Skip to content

Bump composer/composer from 2.0.13 to 2.1.6#464

Closed
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/composer/composer/composer-2.1.6
Closed

Bump composer/composer from 2.0.13 to 2.1.6#464
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/composer/composer/composer-2.1.6

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Aug 20, 2021

Bumps composer/composer from 2.0.13 to 2.1.6.

Release notes

Sourced from composer/composer's releases.

2.1.6

  • Updated internal PHAR signatures to be SHA512 instead of SHA1
  • Fixed uncaught exception handler regression (#10022)
  • Fixed more PHP 8.1 deprecation warnings (#10036, #10038, #10061)
  • Fixed corrupted zips in the cache from blocking installs until a cache clear, the bad archives are now deleted automatically on first failure (#10028)
  • Fixed URL sanitizer handling of new github tokens (#10048)
  • Fixed issue finding classes with very long heredocs in classmap autoload (#10050)
  • Fixed proc_open being required for simple installs from zip, as well as diagnose (#9253)
  • Fixed path repository bug causing symlinks to be left behind after a package is uninstalled (#10023)
  • Fixed issue in 7-zip support on windows with certain archives (#10058)
  • Fixed bootstrapping process to avoid loading the composer.json and plugins until necessary, speeding things up slightly (#10064)
  • Fixed lib-openssl detection on FreeBSD (#10046)
  • Fixed support for ircs:// protocol for support.irc composer.json entries

2.1.5

  • Fixed create-project creating a php: directory in the directory it was executed in (#10020, #10021)
  • Fixed curl downloader to respect default_socket_timeout if it is bigger than our default 300s (#10018)

2.1.4

  • Fixed PHP 8.1 deprecation warnings (#10008)
  • Fixed support for working within UNC/WSL paths on Windows (#9993)
  • Fixed 7-zip support to also be looked up on Linux/macOS as 7z or 7zz (#9951)
  • Fixed repositories' only/exclude properties to avoid matching names as sub-strings of full package names (#10001)
  • Fixed open_basedir regression from #9855
  • Fixed schema errors being reported incorrectly in some conditions (#9986)
  • Fixed archive command not working with async archive extraction
  • Fixed init command being able to generate an invalid composer.json (#9986)

2.1.3

  • Add "symlink" option for "bin-compat" config to force symlinking even on WSL/Windows (#9959)
  • Fixed source binaries not being made executable when symlinks cannot be used (#9961)
  • Fixed more deletion edge cases (#9955, #9956)
  • Fixed dump-autoload command not dispatching scripts anymore, regressed in 2.1.2 (#9954)

2.1.2

  • Added --dev to dump-autoload command to allow force-dumping dev autoload rules even if dev requirements are not present (#9946)
  • Fixed --no-scripts disabling events for plugins too instead of only disabling script handlers, using --no-plugins is the way to disable plugins (#9942)
  • Fixed handling of deletions during package installs on some filesystems (#9945, #9947)
  • Fixed undefined array access when using @php <absolute path> in a script handler (#9943)
  • Fixed usage of InstalledVersions when loaded from composer/composer installed as a dependency and runtime Composer is v1 (#9937)

2.1.1

  • Fixed regression in autoload generation when --no-scripts is used (#9935)
  • Fixed outdated color legend to have the right color in the right place (#9939)
  • Fixed PCRE bug causing a previously valid pattern to fail to match (#9941)
  • Fixed JsonFile::validateSchema regression when used as a library to validate custom schema files (#9938)

2.1.0

  • Bumped composer-runtime-api and composer-plugin-api to 2.1.0
  • UX Change: The default install method for packages is now always dist/zip, even for dev packages, added --prefer-install=auto if you want the old behavior (#9603)

... (truncated)

Changelog

Sourced from composer/composer's changelog.

[2.1.6] 2021-08-19

  • Updated internal PHAR signatures to be SHA512 instead of SHA1
  • Fixed uncaught exception handler regression (#10022)
  • Fixed more PHP 8.1 deprecation warnings (#10036, #10038, #10061)
  • Fixed corrupted zips in the cache from blocking installs until a cache clear, the bad archives are now deleted automatically on first failure (#10028)
  • Fixed URL sanitizer handling of new github tokens (#10048)
  • Fixed issue finding classes with very long heredocs in classmap autoload (#10050)
  • Fixed proc_open being required for simple installs from zip, as well as diagnose (#9253)
  • Fixed path repository bug causing symlinks to be left behind after a package is uninstalled (#10023)
  • Fixed issue in 7-zip support on windows with certain archives (#10058)
  • Fixed bootstrapping process to avoid loading the composer.json and plugins until necessary, speeding things up slightly (#10064)
  • Fixed lib-openssl detection on FreeBSD (#10046)
  • Fixed support for ircs:// protocol for support.irc composer.json entries

[2.1.5] 2021-07-23

  • Fixed create-project creating a php: directory in the directory it was executed in (#10020, #10021)
  • Fixed curl downloader to respect default_socket_timeout if it is bigger than our default 300s (#10018)

[2.1.4] 2021-07-22

  • Fixed PHP 8.1 deprecation warnings (#10008)
  • Fixed support for working within UNC/WSL paths on Windows (#9993)
  • Fixed 7-zip support to also be looked up on Linux/macOS as 7z or 7zz (#9951)
  • Fixed repositories' only/exclude properties to avoid matching names as sub-strings of full package names (#10001)
  • Fixed open_basedir regression from #9855
  • Fixed schema errors being reported incorrectly in some conditions (#9986)
  • Fixed archive command not working with async archive extraction
  • Fixed init command being able to generate an invalid composer.json (#9986)

[2.1.3] 2021-06-09

  • Add "symlink" option for "bin-compat" config to force symlinking even on WSL/Windows (#9959)
  • Fixed source binaries not being made executable when symlinks cannot be used (#9961)
  • Fixed more deletion edge cases (#9955, #9956)
  • Fixed dump-autoload command not dispatching scripts anymore, regressed in 2.1.2 (#9954)

[2.1.2] 2021-06-07

  • Added --dev to dump-autoload command to allow force-dumping dev autoload rules even if dev requirements are not present (#9946)
  • Fixed --no-scripts disabling events for plugins too instead of only disabling script handlers, using --no-plugins is the way to disable plugins (#9942)
  • Fixed handling of deletions during package installs on some filesystems (#9945, #9947)
  • Fixed undefined array access when using "@​php " in a script handler (#9943)
  • Fixed usage of InstalledVersions when loaded from composer/composer installed as a dependency and runtime Composer is v1 (#9937)

[2.1.1] 2021-06-04

  • Fixed regression in autoload generation when --no-scripts is used (#9935)
  • Fixed outdated color legend to have the right color in the right place (#9939)

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [composer/composer](https://github.com/composer/composer) from 2.0.13 to 2.1.6.
- [Release notes](https://github.com/composer/composer/releases)
- [Changelog](https://github.com/composer/composer/blob/master/CHANGELOG.md)
- [Commits](composer/composer@2.0.13...2.1.6)

---
updated-dependencies:
- dependency-name: composer/composer
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Aug 20, 2021
@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github Sep 14, 2021

Superseded by #465.

@dependabot dependabot bot closed this Sep 14, 2021
@dependabot dependabot bot deleted the dependabot/composer/composer/composer-2.1.6 branch September 14, 2021 15:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Development

Successfully merging this pull request may close these issues.

0 participants