Skip to content

Bump the "maintenance" group with 1 update across multiple ecosystems - #72

Open
dependabot[bot] wants to merge 1 commit into
6.xfrom
dependabot/maintenance-fca28bccc4
Open

dependabot[bot] wants to merge 1 commit into
6.xfrom
dependabot/maintenance-fca28bccc4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the maintenance group with 6 updates:

Package From To
phpstan/phpstan 2.2.6 2.2.16
squizlabs/php_codesniffer 4.0.1 4.0.4
vlucas/phpdotenv 5.6.4 5.7.0
symfony/console 8.1.2 8.1.8
lion/test 4.1.4 4.1.5
phpunit/phpunit 13.2.6 13.3.5

Updates phpstan/phpstan from 2.2.6 to 2.2.16

Commits

Updates squizlabs/php_codesniffer from 4.0.1 to 4.0.4

Release notes

Sourced from squizlabs/php_codesniffer's releases.

4.0.4 - 2026-08-06

The 4.0.2 release, the 4.0.3 and the 4.0.4 release are 100% the same (aside from the version number), there was just a slight snafu in the release publication on GitHub (missing PHAR assets). Sorry for the confusion.

4.0.2 - 2026-08-06

This is a security release and all users are advised to update their install(s) as soon as possible. The security issue only affects users of the Gitblame, Hgblame or Svnblame report(s).

Added

  • Tokenizer support for the PHP 8.5 (void) cast. #1325 The T_VOID_CAST token has been added to the Tokens::CAST_TOKENS array.
  • suggest section to the composer.json file to inform users about the recommended iconv and pcntl PHP extensions. #1388

Changed

  • Clarified that libxml is a required PHP extension. #1409
  • Squiz.Scope.StaticThisUsage: the sniff will now also search for the use of $this in static closures. #1377
  • The Generic.PHP.LowerCaseKeyword, Generic.WhiteSpace.LanguageConstructSpacing and Squiz.Functions.FunctionDeclarationArgumentSpacing sniffs no longer embed UTF-8 middot characters for spaces in error messages. #1379, #1389 Fixes [Squiz/#2652](squizlabs/PHP_CodeSniffer#2652).
  • PSR2.ControlStructures.SwitchDeclaration: the error message for the use of colon + curly braces (WrongOpener*) has been made more informative. #1358. Fixes #1322.
  • The error messages for the following sniffs have been improved by exposing more data placeholders:
    • PEAR.Functions.FunctionDeclaration #1445
      • The CloseBracketLine error message now exposes 1 data value (previously 0).
      • The EmptyLine error message now exposes 1 data value (previously 0).
      • The Indent error message now exposes 3 data values (previously 2).
      • These changes also affect the same error codes for the PSR12.Classes.AnonClassDeclaration and Squiz.Functions.MultiLineFunctionDeclaration sniffs.
    • PSR2.Classes.ClassDeclaration #1446
      • The ExtendsLine and ImplementsLine error messages now expose 3 data values (previously 1).
      • The SpaceBeforeExtends and SpaceBeforeImplements error messages now expose 2 data values (previously 1).
      • These changes also affect the same error codes for the PSR12.Classes.AnonClassDeclaration and Squiz.Classes.ClassDeclaration sniffs.
    • PSR2.ControlStructures.SwitchDeclaration #1447
      • The defaultNotLower and caseNotLower error messages now expose 3 data values (previously 2).
      • The SpaceBeforeColonDEFAULT and SpaceBeforeColonCASE error messages now expose 1 data value (previously 0).
      • The BodyOnNextLineDEFAULT and BodyOnNextLineCASE error messages now expose 1 data value (previously 0).
      • The WrongOpenerdefault and WrongOpenercase error messages now expose 1 data value (previously 0).
    • Squiz.ControlStructures.SwitchDeclaration #1449
      • The CaseNotLower and DefaultNotLower error messages now expose 3 data values (previously 2).
      • The CaseIndent and DefaultIndent error messages now expose 2 data values (previously 0).
      • The SpaceBeforeColonCase and SpaceBeforeColonDefault error messages now expose 1 data value (previously 0).
      • The BreakIndent error message now exposes 1 data value (previously 0).
      • The SpacingAfterCase and SpacingAfterDefault error messages now expose 1 data value (previously 0).
    • Squiz.Functions.FunctionDeclarationArgumentSpacing #1452
      • The SpaceBeforeEquals error message now exposes 3 data values (previously 2).
      • The SpaceAfterEquals error message now exposes 3 data values (previously 2).
    • Squiz.Functions.MultiLineFunctionDeclaration #1453
      • The FirstParamSpacing and UseFirstParamSpacing error messages now expose 1 data value (previously 0).
      • The OneParamPerLine and UseOneParamPerLine error messages now expose 1 data value (previously 0).
      • These changes also affect the same error codes for the PSR12.Classes.AnonClassDeclaration sniff.
    • If you have customised the error messages of these sniffs, please review your ruleset after upgrading.
    • Thanks to Zhang WenTao for these patches.

... (truncated)

Changelog

Sourced from squizlabs/php_codesniffer's changelog.

[4.0.4] - 2026-08-06

The 4.0.2 release, the 4.0.3 and the 4.0.4 release are 100% the same, there was just a slight snafu in the release publication on GitHub. Sorry for the confusion.

[4.0.3] - 2026-08-06

WITHDRAWN

[4.0.2] - 2026-08-06

This is a security release and all users are advised to update their install(s) as soon as possible. The security issue only affects users of the Gitblame, Hgblame or Svnblame report(s).

Added

  • Tokenizer support for the PHP 8.5 (void) cast. #1325 The T_VOID_CAST token has been added to the Tokens::CAST_TOKENS array.
  • suggest section to the composer.json file to inform users about the recommended iconv and pcntl PHP extensions. #1388

Changed

  • Clarified that libxml is a required PHP extension. #1409
  • Squiz.Scope.StaticThisUsage: the sniff will now also search for the use of $this in static closures. #1377
  • The Generic.PHP.LowerCaseKeyword, Generic.WhiteSpace.LanguageConstructSpacing and Squiz.Functions.FunctionDeclarationArgumentSpacing sniffs no longer embed UTF-8 middot characters for spaces in error messages. #1379, #1389 Fixes [Squiz/#2652][sq-2652].
  • PSR2.ControlStructures.SwitchDeclaration: the error message for the use of colon + curly braces (WrongOpener*) has been made more informative. #1358. Fixes #1322.
  • The error messages for the following sniffs have been improved by exposing more data placeholders:
    • PEAR.Functions.FunctionDeclaration #1445
      • The CloseBracketLine error message now exposes 1 data value (previously 0).
      • The EmptyLine error message now exposes 1 data value (previously 0).
      • The Indent error message now exposes 3 data values (previously 2).
      • These changes also affect the same error codes for the PSR12.Classes.AnonClassDeclaration and Squiz.Functions.MultiLineFunctionDeclaration sniffs.
    • PSR2.Classes.ClassDeclaration #1446
      • The ExtendsLine and ImplementsLine error messages now expose 3 data values (previously 1).
      • The SpaceBeforeExtends and SpaceBeforeImplements error messages now expose 2 data values (previously 1).
      • These changes also affect the same error codes for the PSR12.Classes.AnonClassDeclaration and Squiz.Classes.ClassDeclaration sniffs.
    • PSR2.ControlStructures.SwitchDeclaration #1447
      • The defaultNotLower and caseNotLower error messages now expose 3 data values (previously 2).
      • The SpaceBeforeColonDEFAULT and SpaceBeforeColonCASE error messages now expose 1 data value (previously 0).
      • The BodyOnNextLineDEFAULT and BodyOnNextLineCASE error messages now expose 1 data value (previously 0).
      • The WrongOpenerdefault and WrongOpenercase error messages now expose 1 data value (previously 0).
    • Squiz.ControlStructures.SwitchDeclaration #1449
      • The CaseNotLower and DefaultNotLower error messages now expose 3 data values (previously 2).
      • The CaseIndent and DefaultIndent error messages now expose 2 data values (previously 0).
      • The SpaceBeforeColonCase and SpaceBeforeColonDefault error messages now expose 1 data value (previously 0).
      • The BreakIndent error message now exposes 1 data value (previously 0).
      • The SpacingAfterCase and SpacingAfterDefault error messages now expose 1 data value (previously 0).
    • Squiz.Functions.FunctionDeclarationArgumentSpacing #1452
      • The SpaceBeforeEquals error message now exposes 3 data values (previously 2).
      • The SpaceAfterEquals error message now exposes 3 data values (previously 2).

... (truncated)

Commits
  • bbdc3d0 Merge branch '3.x' into 4.x
  • 3d9e4c6 Merge pull request #1471 from PHPCSStandards/feature/update-gpg-key-info
  • 0c3dc35 Changelog: add release links
  • ddc0bf9 Changelog update for 4.0.3 + 4.0.4
  • 09a2847 Config: update version nr to next
  • aa43975 Merge branch '3.x' into 4.x
  • 29a0859 Config: update version nr to next
  • 305aebb Update for new GPG keys
  • 74ee2d4 Merge pull request #1475 from PHPCSStandards/feature/changelog-4.0.2
  • 2f4a106 Changelog for the 4.0.2 release
  • Additional commits viewable in compare view

Updates vlucas/phpdotenv from 5.6.4 to 5.7.0

Release notes

Sourced from vlucas/phpdotenv's releases.

v5.7.0

What's Changed

New Contributors

Full Changelog: vlucas/phpdotenv@v5.6.4...v5.7.0

Commits
  • 301c079 Resolve the remaining static analysis baseline entries (#614)
  • 5d0bb3b Document the real parsing, nesting, comment, escape and validation rules (#609)
  • 4426075 Stop comments from starting multiline values (#615)
  • eec19ee Add regression tests for existing behaviour (#608)
  • 226b4ed Improve diagnostics and messages (#607)
  • 4f84f7e Strip a leading UTF-8 byte order mark from string content (#606)
  • 4b900c5 Resolve nested variables without re-copying the value prefix (#605)
  • dd5b391 Remove quadratic value parsing (#604)
  • 46d5ce3 Skip environment writes and reads for names or values containing a null byte ...
  • 8bf174e Fix memory-safety crash on invalid UTF-8 variable names (#602)
  • Additional commits viewable in compare view

Updates symfony/console from 8.1.2 to 8.1.8

Release notes

Sourced from symfony/console's releases.

v8.1.8

Changelog (symfony/console@v8.1.7...v8.1.8)

v8.1.7

Changelog (symfony/console@v8.1.6...v8.1.7)

v8.1.6

Changelog (symfony/console@v8.1.5...v8.1.6)

v8.1.5

Changelog (symfony/console@v8.1.4...v8.1.5)

v8.1.4

Changelog (symfony/console@v8.1.2...v8.1.4)

Commits
  • 4b81146 Merge branch '7.4' into 8.1
  • d7bca2f Merge branch '6.4' into 7.4
  • 0f758df [Console] Fix quadratic formatting of non-ASCII content
  • 29afb89 Merge branch '7.4' into 8.1
  • 3a19734 [Console] Report a validation error instead of a TypeError on numeric argumen...
  • 117a485 Merge branch '7.4' into 8.1
  • 9553be3 [Console] [FrameworkBundle] Adapt merged tests to the 7.4 APIs
  • 30dc1f2 Merge branch '6.4' into 7.4
  • 9e118dd [Console] Keep messages containing malformed UTF-8 when wrapping
  • 31de385 Merge branch '7.4' into 8.1
  • Additional commits viewable in compare view

Updates lion/test from 4.1.4 to 4.1.5

Release notes

Sourced from lion/test's releases.

v4.1.5

What's Changed

Full Changelog: lion-packages/test@v4.1.4...v4.1.5

Commits
  • 9b72176 Merge pull request #77 from lion-packages/dependabot/maintenance-186b4b21e5
  • 0c10b33 build(deps-dev): bump squizlabs/php_codesniffer from 4.0.1 to 4.0.2
  • ce2dd6a Merge pull request #76 from lion-packages/dependabot/maintenance-e526da95e7
  • 07d4f95 build(deps-dev): bump the maintenance group with 4 updates
  • See full diff in compare view

Updates phpunit/phpunit from 13.2.6 to 13.3.5

Release notes

Sourced from phpunit/phpunit's releases.

PHPUnit 13.3.5

Changed

  • Control characters and ANSI escape sequences in user-supplied strings such as test names, data set names, and messages are now made visible as \u{NNNN} escape sequences instead of being passed through to the terminal
  • Control characters in user-supplied strings are now also made visible in the compact output
  • Line feeds in the name of a test no longer break the header line of a record in the compact output

Learn how to install or update PHPUnit 13.3 in the documentation.

Keep up to date with PHPUnit:

PHPUnit 13.3.4

Fixed

  • #6965: Temporary file used by SourceMapper may be deleted prematurely
  • The compact output displays details on PHPUnit deprecations and PHPUnit notices even when --display-phpunit-deprecations and --display-phpunit-notices are not used
  • The summary line of the compact output does not report the number of PHPUnit deprecations, PHPUnit notices, and PHPUnit warnings

Learn how to install or update PHPUnit 13.3 in the documentation.

Keep up to date with PHPUnit:

PHPUnit 13.3.3

Fixed

  • Paths of included files are now escaped when generating the code that is executed in a separate process, so that a path containing special characters no longer produces broken code
  • Tests of a test class that is skipped as a whole are missing from the TestDox output
  • A test that is skipped or marked incomplete before it started is missing from the TestDox output
  • A test that is marked incomplete before it started is not counted in the number of tests that ran
  • No progress is printed for a test that is marked incomplete before it started

Learn how to install or update PHPUnit 13.3 in the documentation.

Keep up to date with PHPUnit:

... (truncated)

Changelog

Sourced from phpunit/phpunit's changelog.

[13.3.5] - 2026-09-25

Changed

  • Control characters and ANSI escape sequences in user-supplied strings such as test names, data set names, and messages are now made visible as \u{NNNN} escape sequences instead of being passed through to the terminal
  • Control characters in user-supplied strings are now also made visible in the compact output
  • Line feeds in the name of a test no longer break the header line of a record in the compact output

[13.3.4] - 2026-09-15

Fixed

  • #6965: Temporary file used by SourceMapper may be deleted prematurely
  • The compact output displays details on PHPUnit deprecations and PHPUnit notices even when --display-phpunit-deprecations and --display-phpunit-notices are not used
  • The summary line of the compact output does not report the number of PHPUnit deprecations, PHPUnit notices, and PHPUnit warnings

[13.3.3] - 2026-09-09

Fixed

  • Paths of included files are now escaped when generating the code that is executed in a separate process, so that a path containing special characters no longer produces broken code
  • Tests of a test class that is skipped as a whole are missing from the TestDox output
  • A test that is skipped or marked incomplete before it started is missing from the TestDox output
  • A test that is marked incomplete before it started is not counted in the number of tests that ran
  • No progress is printed for a test that is marked incomplete before it started

[13.3.2] - 2026-08-27

Fixed

  • #6904: SourceMap is built in child process even though identifyIssueTrigger is disabled
  • #6924: #[CoversFile] attribute is not considered for risky test check

[13.3.1] - 2026-08-13

Changed

  • Invoking a static hook method such as setUpBeforeClass() no longer triggers a deprecation warning on PHP 8.6

[13.3.0] - 2026-08-07

Added

  • #3794: Filesystem-based code coverage targeting
  • #5758: Make export of objects customizable
  • #6546: Both property hooks can now be configured on test doubles of virtual hooked properties, even when the doubled property only declares one of them
  • #6586: Custom code coverage driver support
  • #6591: Repeated test execution using --repeat CLI option and #[Repeat] attribute
  • #6701: Allow expectOutputString() and expectOutputRegex() to be combined and repeated
  • #6710: Deprecation Filters

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the maintenance group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [phpstan/phpstan](https://github.com/phpstan/phpstan-phar-composer-source) | `2.2.6` | `2.2.16` |
| [squizlabs/php_codesniffer](https://github.com/PHPCSStandards/PHP_CodeSniffer) | `4.0.1` | `4.0.4` |
| [vlucas/phpdotenv](https://github.com/vlucas/phpdotenv) | `5.6.4` | `5.7.0` |
| [symfony/console](https://github.com/symfony/console) | `8.1.2` | `8.1.8` |
| [lion/test](https://github.com/lion-packages/test) | `4.1.4` | `4.1.5` |
| [phpunit/phpunit](https://github.com/sebastianbergmann/phpunit) | `13.2.6` | `13.3.5` |


Updates `phpstan/phpstan` from 2.2.6 to 2.2.16
- [Commits](https://github.com/phpstan/phpstan-phar-composer-source/commits)

Updates `squizlabs/php_codesniffer` from 4.0.1 to 4.0.4
- [Release notes](https://github.com/PHPCSStandards/PHP_CodeSniffer/releases)
- [Changelog](https://github.com/PHPCSStandards/PHP_CodeSniffer/blob/4.x/CHANGELOG-4.x.md)
- [Commits](PHPCSStandards/PHP_CodeSniffer@4.0.1...4.0.4)

Updates `vlucas/phpdotenv` from 5.6.4 to 5.7.0
- [Release notes](https://github.com/vlucas/phpdotenv/releases)
- [Commits](vlucas/phpdotenv@v5.6.4...v5.7.0)

Updates `symfony/console` from 8.1.2 to 8.1.8
- [Release notes](https://github.com/symfony/console/releases)
- [Changelog](https://github.com/symfony/console/blob/8.2/CHANGELOG.md)
- [Commits](symfony/console@v8.1.2...v8.1.8)

Updates `lion/test` from 4.1.4 to 4.1.5
- [Release notes](https://github.com/lion-packages/test/releases)
- [Commits](lion-packages/test@v4.1.4...v4.1.5)

Updates `phpunit/phpunit` from 13.2.6 to 13.3.5
- [Release notes](https://github.com/sebastianbergmann/phpunit/releases)
- [Changelog](https://github.com/sebastianbergmann/phpunit/blob/13.3.5/ChangeLog-13.3.md)
- [Commits](sebastianbergmann/phpunit@13.2.6...13.3.5)

---
updated-dependencies:
- dependency-name: phpstan/phpstan
  dependency-version: 2.2.16
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maintenance
- dependency-name: squizlabs/php_codesniffer
  dependency-version: 4.0.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maintenance
- dependency-name: vlucas/phpdotenv
  dependency-version: 5.7.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maintenance
- dependency-name: symfony/console
  dependency-version: 8.1.8
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maintenance
- dependency-name: lion/test
  dependency-version: 4.1.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maintenance
- dependency-name: phpunit/phpunit
  dependency-version: 13.3.5
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maintenance
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Project dependencies are updated php Pull requests that update php code labels Oct 1, 2026
@sonarqubecloud

sonarqubecloud Bot commented Oct 1, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Project dependencies are updated php Pull requests that update php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants