Skip to content

Update all composer non-major dependencies - #627

Merged
renovate[bot] merged 1 commit into
masterfrom
renovate/composer-all-minor-patch
Sep 28, 2026
Merged

renovate[bot] merged 1 commit into
masterfrom
renovate/composer-all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
intervention/image (source) ^3.11.8 → ^3.11.9 age adoption passing confidence
league/commonmark (source) ^2.10.1 → ^2.10.3 age adoption passing confidence
phpstan/phpstan 2.2.14 → 2.2.16 age adoption passing confidence
twig/intl-extra (source) ^3.29.0 → ^3.30.0 age adoption passing confidence
twig/twig (source) ^3.29.0 → ^3.30.0 age adoption passing confidence

Release Notes

Intervention/image (intervention/image)

v3.11.9

Compare Source

What's Changed

Full Changelog: Intervention/image@3.11.8...3.11.9

thephpleague/commonmark (league/commonmark)

v2.10.3

Compare Source

Fixed
  • Fixed footnote links and backlinks pointing at the wrong anchor when footnote/footnote_id_prefix or footnote/ref_id_prefix contains an uppercase character; the configured prefix is now emitted verbatim in the href as it already was in the matching id (#​524)
  • Fixed inline raw HTML tags being escaped when the tag name or an attribute name contains an uppercase letter, such as <svg viewBox="..."> or <Warning> (#​1096)

v2.10.2

Compare Source

This is a security release to address a denial of service vulnerability in the Table extension and a raw HTML filtering bypass in the DisallowedRawHtml extension.

Changed
  • Improved performance of parsing table delimiter rows and splitting table rows into cells by scanning bytes directly instead of stepping a Cursor (roughly 4x faster for delimiter rows and 6x for cell splitting, and more on multibyte rows)
Fixed
  • Fixed DisallowedRawHtmlRenderer not blocking raw HTML that ends with a disallowed tag name, such as a line containing only <script (GHSA-97jj-33gv-5xf9)
  • Fixed quadratic-time parsing of long paragraphs when the Table extension is enabled (GHSA-3q6v-r5mr-hxv8)
  • Fixed table detection to match the GFM spec and reference implementation:
    • Header rows no longer require a | character
    • Header rows must now have the same number of cells as the delimiter row (previously, fewer cells were accepted)
phpstan/phpstan-phar-composer-source (phpstan/phpstan)

v2.2.16

Compare Source

v2.2.15

Compare Source

twigphp/intl-extra (twig/intl-extra)

v3.30.0

Compare Source

Changelog (twigphp/intl-extra@v3.29.0...v3.30.0)

  • minor #​4948 Compare the date formatter prototype pattern with the derived one once per pattern (@​fabpot)
  • bug #​4932 Fix IntlExtension inheriting values derived by ICU from a date formatter prototype (@​fabpot)
twigphp/Twig (twig/twig)

v3.30.0

Compare Source

  • Fix split, random, and shuffle merging a trailing newline into the last character of a string
  • Speed up splitting a string into characters in split, random, and shuffle
  • Speed up escaping by fetching the escaper runtime once per template
  • Speed up adding extensions to an environment
  • Fix the escaping safe analysis retaining every compiled template node for the lifetime of the environment
  • Speed up loading a template that the environment has already loaded
  • Speed up rendering by compiling a cheaper generator guard into templates
  • Speed up compiling filter, function, and test calls
  • Fix IntlExtension letting the pattern derived from a date formatter prototype override an explicit locale
  • Fix IntlExtension not honoring the locale of a date formatter prototype configured with no date and time styles
  • Speed up macro calls
  • Fix TemplateWrapper::unwrap() failing when called without arguments, which is now deprecated
  • Add TemplateWrapper::getDefaultEscapeStrategy() to know the escaping strategy a template was compiled with
  • Report a clear error when random, reverse, shuffle, and split receive a string that is not valid UTF-8
  • Fix the deprecation about omitting parentheses when calling a macro being reported twice for the same call
  • Add the macro name to the deprecation about omitting parentheses when calling a macro
  • Deprecate cloning a Twig\Environment instance
  • Fix array access with a Stringable key on subclasses of ArrayObject and ArrayIterator

Configuration

📅 Schedule: (in timezone UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

| datasource | package            | from   | to     |
| ---------- | ------------------ | ------ | ------ |
| packagist  | intervention/image | 3.11.8 | 3.11.9 |
| packagist  | league/commonmark  | 2.10.1 | 2.10.3 |
| packagist  | phpstan/phpstan    | 2.2.14 | 2.2.16 |
| packagist  | twig/intl-extra    | 3.29.0 | 3.30.0 |
| packagist  | twig/twig          | 3.29.0 | 3.30.0 |
@renovate renovate Bot added the renovate label Sep 28, 2026
@renovate
renovate Bot enabled auto-merge (squash) September 28, 2026 00:04
@renovate
renovate Bot merged commit efdc732 into master Sep 28, 2026
1 check passed
@renovate
renovate Bot deleted the renovate/composer-all-minor-patch branch September 28, 2026 00:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants