Skip to content

Conversation

@dependabot-preview
Copy link

Bumps composer/composer from 1.9.0 to 1.9.3.

Release notes

Sourced from composer/composer's releases.

1.9.3

  • Fixed GitHub deprecation of access_token query parameter, now using Authorization header

1.9.2

  • Fixed minor git driver bugs
  • Fixed schema validation for version field to allow dev-* versions too
  • Fixed external processes' output being formatted even though it should not
  • Fixed issue with path repositories when trying to install feature branches

1.9.1

  • Fixed various credential handling issues with gitlab and github
  • Fixed credentials being present in git remotes in Composer cache and vendor directory when not using SSH keys
  • Fixed composer why not listing replacers as a reason something is present
  • Fixed various PHP 7.4 compatibility issues
  • Fixed root warnings always present in Docker containers, setting COMPOSER_ALLOW_SUPERUSER is not necessary anymore
  • Fixed GitHub access tokens leaking into debug-verbosity output
  • Fixed several edge case issues detecting GitHub, Bitbucket and GitLab repository types
  • Fixed Composer asking if you want to use a composer.json in a parent directory when ran in non-interactive mode
  • Fixed classmap autoloading issue finding classes located within a few non-PHP context blocks (?>...<?php)
Changelog

Sourced from composer/composer's changelog.

[1.9.3] 2020-02-04

  • Fixed GitHub deprecation of access_token query parameter, now using Authorization header

[1.9.2] 2020-01-14

  • Fixed minor git driver bugs
  • Fixed schema validation for version field to allow dev-* versions too
  • Fixed external processes' output being formatted even though it should not
  • Fixed issue with path repositories when trying to install feature branches

[1.9.1] 2019-11-01

  • Fixed various credential handling issues with gitlab and github
  • Fixed credentials being present in git remotes in Composer cache and vendor directory when not using SSH keys
  • Fixed composer why not listing replacers as a reason something is present
  • Fixed various PHP 7.4 compatibility issues
  • Fixed root warnings always present in Docker containers, setting COMPOSER_ALLOW_SUPERUSER is not necessary anymore
  • Fixed GitHub access tokens leaking into debug-verbosity output
  • Fixed several edge case issues detecting GitHub, Bitbucket and GitLab repository types
  • Fixed Composer asking if you want to use a composer.json in a parent directory when ran in non-interactive mode
  • Fixed classmap autoloading issue finding classes located within a few non-PHP context blocks (?>...<?php)
Commits
  • 1291a16 Release 1.9.3
  • ca0b236 Update changelog
  • 460c673 Use Authorization header instead of deprecated access_token query param, fixe...
  • be08638 Update changelog
  • a2dadb9 Return two packages in PathRepository when on a feature branch, one for featu...
  • 0b767e0 Allow calling getProviderNames multiple times, refs #8516
  • 3791a57 Provide partial packages names if available, closes #8516, fixes #8526
  • ef6ef8a Hint at the partial update command, fixes #8508, refs #8332
  • 4e667f8 Fix 5.3 build
  • d3f1c66 Avoid formatting output from external processes, fixes #8524
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

Bumps [composer/composer](https://github.com/composer/composer) from 1.9.0 to 1.9.3.
- [Release notes](https://github.com/composer/composer/releases)
- [Changelog](https://github.com/composer/composer/blob/master/CHANGELOG.md)
- [Commits](composer/composer@1.9.0...1.9.3)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@dependabot-preview dependabot-preview bot added the dependencies Pull requests that update a dependency file label Feb 5, 2020
@dependabot-preview
Copy link
Author

Superseded by #55.

@dependabot-preview dependabot-preview bot deleted the dependabot/composer/composer/composer-1.9.3 branch March 11, 2020 07:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants