🚨 [security] [php] Update phpunit/phpunit 11.5.24 → 11.5.52 (patch)#56
Closed
depfu[bot] wants to merge 1 commit intomainfrom
Closed
🚨 [security] [php] Update phpunit/phpunit 11.5.24 → 11.5.52 (patch)#56depfu[bot] wants to merge 1 commit intomainfrom
depfu[bot] wants to merge 1 commit intomainfrom
Conversation
This was referenced Feb 9, 2026
Author
|
Closed in favor of #59. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Welcome to Depfu 👋
This is one of the first three pull requests with dependency updates we've sent your way. We tried to start with a few easy patch-level updates. Hopefully your tests will pass and you can merge this pull request without too much risk. This should give you an idea how Depfu works in general.
After you merge your first pull request, we'll send you a few more. We'll never open more than seven PRs at the same time so you're not getting overwhelmed with updates.
Let us know if you have any questions. Thanks so much for giving Depfu a try!
🚨 Your current dependencies have known security vulnerabilities 🚨
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this update. Please take a good look at what changed and the test results before merging this pull request.
What changed?
✳️ phpunit/phpunit (11.5.24 → 11.5.52) · Repo
Security Advisories 🚨
🚨 PHPUnit Vulnerable to Unsafe Deserialization in PHPT Code Coverage Handling
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Release Notes
1.13.4
1.13.3
1.13.2
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 6 commits:
Merge pull request #207 from W0rma/reflection-set-accessiblesetAccessible() has no effect as of PHP 8.1Merge pull request #206 from ruudk/patch-2Change TObject to mixedMerge pull request #205 from ruudk/patch-1Add generic to DeepCopy::copy methodRelease Notes
5.7.0
5.6.2
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 15 commits:
Release PHP-Parser 5.7.0Add shouldPrintRawValue attribute to print rawValue (#1127)Document attributes used by pretty printerStop using a semicolon (;) at the end of case statements for PHP 8.5[types] add known docblock types to traverseArray(), cleanup no relevant git ignoresOmit new parentheses when printing for PHP 8.4Print parentheses around arrow function in pipe operatorEmit error for unparenthesized arrow function in pipe operatorFix modifier change on anonymous classFix version reference in changelogRelease PHP-Parser 5.6.2FPPP: Fix visibility change with attributesSupport Param isFinal()Fix chr() deprecation warningUse @deprecated above class to allow static analyzer like PHPStan detect deprecation (#1103)Release Notes
11.0.12
11.0.11
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 33 commits:
Prepare releaseMerge branch '10.1' into 11.0UpdateRemove superfluous importsRefactorCloses #1131Remove superfluous line-breakUpdate toolsUpdate dependenciesMerge branch '10.1' into 11.0Test with PHP 8.6Update PHP-CS-Fixer configurationUpdate toolsUpdate toolsMerge branch '10.1' into 11.0Also upload test results to codecov.ioCache Composer's cache directoryDo not fetch tagsIntroduce PHP_VERSION variableTest with PHP 8.5Remove superfluous double-quotesUpdate toolsExtract methods to reduce code duplication and handle error in DOMDocument::saveXML() for #1092Update dependenciesPrepare releaseFix CS/WS issueConfigure separate result cache path per branchUpdate toolsSimplify applyFilter()invoke skipEmptyLines() even earlierImprove performance by skipping empty lines after filter has been appliedUpdate PHP-CS-Fixer configurationUpdate toolsCommits
See the full diff on Github. The new version differs by 28 commits:
Prepare releaseCloses #84Update toolsMerge branch '4.1' into 5.1Update Psalm baselineSync with CI pipeline configuration for PHPUnitUpdate toolsUpdate toolsMerge branch '4.1'Update toolsFix CS/WS issueImprove variable namesAdd return type declarationMerge branch '4.1'Bump copyright yearAdd documentation on how to contributeIncrease PHPStan rule level to 10Fix CS/WS issueUpdate PHP-CS-Fixer configurationUpdate toolsMerge branch '4.1'Test with PHP 8.5BumpBumpMerge branch '4.1'Set COMPOSER_ROOT_VERSION to X.Y.x-dev instead of X.Y-devBumpUpdate PHPUnit configurationRelease Notes
6.3.3
6.3.2
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 28 commits:
Prepare releaseMerge branch '5.0' into 6.3Prepare releaseMerge branch '4.0' into 5.0Prepare releaseMerge branch '3.0' into 4.0Prepare releaseFix CS/WS issueMerge branch '5.0' into 6.3Fix CS/WS issueMerge branch '5.0' into 6.3Merge branch '4.0' into 5.0Merge branch '3.0' into 4.0Update toolsCloses #134Merge branch '5.0' into 6.3Update toolsSync with CI pipeline configuration for PHPUnitMerge branch '5.0' into 6.3Prepare releaseDo not use SplObjectStorage methods that will be deprecated in PHP 8.5Use PHP 8.4 for coding-guidelines jobUpdate toolsDo not use SplObjectStorage methods that will be deprecated in PHP 8.5Fix constraintDo not use SplObjectStorage methods that will be deprecated in PHP 8.5Do not use SplObjectStorage methods that will be deprecated in PHP 8.5Update toolsRelease Notes
6.3.2
6.3.1
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 31 commits:
Prepare releaseMerge branch '5.1' into 6.3Prepare releaseMerge branch '4.0' into 5.1Prepare releaseMerge branch '3.1' into 4.0Suppress warningSuppress warningUse SplObjectStorage::offsetSet() instead of deprecated SplObjectStorage::attach()Prepare releaseIgnore errorMerge branch '5.1' into 6.3Use SplObjectStorage::offsetSet() instead of deprecated SplObjectStorage::attach()Suppress warningUpdate toolsMerge branch '4.0' into 5.1Prepare releaseUse SplObjectStorage::offsetSet() instead of deprecated SplObjectStorage::attach()Suppress warningMerge branch '3.1' into 4.0Prepare releaseTest with more versionsDo not cache Composer dependenciesSuppress warningUpdate toolsUpdate toolsFixUpdate toolsMerge branch '5.1'Bump copyright yearAdd documentation on how to contributeRelease Notes
6.0.3
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 21 commits:
Prepare releaseMerge branch '5.0' into 6.0Do not use SplObjectStorage methods that will be deprecated in PHP 8.5Update toolsUpdate toolsMerge branch '5.0'Bump copyright yearAdd documentation on how to contributeIncrease PHPStan rule level to 10Update PHP-CS-Fixer configurationUpdate toolsMerge branch '5.0'Test with PHP 8.5Merge branch '5.0'Update PHPUnit configurationBumpSet COMPOSER_ROOT_VERSION to X.Y.x-dev instead of X.Y-devUpdate Codecov.io action(s)Merge branch '5.0'Use XdebugUpdate badge URLRelease Notes
5.1.3
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 5 commits:
Prepare releaseUpdate PHPUnit configurationUpdate PHP-CS-Fixer configurationUpdate toolsAdd /infection.json to .gitattributesRelease Notes
1.3.1
1.3.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 26 commits:
Fix BC Break introduced with 1.3.0 (Closes #37)Merge pull request #34 from staabm/const-arrMerge pull request #36 from staabm/fixFix asymmetry in startElement() endElement()Update Tokenizer.phpTokenizer: Use const arrayMerge pull request #32 from staabm/streamStreamline Tokenizer->fillBlanks()Drop PHP 7.2Make failing tests fail the buildMerge pull request #29 from staabm/patch-2Streamline XMLSerializerFix aftermath issues: update tests, update outdated token fixture, remove dead codeUpdate toolsFix wrong use of iterator introduced with changing the PR from @staabmMerge pull request #25 from staabm/collMerge branch 'master' into collMerge pull request #24 from staabm/patch-1use more local storageSimplify XMLSerializersupport static analysisSimplify TokenCollectionMerge pull request #28 from staabm/ciTest latest PHP versions in CIMerge pull request #21 from DannyvdSluijs/patch-2Update to use actions/checkout@v4Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase.All Depfu comment commands