Skip to content

Bump the "maintenance" group with 1 update across multiple ecosystems - #73

Open
dependabot[bot] wants to merge 1 commit into
12.xfrom
dependabot/maintenance-e6c941b261
Open

dependabot[bot] wants to merge 1 commit into
12.xfrom
dependabot/maintenance-e6c941b261

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the maintenance group with 7 updates:

Package From To
firebase/php-jwt 7.1.0 7.2.0
guzzlehttp/guzzle 8.1.0 8.2.0
lion/test 4.1.4 4.1.5
phpstan/phpstan 2.2.6 2.2.16
squizlabs/php_codesniffer 4.0.2 4.0.4
phpunit/phpunit 13.2.6 13.3.5
infection/infection 0.34.1 0.35.5

Updates firebase/php-jwt from 7.1.0 to 7.2.0

Release notes

Sourced from firebase/php-jwt's releases.

firebase/php-jwt v7.2.0

Miscellaneous Chores

v7.1.1

7.1.1 (2026-09-02)

Bug Fixes

  • Limit the number of segments a JWT can be exploded into (#639) (93d248c)
Changelog

Sourced from firebase/php-jwt's changelog.

Changelog

7.1.1 (2026-09-02)

Bug Fixes

  • Limit the number of segments a JWT can be exploded into (#639) (93d248c)
Commits
  • f502cdb chore(main): release 0.346.0 (#9692)
  • ba85774 chore: move Auth and Jwt tests into tests/Unit (#9705)
  • d5d5b2e chore(Jwt): add VERSION (#9707)
  • ca2cf80 chore: prepare the JWT library for migration to the monorepo
  • d92e079 chore(main): release 7.1.1
  • 38e36fc fix: limit the number of segments a JWT can be exploded into (firebase/php-jw...
  • b1e8e7cfirebase/php-jwt#643
  • 272f195firebase/php-jwt#641
  • 5f0b513firebase/php-jwt#640
  • 1f4c6dcfirebase/php-jwt#637
  • Additional commits viewable in compare view

Updates guzzlehttp/guzzle from 8.1.0 to 8.2.0

Release notes

Sourced from guzzlehttp/guzzle's releases.

8.2.0

Changed

  • Allow connection caps to be combined with persistent transport sharing on libcurl 8.22.0+
Changelog

Sourced from guzzlehttp/guzzle's changelog.

8.2.0 - 2026-09-06

Changed

  • Allow connection caps to be combined with persistent transport sharing on libcurl 8.22.0+
Commits

Updates lion/test from 4.1.4 to 4.1.5

Release notes

Sourced from lion/test's releases.

v4.1.5

What's Changed

Full Changelog: lion-packages/test@v4.1.4...v4.1.5

Commits
  • 9b72176 Merge pull request #77 from lion-packages/dependabot/maintenance-186b4b21e5
  • 0c10b33 build(deps-dev): bump squizlabs/php_codesniffer from 4.0.1 to 4.0.2
  • ce2dd6a Merge pull request #76 from lion-packages/dependabot/maintenance-e526da95e7
  • 07d4f95 build(deps-dev): bump the maintenance group with 4 updates
  • See full diff in compare view

Updates phpstan/phpstan from 2.2.6 to 2.2.16

Commits

Updates squizlabs/php_codesniffer from 4.0.2 to 4.0.4

Release notes

Sourced from squizlabs/php_codesniffer's releases.

4.0.4 - 2026-08-06

The 4.0.2 release, the 4.0.3 and the 4.0.4 release are 100% the same (aside from the version number), there was just a slight snafu in the release publication on GitHub (missing PHAR assets). Sorry for the confusion.

Changelog

Sourced from squizlabs/php_codesniffer's changelog.

[4.0.4] - 2026-08-06

The 4.0.2 release, the 4.0.3 and the 4.0.4 release are 100% the same, there was just a slight snafu in the release publication on GitHub. Sorry for the confusion.

[4.0.3] - 2026-08-06

WITHDRAWN

Commits
  • bbdc3d0 Merge branch '3.x' into 4.x
  • 3d9e4c6 Merge pull request #1471 from PHPCSStandards/feature/update-gpg-key-info
  • 0c3dc35 Changelog: add release links
  • ddc0bf9 Changelog update for 4.0.3 + 4.0.4
  • 09a2847 Config: update version nr to next
  • aa43975 Merge branch '3.x' into 4.x
  • 29a0859 Config: update version nr to next
  • 305aebb Update for new GPG keys
  • See full diff in compare view

Updates phpunit/phpunit from 13.2.6 to 13.3.5

Release notes

Sourced from phpunit/phpunit's releases.

PHPUnit 13.3.5

Changed

  • Control characters and ANSI escape sequences in user-supplied strings such as test names, data set names, and messages are now made visible as \u{NNNN} escape sequences instead of being passed through to the terminal
  • Control characters in user-supplied strings are now also made visible in the compact output
  • Line feeds in the name of a test no longer break the header line of a record in the compact output

Learn how to install or update PHPUnit 13.3 in the documentation.

Keep up to date with PHPUnit:

  • You can follow @​[email protected] to stay up to date with PHPUnit's development.
  • You can subscribe to the PHPUnit Updates newsletter to receive updates about and tips for PHPUnit.

PHPUnit 13.3.4

Fixed

  • #6965: Temporary file used by SourceMapper may be deleted prematurely
  • The compact output displays details on PHPUnit deprecations and PHPUnit notices even when --display-phpunit-deprecations and --display-phpunit-notices are not used
  • The summary line of the compact output does not report the number of PHPUnit deprecations, PHPUnit notices, and PHPUnit warnings

Learn how to install or update PHPUnit 13.3 in the documentation.

Keep up to date with PHPUnit:

  • You can follow @​[email protected] to stay up to date with PHPUnit's development.
  • You can subscribe to the PHPUnit Updates newsletter to receive updates about and tips for PHPUnit.

PHPUnit 13.3.3

Fixed

  • Paths of included files are now escaped when generating the code that is executed in a separate process, so that a path containing special characters no longer produces broken code
  • Tests of a test class that is skipped as a whole are missing from the TestDox output
  • A test that is skipped or marked incomplete before it started is missing from the TestDox output
  • A test that is marked incomplete before it started is not counted in the number of tests that ran
  • No progress is printed for a test that is marked incomplete before it started

Learn how to install or update PHPUnit 13.3 in the documentation.

Keep up to date with PHPUnit:

  • You can follow @​[email protected] to stay up to date with PHPUnit's development.
  • You can subscribe to the PHPUnit Updates newsletter to receive updates about and tips for PHPUnit.

... (truncated)

Changelog

Sourced from phpunit/phpunit's changelog.

[13.3.5] - 2026-09-25

Changed

  • Control characters and ANSI escape sequences in user-supplied strings such as test names, data set names, and messages are now made visible as \u{NNNN} escape sequences instead of being passed through to the terminal
  • Control characters in user-supplied strings are now also made visible in the compact output
  • Line feeds in the name of a test no longer break the header line of a record in the compact output

[13.3.4] - 2026-09-15

Fixed

  • #6965: Temporary file used by SourceMapper may be deleted prematurely
  • The compact output displays details on PHPUnit deprecations and PHPUnit notices even when --display-phpunit-deprecations and --display-phpunit-notices are not used
  • The summary line of the compact output does not report the number of PHPUnit deprecations, PHPUnit notices, and PHPUnit warnings

[13.3.3] - 2026-09-09

Fixed

  • Paths of included files are now escaped when generating the code that is executed in a separate process, so that a path containing special characters no longer produces broken code
  • Tests of a test class that is skipped as a whole are missing from the TestDox output
  • A test that is skipped or marked incomplete before it started is missing from the TestDox output
  • A test that is marked incomplete before it started is not counted in the number of tests that ran
  • No progress is printed for a test that is marked incomplete before it started

[13.3.2] - 2026-08-27

Fixed

  • #6904: SourceMap is built in child process even though identifyIssueTrigger is disabled
  • #6924: #[CoversFile] attribute is not considered for risky test check

[13.3.1] - 2026-08-13

Changed

  • Invoking a static hook method such as setUpBeforeClass() no longer triggers a deprecation warning on PHP 8.6

[13.3.0] - 2026-08-07

Added

  • #3794: Filesystem-based code coverage targeting
  • #5758: Make export of objects customizable
  • #6546: Both property hooks can now be configured on test doubles of virtual hooked properties, even when the doubled property only declares one of them
  • #6586: Custom code coverage driver support
  • #6591: Repeated test execution using --repeat CLI option and #[Repeat] attribute
  • #6701: Allow expectOutputString() and expectOutputRegex() to be combined and repeated
  • #6710: Deprecation Filters

... (truncated)

Commits

Updates infection/infection from 0.34.1 to 0.35.5

Release notes

Sourced from infection/infection's releases.

0.35.5

Fixed:

Internal:

New Contributors

Full Changelog: infection/infection@0.35.4...0.35.5

0.35.4

Fixed:

Full Changelog: infection/infection@0.35.3...0.35.4

0.35.3

Fixed:

Full Changelog: infection/infection@0.35.2...0.35.3

0.35.2

Fixed:

New Contributors

... (truncated)

Commits
  • 0db8529 Update .gitattributes (#3591)
  • cea8144 build(deps): bump the dependencies group in /.github/workflows with 3 updates...
  • 5f02b65 fix(reporter): Fix avoid null array key deprecation in the Stryker HTML repor...
  • b230075 [Conductor] Update doctrine/lexer to 3.0.2 (#3581)
  • 650a10b Add PHP 8.6 docker service for compose (#3579)
  • eb4405a Run e2e tests on 8.5 and 8.6 (#3575)
  • 55b951c Instruct AI to use docker (#3577)
  • e5eded0 Add PHP 8.6 support on CI matrix (#3574)
  • be3a1ca [Conductor] Update sidz/phpstan-rules to 0.5.3 (#3580)
  • 5525954 [Conductor] Update webmozarts/strict-phpunit to 7.25.0 (#3578)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the maintenance group with 7 updates:

| Package | From | To |
| --- | --- | --- |
| [firebase/php-jwt](https://github.com/googleapis/php-jwt) | `7.1.0` | `7.2.0` |
| [guzzlehttp/guzzle](https://github.com/guzzle/guzzle) | `8.1.0` | `8.2.0` |
| [lion/test](https://github.com/lion-packages/test) | `4.1.4` | `4.1.5` |
| [phpstan/phpstan](https://github.com/phpstan/phpstan-phar-composer-source) | `2.2.6` | `2.2.16` |
| [squizlabs/php_codesniffer](https://github.com/PHPCSStandards/PHP_CodeSniffer) | `4.0.2` | `4.0.4` |
| [phpunit/phpunit](https://github.com/sebastianbergmann/phpunit) | `13.2.6` | `13.3.5` |
| [infection/infection](https://github.com/infection/infection) | `0.34.1` | `0.35.5` |


Updates `firebase/php-jwt` from 7.1.0 to 7.2.0
- [Release notes](https://github.com/googleapis/php-jwt/releases)
- [Changelog](https://github.com/googleapis/php-jwt/blob/main/CHANGELOG.md)
- [Commits](googleapis/php-jwt@v7.1.0...v7.2.0)

Updates `guzzlehttp/guzzle` from 8.1.0 to 8.2.0
- [Release notes](https://github.com/guzzle/guzzle/releases)
- [Changelog](https://github.com/guzzle/guzzle/blob/8.2/CHANGELOG.md)
- [Commits](guzzle/guzzle@8.1.0...8.2.0)

Updates `lion/test` from 4.1.4 to 4.1.5
- [Release notes](https://github.com/lion-packages/test/releases)
- [Commits](lion-packages/test@v4.1.4...v4.1.5)

Updates `phpstan/phpstan` from 2.2.6 to 2.2.16
- [Commits](https://github.com/phpstan/phpstan-phar-composer-source/commits)

Updates `squizlabs/php_codesniffer` from 4.0.2 to 4.0.4
- [Release notes](https://github.com/PHPCSStandards/PHP_CodeSniffer/releases)
- [Changelog](https://github.com/PHPCSStandards/PHP_CodeSniffer/blob/4.x/CHANGELOG-4.x.md)
- [Commits](PHPCSStandards/PHP_CodeSniffer@4.0.2...4.0.4)

Updates `phpunit/phpunit` from 13.2.6 to 13.3.5
- [Release notes](https://github.com/sebastianbergmann/phpunit/releases)
- [Changelog](https://github.com/sebastianbergmann/phpunit/blob/13.3.5/ChangeLog-13.3.md)
- [Commits](sebastianbergmann/phpunit@13.2.6...13.3.5)

Updates `infection/infection` from 0.34.1 to 0.35.5
- [Release notes](https://github.com/infection/infection/releases)
- [Changelog](https://github.com/infection/infection/blob/master/CHANGELOG.md)
- [Commits](infection/infection@0.34.1...0.35.5)

---
updated-dependencies:
- dependency-name: firebase/php-jwt
  dependency-version: 7.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maintenance
- dependency-name: guzzlehttp/guzzle
  dependency-version: 8.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maintenance
- dependency-name: lion/test
  dependency-version: 4.1.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maintenance
- dependency-name: phpstan/phpstan
  dependency-version: 2.2.16
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maintenance
- dependency-name: squizlabs/php_codesniffer
  dependency-version: 4.0.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maintenance
- dependency-name: phpunit/phpunit
  dependency-version: 13.3.5
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maintenance
- dependency-name: infection/infection
  dependency-version: 0.35.5
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maintenance
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot added dependencies Project dependencies are updated php Pull requests that update php code labels Oct 1, 2026
@sonarqubecloud

sonarqubecloud Bot commented Oct 1, 2026

Copy link
Copy Markdown

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

Scorecard details
PackageVersionScoreDetails
composer/fidry/cpu-core-counter 1.4.1 UnknownUnknown
composer/firebase/php-jwt 7.2.0 UnknownUnknown
composer/guzzlehttp/guzzle 8.2.0 UnknownUnknown
composer/infection/infection 0.35.5 UnknownUnknown
composer/justinrainbow/json-schema 6.13.1 UnknownUnknown
composer/lion/test 4.1.5 UnknownUnknown
composer/myclabs/deep-copy 1.14.0 UnknownUnknown
composer/nikic/php-parser 5.9.0 UnknownUnknown
composer/phpstan/phpstan 2.2.16 UnknownUnknown
composer/phpunit/php-code-coverage 14.4.0 UnknownUnknown
composer/phpunit/php-file-iterator 7.0.2 UnknownUnknown
composer/phpunit/phpunit 13.3.5 UnknownUnknown
composer/sanmai/di-container 0.2 UnknownUnknown
composer/sanmai/pipeline 7.12 UnknownUnknown
composer/sebastian/comparator 8.4.0 UnknownUnknown
composer/sebastian/diff 9.0.1 UnknownUnknown
composer/sebastian/exporter 8.2.1 UnknownUnknown
composer/sebastian/object-enumerator 8.1.0 UnknownUnknown
composer/sebastian/object-reflector 6.1.0 UnknownUnknown
composer/sebastian/recursion-context 8.0.1 UnknownUnknown
composer/sebastian/type 7.0.2 UnknownUnknown
composer/squizlabs/php_codesniffer 4.0.4 UnknownUnknown
composer/symfony/console 8.1.8 UnknownUnknown
composer/symfony/filesystem 8.1.6 UnknownUnknown
composer/symfony/finder 8.1.8 UnknownUnknown
composer/symfony/polyfill-intl-grapheme 1.43.0 UnknownUnknown
composer/symfony/polyfill-intl-normalizer 1.43.0 UnknownUnknown
composer/symfony/polyfill-mbstring 1.43.0 UnknownUnknown
composer/symfony/polyfill-php80 1.43.0 UnknownUnknown
composer/symfony/polyfill-php82 1.43.0 UnknownUnknown
composer/symfony/polyfill-php85 1.43.0 UnknownUnknown
composer/symfony/process 8.1.7 UnknownUnknown
composer/symfony/service-contracts 3.7.3 UnknownUnknown
composer/symfony/string 8.1.7 UnknownUnknown

Scanned Files

  • composer.lock

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Project dependencies are updated php Pull requests that update php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants