Update dependency composer/composer to v2.8.1 #799

Merged
mwalbeck merged 1 commits from renovate/composer-composer-2.x into master 2024-10-05 14:35:16 +00:00
Collaborator

This PR contains the following updates:

Package Update Change
composer/composer minor 2.7.9 -> 2.8.1

Release Notes

composer/composer (composer/composer)

v2.8.1

Compare Source

  • Fixed init command regression when no license is provided (#​12145)
    • Fixed --strict-ambiguous flag handling whereas it sometimes did not report all issues (#​12148)
    • Fixed create-project to inherit the target folder's permissions for installed project files (#​12146)
    • Fixed a few cases where the prompt for using a parent dir's composer.json fails to work correctly (#​8023)

v2.8.0

Compare Source

  • BC Warning: Fixed https_proxy env var falling back to http_proxy's value. The fallback and warning have now been removed per the 2.7.3 release notes (#​11938, #​11915)
    • Added --patch-only flag to the update command to restrict updates to patch versions and make an update of all deps safer (#​12122)
    • Added --abandoned flag to the audit command to configure how abandoned packages should be treated, overriding the audit.abandoned config setting (#​12091)
    • Added --ignore-severity flag to the audit command to ignore one or more advisory severities (#​12132)
    • Added --bump-after-update flag to the update command to run bump after the update is done (#​11942)
    • Added a way to control which scripts receive additional CLI arguments and where they appear in the command, see the docs (#​12086)
    • Added allow-missing-requirements config setting to skip the error when the lock file is not fulfilling the composer.json's dependencies (#​11966)
    • Added a JSON schema for the composer.lock file (#​12123)
    • Added better support for Bitbucket app passwords when cloning repos / installing from source (#​12103)
    • Added --type flag to filter packages by type(s) in the reinstall command (#​12114)
    • Added --strict-ambiguous flag to the dump-autoload command to make it return with an error code if duplicate classes are found (#​12119)
    • Added warning in dump-autoload when vendor files have been deleted (#​12139)
    • Added warnings for each missing platform package when running create-project to avoid having to run it again and again (#​12120)
    • Added sorting of packages in allow-plugins when sort-packages is enabled (#​11348)
    • Added suggestion of provider packages / polyfills when an ext or lib package is missing (#​12113)
    • Improved interactive package update selection by first outputting all packages and their possible updates (#​11990)
    • Improved dependency resolution failure output by sorting the output in a deterministic and (often) more logical way (#​12111)
    • Fixed PHP 8.4 deprecation warnings about E_STRICT (#​12116)
    • Fixed init command to validate the given license identifier (#​12115)
    • Fixed version guessing to be more deterministic on feature branches if it appears that it could come from either of two mainline branches (#​12129)
    • Fixed COMPOSER_ROOT_VERSION env var handling to treat 1.2 the same as 1.2.x-dev and not 1.2.0 (#​12109)
    • Fixed require command skipping new stability flags from the lock file, causing invalid lock file diffs (#​12112)
    • Fixed php://stdin potentially being open several times when running Composer programmatically (#​12107)
    • Fixed handling of platform packages in why-not command and partial updates (#​12110)
    • Reverted "Fixed transport-options.ssl for local cert authorization being stored in lock file making them less portable (#​12019)" from 2.7.8 as it was broken

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | [composer/composer](https://github.com/composer/composer) | minor | `2.7.9` -> `2.8.1` | --- ### Release Notes <details> <summary>composer/composer (composer/composer)</summary> ### [`v2.8.1`](https://github.com/composer/composer/blob/HEAD/CHANGELOG.md#281-2024-10-04) [Compare Source](https://github.com/composer/composer/compare/2.8.0...2.8.1) - Fixed `init` command regression when no license is provided ([#&#8203;12145](https://github.com/composer/composer/issues/12145)) - Fixed `--strict-ambiguous` flag handling whereas it sometimes did not report all issues ([#&#8203;12148](https://github.com/composer/composer/issues/12148)) - Fixed `create-project` to inherit the target folder's permissions for installed project files ([#&#8203;12146](https://github.com/composer/composer/issues/12146)) - Fixed a few cases where the prompt for using a parent dir's composer.json fails to work correctly ([#&#8203;8023](https://github.com/composer/composer/issues/8023)) ### [`v2.8.0`](https://github.com/composer/composer/blob/HEAD/CHANGELOG.md#280-2024-10-02) [Compare Source](https://github.com/composer/composer/compare/2.7.9...2.8.0) - BC Warning: Fixed `https_proxy` env var falling back to `http_proxy`'s value. The fallback and warning have now been removed per the 2.7.3 release notes ([#&#8203;11938](https://github.com/composer/composer/issues/11938), [#&#8203;11915](https://github.com/composer/composer/issues/11915)) - Added `--patch-only` flag to the `update` command to restrict updates to patch versions and make an update of all deps safer ([#&#8203;12122](https://github.com/composer/composer/issues/12122)) - Added `--abandoned` flag to the `audit` command to configure how abandoned packages should be treated, overriding the `audit.abandoned` config setting ([#&#8203;12091](https://github.com/composer/composer/issues/12091)) - Added `--ignore-severity` flag to the `audit` command to ignore one or more advisory severities ([#&#8203;12132](https://github.com/composer/composer/issues/12132)) - Added `--bump-after-update` flag to the `update` command to run bump after the update is done ([#&#8203;11942](https://github.com/composer/composer/issues/11942)) - Added a way to control which `scripts` receive additional CLI arguments and where they appear in the command, see [the docs](https://getcomposer.org/doc/articles/scripts.md#controlling-additional-arguments) ([#&#8203;12086](https://github.com/composer/composer/issues/12086)) - Added `allow-missing-requirements` config setting to skip the error when the lock file is not fulfilling the composer.json's dependencies ([#&#8203;11966](https://github.com/composer/composer/issues/11966)) - Added a JSON schema for the composer.lock file ([#&#8203;12123](https://github.com/composer/composer/issues/12123)) - Added better support for Bitbucket app passwords when cloning repos / installing from source ([#&#8203;12103](https://github.com/composer/composer/issues/12103)) - Added `--type` flag to filter packages by type(s) in the `reinstall` command ([#&#8203;12114](https://github.com/composer/composer/issues/12114)) - Added `--strict-ambiguous` flag to the `dump-autoload` command to make it return with an error code if duplicate classes are found ([#&#8203;12119](https://github.com/composer/composer/issues/12119)) - Added warning in `dump-autoload` when vendor files have been deleted ([#&#8203;12139](https://github.com/composer/composer/issues/12139)) - Added warnings for each missing platform package when running `create-project` to avoid having to run it again and again ([#&#8203;12120](https://github.com/composer/composer/issues/12120)) - Added sorting of packages in allow-plugins when `sort-packages` is enabled ([#&#8203;11348](https://github.com/composer/composer/issues/11348)) - Added suggestion of provider packages / polyfills when an ext or lib package is missing ([#&#8203;12113](https://github.com/composer/composer/issues/12113)) - Improved interactive package update selection by first outputting all packages and their possible updates ([#&#8203;11990](https://github.com/composer/composer/issues/11990)) - Improved dependency resolution failure output by sorting the output in a deterministic and (often) more logical way ([#&#8203;12111](https://github.com/composer/composer/issues/12111)) - Fixed PHP 8.4 deprecation warnings about `E_STRICT` ([#&#8203;12116](https://github.com/composer/composer/issues/12116)) - Fixed `init` command to validate the given license identifier ([#&#8203;12115](https://github.com/composer/composer/issues/12115)) - Fixed version guessing to be more deterministic on feature branches if it appears that it could come from either of two mainline branches ([#&#8203;12129](https://github.com/composer/composer/issues/12129)) - Fixed COMPOSER_ROOT_VERSION env var handling to treat 1.2 the same as 1.2.x-dev and not 1.2.0 ([#&#8203;12109](https://github.com/composer/composer/issues/12109)) - Fixed require command skipping new stability flags from the lock file, causing invalid lock file diffs ([#&#8203;12112](https://github.com/composer/composer/issues/12112)) - Fixed php://stdin potentially being open several times when running Composer programmatically ([#&#8203;12107](https://github.com/composer/composer/issues/12107)) - Fixed handling of platform packages in why-not command and partial updates ([#&#8203;12110](https://github.com/composer/composer/issues/12110)) - Reverted "Fixed transport-options.ssl for local cert authorization being stored in lock file making them less portable ([#&#8203;12019](https://github.com/composer/composer/issues/12019))" from 2.7.8 as it was broken </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC4xMDEuMSIsInVwZGF0ZWRJblZlciI6IjM4LjEwMS4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbXX0=-->
renovate-bot added 1 commit 2024-10-02 15:04:38 +00:00
Update dependency composer/composer to v2.8.0
All checks were successful
continuous-integration/drone/pr Build is passing
21884d8389
renovate-bot force-pushed renovate/composer-composer-2.x from 21884d8389 to 5ddf34939c 2024-10-04 10:04:45 +00:00 Compare
renovate-bot changed title from Update dependency composer/composer to v2.8.0 to Update dependency composer/composer to v2.8.1 2024-10-04 10:04:45 +00:00
mwalbeck merged commit 99ffdc0a8e into master 2024-10-05 14:35:16 +00:00
Sign in to join this conversation.
No reviewers
No Label
No Milestone
No project
No Assignees
1 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: mwalbeck/docker-composer#799
No description provided.