Repository navigation
Update all non-major dependencies - #16
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
2 times, most recently
from
October 5, 2026 08:13
8b2478c to
a42d9ad
Compare
| datasource | package | from | to | | ---------- | ---------------------------- | ------- | ------- | | packagist | carthage-software/mago | 1.50.0 | 1.53.0 | | packagist | phpstan/phpstan | 2.2.16 | 2.3.0 | | packagist | phpstan/phpstan-phpunit | 2.0.18 | 2.1.1 | | packagist | phpstan/phpstan-strict-rules | 2.0.12 | 2.1.0 | | packagist | phpstan/phpstan-symfony | 2.0.20 | 2.1.0 | | packagist | phpunit/phpunit | 12.5.36 | 12.5.38 | | packagist | twig/twig | 3.23.0 | 3.30.0 |
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
October 8, 2026 04:12
a42d9ad to
509c48e
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^1.50.0→^1.53.0^2.2.16→^2.3.0^2.0.18→^2.1.1^2.0.12→^2.1.0^2.0.20→^2.1.0^12.5.36→^12.5.38^3.23.0→^3.30.0Release Notes
carthage-software/mago (carthage-software/mago)
v1.53.0: Mago 1.53.0Compare Source
Mago 1.53.0 improves analysis performance, file loading, name handling, and reporting, and fixes formatting of
yield, directnewcalls, and nested logical groups.🐛 Bug Fixes
Formatter
yieldandyield frombehavior in binary expressions. (#2432,d374fef)newcalls: omits redundant parentheses on PHP 8.4+, while honoring formatter settings. (#2430,cb4356f)314b53f)🏗️ Internal
Analyzer
2420161)Codex
06b88f4)efac017)Pipeline
104ca16)Syntax
a07da1c,073f748)Fingerprints
e2de0e7)Reporting
7454dd6)4e8f36e)🧩 Extension Protocol
No protocol changes in this release.
🙏 Thank You
Contributors
Thank you to everyone who contributed to this release:
Issue Reporters
Thank you to everyone who reported issues that shaped this release:
Full Changelog: carthage-software/mago@1.52.0...1.53.0
v1.52.0: Mago 1.52.0Compare Source
Mago 1.52.0 makes analysis faster from file loading through reporting, adds rdkafka stubs, and fixes constant visibility, nullsafe loop types, magic-method names, and built-in signatures.
✨ Features
Prelude
6e08eb3)🐛 Bug Fixes
Analyzer
9bcd3d4)11cd6a0,29fe098)??. (#2428,ab12076)Linter
'refresh_token'while still checking names. (#2028, #2420,4a9913b)Prelude
4502745)null, inDs\Map::get()andremove(). (#2425,cbb33fe)📖 Documentation
Website
375ac4b)40d1aa2)1d0720b)🏗️ Internal
Analyzer
025f27f,1535109,089078e)Codex
b306923,b5f1d4a)bcba31b,6e0a553)Pipeline
480cb16,96e49e6)3608259,4ec8478)Algebra
decbfd5,5e599f0)Syntax
cdf8266,c045c7f)37bf655,f9faeb5,9e600e1)Reporting
a1392d0,9e355dd)🧩 Extension Protocol
No protocol changes in this release.
🙏 Thank You
Contributors
Thank you to everyone who contributed to this release:
Issue Reporters
Thank you to everyone who reported issues that shaped this release:
Full Changelog: carthage-software/mago@1.51.2...1.52.0
v1.51.2: Mago 1.51.2Compare Source
Mago 1.51.2 fixes macOS and FreeBSD release builds. There are no analyzer, linter, formatter, or guard changes.
🏗️ Internal
Release Pipeline
e1c4ab6)libcto 0.2.189 to fix the missingNOTE_PCTRLMASKerror inmio. (e1c4ab6)🧩 Extension Protocol
No protocol changes in this release.
Full Changelog: carthage-software/mago@1.51.1...1.51.2
v1.51.1: Mago 1.51.1Compare Source
Mago 1.51.1 fixes false positives in mixed-condition analysis, restores optional built-in arguments, and corrects PSR-12 declarations, parameter alignment, and method-chain formatting.
🐛 Bug Fixes
Analyzer
b100d6b)Formatter
=indeclarestatements. (#2416,6fcc28d)...and&attached to parameter names. (#2182, #2417,0dea4da)8d3ab4a)Prelude
f9c74cf)array_find_key: infersnullfor empty arrays and keeps input key types otherwise. (#2389,df7b3c7)🏗️ Internal
Maintenance
54127eb)cf5f0d9)🧩 Extension Protocol
No protocol changes in this release.
🙏 Thank You
Contributors
Thank you to everyone who contributed code to this release:
Issue Reporters
Thank you to everyone who reported issues that shaped this release:
Full Changelog: carthage-software/mago@1.51.0...1.51.1
v1.51.0: Mago 1.51.0Compare Source
Mago 1.51.0 adds Swoole stubs and improves type analysis, with fixes for static locals, loop types, boolean guards, lint suggestions, and formatting.
✨ Features
Prelude
25b7c5f)🐛 Bug Fixes
Analyzer
452721b)__invokeresults marked#[NoDiscard]or@must-use. (#2400,f01b94e)2e560fa)9608b8c)finallyblocks. (#2410,71764f0)ifand changes in one branch. (#2411,0d0224d)Codex
4808b0a)Linter
185644f)list(). (#2407, #2408,a11d5e3,5d804d7)hook_*names in*.api.phpunchanged with Drupal integration. (#2390, #2391,335d8a7)245c4a2)Formatter
?>after method chains with a semicolon on its own line. (#2393,17cc593)22e0128)Configuration
extendsto the schema. (#2354,8556e0e)Prelude
str_increment: marks its return type asnon-empty-string. (452721b)Syntax
de4c9b8)📖 Documentation
Reference
number or null, using the schema. (#2398,7ceff94)56b8844)🧩 Extension Protocol
No protocol changes in this release.
🙏 Thank You
Contributors
A huge thank you to everyone who contributed to this release:
Issue Reporters
Thank you to everyone who reported issues that shaped this release:
Full Changelog: 1.50.0...1.51.0
phpstan/phpstan-phar-composer-source (phpstan/phpstan)
v2.3.0Compare Source
v2.2.17Compare Source
phpstan/phpstan-phpunit (phpstan/phpstan-phpunit)
v2.1.1Compare Source
AssertEmptyIsDiscouragedRuleis auto-fixable (#342)AssertSameWithCountRuleauto-fixable (#259)v2.1.0Compare Source
v2.0.21Compare Source
AssertEmptyIsDiscouragedRule: in case you are using PHPStan strict-rules
assertEmpty: falseoption, you can ignore the newly added errors by error-identifierphpunit.assertEmpty.v2.0.20Compare Source
AssertEmptyIsDiscouragedRule: in case you are using PHPStan strict-rules
assertEmpty: falseoption, you can ignore the newly added errors by error-identifierphpunit.assertEmpty.v2.0.19Compare Source
phpstan/phpstan-strict-rules (phpstan/phpstan-strict-rules)
v2.1.0Compare Source
phpstan/phpstan-symfony (phpstan/phpstan-symfony)
v2.1.0Compare Source
sebastianbergmann/phpunit (phpunit/phpunit)
v12.5.38: PHPUnit 12.5.38Compare Source
Changed
Fixed
setUpBeforeClass()andtearDownAfterClass()were run twice for a test class that is the only test class in a test suite of the XML configuration file that has the name of that test class--ARGS--section of a PHPT test that start with-were interpreted by PHP instead of being passed to the test when the test also has a--STDIN--sectionLearn how to install or update PHPUnit 12.5 in the documentation.
Keep up to date with PHPUnit:
v12.5.37: PHPUnit 12.5.37Compare Source
Fixed
#[RequiresMethod]is declared asclass-string, so static analysis reports an error when it refers to a class that does not exist#[RequiresMethod]attribute that refers to a class which cannot be loaded, for instance because its parent class does not exist, aborts the test run instead of skipping the testLearn how to install or update PHPUnit 12.5 in the documentation.
Keep up to date with PHPUnit:
twigphp/Twig (twig/twig)
v3.30.0Compare Source
split,random, andshufflemerging a trailing newline into the last character of a stringsplit,random, andshuffleIntlExtensionletting the pattern derived from a date formatter prototype override an explicit localeIntlExtensionnot honoring the locale of a date formatter prototype configured with no date and time stylesTemplateWrapper::unwrap()failing when called without arguments, which is now deprecatedTemplateWrapper::getDefaultEscapeStrategy()to know the escaping strategy a template was compiled withrandom,reverse,shuffle, andsplitreceive a string that is not valid UTF-8Twig\EnvironmentinstanceStringablekey on subclasses ofArrayObjectandArrayIteratorv3.29.0Compare Source
{% cache %}always missing in the Symfony bundle whenframework.cache.appuses a natively tag aware adapterusetrait templates before checking that theusetag is allowedhtml_attrdroppingstyledeclarations whose value is0,0.0or'0'defaultfilter fallback emitting an undefined variable warning when it uses the null-safe operatormatchesoperator silently treating PCRE execution errors as non-matches; it now throws aRuntimeErrorTemplateWrapper::streamBlock(),TemplateWrapper::hasBlock(), andTemplateWrapper::getBlockNames()omitting environment globalsBlockChainclass to compose blocks from multiple templates without using template internalsTemplateWrapper::hasBlock()andTemplateWrapper::getBlockNames()losing theextendsline when the parent template does not existHtmlExtension::htmlAttrValue()method to resolve a single HTML attribute value the way thehtml_attrfunction renders ithtml_attrJSON encoding aStringablevalue in adata-*attribute instead of using its string representationSyntaxErrorTypeErrorMissingExtensionSuggestornot suggesting thetwig/*-extrapackage to install for somehtml-extra,intl-extra, andstring-extrafilters and functionsTempestMarkdownto usetempest/markdownas themarkdown_to_htmlconverterinclude_onlyfunction to render a template without giving it access to the current contextTwig\Sandbox\SandboxInterfaceinterface andTwig\Sandbox\Sandboxclass to render untrusted templates through a dedicated, always-sandboxed environment crafted for itTemplateWrapperinstances created by anotherEnvironmentTwig\Extension\SandboxBridgeExtensionto render sandboxed templates from trusted templates with an explicit output escaping strategyTwig\Sandbox\SecurityCheckerclass used by compiled templates andCoreExtensionSandboxExtensionas internal, useTwig\Sandbox\Sandboxinsteadsandboxedargument of theincludefunction, useTwig\Sandbox\SandboxinsteadSandboxExtension::enableSandbox(),disableSandbox(), andisSandboxedGlobally()IntlExtensionignoring explicit date/time formats and configured calendars when using a date formatter prototypeformat_listfilter toIntlExtensionto format a list of strings using PHP 8.5'sIntlListFormatterStringablekey forArrayObjectandArrayIteratorwhile preserving object keys forSplObjectStorageSyntaxErrorTemplateVariableandAssignTemplateVariable; useMacroVariableandAssignMacroVariableinsteadSyntaxErrorin 4.0definedtest; it will throw aSyntaxErrorin 4.0{% macro foo(a, ...rest) %})macro_-prefixed PHP methodsTwig\Node\MacroNodeas@final; it will be final in Twig 4.0MacrosNodeinstance as the macros of aModuleNodeconstructorMacroReferenceExpressionto take the bare macro name instead of amacro_-prefixed method namemacro_-prefixed name; pass the bare macro name toMacroReferenceExpressionv3.28.0Compare Source
html_attrfunctionchr()deprecation when decoding an octal string escape sequence larger than\377(such as"\777")Twig\Markupas@final; it will be final in Twig 4.0forloopsmacros.(name)(args))Error::getTemplateColumn()Token::getOffset()block()calls to resolve against the overriding template when a block rendered throughblock(name, template)callsparent()blocktag within a capture node (likeset)blocktag within a capture node (likeset) in child templatesmacro,extends, orusetag outside the root of a templateIntegrationTestCasewhen there is no legacy test to runmarkdown_to_htmlto strip the indentation shared by all lines instead of mangling content that starts with a blank lineIntegrationTestCaseandNodeTestCasetest helpers compatible with PHPUnit 11Stringableobjects, ...) report a usable stack trace at the print locationinclude()function return aMarkupobject so an assigned result is not re-escaped when printed__toStringcheck on arguments whose PHP parameter type cannot implicitly coerce to stringalways_allowed_in_sandboxoption for filters, functions, and tests, and anisAlwaysAllowedInSandbox()method for token parsers, to let authors mark callables and tags that are always allowed in sandbox mode without explicit allow-listingTwig\Sandbox\SecurityPolicy, with the safe built-in tests flagged as always allowed so they keep working without allow-listingv3.27.1Compare Source
Stringablekey to coerce the key to string consistently instead of throwing in the optimized pathIteratorAggregatearguments (e.g. Symfony'sFormView) by a plain arrayv3.27.0Compare Source
Twig\Sandbox\SecurityPolicyto opt-in to the 4.0 behavior for theextends/usetags and theparent/block/attributefunctions, which are otherwise still implicitly allowed in a sandboxparent,block, andattributefunctions are always allowed in a sandboxed templateTemplateinstanceArrayAccessattribute access with a float keyTwig\Profiler\Profile::unserialize()to prevent arbitrary class instantiationHtmlDumpertwig_array_some(),twig_array_every(), andtwig_check_arrow_in_sandbox()(src/Resources/core.php)Twig\Sandbox\SourcePolicyInterfaceinterface with no replacementConfiguration
📅 Schedule: (in timezone UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
Renovate Bot