Skip to content

Bump Symfony, Guzzle and Twig dependencies (combined Dependabot updates)#580

Closed
lgladdy wants to merge 2 commits into
developfrom
bulk-dependabot
Closed

Bump Symfony, Guzzle and Twig dependencies (combined Dependabot updates)#580
lgladdy wants to merge 2 commits into
developfrom
bulk-dependabot

Conversation

@lgladdy

@lgladdy lgladdy commented Jun 22, 2026

Copy link
Copy Markdown
Member

Combines the 8 open Dependabot updates into a single lockfile update, plus the transitive bumps required to resolve a fully security-clean dependency set:

Plus transitive: guzzle command/promises/uri-template, symfony error-handler/event-dispatcher/var-dumper 8.1.0, contracts and polyfills.

All bumps are within-major (semver minor/patch). composer audit on the resulting lock reports no remaining advisories.

lgladdy and others added 2 commits June 22, 2026 12:29
Combines the 8 open Dependabot updates into a single lockfile update, plus
the transitive bumps required to resolve a fully security-clean dependency set:

- symfony/routing 8.0.4 => 8.1.0 (#577)
- symfony/http-foundation 8.0.4 => 8.1.0 (#576)
- guzzlehttp/psr7 2.8.0 => 2.12.1 (#575 targeted 2.11.0, still affected by CVE-2026-55766)
- guzzlehttp/guzzle-services 1.4.2 => 1.7.0 (#574)
- symfony/yaml 7.4.1 => 7.4.13 (#572)
- symfony/cache 7.4.4 => 7.4.13 (#571)
- symfony/http-kernel 7.4.4 => 7.4.13 (#570)
- symfony/monolog-bridge 7.4.4 => 7.4.12 (#569)
- guzzlehttp/guzzle 7.10.0 => 7.12.1 (CVE-2026-55767, CVE-2026-55568; no PR)
- twig/twig 3.26.0 => 3.27.1 (CVE-2026-48808, CVE-2026-48805, CVE-2026-46636; no PR)

Plus transitive: guzzle command/promises/uri-template, symfony
error-handler/event-dispatcher/var-dumper 8.1.0, contracts and polyfills.

All bumps are within-major (semver minor/patch). `composer audit` on the
resulting lock reports no remaining advisories.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@lgladdy lgladdy requested review from a team and JamesDominy as code owners June 22, 2026 14:04
@lgladdy lgladdy closed this Jun 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant