SYN-648: Bump guzzle, phpunit and symfony/process to clear High alerts - #193
Conversation
Regenerate composer.lock so guzzlehttp/guzzle (7.15.5), phpunit/phpunit (9.6.37) and symfony/process (5.4.51) are at patched versions, clearing the 3 open High Dependabot alerts. composer.json is unchanged. Also fix the missing space in run_tests.yml so CI actually runs the unit suite. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The test referenced USVerificationsApi, but the generated class is UsVerificationsApi, so PSR-4 autoloading fails on case-sensitive filesystems. This was hidden because CI ran zero unit tests until the run_tests.yml fix in this branch. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
PR Summary by QodoPatch high-risk PHP dependencies and restore CI unit-test coverage
AI Description
Diagram
High-Level Assessment
Files changed (3)
|
Code Review by Qodo
1.
|
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Description
Clears the 3 open High Dependabot alerts on lob-php (guzzlehttp/guzzle #53, phpunit/phpunit #25, symfony/process #24) by regenerating
composer.lock.composer.jsonis unchanged because its ranges already allowed the patched versions.Files:
composer.lock,.github/workflows/run_tests.yml,test/Unit/USVerificationsApiUnitTest.php.CI fix:
run_tests.yml:20ran--group unit--coverage-text(missing space), so CI ran zero unit tests. It now runs--group unit --coverage-text, so CI actually runs the unit suite from this PR on.Hidden test failure fixed (operator-approved): once CI actually ran the unit suite, 9 tests in
test/Unit/USVerificationsApiUnitTest.phperrored on Linux withClass "OpenAPI\Client\Api\USVerificationsApi" not found. The generated class isUsVerificationsApi(lib/Api/UsVerificationsApi.php), and PSR-4 autoloading is case-sensitive on Linux. The test has referenced the wrong case since #189 (2c235e4). It stayed hidden because the--group unit--coverage-texttypo matched zero tests, and case-insensitive macOS filesystems resolve it anyway. The fix changes only the test'suse/newreferences toUsVerificationsApi. Generatedlib/and file names are untouched. Verified 357/357 on a case-sensitive filesystem.Transitive major bumps in the lock (pulled in by guzzle 7.15 / phpunit 9.6 via
--with-all-dependencies, not hand-picked):lib/doesn't implement PSR-7 interfaces or call removed promise functions; onlyPsr7\Utils::tryFopenis used.composer.jsonranges.PHP version: the lock was regenerated and tested on PHP 8.1 (
php:8.1-cli), the lowest 8.x incomposer.json's^7.3 || ^8.1. The existing base lock couldn't install on PHP >= 8.2 (prophecy), and the lock's dev set now effectively needs PHP >= 8.1 (doctrine/instantiator 2). The tech-lead review also ran the suite on PHP 8.3 (matchingubuntu-latest).Supersedes Dependabot PR #171 (guzzlehttp/psr7 2.4.5, Medium), since psr7 is now 2.13.1. Close it after this merges.
Story
SYN-648 (parent SYN-624, Sync High CVE Remediation 2026-08)
Related PR's
Verify
Gate results (run in Docker,
php:8.1-cli+ Composer 2):vendor/bin/phpunit --group unit --coverage-text --configuration=phpunit.xml.dist: base 357 tests / 542 assertions OK; after 357 / 542 OK (also run on a case-sensitive filesystem copy, matching Linux CI).composer installfrom a cleanvendor/: OK.composer showconfirms the versions above.test/Integration, needs live Lob API keys): not run. It's an optional manual check.To test:
composer install && vendor/bin/phpunit --group unit --configuration=phpunit.xml.diston PHP 8.1+.Review
1 round: the lob-php specialist and the tech lead both approved. 1 minor finding (flag the transitive major bumps) is addressed above.
Acceptance criteria
guzzlehttp/guzzleresolves to >= 7.15.2 incomposer.lockand thecomposer.jsonconstrphpunit/phpunitresolves to >= 9.6.33 andsymfony/processto >= 5.4.46 in `composer.locorg.json:jsonresolves to >= 20231013 andcom.squareup.okhttp3:okhttpto >= 4.9.2 in tPending checks (the PR stays draft until these pass)
AC5-manual-operatorAC5 · manual-operator · owner: operatorRisks (every review round)
--with-all-dependenciespulled transitive major bumps into composer.lock: guzzlehttp/promises 1.5.1 -> 2.5.3, psr/http-message 1.0.1 -> 2.0 (runtime), nikic/php-parser v4 -> v5 and doctrine/instantiator 1 -> 2 (dev). phpspec/prophecy, phpdocumentor/* and webmozart/assert were dropped. lib/ doesn't implement any PSR-7 interface and doesn't call removed promise functions. Only Psr7\Utils::tryFopen is used. composer.json ranges are unchanged, so SDK consumers resolve their own versions. (r1)mvn clean compile, notinstall -DskipTests, because the maven-gpg-plugin is bound at verify (pom.xml:223-238) and needs a signing key. This predates the change. (r1)Follow-ups
🤖 Generated with Claude Code