Skip to content

Bump the all-dependencies group with 5 updates - #596

Closed
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/composer/all-dependencies-80f5fe9a93
Closed

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/composer/all-dependencies-80f5fe9a93

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the all-dependencies group with 5 updates:

Package From To
symfony/console 7.4.18 7.4.19
symfony/form 7.4.18 7.4.19
symfony/twig-bundle 7.4.15 7.4.19
twig/extra-bundle 3.24.0 3.29.0
twig/twig 3.28.0 3.29.0

Updates symfony/console from 7.4.18 to 7.4.19

Release notes

Sourced from symfony/console's releases.

v7.4.19

Changelog (symfony/console@v7.4.18...v7.4.19)

Commits
  • 3a19734 [Console] Report a validation error instead of a TypeError on numeric argumen...
  • 9553be3 [Console] [FrameworkBundle] Adapt merged tests to the 7.4 APIs
  • 30dc1f2 Merge branch '6.4' into 7.4
  • 9e118dd [Console] Keep messages containing malformed UTF-8 when wrapping
  • 2e7eaed [Console] Type the autocompleter callback as returning a list
  • 9e7bbe1 [Console] Disambiguate the autocompleter callback return type
  • a3ae4ce Merge branch '6.4' into 7.4
  • 91860d4 [Console] Cover the zsh completion against running the typed command line
  • fef95ef [Console] Do not evaluate the command line in the zsh completion
  • 7e9e790 Merge branch '6.4' into 7.4
  • Additional commits viewable in compare view

Updates symfony/form from 7.4.18 to 7.4.19

Release notes

Sourced from symfony/form's releases.

v7.4.19

Changelog (symfony/form@v7.4.18...v7.4.19)

Commits
  • ededc32 Merge branch '6.4' into 7.4
  • b0f1e86 [Form] Add the BoundsType compare message translation unit
  • 4e72be3 Merge branch '6.4' into 7.4
  • 644c86a [Form] Describe the options of a type extension registered on a type and its ...
  • 6757334 Merge branch '6.4' into 7.4
  • f281151 [Form][Validator] Review Romanian (ro) translations
  • 781aaa7 Merge branch '6.4' into 7.4
  • 752748f Review Catalan validator translations
  • 3b35b3a Merge branch '6.4' into 7.4
  • 6cb5430 [Form] Accept UTC-equivalent timezones for DateTimeType, DateType and TimeTyp...
  • Additional commits viewable in compare view

Updates symfony/twig-bundle from 7.4.15 to 7.4.19

Release notes

Sourced from symfony/twig-bundle's releases.

v7.4.19

Changelog (symfony/twig-bundle@v7.4.15...v7.4.19)

Commits
  • 231c0b3 Merge branch '6.4' into 7.4
  • d5996b3 [HttpKernel][FrameworkBundle][TwigBundle][DoctrineBridge] Escape percent sign...
  • d157272 Check arrays and bools directly instead of comparing them to count()/true/fal...
  • See full diff in compare view

Updates twig/extra-bundle from 3.24.0 to 3.29.0

Release notes

Sourced from twig/extra-bundle's releases.

v3.29.0

Changelog (twigphp/twig-extra-bundle@v3.27.0...v3.29.0)

Commits
  • aaa2993 Fix wrapping the Twig cache pool in a second tag aware adapter
  • d8ee103 Restore void return type compatibility for extension points
  • 0c39e53 Test extra extension catalog against local sources
  • 5c8545f Register the missing extra callables in MissingExtensionSuggestor
  • 4e4ced8 Add void return type hint even in tests
  • c432607 Install a custom exception handler before bootstrapping KernelTestCase
  • See full diff in compare view

Updates twig/twig from 3.28.0 to 3.29.0

Release notes

Sourced from twig/twig's releases.

v3.29.0

Changelog (twigphp/Twig@v3.28.0...v3.29.0)

  • feature #4910 Reject template wrappers from another environment (@​fabpot)
  • bug #4927 Report a clear error when using macros imported in a template body that was not rendered (@​fabpot)
  • feature #4926 Allow block chains to be composed of other block chains (@​fabpot)
  • feature #4925 Resolve block chains against the render context (@​fabpot)
  • bug #4924 Resolve constant parent templates once instead of on every lookup (@​fabpot)
  • bug #4923 Fix wrapping the Twig cache pool in a second tag aware adapter (@​nicolas-grekas)
  • feature #4917 Template runtime and block composition (@​fabpot)
  • bug #4918 Check that the use tag is allowed before resolving trait templates (@​fabpot)
  • bug #4922 Wrap dynamic parent expression errors (@​fabpot)
  • bug #4921 Fix TemplateWrapper::hasBlock() and TemplateWrapper::getBlockNames() omitting environment globals (@​fabpot)
  • bug #4916 Fix html_attr dropping style declarations whose value is zero (@​dylanpulver)
  • bug #4915 Fix the default filter fallback reusing a null-safe temporary variable (@​lazerg, @​fabpot)
  • minor #4908 Remove the documentation comments compilation overhead (@​fabpot)
  • minor #4904 Release destructuring temporaries after assignment (@​fabpot)
  • bug #4909 Report regular expression errors from the matches operator (@​fabpot)
  • bug #4906 Deprecate prefixed macro definedness checks (@​fabpot)
  • bug #4907 Fix duplicate macro deprecation wording (@​fabpot)
  • bug #4905 Throw when list formatting fails (@​fabpot)
  • feature #4902 Remove lazy macro import resolution (@​fabpot)
  • bug #4900 Honor date formatter prototype calendars (@​fabpot)
  • bug #4899 Fix Stringable keys for ArrayAccess implementations (@​fabpot)
  • bug #4901 Evaluate object destructuring expressions once (@​fabpot)
  • bug #4896 Restore void return type compatibility for extension points (@​fabpot)
  • bug #4898 Reject destructuring patterns containing no variables (@​fabpot)
  • feature #4895 Extract htmlAttrValue() from html_attr for standalone attribute rendering (@​Kocal)
  • bug #4894 Fix an empty destructuring pattern triggering a PHP fatal error instead of a SyntaxError (@​fabpot)
  • feature #4893 Fix array destructuring from a Traversable (@​iliaal, @​fabpot)
  • bug #4892 Register the missing extra callables in MissingExtensionSuggestor (@​smnandre)
  • bug #4891 Fix the empty comment "{##}" being lexed as a documentation comment opening (@​Amoifr)
  • feature #4871 Attach documentation comments to nodes (@​fabpot)
  • feature #4434 Add the include_only function (@​fabpot)
  • feature #4890 Add support for tempest/markdown in markdown-extra (@​ker0x)
  • feature #4881 Nested macro imports (@​fabpot)
  • feature #4878 Deprecate using parentheses when testing a macro with the defined test (@​fabpot)
  • feature #4851 Redesign macro calls and argument handling (@​fabpot)
  • feature #4854 Make the sandbox a first-class citizen with a dedicated Sandbox class (@​fabpot)
  • feature #4877 Deprecate macro calls without parentheses (@​fabpot)
  • feature #4876 Rename macro variable AST nodes (@​fabpot)
  • feature #4874 Normalize destructuring assignment targets (@​fabpot)
  • feature #4873 Deprecate duplicate macro definitions (@​fabpot)
  • bug #4859 Fix IntlExtension ignoring explicit formats when a date formatter prototype is set (@​fabpot)
  • feature #4852 [Intl] Add format_list filter using PHP 8.5's IntlListFormatter (@​BreyndotEchse)
  • bug #4856 Fix array access with a Stringable key on ArrayAccess objects using object keys (@​fabpot)
  • bug #4853 Throw a SyntaxError instead of a PHP fatal error when a macro argument is defined twice (@​fabpot)
Changelog

Sourced from twig/twig's changelog.

3.29.0 (2026-09-18)

  • Fix the PHP warning and cryptic error when a block or a macro rendered on its own uses macros imported in the template body
  • Fix {% cache %} always missing in the Symfony bundle when framework.cache.app uses a natively tag aware adapter
  • Fix the sandbox resolving use trait templates before checking that the use tag is allowed
  • Fix html_attr dropping style declarations whose value is 0, 0.0 or '0'
  • Fix the default filter fallback emitting an undefined variable warning when it uses the null-safe operator
  • Fix the matches operator silently treating PCRE execution errors as non-matches; it now throws a RuntimeError
  • Fix TemplateWrapper::streamBlock(), TemplateWrapper::hasBlock(), and TemplateWrapper::getBlockNames() omitting environment globals
  • Fix exceptions from dynamic parent expressions escaping without template context
  • Add the BlockChain class to compose blocks from multiple templates without using template internals
  • Fix TemplateWrapper::hasBlock() and TemplateWrapper::getBlockNames() losing the extends line when the parent template does not exist
  • Fix an output buffer leak when a parent block rendered in an expression throws in non-yield mode
  • Add the HtmlExtension::htmlAttrValue() method to resolve a single HTML attribute value the way the html_attr function renders it
  • Fix html_attr JSON encoding a Stringable value in a data-* attribute instead of using its string representation
  • Add documentation comments to attach metadata to nodes (experimental)
  • Fix destructuring patterns containing no variables (empty patterns or sequences with only empty slots) triggering a PHP fatal error instead of a SyntaxError
  • Fix object and mapping destructuring evaluating the right-hand expression more than once
  • Fix sequence destructuring of iterators throwing a TypeError
  • Fix MissingExtensionSuggestor not suggesting the twig/*-extra package to install for some html-extra, intl-extra, and string-extra filters and functions
  • Add TempestMarkdown to use tempest/markdown as the markdown_to_html converter
  • Add the include_only function to render a template without giving it access to the current context
  • Add the Twig\Sandbox\SandboxInterface interface and Twig\Sandbox\Sandbox class to render untrusted templates through a dedicated, always-sandboxed environment crafted for it
  • Reject TemplateWrapper instances created by another Environment
  • Add the Twig\Extension\SandboxBridgeExtension to render sandboxed templates from trusted templates with an explicit output escaping strategy
  • Extract the sandbox runtime enforcement into a new internal Twig\Sandbox\SecurityChecker class used by compiled templates and CoreExtension
  • Mark SandboxExtension as internal, use Twig\Sandbox\Sandbox instead
  • Deprecate the sandboxed argument of the include function, use Twig\Sandbox\Sandbox instead
  • Deprecate SandboxExtension::enableSandbox(), disableSandbox(), and isSandboxedGlobally()
  • Normalize destructuring variable AST nodes as assignment targets
  • Fix IntlExtension ignoring explicit date/time formats and configured calendars when using a date formatter prototype
  • Add a format_list filter to IntlExtension to format a list of strings using PHP 8.5's IntlListFormatter
  • Fix array access with a Stringable key for ArrayObject and ArrayIterator while preserving object keys for SplObjectStorage
  • Fix duplicated macro argument names triggering a PHP fatal error instead of a SyntaxError
  • Deprecate defining a macro more than once in the same template
  • Deprecate TemplateVariable and AssignTemplateVariable; use MacroVariable and AssignMacroVariable instead
  • Deprecate calling or testing a macro with a name whose case differs from its definition; macro names will be case-sensitive in 4.0
  • Deprecate omitting parentheses when calling a macro; it will throw a SyntaxError in 4.0
  • Deprecate using parentheses when testing a macro with the defined test; it will throw a SyntaxError in 4.0
  • Deprecate calling a macro without a value for an argument that has no default value; the argument will be required in 4.0
  • Deprecate passing extra or unknown arguments to a macro that does not declare a variadic argument; it will throw in 4.0
  • Add support for declaring an explicit variadic macro argument ({% macro foo(a, ...rest) %})
  • Compile macros as closures stored in a per-template registry instead of macro_-prefixed PHP methods
  • Represent imported macro namespaces with a narrow capability object instead of template instances
  • Mark Twig\Node\MacroNode as @final; it will be final in Twig 4.0
  • Deprecate not passing a MacrosNode instance as the macros of a ModuleNode constructor
  • Change MacroReferenceExpression to take the bare macro name instead of a macro_-prefixed method name
  • Deprecate resolving a macro through a macro_-prefixed name; pass the bare macro name to MacroReferenceExpression
Commits
  • 45a3c6e Prepare the 3.29.0 release
  • 15207e0 Update CHANGELOG
  • dea0483 feature #4910 Reject template wrappers from another environment (fabpot)
  • 0f5c902 bug #4927 Report a clear error when using macros imported in a template body ...
  • 56e5c07 Clarify the exception message for nested block chains from another environment
  • 053200b feature #4926 Allow block chains to be composed of other block chains (fabpot)
  • d6b81f9 Allow block chains to be composed of other block chains
  • 72c2f66 Report a clear error when using macros imported in a template body that was n...
  • 83e8f7e Reject cross-environment template wrappers in block chains
  • c1fc112 Reject cross-environment template wrappers
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the all-dependencies group with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [symfony/console](https://github.com/symfony/console) | `7.4.18` | `7.4.19` |
| [symfony/form](https://github.com/symfony/form) | `7.4.18` | `7.4.19` |
| [symfony/twig-bundle](https://github.com/symfony/twig-bundle) | `7.4.15` | `7.4.19` |
| [twig/extra-bundle](https://github.com/twigphp/twig-extra-bundle) | `3.24.0` | `3.29.0` |
| [twig/twig](https://github.com/twigphp/Twig) | `3.28.0` | `3.29.0` |


Updates `symfony/console` from 7.4.18 to 7.4.19
- [Release notes](https://github.com/symfony/console/releases)
- [Changelog](https://github.com/symfony/console/blob/8.2/CHANGELOG.md)
- [Commits](symfony/console@v7.4.18...v7.4.19)

Updates `symfony/form` from 7.4.18 to 7.4.19
- [Release notes](https://github.com/symfony/form/releases)
- [Changelog](https://github.com/symfony/form/blob/8.2/CHANGELOG.md)
- [Commits](symfony/form@v7.4.18...v7.4.19)

Updates `symfony/twig-bundle` from 7.4.15 to 7.4.19
- [Release notes](https://github.com/symfony/twig-bundle/releases)
- [Changelog](https://github.com/symfony/twig-bundle/blob/8.2/CHANGELOG.md)
- [Commits](symfony/twig-bundle@v7.4.15...v7.4.19)

Updates `twig/extra-bundle` from 3.24.0 to 3.29.0
- [Release notes](https://github.com/twigphp/twig-extra-bundle/releases)
- [Commits](twigphp/twig-extra-bundle@v3.24.0...v3.29.0)

Updates `twig/twig` from 3.28.0 to 3.29.0
- [Release notes](https://github.com/twigphp/Twig/releases)
- [Changelog](https://github.com/twigphp/Twig/blob/3.x/CHANGELOG)
- [Commits](twigphp/Twig@v3.28.0...v3.29.0)

---
updated-dependencies:
- dependency-name: symfony/console
  dependency-version: 7.4.19
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: symfony/form
  dependency-version: 7.4.19
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: symfony/twig-bundle
  dependency-version: 7.4.19
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: twig/extra-bundle
  dependency-version: 3.29.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-dependencies
- dependency-name: twig/twig
  dependency-version: 3.29.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update php code labels Sep 21, 2026
@dependabot
dependabot Bot requested review from a team and JamesDominy as code owners September 21, 2026 14:32
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update php code labels Sep 21, 2026
@sonarqube-wp-engine-prod

Copy link
Copy Markdown

Quality Gate passed Quality Gate passed

Issues
0 New issues
0 Fixed issues
0 Accepted issues

Measures
0 Security Hotspots
No data about Coverage
No data about Duplication

See analysis details on SonarQube

@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 28, 2026
@dependabot
dependabot Bot deleted the dependabot/composer/all-dependencies-80f5fe9a93 branch September 28, 2026 14:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants