Skip to content

Bump the dependencies group with 4 updates - #2050

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/composer/dependencies-5e0b4c9601
Sep 28, 2026
Merged

github-actions[bot] merged 1 commit into
mainfrom
dependabot/composer/dependencies-5e0b4c9601

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the dependencies group with 4 updates: composer/semver, phpro/grumphp, phpstan/phpstan and twig/twig.

Updates composer/semver from 3.4.4 to 3.5.0

Release notes

Sourced from composer/semver's releases.

3.5.0

  • Added VersionParser::isValid() to check whether a version string can be normalized (#168)
  • Fixed Intervals::compactConstraint() turning constraints that match no dev versions, like > 1.0.0 != 2.0.0 || < 1.9.0, into != 2.0.0 which matches all dev-* versions (#189)
  • Fixed >= and < constraints on RC versions, like >=1.0-RC1, getting an extra -dev suffix which beta and alpha constraints did not get (#187)
  • Improved CompilingMatcher performance by avoiding building concatenated cache keys on every call (#186)

Full Changelog: composer/semver@3.4.4...3.5.0

Changelog

Sourced from composer/semver's changelog.

[3.5.0] 2026-09-24

  • Added VersionParser::isValid() to check whether a version string can be normalized (#168)
  • Fixed Intervals::compactConstraint() turning constraints that match no dev versions, like > 1.0.0 != 2.0.0 || < 1.9.0, into != 2.0.0 which matches all dev-* versions (#189)
  • Fixed >= and < constraints on RC versions, like >=1.0-RC1, getting an extra -dev suffix which beta and alpha constraints did not get (#187)
  • Improved CompilingMatcher performance by avoiding building concatenated cache keys on every call (#186)
Commits
  • f7a296f Update changelog
  • b60bbab Do not compact a dev-free constraint into bare != constraints that match dev ...
  • 346ebc8 Avoid concatenated cache keys in CompilingMatcher (#186)
  • 9255780 Add CI job running the VERS spec test suite (#188)
  • 9ee1a95 Fix RC stability suffix getting an extra -dev in < and >= constraints (#187)
  • dee3264 Bump zizmorcore/zizmor-action from 0.6.1 to 0.6.2 (#185)
  • 1cbc9b5 Bump actions/checkout from 7.0.0 to 7.0.1 (#183)
  • 52bf964 Bump zizmorcore/zizmor-action from 0.5.7 to 0.6.1 (#182)
  • a5e1d2d Bump shivammathur/setup-php from 2.37.1 to 2.37.2 (#181)
  • 0de3018 Bump actions/checkout from 6.0.2 to 7.0.0 (#179)
  • Additional commits viewable in compare view

Updates phpro/grumphp from 2.23.0 to 2.24.0

Release notes

Sourced from phpro/grumphp's releases.

Version 2.24.0

What's Changed

New Contributors

Full Changelog: phpro/grumphp@v2.23.0...v2.24.0

Commits
  • 8abcadb 2.24.0 release
  • d398a8a Merge pull request #1233 from veewee/bugfix/e2e-flaky-tests
  • b6c7a4a Run AppVeyor on the Visual Studio 2022 image
  • 4cb4b09 Fix E2E failures on v2.x and with git 2.47+
  • bcbb8f3 Merge pull request #1231 from maarsson-io/feature/phplint-php-executable
  • 94cf026 feat(phplint): add php_executable option for parallel-lint configuration
  • 339c2a7 Merge pull request #1229 from freezysko/phpmd-report-format
  • 4387fe3 feat(phpmd): PHPMD report format allowed values matches renderers https://php...
  • See full diff in compare view

Updates phpstan/phpstan from 2.2.14 to 2.2.16

Commits

Updates twig/twig from 3.29.0 to 3.30.0

Release notes

Sourced from twig/twig's releases.

v3.30.0

Changelog (twigphp/Twig@v3.29.0...v3.30.0)

  • minor #4950 Fetch the escaper runtime once in the constructor of templates that escape (@​fabpot)
  • minor #4948 Compare the date formatter prototype pattern with the derived one once per pattern (@​fabpot)
  • bug #4946 Fix split trailing newline (@​fabpot)
  • minor #4945 Speed up adding extensions to an environment (@​nicolas-grekas)
  • minor #4940 Reuse the already resolved callable when compiling call arguments (@​fabpot)
  • minor #4939 Compile the generator guard as an unreachable yield instead of a yield from (@​fabpot)
  • feature #4938 Speed up loading a template that the environment has already loaded (@​fabpot)
  • bug #4937 Stop the escaping safe analysis from retaining every analyzed node (@​fabpot)
  • feature #4936 Allow to call TemplateWrapper::unwrap() without arguments (@​derrabus)
  • feature #4934 Expose the escaping strategy a template was compiled with (@​fabpot)
  • minor #4933 Improve macro call performance (@​fabpot)
  • bug #4932 Fix IntlExtension inheriting values derived by ICU from a date formatter prototype (@​fabpot)
  • bug #4931 Fix array access with a Stringable key on subclasses of ArrayObject and ArrayIterator (@​fabpot)
  • bug #4930 Report a clear error when a string cannot be split into characters (@​fabpot)
  • feature #4929 Deprecate cloning a Twig environment (@​fabpot)
  • minor #4928 Report the macro call parentheses deprecation once per call site and name the macro (@​fabpot)
Changelog

Sourced from twig/twig's changelog.

3.30.0 (2026-09-25)

  • Fix split, random, and shuffle merging a trailing newline into the last character of a string
  • Speed up splitting a string into characters in split, random, and shuffle
  • Speed up escaping by fetching the escaper runtime once per template
  • Speed up adding extensions to an environment
  • Fix the escaping safe analysis retaining every compiled template node for the lifetime of the environment
  • Speed up loading a template that the environment has already loaded
  • Speed up rendering by compiling a cheaper generator guard into templates
  • Speed up compiling filter, function, and test calls
  • Fix IntlExtension letting the pattern derived from a date formatter prototype override an explicit locale
  • Fix IntlExtension not honoring the locale of a date formatter prototype configured with no date and time styles
  • Speed up macro calls
  • Fix TemplateWrapper::unwrap() failing when called without arguments, which is now deprecated
  • Add TemplateWrapper::getDefaultEscapeStrategy() to know the escaping strategy a template was compiled with
  • Report a clear error when random, reverse, shuffle, and split receive a string that is not valid UTF-8
  • Fix the deprecation about omitting parentheses when calling a macro being reported twice for the same call
  • Add the macro name to the deprecation about omitting parentheses when calling a macro
  • Deprecate cloning a Twig\Environment instance
  • Fix array access with a Stringable key on subclasses of ArrayObject and ArrayIterator
Commits
  • 8c73707 Prepare the 3.30.0 release
  • 052c7ef minor #4950 Fetch the escaper runtime once in the constructor of templates th...
  • 3417f48 Fetch the escaper runtime once in the constructor of templates that escape
  • 9e198d7 minor #4948 Compare the date formatter prototype pattern with the derived one...
  • 22e3119 bug #4946 Fix split trailing newline (fabpot)
  • 00861d5 Fix split trailing newline
  • 81cc196 Bump version
  • 10fe980 Compare the date formatter prototype pattern with the derived one once per pa...
  • c8d782e Deprecate calling TemplateWrapper::unwrap() without arguments as of 3.30 and ...
  • 9c3d58e Fix coding standards
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the dependencies group with 4 updates: [composer/semver](https://github.com/composer/semver), [phpro/grumphp](https://github.com/phpro/grumphp), [phpstan/phpstan](https://github.com/phpstan/phpstan-phar-composer-source) and [twig/twig](https://github.com/twigphp/Twig).


Updates `composer/semver` from 3.4.4 to 3.5.0
- [Release notes](https://github.com/composer/semver/releases)
- [Changelog](https://github.com/composer/semver/blob/main/CHANGELOG.md)
- [Commits](composer/semver@3.4.4...3.5.0)

Updates `phpro/grumphp` from 2.23.0 to 2.24.0
- [Release notes](https://github.com/phpro/grumphp/releases)
- [Commits](phpro/grumphp@v2.23.0...v2.24.0)

Updates `phpstan/phpstan` from 2.2.14 to 2.2.16
- [Commits](https://github.com/phpstan/phpstan-phar-composer-source/commits)

Updates `twig/twig` from 3.29.0 to 3.30.0
- [Release notes](https://github.com/twigphp/Twig/releases)
- [Changelog](https://github.com/twigphp/Twig/blob/3.x/CHANGELOG)
- [Commits](twigphp/Twig@v3.29.0...v3.30.0)

---
updated-dependencies:
- dependency-name: composer/semver
  dependency-version: 3.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: phpro/grumphp
  dependency-version: 2.24.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: phpstan/phpstan
  dependency-version: 2.2.16
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: twig/twig
  dependency-version: 3.30.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update Php code labels Sep 28, 2026
@github-actions
github-actions Bot enabled auto-merge (squash) September 28, 2026 14:55
@github-actions

Copy link
Copy Markdown
Contributor

Try the dev build for this PR: https://acquia-cli.s3.amazonaws.com/build/pr/2050/acli.phar

curl -OL https://acquia-cli.s3.amazonaws.com/build/pr/2050/acli.phar
chmod +x acli.phar

@codecov

codecov Bot commented Sep 28, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 92.76%. Comparing base (35d4df3) to head (2087d8a).

Additional details and impacted files
@@            Coverage Diff            @@
##               main    #2050   +/-   ##
=========================================
  Coverage     92.76%   92.76%           
  Complexity     2032     2032           
=========================================
  Files           126      126           
  Lines          7337     7337           
=========================================
  Hits           6806     6806           
  Misses          531      531           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@github-actions
github-actions Bot merged commit 40de030 into main Sep 28, 2026
26 checks passed
@github-actions
github-actions Bot deleted the dependabot/composer/dependencies-5e0b4c9601 branch September 28, 2026 14:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update Php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants