Skip to content

Bump the "maintenance" group with 1 update across multiple ecosystems - #76

Open
dependabot[bot] wants to merge 1 commit into
4.xfrom
dependabot/maintenance-e526da95e7
Open

Bump the "maintenance" group with 1 update across multiple ecosystems#76
dependabot[bot] wants to merge 1 commit into
4.xfrom
dependabot/maintenance-e526da95e7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the maintenance group with 4 updates: phpstan/phpstan, lion/exceptions, phpunit/phpunit and infection/infection.

Updates phpstan/phpstan from 2.2.3 to 2.2.6

Commits

Updates lion/exceptions from 3.0.3 to 3.0.4

Release notes

Sourced from lion/exceptions's releases.

v3.0.4

What's Changed

Full Changelog: lion-packages/exceptions@v3.0.3...v3.0.4

Commits
  • 80b59b7 Merge pull request #51 from lion-packages/dependabot/maintenance-15470f118e
  • b0695ca build(deps-dev): bump the maintenance group with 5 updates
  • See full diff in compare view

Updates phpunit/phpunit from 13.1.13 to 13.2.6

Release notes

Sourced from phpunit/phpunit's releases.

PHPUnit 13.2.6

Fixed

  • #6861: Hook methods run twice when a template method is marked with its corresponding attribute
  • Regression that stopped test methods from being sorted by source code location

Learn how to install or update PHPUnit 13.2 in the documentation.

Keep up to date with PHPUnit:

PHPUnit 13.2.5

Changed

  • Messages for tests that are skipped because of an unsatisfied RequiresPhp, RequiresPhpunit, or RequiresPhpExtension version requirement now include the version that is actually being used
  • Warning messages about incomplete version requirements as well as version requirements without a version comparison operator, and the error message for invalid version requirements, now include the full version requirement and explain what is expected

Fixed

  • #6825: Forwarding to previous error handler can result in infinite recursion
  • #6831: PHPUnit's error handler does not respect @ error suppression and forwards suppressed warnings to previous error handler
  • #6833: assertArrayHasKey() does not accept ArrayAccess implementations with a specific value type when test code is analysed with PHPStan at level 9
  • #6854: Deprecation triggered in first-party code is wrongly classified as indirect when the first-party code is called from third-party code
  • Test classes were not sorted relative to each other when tests were ordered by duration

Learn how to install or update PHPUnit 13.2 in the documentation.

Keep up to date with PHPUnit:

PHPUnit 13.2.4

Fixed

  • #6817: Issue is reported even when previously registered error handler turns the error into an exception
  • #6818: Issue is reported when custom error handler checks error_reporting() output dynamically

Learn how to install or update PHPUnit 13.2 in the documentation.

Keep up to date with PHPUnit:

... (truncated)

Changelog

Sourced from phpunit/phpunit's changelog.

[13.2.6] - 2026-07-28

Fixed

  • #6861: Hook methods run twice when a template method is marked with its corresponding attribute
  • Regression that stopped test methods from being sorted by source code location

[13.2.5] - 2026-07-25

Changed

  • Messages for tests that are skipped because of an unsatisfied RequiresPhp, RequiresPhpunit, or RequiresPhpExtension version requirement now include the version that is actually being used
  • Warning messages about incomplete version requirements as well as version requirements without a version comparison operator, and the error message for invalid version requirements, now include the full version requirement and explain what is expected

Fixed

  • #6825: Forwarding to previous error handler can result in infinite recursion
  • #6831: PHPUnit's error handler does not respect @ error suppression and forwards suppressed warnings to previous error handler
  • #6833: assertArrayHasKey() does not accept ArrayAccess implementations with a specific value type when test code is analysed with PHPStan at level 9
  • #6854: Deprecation triggered in first-party code is wrongly classified as indirect when the first-party code is called from third-party code
  • Test classes were not sorted relative to each other when tests were ordered by duration

[13.2.4] - 2026-07-08

Fixed

  • #6817: Issue is reported even when previously registered error handler turns the error into an exception
  • #6818: Issue is reported when custom error handler checks error_reporting() output dynamically

[13.2.3] - 2026-07-06

Changed

  • #6797: Adapt code generated for test double of interface with constructor for PHP 8.6

[13.2.2] - 2026-06-29

Fixed

  • #6768: Negative priorities for hook methods are rejected by static analysis
  • #6778: Deprecation triggered outside of tests cannot be ignored

[13.2.1] - 2026-06-15

Fixed

  • #6741: Test is not run when --filter matches the name of a data set but not the name of the test method
  • #6743: Improve error message for invalid version constraint in attribute
  • #6744: Environment variable attributes reject empty-string values since PHPUnit 13.2.0

... (truncated)

Commits
  • 5d2afe1 Prepare release
  • 2bf4722 Merge branch '12.5' into 13.2
  • b98e028 Prepare release
  • 487be9d Merge branch '12.5' into 13.2
  • 80764d5 Fix regression introduced in 612d48fde that stopped test methods from being s...
  • e4eafbb Merge branch '12.5' into 13.2
  • 0f65ecb Sort test classes by their prettified name using case-insensitive natural ord...
  • 37ae898 Merge branch '12.5' into 13.2
  • 5ac8620 Fix errors reported by PHPStan
  • dc03cdf Update tools
  • Additional commits viewable in compare view

Updates infection/infection from 0.34.0 to 0.34.1

Release notes

Sourced from infection/infection's releases.

Bugfixes and internal stuff

Fixed

Docs

Various ADRs additions:

Misc:

Internal

Various AutoReview related changes/improvements:

A few Docker Sandbox related changes:

... (truncated)

Commits
  • 263a6e3 fix(git): Resolve diff paths from the configuration directory (#3399)
  • d26b3f9 ai: Add a handoff skill (#3421)
  • 9a92be8 ci: Enable back the integration tests on Windows (#1805)
  • b273136 doc: Add an ADR for the final usage (#3381)
  • ecea037 test(ast): Add a benchmark for AST processing (#3088)
  • 42100c4 doc: Fix the ADR numbering (#3420)
  • 7a47012 ci: Ignore zizimor error in the metrics collection workflow (#3419)
  • 39a3927 [Conductor] Update phpunit/phpunit to 12.5.32 (#3418)
  • 4e7ecd3 [Conductor] Update carthage-software/mago to 1.45.0 (#3406)
  • d6c1b77 ci: Collect performance metrics on release tag pushes (#3416)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the maintenance group with 4 updates: [phpstan/phpstan](https://github.com/phpstan/phpstan-phar-composer-source), [lion/exceptions](https://github.com/lion-packages/exceptions), [phpunit/phpunit](https://github.com/sebastianbergmann/phpunit) and [infection/infection](https://github.com/infection/infection).


Updates `phpstan/phpstan` from 2.2.3 to 2.2.6
- [Commits](https://github.com/phpstan/phpstan-phar-composer-source/commits)

Updates `lion/exceptions` from 3.0.3 to 3.0.4
- [Release notes](https://github.com/lion-packages/exceptions/releases)
- [Commits](lion-packages/exceptions@v3.0.3...v3.0.4)

Updates `phpunit/phpunit` from 13.1.13 to 13.2.6
- [Release notes](https://github.com/sebastianbergmann/phpunit/releases)
- [Changelog](https://github.com/sebastianbergmann/phpunit/blob/13.2.6/ChangeLog-13.2.md)
- [Commits](sebastianbergmann/phpunit@13.1.13...13.2.6)

Updates `infection/infection` from 0.34.0 to 0.34.1
- [Release notes](https://github.com/infection/infection/releases)
- [Changelog](https://github.com/infection/infection/blob/master/CHANGELOG.md)
- [Commits](infection/infection@0.34.0...0.34.1)

---
updated-dependencies:
- dependency-name: phpstan/phpstan
  dependency-version: 2.2.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maintenance
- dependency-name: lion/exceptions
  dependency-version: 3.0.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maintenance
- dependency-name: phpunit/phpunit
  dependency-version: 13.2.6
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maintenance
- dependency-name: infection/infection
  dependency-version: 0.34.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maintenance
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Project dependencies are updated php Pull requests that update php code labels Aug 1, 2026
@sonarqubecloud

sonarqubecloud Bot commented Aug 1, 2026

Copy link
Copy Markdown

@github-actions

github-actions Bot commented Aug 1, 2026

Copy link
Copy Markdown

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 1 package(s) with unknown licenses.
See the Details below.

License Issues

composer.json

PackageVersionLicenseIssue Type
php>= 8.5NullUnknown License

OpenSSF Scorecard

Scorecard details
PackageVersionScoreDetails
composer/php >= 8.5 UnknownUnknown
composer/composer/pcre 3.4.0 🟢 5.2
Details
CheckScoreReason
Token-Permissions⚠️ -1No tokens found
Packaging⚠️ -1packaging workflow not detected
Code-Review🟢 3Found 7/22 approved changesets -- score normalized to 3
Maintained🟢 79 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 7
Binary-Artifacts🟢 10no binaries found in the repo
Dangerous-Workflow⚠️ -1no workflows found
Pinned-Dependencies⚠️ -1no dependencies found
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Security-Policy🟢 9security policy file detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
composer/infection/abstract-testframework-adapter 0.5.1 UnknownUnknown
composer/infection/include-interceptor 1.0.0 UnknownUnknown
composer/infection/infection 0.34.1 UnknownUnknown
composer/justinrainbow/json-schema 6.10.0 UnknownUnknown
composer/lion/exceptions 3.0.4 UnknownUnknown
composer/nikic/php-parser 5.8.0 UnknownUnknown
composer/overtrue/phplint 9.7.2 UnknownUnknown
composer/phpstan/phpstan 2.2.6 UnknownUnknown
composer/phpunit/php-code-coverage 14.2.4 UnknownUnknown
composer/phpunit/php-file-iterator 7.0.0 UnknownUnknown
composer/phpunit/php-invoker 7.0.0 UnknownUnknown
composer/phpunit/php-text-template 6.0.0 UnknownUnknown
composer/phpunit/php-timer 9.0.0 UnknownUnknown
composer/phpunit/phpunit 13.2.6 UnknownUnknown
composer/sanmai/di-container 0.1.17 UnknownUnknown
composer/sanmai/duoclock 0.1.3 UnknownUnknown
composer/sanmai/later 0.1.8 UnknownUnknown
composer/sanmai/pipeline 7.9 UnknownUnknown
composer/sebastian/cli-parser 5.0.1 UnknownUnknown
composer/sebastian/comparator 8.3.0 UnknownUnknown
composer/sebastian/complexity 6.0.0 UnknownUnknown
composer/sebastian/diff 9.0.0 UnknownUnknown
composer/sebastian/environment 9.3.2 UnknownUnknown
composer/sebastian/exporter 8.1.1 UnknownUnknown
composer/sebastian/file-filter 1.0.0 UnknownUnknown
composer/sebastian/git-state 1.0.0 UnknownUnknown
composer/sebastian/global-state 9.0.1 UnknownUnknown
composer/sebastian/lines-of-code 5.0.2 UnknownUnknown
composer/sebastian/object-enumerator 8.0.0 UnknownUnknown
composer/sebastian/object-reflector 6.0.0 UnknownUnknown
composer/sebastian/recursion-context 8.0.0 UnknownUnknown
composer/sebastian/type 7.0.1 UnknownUnknown
composer/sebastian/version 7.0.0 UnknownUnknown
composer/squizlabs/php_codesniffer 4.0.1 UnknownUnknown
composer/symfony/cache 8.1.1 UnknownUnknown
composer/symfony/cache-contracts 3.7.1 UnknownUnknown
composer/symfony/console 8.1.2 UnknownUnknown
composer/symfony/deprecation-contracts 3.7.1 UnknownUnknown
composer/symfony/event-dispatcher 8.1.1 UnknownUnknown
composer/symfony/event-dispatcher-contracts 3.7.1 UnknownUnknown
composer/symfony/filesystem 8.1.2 UnknownUnknown
composer/symfony/finder 8.1.1 UnknownUnknown
composer/symfony/options-resolver 8.1.0 UnknownUnknown
composer/symfony/polyfill-ctype 1.37.0 🟢 3
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
SAST⚠️ 0no SAST tool detected
Dangerous-Workflow⚠️ -1no workflows found
Pinned-Dependencies⚠️ -1no dependencies found
Token-Permissions⚠️ -1No tokens found
Code-Review⚠️ 0Found 0/30 approved changesets -- score normalized to 0
Maintained⚠️ 00 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
Binary-Artifacts🟢 10no binaries found in the repo
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
Security-Policy🟢 10security policy file detected
composer/symfony/polyfill-deepclone 1.40.0 UnknownUnknown
composer/symfony/polyfill-intl-grapheme 1.41.0 UnknownUnknown
composer/symfony/polyfill-intl-normalizer 1.38.0 🟢 3
Details
CheckScoreReason
Pinned-Dependencies⚠️ -1no dependencies found
Packaging⚠️ -1packaging workflow not detected
Code-Review⚠️ 0Found 0/30 approved changesets -- score normalized to 0
SAST⚠️ 0no SAST tool detected
Maintained⚠️ 01 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
Dangerous-Workflow⚠️ -1no workflows found
Token-Permissions⚠️ -1No tokens found
Binary-Artifacts🟢 10no binaries found in the repo
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
Security-Policy🟢 10security policy file detected
composer/symfony/polyfill-mbstring 1.38.2 🟢 4.2
Details
CheckScoreReason
Maintained🟢 810 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 8
Packaging⚠️ -1packaging workflow not detected
Pinned-Dependencies⚠️ -1no dependencies found
Dangerous-Workflow⚠️ -1no workflows found
Token-Permissions⚠️ -1No tokens found
Code-Review⚠️ 0Found 0/30 approved changesets -- score normalized to 0
Binary-Artifacts🟢 10no binaries found in the repo
SAST⚠️ 0no SAST tool detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
Security-Policy🟢 10security policy file detected
composer/symfony/polyfill-php85 1.41.0 UnknownUnknown
composer/symfony/process 8.1.0 UnknownUnknown
composer/symfony/service-contracts 3.7.1 UnknownUnknown
composer/symfony/string 8.1.2 UnknownUnknown
composer/symfony/var-exporter 8.1.1 UnknownUnknown
composer/symfony/yaml 8.1.1 UnknownUnknown
composer/thecodingmachine/safe 3.4.0 UnknownUnknown
composer/theseer/tokenizer 2.0.1 UnknownUnknown
composer/webmozart/assert 2.4.1 🟢 4.6
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Token-Permissions⚠️ -1No tokens found
Dangerous-Workflow⚠️ -1no workflows found
Binary-Artifacts🟢 10no binaries found in the repo
Code-Review🟢 3Found 9/25 approved changesets -- score normalized to 3
Maintained🟢 109 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
Pinned-Dependencies⚠️ -1no dependencies found
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Security-Policy⚠️ 0security policy file not detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases⚠️ -1no releases found
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0

Scanned Files

  • composer.json
  • composer.lock

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Project dependencies are updated php Pull requests that update php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants