Skip to content

Conversation

@dependabot-preview
Copy link

Bumps composer/composer from 1.9.0 to 1.10.10.

Release notes

Sourced from composer/composer's releases.

1.10.10

  • Fixed create-project not triggering events while installing the root package
  • Fixed PHP 8 compatibility issue
  • Fixed self-update to avoid automatically upgrading to the next major version once it becomes stable

1.10.9

  • Fixed Bitbucket redirect loop when credentials are outdated
  • Fixed GitLab auth prompt wording
  • Fixed self-update handling of files requiring admin permissions to write to on Windows (it now does a UAC prompt)
  • Fixed parsing issues in funding.yml files

1.10.8

  • Fixed compatibility issue with git being configured to show signatures by default
  • Fixed discarding of local changes when updating packages to include untracked files
  • Several minor fixes

1.10.7

  • Fix PHP 8 deprecations
  • Fixed detection of pcntl_signal being in disabled_functions when pcntl_async_signal is allowed

1.10.6

  • Fixed version guessing to take composer-runtime-api and composer-plugin-api requirements into account to avoid selecting packages which require Composer 2
  • Fixed package name validation to allow several dashes following each other
  • Fixed post-status-cmd script not firing when there were no changes to be displayed
  • Fixed composer-runtime-api support on Composer 1.x, the package is now present as 1.0.0
  • Fixed support for composer show --name-only --self
  • Fixed detection of GitLab URLs when handling authentication in some cases

1.10.5

  • Fixed self-update on PHP <5.6, seriously please upgrade people, it's time
  • Fixed 1.10.2 regression with PATH resolution in scripts

1.10.4

  • Fixed 1.10.2 regression in path symlinking with absolute path repos

1.10.3

  • Fixed invalid --2 flag warning in self-update when no channel is requested

1.10.2

  • Added --1 flag to self-update command which can be added to automated self-update runs to make sure it won't automatically jump to 2.0 once that is released
  • Fixed path repository symlinks being made relative when the repo url is defined as absolute paths
  • Fixed potential issues when using "composer ..." in scripts and composer/composer was also required in the project
  • Fixed 1.10.0 regression when downloading GitHub archives from non-API URLs
  • Fixed handling of malformed info in fund command
  • Fixed Symfony5 compatibility issues in a few commands

1.10.1

  • Fixed path repository warning on empty path when using wildcards
  • Fixed superfluous warnings when generating optimized autoloaders
Changelog

Sourced from composer/composer's changelog.

[1.10.10] 2020-08-03

  • Fixed create-project not triggering events while installing the root package
  • Fixed PHP 8 compatibility issue
  • Fixed self-update to avoid automatically upgrading to the next major version once it becomes stable

[1.10.9] 2020-07-16

  • Fixed Bitbucket redirect loop when credentials are outdated
  • Fixed GitLab auth prompt wording
  • Fixed self-update handling of files requiring admin permissions to write to on Windows (it now does a UAC prompt)
  • Fixed parsing issues in funding.yml files

[1.10.8] 2020-06-24

  • Fixed compatibility issue with git being configured to show signatures by default
  • Fixed discarding of local changes when updating packages to include untracked files
  • Several minor fixes

[1.10.7] 2020-06-03

  • Fixed PHP 8 deprecations
  • Fixed detection of pcntl_signal being in disabled_functions when pcntl_async_signal is allowed

[1.10.6] 2020-05-06

  • Fixed version guessing to take composer-runtime-api and composer-plugin-api requirements into account to avoid selecting packages which require Composer 2
  • Fixed package name validation to allow several dashes following each other
  • Fixed post-status-cmd script not firing when there were no changes to be displayed
  • Fixed composer-runtime-api support on Composer 1.x, the package is now present as 1.0.0
  • Fixed support for composer show --name-only --self
  • Fixed detection of GitLab URLs when handling authentication in some cases

[1.10.5] 2020-04-10

  • Fixed self-update on PHP <5.6, seriously please upgrade people, it's time
  • Fixed 1.10.2 regression with PATH resolution in scripts

[1.10.4] 2020-04-09

  • Fixed 1.10.2 regression in path symlinking with absolute path repos

[1.10.3] 2020-04-09

  • Fixed invalid --2 flag warning in self-update when no channel is requested

[1.10.2] 2020-04-09

  • Added --1 flag to self-update command which can be added to automated self-update runs to make sure it won't automatically jump to 2.0 once that is released
  • Fixed path repository symlinks being made relative when the repo url is defined as absolute paths
Commits
  • 32966a3 Release 1.10.10
  • b112f90 Update changelog
  • 393acc7 Merge pull request #9092 from composer/revert-9085-lib-cldr
  • 00f712a Revert "Allow specifying a version requirement for CLDR"
  • 387e828 Promote next major version when running stable self-update, and prevent self-...
  • 5bd61ac Cache versions data to avoid redownloading it twice during self-update
  • 7028d0c Merge pull request #9077 from glaubinix/f/api-data-detection
  • daae46e Merge pull request #9085 from lstrojny/lib-cldr
  • 868aa10 Merge pull request #9076 from TysonAndre/named-arguments-bugfix
  • 5a02ea6 Check that class exists
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

Bumps [composer/composer](https://github.com/composer/composer) from 1.9.0 to 1.10.10.
- [Release notes](https://github.com/composer/composer/releases)
- [Changelog](https://github.com/composer/composer/blob/master/CHANGELOG.md)
- [Commits](composer/composer@1.9.0...1.10.10)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@dependabot-preview dependabot-preview bot added the dependencies Pull requests that update a dependency file label Aug 4, 2020
@dependabot-preview
Copy link
Author

Superseded by #73.

@dependabot-preview dependabot-preview bot deleted the dependabot/composer/composer/composer-1.10.10 branch September 8, 2020 21:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant