Skip to content

Bump the all-dependencies group across 1 directory with 8 updates - #599

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/composer/all-dependencies-6233e90719
Open

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/composer/all-dependencies-6233e90719

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the all-dependencies group with 8 updates in the / directory:

Package From To
doctrine/dbal 4.4.4 4.5.0
doctrine/orm 3.7.1 3.7.3
symfony/console 7.4.18 7.4.20
symfony/form 7.4.18 7.4.20
symfony/twig-bundle 7.4.15 7.4.19
symfony/yaml 7.4.18 7.4.20
twig/extra-bundle 3.24.0 3.29.0
twig/twig 3.28.0 3.30.0

Updates doctrine/dbal from 4.4.4 to 4.5.0

Release notes

Sourced from doctrine/dbal's releases.

4.5.0

Release Notes for 4.5.0

4.5.0

  • Total issues resolved: 0
  • Total pull requests resolved: 38
  • Total contributors: 10

New Features

Deprecations

Bugfixes

Test Suite

... (truncated)

Commits
  • c435cd7 Merge pull request #7516 from GromNaN/fix/column-definition-type-key
  • 3eb3373 Accept the legacy "type" key in column definition arrays
  • 0ad5db2 Merge pull request #7490 from GromNaN/feature/column-type-name
  • 7aeabb0 Deprecate Column::getType() in favor of Column::getTypeName()
  • b4f1086 Merge branch '4.4.x' into 4.5.x
  • 205fdf5 Fix TransactionTest for MySQL 9.7
  • 52a6900 Merge branch '3.10.x' into 4.4.x
  • 429d4e5 Add SQLite WITHOUT ROWID table option (#7474)
  • ee81a5a CI: Use MySQL 9.7 (#7508)
  • 5f46f87 Fix phantom schema diff for float columns with default values (#7501)
  • Additional commits viewable in compare view

Updates doctrine/orm from 3.7.1 to 3.7.3

Release notes

Sourced from doctrine/orm's releases.

3.7.3

Release Notes for 3.7.3

3.7.x bugfix release (patch)

3.7.3

  • Total issues resolved: 0
  • Total pull requests resolved: 2
  • Total contributors: 2

Bugfixes

Static Analysis

3.7.2

Release Notes for 3.7.2

3.7.x bugfix release (patch)

3.7.2

  • Total issues resolved: 0
  • Total pull requests resolved: 6
  • Total contributors: 6

Bugfixes

Static Analysis

Test Suite

Commits
  • 2637802 Merge pull request #12635 from greg0ire/adapt-phpstan
  • 854827e Adapt PHPStan ignore rules
  • 6377c9a Merge pull request #12620 from mvanhorn/fix/5593-preserve-fulltext-index-with...
  • 47bfd62 fix: preserve fulltext indexes alongside unique constraints
  • 6b47a02 Merge pull request #12631 from whataboutpereira/treat-php-doc-types-as-certain
  • 731ffab Merge pull request #12628 from seb-jean/GH-12624-cursor-param-collision
  • eb52c5e Disable treatPhpDocTypesAsCertain phpstan option and clean up baseline and ...
  • a326ba7 Namespace the parameters generated for the cursor predicate
  • 65ddba5 Merge pull request #12617 from SherinBloemendaal/fix-initialize-object-for-na...
  • 8860edd Merge pull request #12623 from greg0ire/single-pr-template
  • Additional commits viewable in compare view

Updates symfony/console from 7.4.18 to 7.4.20

Release notes

Sourced from symfony/console's releases.

v7.4.20

Changelog (symfony/console@v7.4.19...v7.4.20)

v7.4.19

Changelog (symfony/console@v7.4.18...v7.4.19)

Commits
  • d7bca2f Merge branch '6.4' into 7.4
  • 0f758df [Console] Fix quadratic formatting of non-ASCII content
  • 3a19734 [Console] Report a validation error instead of a TypeError on numeric argumen...
  • 9553be3 [Console] [FrameworkBundle] Adapt merged tests to the 7.4 APIs
  • 30dc1f2 Merge branch '6.4' into 7.4
  • 9e118dd [Console] Keep messages containing malformed UTF-8 when wrapping
  • 2e7eaed [Console] Type the autocompleter callback as returning a list
  • 9e7bbe1 [Console] Disambiguate the autocompleter callback return type
  • a3ae4ce Merge branch '6.4' into 7.4
  • 91860d4 [Console] Cover the zsh completion against running the typed command line
  • Additional commits viewable in compare view

Updates symfony/form from 7.4.18 to 7.4.20

Release notes

Sourced from symfony/form's releases.

v7.4.20

Changelog (symfony/form@v7.4.19...v7.4.20)

v7.4.19

Changelog (symfony/form@v7.4.18...v7.4.19)

Commits
  • a36c175 Merge branch '6.4' into 7.4
  • 5753fe9 [Form][Validator] Review Dutch (nl) translations
  • 0b2f23c Merge branch '6.4' into 7.4
  • e348736 minor #66363 [Translation] Updating and improving Albanian translations (gazi04)
  • bc81acf minor #66225 [Validator] Review Albanian translations (gazi04)
  • da7f066 [Translation] Updating and improving Albanian translations
  • 0d26422 Merge branch '6.4' into 7.4
  • 9908ecc Merge branch '5.4' into 6.4
  • 3998d0f [Form] Handle NumberFormatter::parse() returning its position in bytes as of ...
  • b49649e Merge branch '6.4' into 7.4
  • Additional commits viewable in compare view

Updates symfony/twig-bundle from 7.4.15 to 7.4.19

Release notes

Sourced from symfony/twig-bundle's releases.

v7.4.19

Changelog (symfony/twig-bundle@v7.4.15...v7.4.19)

Commits
  • 231c0b3 Merge branch '6.4' into 7.4
  • d5996b3 [HttpKernel][FrameworkBundle][TwigBundle][DoctrineBridge] Escape percent sign...
  • d157272 Check arrays and bools directly instead of comparing them to count()/true/fal...
  • See full diff in compare view

Updates symfony/yaml from 7.4.18 to 7.4.20

Release notes

Sourced from symfony/yaml's releases.

v7.4.20

Changelog (symfony/yaml@v7.4.18...v7.4.20)

Commits
  • 0222bf4 Merge branch '6.4' into 7.4
  • 928e3ef [Yaml] Fix tabs in block scalars and comments after empty ones
  • 262f736 bug #66340 [Yaml] Fix !!str and !!float tags on block scalars (nicolas-gr...
  • d191b39 [Yaml] Fix several parsing edge cases
  • 919797d [Yaml] Fix !!str and !!float tags on block scalars
  • 93fa40f Merge branch '6.4' into 7.4
  • 4d2db33 Stop referencing issues and pull requests in tests
  • d666012 Merge branch '6.4' into 7.4
  • 5639865 [Yaml] Fix the line offset handed to nested block parsers
  • See full diff in compare view

Updates twig/extra-bundle from 3.24.0 to 3.29.0

Release notes

Sourced from twig/extra-bundle's releases.

v3.29.0

Changelog (twigphp/twig-extra-bundle@v3.27.0...v3.29.0)

Commits
  • aaa2993 Fix wrapping the Twig cache pool in a second tag aware adapter
  • d8ee103 Restore void return type compatibility for extension points
  • 0c39e53 Test extra extension catalog against local sources
  • 5c8545f Register the missing extra callables in MissingExtensionSuggestor
  • 4e4ced8 Add void return type hint even in tests
  • c432607 Install a custom exception handler before bootstrapping KernelTestCase
  • See full diff in compare view

Updates twig/twig from 3.28.0 to 3.30.0

Release notes

Sourced from twig/twig's releases.

v3.30.0

Changelog (twigphp/Twig@v3.29.0...v3.30.0)

  • minor #4950 Fetch the escaper runtime once in the constructor of templates that escape (@​fabpot)
  • minor #4948 Compare the date formatter prototype pattern with the derived one once per pattern (@​fabpot)
  • bug #4946 Fix split trailing newline (@​fabpot)
  • minor #4945 Speed up adding extensions to an environment (@​nicolas-grekas)
  • minor #4940 Reuse the already resolved callable when compiling call arguments (@​fabpot)
  • minor #4939 Compile the generator guard as an unreachable yield instead of a yield from (@​fabpot)
  • feature #4938 Speed up loading a template that the environment has already loaded (@​fabpot)
  • bug #4937 Stop the escaping safe analysis from retaining every analyzed node (@​fabpot)
  • feature #4936 Allow to call TemplateWrapper::unwrap() without arguments (@​derrabus)
  • feature #4934 Expose the escaping strategy a template was compiled with (@​fabpot)
  • minor #4933 Improve macro call performance (@​fabpot)
  • bug #4932 Fix IntlExtension inheriting values derived by ICU from a date formatter prototype (@​fabpot)
  • bug #4931 Fix array access with a Stringable key on subclasses of ArrayObject and ArrayIterator (@​fabpot)
  • bug #4930 Report a clear error when a string cannot be split into characters (@​fabpot)
  • feature #4929 Deprecate cloning a Twig environment (@​fabpot)
  • minor #4928 Report the macro call parentheses deprecation once per call site and name the macro (@​fabpot)

v3.29.0

Changelog (twigphp/Twig@v3.28.0...v3.29.0)

  • feature #4910 Reject template wrappers from another environment (@​fabpot)
  • bug #4927 Report a clear error when using macros imported in a template body that was not rendered (@​fabpot)
  • feature #4926 Allow block chains to be composed of other block chains (@​fabpot)
  • feature #4925 Resolve block chains against the render context (@​fabpot)
  • bug #4924 Resolve constant parent templates once instead of on every lookup (@​fabpot)
  • bug #4923 Fix wrapping the Twig cache pool in a second tag aware adapter (@​nicolas-grekas)
  • feature #4917 Template runtime and block composition (@​fabpot)
  • bug #4918 Check that the use tag is allowed before resolving trait templates (@​fabpot)
  • bug #4922 Wrap dynamic parent expression errors (@​fabpot)
  • bug #4921 Fix TemplateWrapper::hasBlock() and TemplateWrapper::getBlockNames() omitting environment globals (@​fabpot)
  • bug #4916 Fix html_attr dropping style declarations whose value is zero (@​dylanpulver)
  • bug #4915 Fix the default filter fallback reusing a null-safe temporary variable (@​lazerg, @​fabpot)
  • minor #4908 Remove the documentation comments compilation overhead (@​fabpot)
  • minor #4904 Release destructuring temporaries after assignment (@​fabpot)
  • bug #4909 Report regular expression errors from the matches operator (@​fabpot)
  • bug #4906 Deprecate prefixed macro definedness checks (@​fabpot)
  • bug #4907 Fix duplicate macro deprecation wording (@​fabpot)
  • bug #4905 Throw when list formatting fails (@​fabpot)
  • feature #4902 Remove lazy macro import resolution (@​fabpot)
  • bug #4900 Honor date formatter prototype calendars (@​fabpot)
  • bug #4899 Fix Stringable keys for ArrayAccess implementations (@​fabpot)
  • bug #4901 Evaluate object destructuring expressions once (@​fabpot)
  • bug #4896 Restore void return type compatibility for extension points (@​fabpot)
  • bug #4898 Reject destructuring patterns containing no variables (@​fabpot)
  • feature #4895 Extract htmlAttrValue() from html_attr for standalone attribute rendering (@​Kocal)
  • bug #4894 Fix an empty destructuring pattern triggering a PHP fatal error instead of a SyntaxError (@​fabpot)
  • feature #4893 Fix array destructuring from a Traversable (@​iliaal, @​fabpot)

... (truncated)

Changelog

Sourced from twig/twig's changelog.

3.30.0 (2026-09-25)

  • Fix split, random, and shuffle merging a trailing newline into the last character of a string
  • Speed up splitting a string into characters in split, random, and shuffle
  • Speed up escaping by fetching the escaper runtime once per template
  • Speed up adding extensions to an environment
  • Fix the escaping safe analysis retaining every compiled template node for the lifetime of the environment
  • Speed up loading a template that the environment has already loaded
  • Speed up rendering by compiling a cheaper generator guard into templates
  • Speed up compiling filter, function, and test calls
  • Fix IntlExtension letting the pattern derived from a date formatter prototype override an explicit locale
  • Fix IntlExtension not honoring the locale of a date formatter prototype configured with no date and time styles
  • Speed up macro calls
  • Fix TemplateWrapper::unwrap() failing when called without arguments, which is now deprecated
  • Add TemplateWrapper::getDefaultEscapeStrategy() to know the escaping strategy a template was compiled with
  • Report a clear error when random, reverse, shuffle, and split receive a string that is not valid UTF-8
  • Fix the deprecation about omitting parentheses when calling a macro being reported twice for the same call
  • Add the macro name to the deprecation about omitting parentheses when calling a macro
  • Deprecate cloning a Twig\Environment instance
  • Fix array access with a Stringable key on subclasses of ArrayObject and ArrayIterator

3.29.0 (2026-09-18)

  • Fix the PHP warning and cryptic error when a block or a macro rendered on its own uses macros imported in the template body
  • Fix {% cache %} always missing in the Symfony bundle when framework.cache.app uses a natively tag aware adapter
  • Fix the sandbox resolving use trait templates before checking that the use tag is allowed
  • Fix html_attr dropping style declarations whose value is 0, 0.0 or '0'
  • Fix the default filter fallback emitting an undefined variable warning when it uses the null-safe operator
  • Fix the matches operator silently treating PCRE execution errors as non-matches; it now throws a RuntimeError
  • Fix TemplateWrapper::streamBlock(), TemplateWrapper::hasBlock(), and TemplateWrapper::getBlockNames() omitting environment globals
  • Fix exceptions from dynamic parent expressions escaping without template context
  • Add the BlockChain class to compose blocks from multiple templates without using template internals
  • Fix TemplateWrapper::hasBlock() and TemplateWrapper::getBlockNames() losing the extends line when the parent template does not exist
  • Fix an output buffer leak when a parent block rendered in an expression throws in non-yield mode
  • Add the HtmlExtension::htmlAttrValue() method to resolve a single HTML attribute value the way the html_attr function renders it
  • Fix html_attr JSON encoding a Stringable value in a data-* attribute instead of using its string representation
  • Add documentation comments to attach metadata to nodes (experimental)
  • Fix destructuring patterns containing no variables (empty patterns or sequences with only empty slots) triggering a PHP fatal error instead of a SyntaxError
  • Fix object and mapping destructuring evaluating the right-hand expression more than once
  • Fix sequence destructuring of iterators throwing a TypeError
  • Fix MissingExtensionSuggestor not suggesting the twig/*-extra package to install for some html-extra, intl-extra, and string-extra filters and functions
  • Add TempestMarkdown to use tempest/markdown as the markdown_to_html converter
  • Add the include_only function to render a template without giving it access to the current context
  • Add the Twig\Sandbox\SandboxInterface interface and Twig\Sandbox\Sandbox class to render untrusted templates through a dedicated, always-sandboxed environment crafted for it
  • Reject TemplateWrapper instances created by another Environment
  • Add the Twig\Extension\SandboxBridgeExtension to render sandboxed templates from trusted templates with an explicit output escaping strategy
  • Extract the sandbox runtime enforcement into a new internal Twig\Sandbox\SecurityChecker class used by compiled templates and CoreExtension
  • Mark SandboxExtension as internal, use Twig\Sandbox\Sandbox instead
  • Deprecate the sandboxed argument of the include function, use Twig\Sandbox\Sandbox instead
  • Deprecate SandboxExtension::enableSandbox(), disableSandbox(), and isSandboxedGlobally()

... (truncated)

Commits
  • 8c73707 Prepare the 3.30.0 release
  • 052c7ef minor #4950 Fetch the escaper runtime once in the constructor of templates th...
  • 3417f48 Fetch the escaper runtime once in the constructor of templates that escape
  • 9e198d7 minor #4948 Compare the date formatter prototype pattern with the derived one...
  • 22e3119 bug #4946 Fix split trailing newline (fabpot)
  • 00861d5 Fix split trailing newline
  • 81cc196 Bump version
  • 10fe980 Compare the date formatter prototype pattern with the derived one once per pa...
  • c8d782e Deprecate calling TemplateWrapper::unwrap() without arguments as of 3.30 and ...
  • 9c3d58e Fix coding standards
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the all-dependencies group with 8 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [doctrine/dbal](https://github.com/doctrine/dbal) | `4.4.4` | `4.5.0` |
| [doctrine/orm](https://github.com/doctrine/orm) | `3.7.1` | `3.7.3` |
| [symfony/console](https://github.com/symfony/console) | `7.4.18` | `7.4.20` |
| [symfony/form](https://github.com/symfony/form) | `7.4.18` | `7.4.20` |
| [symfony/twig-bundle](https://github.com/symfony/twig-bundle) | `7.4.15` | `7.4.19` |
| [symfony/yaml](https://github.com/symfony/yaml) | `7.4.18` | `7.4.20` |
| [twig/extra-bundle](https://github.com/twigphp/twig-extra-bundle) | `3.24.0` | `3.29.0` |
| [twig/twig](https://github.com/twigphp/Twig) | `3.28.0` | `3.30.0` |



Updates `doctrine/dbal` from 4.4.4 to 4.5.0
- [Release notes](https://github.com/doctrine/dbal/releases)
- [Commits](doctrine/dbal@4.4.4...4.5.0)

Updates `doctrine/orm` from 3.7.1 to 3.7.3
- [Release notes](https://github.com/doctrine/orm/releases)
- [Commits](doctrine/orm@3.7.1...3.7.3)

Updates `symfony/console` from 7.4.18 to 7.4.20
- [Release notes](https://github.com/symfony/console/releases)
- [Changelog](https://github.com/symfony/console/blob/8.2/CHANGELOG.md)
- [Commits](symfony/console@v7.4.18...v7.4.20)

Updates `symfony/form` from 7.4.18 to 7.4.20
- [Release notes](https://github.com/symfony/form/releases)
- [Changelog](https://github.com/symfony/form/blob/8.2/CHANGELOG.md)
- [Commits](symfony/form@v7.4.18...v7.4.20)

Updates `symfony/twig-bundle` from 7.4.15 to 7.4.19
- [Release notes](https://github.com/symfony/twig-bundle/releases)
- [Changelog](https://github.com/symfony/twig-bundle/blob/8.2/CHANGELOG.md)
- [Commits](symfony/twig-bundle@v7.4.15...v7.4.19)

Updates `symfony/yaml` from 7.4.18 to 7.4.20
- [Release notes](https://github.com/symfony/yaml/releases)
- [Changelog](https://github.com/symfony/yaml/blob/8.2/CHANGELOG.md)
- [Commits](symfony/yaml@v7.4.18...v7.4.20)

Updates `twig/extra-bundle` from 3.24.0 to 3.29.0
- [Release notes](https://github.com/twigphp/twig-extra-bundle/releases)
- [Commits](twigphp/twig-extra-bundle@v3.24.0...v3.29.0)

Updates `twig/twig` from 3.28.0 to 3.30.0
- [Release notes](https://github.com/twigphp/Twig/releases)
- [Changelog](https://github.com/twigphp/Twig/blob/3.x/CHANGELOG)
- [Commits](twigphp/Twig@v3.28.0...v3.30.0)

---
updated-dependencies:
- dependency-name: doctrine/dbal
  dependency-version: 4.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-dependencies
- dependency-name: doctrine/orm
  dependency-version: 3.7.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: symfony/console
  dependency-version: 7.4.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: symfony/form
  dependency-version: 7.4.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: symfony/twig-bundle
  dependency-version: 7.4.19
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: symfony/yaml
  dependency-version: 7.4.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: twig/extra-bundle
  dependency-version: 3.29.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-dependencies
- dependency-name: twig/twig
  dependency-version: 3.30.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update php code labels Oct 5, 2026
@dependabot
dependabot Bot requested review from a team and JamesDominy as code owners October 5, 2026 14:33
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update php code labels Oct 5, 2026
@sonarqube-wp-engine-prod

Copy link
Copy Markdown

Quality Gate passed Quality Gate passed

Issues
0 New issues
0 Fixed issues
0 Accepted issues

Measures
0 Security Hotspots
No data about Coverage
No data about Duplication

See analysis details on SonarQube

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants