Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Sep 18, 2023

Bumps composer/composer from 2.6.2 to 2.6.3.

Release notes

Sourced from composer/composer's releases.

2.6.3

  • Added audit.abandoned config setting. Can be set to ignore, report (current default) or fail (future default in 2.7) to make the audit command report abandoned packages as a security problem (#11639)
  • Added a warning when duplicates files autoload rules are detected (#11109)
  • Fixed unhandled promise rejection regression (#11620)
  • Fixed loading of root aliases on path repo packages when doing partial updates (#11632)
  • Fixed archive command not producing the correct output if the temp dir is a symlink (#11636)
  • Fixed some replaced packages being incorrectly missing when unlocked in a partial update (#11629)
Changelog

Sourced from composer/composer's changelog.

[2.6.3] 2023-09-15

  • Added audit.abandoned config setting. Can be set to ignore, report (current default) or fail (future default in 2.7) to make the audit command report abandoned packages as a security problem (#11639)
  • Added a warning when duplicates files autoload rules are detected (#11109)
  • Fixed unhandled promise rejection regression (#11620)
  • Fixed loading of root aliases on path repo packages when doing partial updates (#11632)
  • Fixed archive command not producing the correct output if the temp dir is a symlink (#11636)
  • Fixed some replaced packages being incorrectly missing when unlocked in a partial update (#11629)
Commits
  • ff47783 Release 2.6.3
  • 14233f1 Update changelog
  • af90590 Update baseline (1689, 92)
  • 218b904 Test status command (#11522)
  • e3484c8 Add audit.abandoned warnings for abandoned packages, fixes #11623 (#11639)
  • 3bc72f7 Fix build, update deps
  • e2f5afd Add warning when duplicate "files" autoload rules are detected (#11109)
  • 5474dc9 Fixed replaced packages being incorrectly missing when unlocked by an old ver...
  • 1e4966c Get realpath for ZipArchive (#11636)
  • 7a7f364 Fix bitbucket redirect URLs failing old PHP builds which do not support long ...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Bumps [composer/composer](https://github.com/composer/composer) from 2.6.2 to 2.6.3. - [Release notes](https://github.com/composer/composer/releases) - [Changelog](https://github.com/composer/composer/blob/main/CHANGELOG.md) - [Commits](composer/composer@2.6.2...2.6.3) --- updated-dependencies: - dependency-name: composer/composer dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file php Pull requests that update Php code labels Sep 18, 2023
@coveralls
Copy link

Pull Request Test Coverage Report for Build 6217086029

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 88.679%

Totals Coverage Status
Change from base Build 6141071192: 0.0%
Covered Lines: 517
Relevant Lines: 583

💛 - Coveralls
@github-actions github-actions bot merged commit 2988951 into main Sep 18, 2023
@github-actions github-actions bot deleted the dependabot/composer/composer/composer-2.6.3 branch September 18, 2023 01:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update Php code

2 participants