Skip to content

[v28-branch]: Update monolog/monolog requirement from ^2.11 to ^3.11 - #1251

Open
dependabot[bot] wants to merge 1 commit into
v28-branchfrom
dependabot/composer/v28-branch/monolog/monolog-tw-3.11
Open

dependabot[bot] wants to merge 1 commit into
v28-branchfrom
dependabot/composer/v28-branch/monolog/monolog-tw-3.11

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 9, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on monolog/monolog to permit the latest version.

Release notes

Sourced from monolog/monolog's releases.

3.11.0

  • Security: Fixed potential XSS in BrowserConsoleHandler when logging user provided content
  • Added RedactingFormatter to automatically redact sensitive data from records, based on key names, #[SensitiveParameter] constructor params and/or regex patterns (#2041)
  • Added FrankenPhpHandler to log records via FrankenPHP's frankenphp_log() function (#2056)
  • Added LogMonsterHandler which complains if the code did not log enough records before the process/request ends, like a dead man's switch for logs (#2039)
  • Added FILE_PER_HOUR rotation mode to RotatingFileHandler (#2040)
  • Added ErrorHandler::captureStackTraces() to attach the stack trace of PHP errors to the records it generates (#2060)
  • Added NormalizerFormatter::setMaxTraceLength() to limit how many stack trace frames are included when normalizing exceptions (#2015)
  • Added extension points to TelegramBotHandler to change the API URL (e.g. for a self-hosted Bot API server) and to send extra curl headers (#2029)
  • Added ability to override IntrospectionProcessor's SKIP_FUNCTIONS in subclasses (#2050)
  • Added $maxLength param to SyslogUdpHandler/UdpSocket to keep datagrams below the path MTU, as fragmented UDP packets are often dropped (#2049)
  • Fixed StreamHandler truncating writes on non-blocking streams, it now loops until the whole record is written (#2016)
  • Fixed stack trace frames without file/line being skipped, they are now reported as internal[function] entries so traces are not truncated or empty (#2061)
  • Fixed RotatingFileHandler cleanup not finding files behind stream wrappers (e.g. private://) as glob() cannot see through those (#2058)
  • Fixed RotatingFileHandler not using the configured timezone when computing the next rotation time (#2022)
  • Fixed scalars being replaced by the "Over N levels deep" message instead of being output when the max normalization depth is reached (#2042)
  • Fixed DeduplicationHandler failing with an undefined array key error when the store file is written to concurrently (#2020)
  • Fixed TelegramBotHandler swallowing errors when the API returns a non-JSON response (#2030)
  • Fixed AbstractProcessingHandler::handle() reading $bubble directly instead of calling getBubble(), so overrides of it were ignored (#2031)
  • Fixed warning on PHP 8.5 when ErrorHandler sets the HTTP response code and a status line was already registered (#2027)

Full Changelog: Seldaek/monolog@3.10.0...3.11.0

Changelog

Sourced from monolog/monolog's changelog.

3.11.0 (2026-09-02)

  • Security: Fixed potential XSS in BrowserConsoleHandler when logging user provided content
  • Added RedactingFormatter to automatically redact sensitive data from records, based on key names, #[SensitiveParameter] constructor params and/or regex patterns (#2041)
  • Added FrankenPhpHandler to log records via FrankenPHP's frankenphp_log() function (#2056)
  • Added LogMonsterHandler which complains if the code did not log enough records before the process/request ends, like a dead man's switch for logs (#2039)
  • Added FILE_PER_HOUR rotation mode to RotatingFileHandler (#2040)
  • Added ErrorHandler::captureStackTraces() to attach the stack trace of PHP errors to the records it generates (#2060)
  • Added NormalizerFormatter::setMaxTraceLength() to limit how many stack trace frames are included when normalizing exceptions (#2015)
  • Added extension points to TelegramBotHandler to change the API URL (e.g. for a self-hosted Bot API server) and to send extra curl headers (#2029)
  • Added ability to override IntrospectionProcessor's SKIP_FUNCTIONS in subclasses (#2050)
  • Added $maxLength param to SyslogUdpHandler/UdpSocket to keep datagrams below the path MTU, as fragmented UDP packets are often dropped (#2049)
  • Fixed StreamHandler truncating writes on non-blocking streams, it now loops until the whole record is written (#2016)
  • Fixed stack trace frames without file/line being skipped, they are now reported as internal[function] entries so traces are not truncated or empty (#2061)
  • Fixed RotatingFileHandler cleanup not finding files behind stream wrappers (e.g. private://) as glob() cannot see through those (#2058)
  • Fixed RotatingFileHandler not using the configured timezone when computing the next rotation time (#2022)
  • Fixed scalars being replaced by the "Over N levels deep" message instead of being output when the max normalization depth is reached (#2042)
  • Fixed DeduplicationHandler failing with an undefined array key error when the store file is written to concurrently (#2020)
  • Fixed TelegramBotHandler swallowing errors when the API returns a non-JSON response (#2030)
  • Fixed AbstractProcessingHandler::handle() reading $bubble directly instead of calling getBubble(), so overrides of it were ignored (#2031)
  • Fixed warning on PHP 8.5 when ErrorHandler sets the HTTP response code and a status line was already registered (#2027)

3.10.0 (2026-01-02)

  • Added automatic directory cleanup in RotatingFileHandler (#2000)
  • Added timezone-aware file rotation to RotatingFileHandler (#1982)
  • Added support for mongodb/mongodb 2.0+ (#1998)
  • Added NoDiscard attribute to TestHandler methods to ensure the result is used (#2013)
  • Fixed JsonFormatter crashing if __toString throws while normalizing data (#1968)
  • Fixed PHP 8.5 deprecation warnings (#1997, #2009)
  • Fixed DeduplicatingHandler collecting duplicate logs if the file cannot be locked (2e97231)
  • Fixed GelfMessageFormatter to use integers instead of bool for gelf 1.1 support (#1973)
  • Fixed empty stack traces being output anyway (#1979)
  • Fixed StreamHandler not reopening the file if the inode changed (#1963)
  • Fixed TelegramBotHandler sending empty messages (#1992)
  • Fixed file paths in stack traces containing backslashes on windows, always using / now to unify logs (#1980)
  • Fixed RotatingFileHandler unlink errors not being suppressed correctly (#1999)

3.9.0 (2025-03-24)

  • BC Warning: Fixed SendGridHandler to use the V3 API as V2 is now shut down, but this requires a new API key (#1952)
  • Deprecated Monolog\Test\TestCase in favor of Monolog\Test\MonologTestCase (#1953)
  • Added extension point for NativeMailerHandler::mail (#1948)
  • Added setHandler method to BufferHandler to modify the nested handler at runtime (#1946)
  • Fixed date format in ElasticsearchFormatter to use +00:00 vs +0000 tz identifiers (#1942)
  • Fixed GelfMessageFormatter handling numeric context/extra keys (#1932)

3.8.1 (2024-12-05)

  • Deprecated Monolog\DateTimeImmutable in favor of Monolog\JsonSerializableDateTimeImmutable (#1928)

... (truncated)

Commits
  • 147f303 Update changelog
  • 7bbffd0 Report stack trace frames that have no file/line instead of skipping them (#2...
  • 567b630 Bump zizmorcore/zizmor-action from 0.6.1 to 0.6.2 (#2063)
  • a3a2046 Align FrankenPhpHandler's level scale with OpenTelemetry's mapping (#2062)
  • d1d7def Fix warning when setting the http response code in case a status has already ...
  • 6949404 Add a way to turn on stack traces for ErrorHandler-generated records (#2060)
  • a4c5f65 Add LogMonsterHandler that requires at least some amount of logging or it log...
  • e7508d8 Replace glob() with RecursiveDirectoryIterator in RotatingFileHandler cleanup...
  • 9435605 Add RedactingFormatter to automatically redact keys/sensitive data before log...
  • fde8b93 Add FrankenPhpHandler (#2056)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Updates the requirements on [monolog/monolog](https://github.com/Seldaek/monolog) to permit the latest version.
- [Release notes](https://github.com/Seldaek/monolog/releases)
- [Changelog](https://github.com/Seldaek/monolog/blob/main/CHANGELOG.md)
- [Commits](Seldaek/monolog@2.11.0...3.11.0)

---
updated-dependencies:
- dependency-name: monolog/monolog
  dependency-version: 3.11.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update php code labels Sep 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants