Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

composer(deps-dev): bump the version-updates group with 2 updates #424

Merged

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Oct 10, 2024

Updates the requirements on phpstan/phpstan and rector/rector to permit the latest version.
Updates phpstan/phpstan to 1.12.6

Release notes

Sourced from phpstan/phpstan's releases.

1.12.6

Bleeding edge 🔪

If you want to see the shape of things to come and adopt bleeding edge features early, you can include this config file in your project's phpstan.neon:

includes:
	- vendor/phpstan/phpstan/conf/bleedingEdge.neon

Of course, there are no backwards compatibility guarantees when you include this file. The behaviour and reported errors can change in minor versions with this file included. Learn more

Improvements 🔧

Bugfixes 🐛

Function signature fixes 🤖

... (truncated)

Commits
  • dc4d2f1 PHPStan 1.12.6
  • eb6a95a Updated PHPStan to commit eb6a95a9230d9c40e738c92edfef4f89e56678d2
  • 7125e1b Updated PHPStan to commit 7125e1ba3d3c474ea8895f57da5865ea42bd8360
  • 133c60e Updated PHPStan to commit 133c60e766fd8874254e1889c01cc474f8558d4d
  • 83ba597 Updated PHPStan to commit 83ba5972466d0b9bdfa4592996ccf381de625b1f
  • 3078f1a Updated PHPStan to commit 3078f1a175d2245aab64f77c8bc5f9fe9cc884f5
  • c6db9a9 Updated PHPStan to commit c6db9a920c35493e09458236f18a267a7548fec3
  • e2654b7 Updated PHPStan to commit e2654b7dc87951e1481bc46d8f1f7ff587e3f484
  • 58b3397 Updated PHPStan to commit 58b33972621d3faf25ac6c7b82b8a6703349b496
  • ca0a7e9 Updated PHPStan to commit ca0a7e9955397eef453b38c94ac67ba6faf7356b
  • Additional commits viewable in compare view

Updates rector/rector to 1.2.6

Release notes

Sourced from rector/rector's releases.

Released Rector 1.2.6

New Features 🥳

  • [TypeDeclaration] Add isset(), empty(), and negation support on BoolReturnTypeFromBooleanStrictReturnsRector (#6339)
  • [TypeDeclaration] Add NativeMethodReflection support on ReturnStrictTypeAnalyzer (#6344)
  • [DX] Show paths not match any file/directory on ProcessCommand when given path not exists (#6307)

Bugfixes 🐛

  • [TypeDeclaration] Convert inline @​var tag to assert() (#6300), Thanks @​carlos-granados!
  • Fix incorrect result after using RemoveByType in PhpDocInfo (#6301), Thanks @​carlos-granados!
  • [TypeDeclaration] Skip nullable callable on TypedPropertyFromAssignsRector (#6308)
  • Fix LocallyCalledStaticMethodToNonStaticRector when static function is called using the class name (#6310), Thanks @​carlos-granados!
  • [Php81] Handle crash on ArrowFunction attribute on FirstClassCallableRector (#6313)
  • [Performance] Reduce double traverse on StrictNativeFunctionReturnTypeAnalyzer (#6320)
  • [PhpParser] Alternative PR for findInstancesOfScoped() to keep existing performance (#6324)
  • [CodingStyle] Use double quote to escape quotes in EncapsedStringsToSprintfRector (#6326)
  • [TypeDeclaration] Handle crash on func call not found on BoolReturnTypeFromBooleanStrictReturnsRector (#6327)
  • Fix first class callable to use combineAcceptors() to avoid assert Arg instance error (#6330)
  • [Php81] Allow used as assign expr on ReadOnlyPropertyRector (#6331)
  • Skip arrow function in scoped search (#6333)
  • [TypeDeclaration] Better approach for native type check on ReturnStrictTypeAnalyzer (#6343)
  • [DeadCode] Skip extension load append variable on RemoveAlwaysTrueIfConditionRector (#6332)
  • [TypeDeclaration] Remove only void type on ReturnedNodesReturnTypeInfererTypeInferer (#6340)
  • [DeadCode] Skip indirect next line definition of @​var on RemoveNonExistingVarAnnotationRector (#6348)

rectorphp/rector-symfony 🎵

  • Added return type declaration rules for FormTypeInterface (#670), Thanks @​stollr

rectorphp/rector-phpunit 🟢

  • [CodeQuality] Add NarrowSingleWillReturnCallbackRector (#374)
  • [CodeQuality] Add SingleWithConsecutiveToWithRector (#370)
  • [CodeQuality] Add NarrowIdenticalWithConsecutiveRector (#369)
  • [CodeQuality] Add AddParentSetupCallOnSetupRector (#364)
  • Include match() to invoke counting in WithConsecutiveRector (#362)
  • Move WithConsecutiveRector to its PHPUnit100 namespace, CreateMockToAnonymousClassRector + PreferPHPUnitSelfCallRector to CodeQuality (#360)
  • Add existing willReturnCallback() support to WithConsecutiveRector (#358)
Commits
  • 6ca85da Rector 1.2.6
  • c154424 Updated Rector to commit c0c7502f55a3884f67a5885ed05ae2443ff53802
  • 68c7b4d Updated Rector to commit b88e910957a85adafd6fb75fbe50991b9ec871d1
  • a3f6293 Updated Rector to commit 0c9edebe4e1ca753d5bbe99e5109378155e87dde
  • b555bd2 Updated Rector to commit d17d3e814eada2fa3ada3601034407df01d84568
  • cdbdb1b Updated Rector to commit 697b37b340c3b4c73ad6f8e4cea26b7bf60ddf62
  • b86f338 Updated Rector to commit a11fc615d18396cef284c18de269711114630676
  • a5a5200 Updated Rector to commit 54a66206986e685787d7e038929618a66e98ec42
  • 32c2df7 Updated Rector to commit 6b065efef08c34f6e3f69ebd24e24f2418f93007
  • 3df699e Updated Rector to commit 6b065efef08c34f6e3f69ebd24e24f2418f93007
  • Additional commits viewable in compare view

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Updates the requirements on [phpstan/phpstan](https://github.com/phpstan/phpstan) and [rector/rector](https://github.com/rectorphp/rector) to permit the latest version.

Updates `phpstan/phpstan` to 1.12.6
- [Release notes](https://github.com/phpstan/phpstan/releases)
- [Changelog](https://github.com/phpstan/phpstan/blob/2.0.x/CHANGELOG.md)
- [Commits](phpstan/phpstan@1.12.5...1.12.6)

Updates `rector/rector` to 1.2.6
- [Release notes](https://github.com/rectorphp/rector/releases)
- [Commits](rectorphp/rector@1.2.5...1.2.6)

---
updated-dependencies:
- dependency-name: phpstan/phpstan
  dependency-type: direct:development
  dependency-group: version-updates
- dependency-name: rector/rector
  dependency-type: direct:development
  dependency-group: version-updates
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot requested a review from mimmi20 as a code owner October 10, 2024 02:40
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Oct 10, 2024
Copy link
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
composer/phpstan/phpstan >= 1.12.6, < 2.0.0 🟢 6.3
Details
CheckScoreReason
Code-Review⚠️ 0Found 0/30 approved changesets -- score normalized to 0
Maintained🟢 1030 commit(s) and 16 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Signed-Releases🟢 85 out of the last 5 releases have a total of 5 signed artifacts.
Branch-Protection⚠️ -1internal error: error during GetBranch(1.12.x): error during branchesHandler.query: internal error: githubv4.Query: Resource not accessible by integration
SAST⚠️ 0no SAST tool detected
Binary-Artifacts🟢 10no binaries found in the repo
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow⚠️ -1no workflows found
Token-Permissions⚠️ -1No tokens found
Fuzzing⚠️ 0project is not fuzzed
Vulnerabilities🟢 100 existing vulnerabilities detected
Pinned-Dependencies⚠️ -1no dependencies found
Security-Policy🟢 10security policy file detected
composer/rector/rector >= 1.2.6, < 2.0.0 🟢 4.8
Details
CheckScoreReason
Code-Review⚠️ 0Found 0/30 approved changesets -- score normalized to 0
Maintained🟢 1030 commit(s) and 18 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow⚠️ -1no workflows found
Token-Permissions⚠️ -1No tokens found
Security-Policy⚠️ 0security policy file not detected
Fuzzing⚠️ 0project is not fuzzed
SAST⚠️ 0no SAST tool detected
Binary-Artifacts🟢 9binaries present in source code
Pinned-Dependencies⚠️ -1no dependencies found
Vulnerabilities🟢 100 existing vulnerabilities detected

Scanned Manifest Files

composer.json
  • phpstan/phpstan@>= 1.12.6, < 2.0.0
  • rector/rector@>= 1.2.6, < 2.0.0
  • phpstan/phpstan@>= 1.12.5, < 2.0.0
  • rector/rector@>= 1.2.5, < 2.0.0

Copy link

codeclimate bot commented Oct 10, 2024

Code Climate has analyzed commit e34a07c and detected 0 issues on this pull request.

The test coverage on the diff in this pull request is 100.0% (50% is the threshold).

This pull request will bring the total coverage in the repository to 100.0% (0.0% change).

View more on Code Climate.

@mimmi20 mimmi20 merged commit 2c6abb1 into master Oct 10, 2024
129 checks passed
@mimmi20 mimmi20 deleted the dependabot/composer/master/version-updates-ec670f5aee branch October 10, 2024 12:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant