release notes](https://github.com/vlucas/phpdotenv/releases)
- [Commits](vlucas/phpdotenv@v5.6.4...v5.7.0)

Updates `brianium/paratest` from 7.23.1 to 7.25.0
- [Release notes](https://github.com/paratestphp/paratest/releases)
- [Commits](paratestphp/paratest@v7.23.1...v7.25.0)

Updates `lion/test` from 4.1.4 to 4.1.5
- [Release notes](https://github.com/lion-packages/test/releases)
- [Commits](lion-packages/test@v4.1.4...v4.1.5)

Updates `phpstan/phpstan` from 2.2.6 to 2.2.16
- [Commits](https://github.com/phpstan/phpstan-phar-composer-source/commits)

---
updated-dependencies:
- dependency-name: lion/command
  dependency-version: 6.2.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maintenance
- dependency-name: lion/database
  dependency-version: 12.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maintenance
- dependency-name: lion/files
  dependency-version: 9.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maintenance
- dependency-name: lion/helpers
  dependency-version: 6.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maintenance
- dependency-name: lion/security
  dependency-version: 12.0.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maintenance
- dependency-name: monolog/monolog
  dependency-version: 3.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maintenance
- dependency-name: nesbot/carbon
  dependency-version: 3.14.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maintenance
- dependency-name: predis/predis
  dependency-version: 3.6.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maintenance
- dependency-name: symfony/console
  dependency-version: 8.1.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maintenance
- dependency-name: symfony/process
  dependency-version: 8.1.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maintenance
- dependency-name: vlucas/phpdotenv
  dependency-version: 5.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maintenance
- dependency-name: brianium/paratest
  dependency-version: 7.25.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maintenance
- dependency-name: lion/test
  dependency-version: 4.1.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maintenance
- dependency-name: phpstan/phpstan
  dependency-version: 2.2.16
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maintenance
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot added this to the Support and maintenance milestone Oct 1, 2026
@dependabot dependabot Bot added dependencies Project dependencies are updated php Pull requests that update php code labels Oct 1, 2026
@sonarqubecloud

sonarqubecloud Bot commented Oct 1, 2026

Copy link
Copy Markdown

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 5 package(s) with unknown licenses.
See the Details below.

License Issues

composer.lock

PackageVersionLicenseIssue Type
lion/command6.2.5NullUnknown License
lion/database12.1.5NullUnknown License
lion/files9.1.5NullUnknown License
lion/helpers6.1.5NullUnknown License
lion/security12.0.5NullUnknown License

OpenSSF Scorecard

Scorecard details
PackageVersionScoreDetails
composer/brianium/paratest 7.25.0 UnknownUnknown
composer/carbonphp/carbon-doctrine-types 3.2.1 UnknownUnknown
composer/fidry/cpu-core-counter 1.4.1 UnknownUnknown
composer/firebase/php-jwt 7.2.1 UnknownUnknown
composer/graham-campbell/result-type 1.2.0 UnknownUnknown
composer/lion/command 6.2.5 UnknownUnknown
composer/lion/database 12.1.5 UnknownUnknown
composer/lion/files 9.1.5 UnknownUnknown
composer/lion/helpers 6.1.5 UnknownUnknown
composer/lion/security 12.0.5 UnknownUnknown
composer/lion/test 4.1.5 UnknownUnknown
composer/monolog/monolog 3.12.0 UnknownUnknown
composer/myclabs/deep-copy 1.14.0 UnknownUnknown
composer/nesbot/carbon 3.14.1 UnknownUnknown
composer/nikic/php-parser 5.9.0 UnknownUnknown
composer/phpoption/phpoption 1.10.0 UnknownUnknown
composer/phpstan/phpstan 2.2.16 UnknownUnknown
composer/phpunit/php-code-coverage 14.4.0 UnknownUnknown
composer/phpunit/php-file-iterator 7.0.2 UnknownUnknown
composer/phpunit/phpunit 13.3.6 UnknownUnknown
composer/predis/predis 3.6.1 UnknownUnknown
composer/sebastian/comparator 8.4.0 UnknownUnknown
composer/sebastian/diff 9.0.1 UnknownUnknown
composer/sebastian/exporter 8.2.1 UnknownUnknown
composer/sebastian/object-enumerator 8.1.0 UnknownUnknown
composer/sebastian/object-reflector 6.1.0 UnknownUnknown
composer/sebastian/recursion-context 8.0.1 UnknownUnknown
composer/sebastian/type 7.0.2 UnknownUnknown
composer/symfony/console 8.1.8 UnknownUnknown
composer/symfony/polyfill-intl-grapheme 1.43.0 UnknownUnknown
composer/symfony/polyfill-intl-normalizer 1.43.0 UnknownUnknown
composer/symfony/polyfill-mbstring 1.43.0 UnknownUnknown
composer/symfony/polyfill-php80 1.43.0 UnknownUnknown
composer/symfony/polyfill-php83 1.43.0 UnknownUnknown
composer/symfony/polyfill-php85 1.43.0 UnknownUnknown
composer/symfony/process 8.1.7 UnknownUnknown
composer/symfony/service-contracts 3.7.3 UnknownUnknown
composer/symfony/string 8.1.7 UnknownUnknown
composer/symfony/translation 8.1.5 UnknownUnknown
composer/vlucas/phpdotenv 5.7.0 UnknownUnknown

Scanned Files

  • composer.lock

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Project dependencies are updated php Pull requests that update php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants