Skip to content

Bump the prod-dependencies group with 7 updates - #842

Merged
pylipp merged 3 commits into
masterfrom
dependabot-composer-prod-dependencies-f935a0d327
Oct 5, 2026
Merged

pylipp merged 3 commits into
masterfrom
dependabot-composer-prod-dependencies-f935a0d327

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the prod-dependencies group with 7 updates:

Package From To
smarty/smarty 5.6.0 5.8.4
kriswallsmith/buzz 1.3.0 1.4.0
endroid/qr-code 6.0.9 6.1.3
sentry/sentry 4.16.0 4.32.0
php-http/curl-client 2.3.3 2.4.0
open-telemetry/exporter-otlp 1.3.2 1.4.0
open-telemetry/sdk 1.7.0 1.15.0

Updates smarty/smarty from 5.6.0 to 5.8.4

Release notes

Sourced from smarty/smarty's releases.

v5.8.4

No release notes provided.

v5.8.3

What's Changed

Full Changelog: smarty-php/smarty@v5.8.2...v5.8.3

v5.8.2

What's Changed

  • Security: prevent symlinks inside a trusted secure_dir/template directory from being used to read files outside of it (CWE-22 path traversal), affecting {include} and {fetch} of local files
  • Security: {html_image} now escapes the file, path_prefix, href/link, width and height attributes (it already escaped alt and pass-through attributes), and {html_select_date} casts day_size/month_size/year_size to int (matching {html_select_time}), preventing untrusted values passed into these attributes from breaking out of the generated HTML (CWE-79)
  • Security: {fetch} no longer follows HTTP redirects for remote resources while a security policy is active, preventing an open redirect on a trusted host from bypassing trusted_uri (CWE-918 server-side request forgery)
  • Fixed "Attempt to assign property step on null" error when using a {for} loop inside a block of an extended template #1036

New Contributors

Full Changelog: smarty-php/smarty@v5.8.1...v5.8.2

v5.8.1

What's Changed

Internal changes

New Contributors

Full Changelog: smarty-php/smarty@v5.8.0...v5.8.1

v5.8.0

What's Changed

Full Changelog: smarty-php/smarty@v5.7.0...v5.8.0

v5.7.0

What's Changed

... (truncated)

Changelog

Sourced from smarty/smarty's changelog.

[5.8.4] - 2026-06-29

  • Fixed a TypeError on PHP 8 when Security::$static_classes was set to a non-array value (e.g. the string 'none') to disable static class access; any non-array value now cleanly denies access. Use Security::$static_classes = null to disable access to all static classes.
  • Security: the built-in stream: resource type now validates the nested stream wrapper against the security policy, so a template such as stream:php://filter/... can no longer bypass Security::$streams (including Security::$streams = null) to read local files (CWE-22)

[5.8.3] - 2026-06-28

  • fixed a regression from #1189 where a child template's block override no longer applied to a template {include}d by the parent #1192

[5.8.2] - 2026-06-24

  • Security: prevent symlinks inside a trusted secure_dir/template directory from being used to read files outside of it (CWE-22 path traversal), affecting {include} and {fetch} of local files
  • Security: {html_image} now escapes the file, path_prefix, href/link, width and height attributes (it already escaped alt and pass-through attributes), and {html_select_date} casts day_size/month_size/year_size to int (matching {html_select_time}), preventing untrusted values passed into these attributes from breaking out of the generated HTML (CWE-79)
  • Security: {fetch} no longer follows HTTP redirects for remote resources while a security policy is active, preventing an open redirect on a trusted host from bypassing trusted_uri (CWE-918 server-side request forgery)
  • Fixed "Attempt to assign property step on null" error when using a {for} loop inside a block of an extended template #1036

[5.8.1] - 2026-06-23

  • Re-activated unit tests for user literals, which were previously disabled due to a bug in refactoring to v5.
  • fixed a bug where child template's block content leaked into subsequent rendering of the parent template #1189
  • Moved all unit test-generated output from inside the working tree to tmp files #1178

[5.8.0] - 2026-02-15

  • Added support for Backed Enums for php versions >= 8.1 #1171
  • Added support for new 'matches' operator doing regex matching #1169
  • Update documentation to clarify that include inline is currently not implemented in Smarty v5 #1152
  • Support for Laravel Collections style object chaining for objects return from function calls implemented as modifiers #1151

[5.7.0] - 2025-11-19

  • PHP 8.5 support
Commits
  • 94a27cb Merge branch 'release/5.8.4'
  • badc5ef version bump
  • 2ae0f9a Fix TypeError for non-array static_classes in Security policy (#1198)
  • b668745 drop unused version attribute from docker-compose.yml
  • 3c9f77a Security: validate nested stream wrapper in stream: resource (CWE-22) (#1195)
  • 042dff6 Merge branch 'release/5.8.3'
  • 1830aa7 version bump
  • b83ffdd requirements for building docs, switched test-runner from mutagen to basic do...
  • ac27e1e fixed a regression from #1189 where a child template's block override no long...
  • 17fae11 update documentation for building and previewing with mkdocs, fix unit tests ...
  • Additional commits viewable in compare view

Updates kriswallsmith/buzz from 1.3.0 to 1.4.0

Release notes

Sourced from kriswallsmith/buzz's releases.

Release 1.4.0

Support for Symfony 8

What's Changed

New Contributors

Full Changelog: kriswallsmith/Buzz@1.3.0...1.4.0

Commits

Updates endroid/qr-code from 6.0.9 to 6.1.3

Commits

Updates sentry/sentry from 4.16.0 to 4.32.0

Release notes

Sourced from sentry/sentry's releases.

4.32.0

The Sentry SDK team is happy to announce the immediate availability of Sentry PHP SDK v4.32.0.

Features

Bug Fixes

4.31.0

The Sentry SDK team is happy to announce the immediate availability of Sentry PHP SDK v4.31.0.

Features

  • Always capture logs and metrics when their APIs or integrations are used. The deprecated enable_logs and enable_metrics options no longer have any effect. To disable sending, return null from before_send_log or before_send_metric. [(#2187)](getsentry/sentry-php#2187)

Misc

4.30.0

The Sentry SDK team is happy to announce the immediate availability of Sentry PHP SDK v4.30.0.

Features

Bug Fixes

  • Strip breadcrumb metadata when capturing out-of-memory errors to prevent events with large breadcrumbs from being silently dropped. [(#2150)](getsentry/sentry-php#2150)

Misc

4.29.0

The Sentry SDK team is happy to announce the immediate availability of Sentry PHP SDK v4.29.0.

Features

... (truncated)

Changelog

Sourced from sentry/sentry's changelog.

4.32.0

The Sentry SDK team is happy to announce the immediate availability of Sentry PHP SDK v4.32.0.

Features

Bug Fixes

4.31.0

The Sentry SDK team is happy to announce the immediate availability of Sentry PHP SDK v4.31.0.

Features

  • Always capture logs and metrics when their APIs or integrations are used. The deprecated enable_logs and enable_metrics options no longer have any effect. To disable sending, return null from before_send_log or before_send_metric. [(#2187)](getsentry/sentry-php#2187)

Misc

4.30.0

The Sentry SDK team is happy to announce the immediate availability of Sentry PHP SDK v4.30.0.

Features

Bug Fixes

  • Strip breadcrumb metadata when capturing out-of-memory errors to prevent events with large breadcrumbs from being silently dropped. [(#2150)](getsentry/sentry-php#2150)

Misc

4.29.0

... (truncated)

Commits
  • c345642 release: 4.32.0
  • 875296f Prepare 4.32.0 (#2221)
  • cdf8aa1 feat: backport attachment support from 5.x (#2217)
  • 26e4aca chore(deps): bump codecov/codecov-action from 7.0.0 to 7.1.1 (#2208)
  • 07966f8 chore(deps): bump getsentry/github-workflows/validate-pr from 4013fc6e1aeb1be...
  • aa5511e chore(deps): bump getsentry/craft from 2.30.1 to 2.31.0 (#2197)
  • f166330 feat: wrap user provided callbacks in try/catch to prevent application crashe...
  • ab0caac fix: Avoid PHP 8.5 warnings when serializing INF, NAN and large floats (#2192)
  • 47b7ceb feat: allow providing a hub when starting a runtime context (#2191)
  • 2b1265c feat: support concurrent runtime contexts (#2190)
  • Additional commits viewable in compare view

Updates php-http/curl-client from 2.3.3 to 2.4.0

Release notes

Sourced from php-http/curl-client's releases.

2.4.0

  • Added support for Symfony 8
  • Added support for PHP 8.5
  • Remove support for PHP < 8.1

2.3.4

  • Added support for Symfony 8
  • Added support for PHP 8.5
Changelog

Sourced from php-http/curl-client's changelog.

2.4.0 - 2025-12-09

  • Added support for Symfony 8
  • Added support for PHP 8.5
  • Remove support for PHP < 8.1
Commits

Updates open-telemetry/exporter-otlp from 1.3.2 to 1.4.0

Release notes

Sourced from open-telemetry/exporter-otlp's releases.

Release 1.4.0

What's Changed:

  • Revert "Fix getLabel() deprecation warning with Protobuf 4.33+" by @​Nevay in 1880

Full Changelog: opentelemetry-php/exporter-otlp@1.3.4...1.4.0

Release 1.3.4

What's Changed:

Full Changelog: opentelemetry-php/exporter-otlp@1.3.3...1.3.4

Release 1.3.3

What's Changed:

Full Changelog: opentelemetry-php/exporter-otlp@1.3.2...1.3.3

Commits

Updates open-telemetry/sdk from 1.7.0 to 1.15.0

Release notes

Sourced from open-telemetry/sdk's releases.

Release 1.15.0

What's Changed:

  • Avoid collecting unsanitized process arguments by @​PuvaanRaaj in 1993
  • fix(sdk): don't emit placeholder service.version in Composer detector by @​PuvaanRaaj in 2004
  • fix(ResourceInfoFactory): Align ResourceInfoFactory detectors to otel specification by @​jerrytfleung in 2006
  • fix(sdk): require sem-conv ^1.38 for VERSION_1_38_0 constant by @​PuvaanRaaj in 2003
  • fix(sdk): skip absent keys in FilteredAttributeProcessor by @​jorgsowa in 2000
  • fix(sdk): guard Span::setAttributes() against mutation after end() by @​jorgsowa in 1999
  • chore(deps): bump open-telemetry/sem-conv to ^1.36.0 by @​intuibase in 1994
  • fix(sdk): wire meterProvider for span self-observability metrics and add otel.sdk.span.ended by @​intuibase in 1990
  • feat(sdk): implement OTel SDK self-observability metrics by @​intuibase in 1987
  • Fix(SDK): Auto root span start timestamps precision by @​zigzagdev in 1985
  • Allow span suppression strategy configuration using file-based and env-based config by @​Nevay in 1920
  • Fix span suppression with non recording spans by @​Nevay in 1921

Full Changelog: opentelemetry-php/sdk@1.14.0...1.15.0

Release 1.14.0

What's Changed:

Full Changelog: opentelemetry-php/sdk@1.13.0...1.14.0

Release 1.13.0

What's Changed:

Full Changelog: opentelemetry-php/sdk@1.12.0...1.13.0

Release 1.12.0

What's Changed:

Full Changelog: opentelemetry-php/sdk@1.11.0...1.12.0

Release 1.11.0

What's Changed:

Full Changelog: opentelemetry-php/sdk@1.10.0...1.11.0

Release 1.10.0

What's Changed:

... (truncated)

Commits
  • 77e1aa7 fix(resource): avoid collecting process arguments (#1993)
  • 9ddbce2 fix(sdk): don't emit placeholder service.version in Composer detector (#2004)
  • bbd83b8 fix(ResourceInfoFactory): Align ResourceInfoFactory detectors to otel specifi...
  • 8e89d16 fix(sdk): require sem-conv ^1.38 for VERSION_1_38_0 constant (#2003)
  • 00a5cda fix(sdk): skip absent keys in FilteredAttributeProcessor (#2000)
  • 22634e8 fix(sdk): guard Span::setAttributes() against mutation after end() (#1999)
  • da5c115 chore(deps): bump open-telemetry/sem-conv to ^1.36.0 (#1994)
  • ca93a7b fix(sdk): wire meterProvider for span self-observability metrics and add otel...
  • 135c15c feat(sdk): implement OTel SDK self-observability metrics (#1987)
  • 809371d Fix(SDK): Auto root span start timestamps precision (#1985)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the prod-dependencies group with 7 updates:

| Package | From | To |
| --- | --- | --- |
| [smarty/smarty](https://github.com/smarty-php/smarty) | `5.6.0` | `5.8.4` |
| [kriswallsmith/buzz](https://github.com/kriswallsmith/Buzz) | `1.3.0` | `1.4.0` |
| [endroid/qr-code](https://github.com/endroid/qr-code) | `6.0.9` | `6.1.3` |
| [sentry/sentry](https://github.com/getsentry/sentry-php) | `4.16.0` | `4.32.0` |
| [php-http/curl-client](https://github.com/php-http/curl-client) | `2.3.3` | `2.4.0` |
| [open-telemetry/exporter-otlp](https://github.com/opentelemetry-php/exporter-otlp) | `1.3.2` | `1.4.0` |
| [open-telemetry/sdk](https://github.com/opentelemetry-php/sdk) | `1.7.0` | `1.15.0` |


Updates `smarty/smarty` from 5.6.0 to 5.8.4
- [Release notes](https://github.com/smarty-php/smarty/releases)
- [Changelog](https://github.com/smarty-php/smarty/blob/master/CHANGELOG.md)
- [Commits](smarty-php/smarty@v5.6.0...v5.8.4)

Updates `kriswallsmith/buzz` from 1.3.0 to 1.4.0
- [Release notes](https://github.com/kriswallsmith/Buzz/releases)
- [Changelog](https://github.com/kriswallsmith/Buzz/blob/master/CHANGELOG.md)
- [Commits](kriswallsmith/Buzz@1.3.0...1.4.0)

Updates `endroid/qr-code` from 6.0.9 to 6.1.3
- [Commits](endroid/qr-code@6.0.9...6.1.3)

Updates `sentry/sentry` from 4.16.0 to 4.32.0
- [Release notes](https://github.com/getsentry/sentry-php/releases)
- [Changelog](https://github.com/getsentry/sentry-php/blob/master/CHANGELOG.md)
- [Commits](getsentry/sentry-php@4.16.0...4.32.0)

Updates `php-http/curl-client` from 2.3.3 to 2.4.0
- [Release notes](https://github.com/php-http/curl-client/releases)
- [Changelog](https://github.com/php-http/curl-client/blob/2.x/CHANGELOG.md)
- [Commits](php-http/curl-client@2.3.3...2.4.0)

Updates `open-telemetry/exporter-otlp` from 1.3.2 to 1.4.0
- [Release notes](https://github.com/opentelemetry-php/exporter-otlp/releases)
- [Commits](opentelemetry-php/exporter-otlp@1.3.2...1.4.0)

Updates `open-telemetry/sdk` from 1.7.0 to 1.15.0
- [Release notes](https://github.com/opentelemetry-php/sdk/releases)
- [Commits](opentelemetry-php/sdk@1.7.0...1.15.0)

---
updated-dependencies:
- dependency-name: smarty/smarty
  dependency-version: 5.8.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-dependencies
- dependency-name: kriswallsmith/buzz
  dependency-version: 1.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-dependencies
- dependency-name: endroid/qr-code
  dependency-version: 6.1.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-dependencies
- dependency-name: sentry/sentry
  dependency-version: 4.32.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-dependencies
- dependency-name: php-http/curl-client
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-dependencies
- dependency-name: open-telemetry/exporter-otlp
  dependency-version: 1.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-dependencies
- dependency-name: open-telemetry/sdk
  dependency-version: 1.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@pylipp

pylipp commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

@copilot remove the open-telemetry packages from composer.json. Pin endroid/qr-code to 6.0.9. Update the composer.lock file.
Verify that you can run the copilot setup steps successfully (esp. composer install -n and php build.php)

Co-authored-by: pylipp <10617122+pylipp@users.noreply.github.com>

Copilot AI commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

@copilot remove the open-telemetry packages from composer.json. Pin endroid/qr-code to 6.0.9. Update the composer.lock file.
Verify that you can run the copilot setup steps successf...

Done in 2eaa8b (commit on top of the bump branch): removed open-telemetry/exporter-otlp and open-telemetry/sdk from composer.json (confirmed unused in the codebase), pinned endroid/qr-code to 6.0.9, and regenerated composer.lock. Verified composer install -n and php build.php both complete successfully.

Copilot AI requested a review from pylipp October 5, 2026 12:58
@pylipp
pylipp requested a balanced review from Copilot October 5, 2026 13:05

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The QR Code and OpenTelemetry changes do not match the seven advertised dependency upgrades.

Review effort: Balanced
Findings: 1 Medium severity · 1 Low severity

Open (2)
What changed in this PR

Updates PHP production dependencies and refreshes resolved transitive packages.

Changes:

  • Upgrades Smarty, Buzz, Sentry, and curl-client.
  • Refreshes transitive dependencies.
  • Pins QR Code unchanged and removes OpenTelemetry, contrary to the PR description.
File Description
composer.json Updates direct dependency constraints.
composer.lock Refreshes resolved production dependencies.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment thread composer.json
Comment thread composer.json
@pylipp
pylipp merged commit c12bdd1 into master Oct 5, 2026
6 checks passed
@pylipp
pylipp deleted the dependabot-composer-prod-dependencies-f935a0d327 branch October 5, 2026 14:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update Php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants