imposter-plugin
imposter-plugin copied to clipboard
Bump composer/composer from 2.0.13 to 2.3.10
Bumps composer/composer from 2.0.13 to 2.3.10.
Release notes
Sourced from composer/composer's releases.
2.3.10
PSA: If you are seeing issues running non-interactive
create-projectwith a project that does not configureallow-plugins, see the top post of #10928 for a workaround.
- Fixed plugins from CWD/vendor being loaded in some cases like create-project or validate even though the target directory is outside of CWD (#10935)
- Fixed support for legacy (Composer 1.x, e.g. hirak/prestissimo) plugins which will not warn/error anymore if not in allow-plugins, as they are anyway not loaded (#10928)
- Fixed pre-install check for allowed plugins not taking --no-plugins into account (#10925)
- Fixed support for disable_functions containing disk_free_space (#10936)
- Fixed RootPackageRepository usages to always clone the root package to avoid interoperability issues with plugins (#10940)
2.3.9
- Fixed non-interactive behavior of allow-plugins to throw instead of continue with a warning to avoid broken installs (#10920)
- Fixed allow-plugins BC mode to ensure old lock files created pre-2.2 can be installed with only a warning but plugins fully loaded (#10920)
- Fixed deprecation notice (#10921)
- Fixed type errors (#10924)
2.3.8
- Fixed support for
cache-read-onlywhere the filesystem is not writable (#10906)- Fixed type error when using
allow-plugins: true(#10909)- Fixed
@putenvscripts receiving arguments passed to the command (#10846)- Fixed support for spaces in paths with binary proxies on Windows (#10836)
- Fixed type error in GitDownloader if branches cannot be listed (#10888)
- Fixed RootPackageInterface issue on PHP 5.3.3 (#10895)
- Fixed type errors (#10904, #10897)
2.3.7
- Fixed a few PHPStan ConfigReturnTypeExtension bugs
- Fixed Config default for auth configs to be empty arrays instead of null, fixes issues with diagnose command (#10814)
- Fixed handling of broken symlinks when checking whether a package is still installed (#6708)
- Fixed bin proxies to allow a proxy to include another one safely (#10823)
- Fixed openssl 3.x version parsing as it is now semver compliant
- Fixed type error when a json file cannot be read (#10818)
- Fixed parsing of multi-line arrays in funding.yml (#10784)
2.3.6
- Added
Composer\PHPStan\ConfigReturnTypeExtensionto improve return types ofConfig::get()which you can also use in plugins CI (#10635)- Fixed name validation regex in schema causing issues with JS IDEs like VS Code (#10811)
- Fixed unnecessary HTTP request in BitbucketDriver (#10729)
- Fixed invalid credentials loop when setting up GitLab token (#10748)
- Fixed PHP 8.2 deprecations (#10766)
- Fixed lock file changes being output even when the lock file creation is disabled
- Fixed race condition when multiple requests asking for auth on the same hostname fired concurrently (#10763)
- Fixed quoting of commas on Windows (#10775)
- Fixed issue installing path repos with a disabled symlink function (#10786)
- Fixed various type errors (#10753, #10739, #10751)
2.3.5
- Security: Fixed command injection vulnerability in HgDriver/GitDriver (GHSA-x7cr-6qr6-2hh6 / CVE-2022-24828)
- Added warning when downloading a file with
verify_peer[_name]disabled (#10722)- Fixed curl downloader not retrying when a DNS resolution failure occurs (#10716)
- Fixed composer.lock file still being used/read when the
lockconfig option is disabled (#10726)
... (truncated)
Changelog
Sourced from composer/composer's changelog.
[2.3.10] 2022-07-13
- Fixed plugins from CWD/vendor being loaded in some cases like create-project or validate even though the target directory is outside of CWD (#10935)
- Fixed support for legacy (Composer 1.x, e.g. hirak/prestissimo) plugins which will not warn/error anymore if not in allow-plugins, as they are anyway not loaded (#10928)
- Fixed pre-install check for allowed plugins not taking --no-plugins into account (#10925)
- Fixed support for disable_functions containing disk_free_space (#10936)
- Fixed RootPackageRepository usages to always clone the root package to avoid interoperability issues with plugins (#10940)
[2.3.9] 2022-07-05
- Fixed non-interactive behavior of allow-plugins to throw instead of continue with a warning to avoid broken installs (#10920)
- Fixed allow-plugins BC mode to ensure old lock files created pre-2.2 can be installed with only a warning but plugins fully loaded (#10920)
- Fixed deprecation notice (#10921)
- Fixed type errors (#10924)
[2.3.8] 2022-07-01
- Fixed support for
cache-read-onlywhere the filesystem is not writable (#10906)- Fixed type error when using
allow-plugins: true(#10909)- Fixed
@putenvscripts receiving arguments passed to the command (#10846)- Fixed support for spaces in paths with binary proxies on Windows (#10836)
- Fixed type error in GitDownloader if branches cannot be listed (#10888)
- Fixed RootPackageInterface issue on PHP 5.3.3 (#10895)
- Fixed type errors (#10904, #10897)
[2.3.7] 2022-06-06
- Fixed a few PHPStan ConfigReturnTypeExtension bugs
- Fixed Config default for auth configs to be empty arrays instead of null, fixes issues with diagnose command (#10814)
- Fixed handling of broken symlinks when checking whether a package is still installed (#6708)
- Fixed bin proxies to allow a proxy to include another one safely (#10823)
- Fixed openssl 3.x version parsing as it is now semver compliant
- Fixed type error when a json file cannot be read (#10818)
- Fixed parsing of multi-line arrays in funding.yml (#10784)
[2.3.6] 2022-06-01
- Added
Composer\PHPStan\ConfigReturnTypeExtensionto improve return types ofConfig::get()which you can also use in plugins CI (#10635)- Fixed name validation regex in schema causing issues with JS IDEs like VS Code (#10811)
- Fixed unnecessary HTTP request in BitbucketDriver (#10729)
- Fixed invalid credentials loop when setting up GitLab token (#10748)
- Fixed PHP 8.2 deprecations (#10766)
- Fixed lock file changes being output even when the lock file creation is disabled
- Fixed race condition when multiple requests asking for auth on the same hostname fired concurrently (#10763)
- Fixed quoting of commas on Windows (#10775)
- Fixed issue installing path repos with a disabled symlink function (#10786)
- Fixed various type errors (#10753, #10739, #10751)
[2.3.5] 2022-04-13
... (truncated)
Commits
ebac357Release 2.3.10f54878dUpdate changeloge1e29bfMerge branch '2.2' into 2.3c5ff1e1Reverting release version changesa8ab507Release 2.2.175cb24aaUpdate changelogb195f38Always clone root package before adding it to a RootPackageRepo to avoid issu...336a0d2Add hint in create-project when it fails due to a missing allow-plugins in pr...0e59fbbFix #10935 in a more generic way which fixes the issue for all Factory::creat...37a7889Fix phpdoc issue- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)