Skip to content

chore(deps): bump the composer group across 1 directory with 18 updates - #685

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/composer/composer-aedc6fe12f
Open

chore(deps): bump the composer group across 1 directory with 18 updates#685
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/composer/composer-aedc6fe12f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 3, 2026

Copy link
Copy Markdown
Contributor

Bumps the composer group with 15 updates in the / directory:

Package From To
doctrine/doctrine-migrations-bundle 4.0.0 4.0.1
phpstan/phpdoc-parser 2.3.3 2.3.5
sentry/sentry-symfony 5.12.0 5.13.0
symfony/dotenv 8.1.2 8.1.6
symfony/property-info 8.1.5 8.1.6
symfony/rate-limiter 8.1.4 8.1.6
symfony/security-bundle 8.1.2 8.1.6
symfony/serializer 8.1.5 8.1.6
symfony/validator 8.1.5 8.1.6
web-auth/webauthn-symfony-bundle 5.3.5 5.3.8
friendsofphp/php-cs-fixer 3.95.22 3.95.24
phpstan/phpstan 2.2.9 2.2.13
phpunit/phpunit 13.3.1 13.3.2
rector/rector 2.6.3 2.6.6
symfony/phpunit-bridge 8.1.5 8.1.6

Updates doctrine/doctrine-migrations-bundle from 4.0.0 to 4.0.1

Release notes

Sourced from doctrine/doctrine-migrations-bundle's releases.

4.0.1

Release Notes for 4.0.1

4.0.1

  • Total issues resolved: 0
  • Total pull requests resolved: 4
  • Total contributors: 3

CI

Documentation

This release also contains changes from https://github.com/doctrine/DoctrineMigrationsBundle/releases/tag/3.7.1

Commits
  • 43e9212 Merge pull request #684 from greg0ire/4.0.x
  • 0eb7b39 Merge remote-tracking branch 'origin/3.7.x' into 4.0.x
  • 0005669 Merge pull request #683 from HypeMC/fix-680
  • a0d82ea Don't disable filesystem migrations when service migrations are enabled
  • 1fd1454 Merge pull request #679 from doctrine/dependabot/github_actions/3.7.x/doctrin...
  • 9c01913 Bump the doctrine group with 6 updates
  • 0faf830 Add SECURITY.md to link to reporting policy and email.
  • d509b0d Bump the doctrine group with 6 updates (#677)
  • df832dc Merge pull request #675 from doctrine/dependabot/github_actions/doctrine-53ad...
  • 17afddd Bump the doctrine group with 6 updates
  • Additional commits viewable in compare view

Updates phpstan/phpdoc-parser from 2.3.3 to 2.3.5

Release notes

Sourced from phpstan/phpdoc-parser's releases.

2.3.5

  • 148ceff - Lexer: extract the matches with PREG_PATTERN_ORDER
  • e59b0c8 - Lexer: make the numeric-separator groups non-capturing

2.3.4

  • 98dbc94 - Write the PHPDoc language down as a grammar, and fuzz from it
  • 58390a4 - Read Foo & .5 as an intersection, not as a reference
  • e4b19f0 - Run the tests written for @pure-unless-parameter-passed
  • d551e9e - Fix three ways a valid PHPDoc is read or written back wrong
  • 7de1fb2 - Update github-actions (#307)
  • 326f797 - Update github-actions (#305)
Commits
  • 148ceff Lexer: extract the matches with PREG_PATTERN_ORDER
  • e59b0c8 Lexer: make the numeric-separator groups non-capturing
  • 98dbc94 Write the PHPDoc language down as a grammar, and fuzz from it
  • 58390a4 Read Foo & .5 as an intersection, not as a reference
  • e4b19f0 Run the tests written for @pure-unless-parameter-passed
  • d551e9e Fix three ways a valid PHPDoc is read or written back wrong
  • 7de1fb2 Update github-actions (#307)
  • 326f797 Update github-actions (#305)
  • See full diff in compare view

Updates sentry/sentry-symfony from 5.12.0 to 5.13.0

Release notes

Sourced from sentry/sentry-symfony's releases.

5.13.0

The Sentry SDK team is happy to announce the immediate availability of Sentry Symfony SDK v5.13.0.

Misc

Changelog

Sourced from sentry/sentry-symfony's changelog.

5.13.0

The Sentry SDK team is happy to announce the immediate availability of Sentry Symfony SDK v5.13.0.

Misc

Commits

Updates symfony/console from 8.1.5 to 8.1.6

Release notes

Sourced from symfony/console's releases.

v8.1.6

Changelog (symfony/console@v8.1.5...v8.1.6)

Commits
  • eb7d995 Merge branch '7.4' into 8.1
  • 23d6f88 Merge branch '6.4' into 7.4
  • 3b8473e [Console][FrameworkBundle] Fix profiling a command stopped at ConsoleEvents::...
  • ad7e62b [Console] Fix service arguments not resolved when a command is invoked by ali...
  • See full diff in compare view

Updates symfony/dotenv from 8.1.2 to 8.1.6

Release notes

Sourced from symfony/dotenv's releases.

v8.1.6

Changelog (symfony/dotenv@v8.1.2...v8.1.6)

Commits

Updates symfony/framework-bundle from 8.1.5 to 8.1.6

Release notes

Sourced from symfony/framework-bundle's releases.

v8.1.6

Changelog (symfony/framework-bundle@v8.1.5...v8.1.6)

Commits
  • 18ea259 Merge branch '7.4' into 8.1
  • 45d6d66 Merge branch '6.4' into 7.4
  • a19f20a Merge branch '5.4' into 6.4
  • af61a85 Revert "Give the Redis test probes an explicit connect timeout"
  • 608e729 Merge branch '7.4' into 8.1
  • 859a180 Merge branch '6.4' into 7.4
  • c658a54 Merge branch '5.4' into 6.4
  • 7179635 Give the Redis test probes an explicit connect timeout
  • 530edfd Declare the polyfills needed by the code on PHP 7.2
  • f7e55a4 Merge branch '7.4' into 8.1
  • Additional commits viewable in compare view

Updates symfony/property-info from 8.1.5 to 8.1.6

Release notes

Sourced from symfony/property-info's releases.

v8.1.6

Changelog (symfony/property-info@v8.1.5...v8.1.6)

Commits
  • d25e1da [PropertyInfo] Read only the doc block of a promoted property in getTypeFromC...
  • 92b3d8d Merge branch '7.4' into 8.1
  • 52420d4 Merge branch '6.4' into 7.4
  • 003ec30 [PropertyInfo] Do not prefer a static named constructor as the property mutator
  • cfbe712 [PropertyInfo] Do not prefer a static named constructor as the property accessor
  • See full diff in compare view

Updates symfony/rate-limiter from 8.1.4 to 8.1.6

Release notes

Sourced from symfony/rate-limiter's releases.

v8.1.6

Changelog (symfony/rate-limiter@v8.1.4...v8.1.6)

Commits

Updates symfony/security-bundle from 8.1.2 to 8.1.6

Release notes

Sourced from symfony/security-bundle's releases.

v8.1.6

Changelog (symfony/security-bundle@v8.1.2...v8.1.6)

Commits
  • b5830ac Merge branch '7.4' into 8.1
  • caaa8b9 [Security] Stop calling the APIs that web-token/jwt-framework 4.3 deprecates
  • 4bd12b7 Merge branch '7.4' into 8.1
  • e9b3f2b Merge branch '6.4' into 7.4
  • de06cd0 [SecurityBundle] Un-skip the explicit lock factory login throttling test
  • da7eb83 Merge branch '7.4' into 8.1
  • 524649d Merge branch '6.4' into 7.4
  • 7984320 Merge branch '5.4' into 6.4
  • 06c3aba [SecurityBundle] Use a lock for login throttling by default
  • 7b0c144 [SecurityBundle] Make the remember-me cookie follow the session cookie defaults
  • Additional commits viewable in compare view

Updates symfony/serializer from 8.1.5 to 8.1.6

Release notes

Sourced from symfony/serializer's releases.

v8.1.6

Changelog (symfony/serializer@v8.1.5...v8.1.6)

Commits
  • 931151b [Serializer] Enforce the element type of nested scalar collections
  • 530caa7 Merge branch '7.4' into 8.1
  • 1f31d4e Merge branch '6.4' into 7.4
  • ad3c87d [Serializer] Fix deep_object_to_populate for collections of objects
  • adc08c4 Merge branch '7.4' into 8.1
  • 8c5db81 Merge branch '6.4' into 7.4
  • 2cec535 [Serializer] Fix max depth counting for subclasses that inherit MaxDepth meta...
  • 384dd37 [Serializer] Let DISABLE_TYPE_ENFORCEMENT keep strings that cannot be converted
  • See full diff in compare view

Updates symfony/validator from 8.1.5 to 8.1.6

Release notes

Sourced from symfony/validator's releases.

v8.1.6

Changelog (symfony/validator@v8.1.5...v8.1.6)

Commits
  • 597f234 Merge branch '7.4' into 8.1
  • 976bd87 Merge branch '6.4' into 7.4
  • 8acf2af Merge branch '5.4' into 6.4
  • d7306fd Merge branch '5.4' into 6.4
  • c9ac623 [Validator] Remove the test that depends on the ExpressionLanguage nesting limit
  • e734df4 [Translation] Fix Persian (fa) translations for Form and Validator components
  • 3c6593d [Validator] Review and finalize Indonesian (id) translation messages
  • 920f591 Merge branch '7.4' into 8.1
  • 17fe0a1 Merge branch '6.4' into 7.4
  • 756423a [ExpressionLanguage] Bound the nesting level of parsed expressions
  • Additional commits viewable in compare view

Updates symfony/yaml from 8.1.5 to 8.1.6

Release notes

Sourced from symfony/yaml's releases.

v8.1.6

Changelog (symfony/yaml@v8.1.5...v8.1.6)

Commits
  • 0b4aa53 Merge branch '7.4' into 8.1
  • 4cef939 Merge branch '6.4' into 7.4
  • a778aba Merge branch '5.4' into 6.4
  • b1903f4 Merge branch '7.4' into 8.1
  • f0e9861 Merge branch '6.4' into 7.4
  • 12c6b4f [Yaml] Bound recursion depth in the inline lexer
  • 7b18a2a [Yaml] Quote strings that look like octal numbers when dumping
  • See full diff in compare view

Updates web-auth/webauthn-symfony-bundle from 5.3.5 to 5.3.8

Commits
  • f46f262 fix(symfony)!: stop registering the insecure RS1 algorithm (#958)
  • a32e781 fix(rp-entity): default rp.name to the Relying Party ID when serializing (#944)
  • 861b99f fix(symfony): keep the legacy repository alias only when it is implemented (#...
  • c382b3e ci: repair the pipeline (#934)
  • See full diff in compare view

Updates friendsofphp/php-cs-fixer from 3.95.22 to 3.95.24

Release notes

Sourced from friendsofphp/php-cs-fixer's releases.

v3.95.24 Adalbertus

What's Changed

New Contributors

Full Changelog: PHP-CS-Fixer/PHP-CS-Fixer@v3.95.23...v3.95.24

v3.95.23 Adalbertus

What's Changed

Full Changelog: PHP-CS-Fixer/PHP-CS-Fixer@v3.95.22...v3.95.23

Changelog

Sourced from friendsofphp/php-cs-fixer's changelog.

Changelog for v3.95.24

  • fix: ControlStructureBracesFixer - do not read a body starting with a parenthesis as a condition (#9815)
  • UX: init - add handling of .gitignore (#9813)
  • UX: init - add sections (#9819)
  • UX: init - command improvements (#9807)
  • UX: init - fix typos and improve wording (#9820)
  • UX: init command - suggest php_unit_test_case_static_method_calls rule (#9810)
  • chore: Fixer name must not be empty (#9756)
  • chore: DescribeCommand - replace dynamic method calls with explicit ones (#9817)
  • chore: PhpdocOrderFixer - fix type of duplicated tags passed to naturalLanguageJoin (#9818)
  • CI: fix warning - Unexpected input(s) 'extensions' (#9809)
  • CI: introduce PHPBench (#9755)
  • refactor: init - move content preparation to helper method (#9812)

Changelog for v3.95.23

  • fix: FunctionsAnalyzer - detect return type of a closure with a use clause (#9806)
Commits
  • 9a4b805 prepared the 3.95.24 release
  • 4cd7e9f UX: init - fix typos and improve wording (#9820)
  • f9a1fb4 UX: init - add handling of .gitignore (#9813)
  • 1c03254 UX: init command - suggest php_unit_test_case_static_method_calls rule (#9810)
  • f610f91 UX: init - add sections (#9819)
  • 5a3e3ec fix: ControlStructureBracesFixer - do not read a body starting with a paren...
  • 529e7b8 chore: DescribeCommand - replace dynamic method calls with explicit ones (#...
  • 460da40 chore: PhpdocOrderFixer - fix type of duplicated tags passed to `naturalLan...
  • edd854e refactor: init - move content preparation to helper method (#9812)
  • 20b8578 CI: fix warning - Unexpected input(s) 'extensions' (#9809)
  • Additional commits viewable in compare view

Updates phpstan/phpstan from 2.2.9 to 2.2.13

Commits

Updates phpunit/phpunit from 13.3.1 to 13.3.2

Release notes

Sourced from phpunit/phpunit's releases.

PHPUnit 13.3.2

Fixed

  • #6904: SourceMap is built in child process even though identifyIssueTrigger is disabled
  • #6924: #[CoversFile] attribute is not considered for risky test check

Learn how to install or update PHPUnit 13.3 in the documentation.

Keep up to date with PHPUnit:

Changelog

Sourced from phpunit/phpunit's changelog.

[13.3.2] - 2026-08-27

Fixed

  • #6904: SourceMap is built in child process even though identifyIssueTrigger is disabled
  • #6924: #[CoversFile] attribute is not considered for risky test check
Commits
  • 22104a5 Prepare release
  • 7da33db Merge branch '12.5' into 13.3
  • 6cbff63 Prepare release
  • b142494 Update dependency phpunit/php-file-iterator to ^7.0.2
  • 2da9ae8 Update dependency sebastian/diff to ^7.0.1
  • 41ad3fa Update dependency phpunit/php-file-iterator to ^6.0.2
  • bdfc83e Update actions/setup-java action to v6
  • 2afb6f7 Closes #6924
  • 76b1c89 Update actions/setup-java action to v6
  • 6356792 Do not use deprecated CLI option in end-to-end test
  • Additional commits viewable in compare view

Updates rector/rector from 2.6.3 to 2.6.6

Release notes

Sourced from rector/rector's releases.

Released Rector 2.6.6

File selection

--filter option to narrow processed files (#8419)

New --filter option keeps only files whose path matches all given patterns. Repeat the option to require several patterns at once, handy for scoping a run to a subtree or a naming convention without editing config paths.

vendor/bin/rector process src --filter Controller --filter Admin

Before: process every file under the given paths. After: process only files matching all --filter patterns.

Bugfixes 🐛

  • Add back RectorConfig::tag() as a no-op BC layer (#8431)
  • TypeDeclarationDocblocks: fix invalid array-in-key docblock when narrowing long array unions (#8430)
  • BetterPhpDocParser: keep import used only in an annotation array key (#8429)
  • RenameVariableToMatchMethodCallReturnTypeRector: fix partial rename with same-named nested arrow param (#8428)
  • ArrayFirstLastRector: skip nested compound assignment (#8425)
  • ReturnTypeFromStrictNewArrayRector: add doc return type only for list and generic arrays (#8423), skip noisy array-shape union return docblock (#8422)

Extension packages

rector-phpunit 🟢

  • AllowMockObjectsForDataProviderRector: skip dynamic method call (#781)
  • AssertEmptyNullableObjectToAssertInstanceofRector: skip assertNull/assertEmpty (#780)
  • AddSeeTestAnnotationRector: skip existing imported or short @see annotation (#779)

rector-downgrade-php ⬇️

  • DowngradeSetAccessibleReflectionPropertyRector: handle getProperties()/getMethods() loop (#396)
  • DowngradeHashAlgorithmXxHashRector: skip PHP_VERSION_ID guarded hash() calls (#394)

Internal / cleanup

  • Add mspirkov/yii2-rector link to README (#8427)
  • Add fixtures for arrow functions returning a ?? expression (#8421)

Released Rector 2.6.5

Caching

This release makes the cache smarter about config changes - fewer needless full re-runs, while still invalidating when results could actually differ.

Configured rule value changes now invalidate the cache (#8400)

... (truncated)

Commits
  • ca069d6 Rector 2.6.6
  • dd1dbd8 Updated Rector to commit c8f5daeffd982de54092ead1bc0d278a60aa3747
  • c6ecc8d Updated Rector to commit 0919678db52fe2ede06192b3b19834401da4a472
  • 27296aa Updated Rector to commit 96fd595f95029db66bd5205e6c5aa60eb4745353
  • 1e88d3d Updated Rector to commit ee2e8d0dd1afbdc754e5c9f6db7835e5136055f8
  • 33b2be9 Updated Rector to commit ee2e8d0dd1afbdc754e5c9f6db7835e5136055f8
  • 0a5abf5 Updated Rector to commit 28a4645c168c2567f79108c1c4463cda1afb4aff
  • 646f9f7 Updated Rector to commit 28a4645c168c2567f79108c1c4463cda1afb4aff
  • 78802da Updated Rector to commit 28a4645c168c2567f79108c1c4463cda1afb4aff
  • 7a20767 Updated Rector to commit 0c3d4f4e3c5c3eb7eabc0f7097bd7efaea657439
  • Additional commits viewable in compare view

Updates symfony/phpunit-bridge from 8.1.5 to 8.1.6

Release notes

Sourced from symfony/phpunit-bridge's releases.

v8.1.6

Changelog (symfony/phpunit-bridge@v8.1.5...v8.1.6)

  • bug #65754 Fix ClockMock::hrtime() when the clock is not mocked and when the nanoseconds have leading zeros (@​nicolas-grekas)
Commits
  • abd3c4e Merge branch '7.4' into 8.1
  • ff3a78a Merge branch '6.4' into 7.4
  • e41aaf9 [PhpUnitBridge] Fix ClockMock::hrtime() when the clock is not mocked and when...
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update php code labels Sep 3, 2026
@github-actions
github-actions Bot enabled auto-merge September 3, 2026 11:44
Bumps the composer group with 15 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [doctrine/doctrine-migrations-bundle](https://github.com/doctrine/DoctrineMigrationsBundle) | `4.0.0` | `4.0.1` |
| [phpstan/phpdoc-parser](https://github.com/phpstan/phpdoc-parser) | `2.3.3` | `2.3.5` |
| [sentry/sentry-symfony](https://github.com/getsentry/sentry-symfony) | `5.12.0` | `5.13.0` |
| [symfony/dotenv](https://github.com/symfony/dotenv) | `8.1.2` | `8.1.6` |
| [symfony/property-info](https://github.com/symfony/property-info) | `8.1.5` | `8.1.6` |
| [symfony/rate-limiter](https://github.com/symfony/rate-limiter) | `8.1.4` | `8.1.6` |
| [symfony/security-bundle](https://github.com/symfony/security-bundle) | `8.1.2` | `8.1.6` |
| [symfony/serializer](https://github.com/symfony/serializer) | `8.1.5` | `8.1.6` |
| [symfony/validator](https://github.com/symfony/validator) | `8.1.5` | `8.1.6` |
| [web-auth/webauthn-symfony-bundle](https://github.com/web-auth/webauthn-symfony-bundle) | `5.3.5` | `5.3.8` |
| [friendsofphp/php-cs-fixer](https://github.com/PHP-CS-Fixer/PHP-CS-Fixer) | `3.95.22` | `3.95.24` |
| [phpstan/phpstan](https://github.com/phpstan/phpstan-phar-composer-source) | `2.2.9` | `2.2.13` |
| [phpunit/phpunit](https://github.com/sebastianbergmann/phpunit) | `13.3.1` | `13.3.2` |
| [rector/rector](https://github.com/rectorphp/rector) | `2.6.3` | `2.6.6` |
| [symfony/phpunit-bridge](https://github.com/symfony/phpunit-bridge) | `8.1.5` | `8.1.6` |



Updates `doctrine/doctrine-migrations-bundle` from 4.0.0 to 4.0.1
- [Release notes](https://github.com/doctrine/DoctrineMigrationsBundle/releases)
- [Commits](doctrine/DoctrineMigrationsBundle@4.0.0...4.0.1)

Updates `phpstan/phpdoc-parser` from 2.3.3 to 2.3.5
- [Release notes](https://github.com/phpstan/phpdoc-parser/releases)
- [Commits](phpstan/phpdoc-parser@2.3.3...2.3.5)

Updates `sentry/sentry-symfony` from 5.12.0 to 5.13.0
- [Release notes](https://github.com/getsentry/sentry-symfony/releases)
- [Changelog](https://github.com/getsentry/sentry-symfony/blob/master/CHANGELOG.md)
- [Commits](getsentry/sentry-symfony@5.12.0...5.13.0)

Updates `symfony/console` from 8.1.5 to 8.1.6
- [Release notes](https://github.com/symfony/console/releases)
- [Changelog](https://github.com/symfony/console/blob/8.2/CHANGELOG.md)
- [Commits](symfony/console@v8.1.5...v8.1.6)

Updates `symfony/dotenv` from 8.1.2 to 8.1.6
- [Release notes](https://github.com/symfony/dotenv/releases)
- [Changelog](https://github.com/symfony/dotenv/blob/8.2/CHANGELOG.md)
- [Commits](symfony/dotenv@v8.1.2...v8.1.6)

Updates `symfony/framework-bundle` from 8.1.5 to 8.1.6
- [Release notes](https://github.com/symfony/framework-bundle/releases)
- [Changelog](https://github.com/symfony/framework-bundle/blob/8.2/CHANGELOG.md)
- [Commits](symfony/framework-bundle@v8.1.5...v8.1.6)

Updates `symfony/property-info` from 8.1.5 to 8.1.6
- [Release notes](https://github.com/symfony/property-info/releases)
- [Changelog](https://github.com/symfony/property-info/blob/8.2/CHANGELOG.md)
- [Commits](symfony/property-info@v8.1.5...v8.1.6)

Updates `symfony/rate-limiter` from 8.1.4 to 8.1.6
- [Release notes](https://github.com/symfony/rate-limiter/releases)
- [Changelog](https://github.com/symfony/rate-limiter/blob/8.2/CHANGELOG.md)
- [Commits](symfony/rate-limiter@v8.1.4...v8.1.6)

Updates `symfony/security-bundle` from 8.1.2 to 8.1.6
- [Release notes](https://github.com/symfony/security-bundle/releases)
- [Changelog](https://github.com/symfony/security-bundle/blob/8.2/CHANGELOG.md)
- [Commits](symfony/security-bundle@v8.1.2...v8.1.6)

Updates `symfony/serializer` from 8.1.5 to 8.1.6
- [Release notes](https://github.com/symfony/serializer/releases)
- [Changelog](https://github.com/symfony/serializer/blob/8.2/CHANGELOG.md)
- [Commits](symfony/serializer@v8.1.5...v8.1.6)

Updates `symfony/validator` from 8.1.5 to 8.1.6
- [Release notes](https://github.com/symfony/validator/releases)
- [Changelog](https://github.com/symfony/validator/blob/8.2/CHANGELOG.md)
- [Commits](symfony/validator@v8.1.5...v8.1.6)

Updates `symfony/yaml` from 8.1.5 to 8.1.6
- [Release notes](https://github.com/symfony/yaml/releases)
- [Changelog](https://github.com/symfony/yaml/blob/8.2/CHANGELOG.md)
- [Commits](symfony/yaml@v8.1.5...v8.1.6)

Updates `web-auth/webauthn-symfony-bundle` from 5.3.5 to 5.3.8
- [Commits](web-auth/webauthn-symfony-bundle@5.3.5...5.3.8)

Updates `friendsofphp/php-cs-fixer` from 3.95.22 to 3.95.24
- [Release notes](https://github.com/PHP-CS-Fixer/PHP-CS-Fixer/releases)
- [Changelog](https://github.com/PHP-CS-Fixer/PHP-CS-Fixer/blob/master/CHANGELOG.md)
- [Commits](PHP-CS-Fixer/PHP-CS-Fixer@v3.95.22...v3.95.24)

Updates `phpstan/phpstan` from 2.2.9 to 2.2.13
- [Commits](https://github.com/phpstan/phpstan-phar-composer-source/commits)

Updates `phpunit/phpunit` from 13.3.1 to 13.3.2
- [Release notes](https://github.com/sebastianbergmann/phpunit/releases)
- [Changelog](https://github.com/sebastianbergmann/phpunit/blob/13.3.2/ChangeLog-13.3.md)
- [Commits](sebastianbergmann/phpunit@13.3.1...13.3.2)

Updates `rector/rector` from 2.6.3 to 2.6.6
- [Release notes](https://github.com/rectorphp/rector/releases)
- [Commits](rectorphp/rector@2.6.3...2.6.6)

Updates `symfony/phpunit-bridge` from 8.1.5 to 8.1.6
- [Release notes](https://github.com/symfony/phpunit-bridge/releases)
- [Changelog](https://github.com/symfony/phpunit-bridge/blob/8.2/CHANGELOG.md)
- [Commits](symfony/phpunit-bridge@v8.1.5...v8.1.6)

---
updated-dependencies:
- dependency-name: doctrine/doctrine-migrations-bundle
  dependency-version: 4.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: composer
- dependency-name: friendsofphp/php-cs-fixer
  dependency-version: 3.95.23
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: composer
- dependency-name: phpstan/phpdoc-parser
  dependency-version: 2.3.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: composer
- dependency-name: phpstan/phpstan
  dependency-version: 2.2.11
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: composer
- dependency-name: phpunit/phpunit
  dependency-version: 13.3.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: composer
- dependency-name: rector/rector
  dependency-version: 2.6.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: composer
- dependency-name: sentry/sentry-symfony
  dependency-version: 5.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: composer
- dependency-name: symfony/console
  dependency-version: 8.1.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: composer
- dependency-name: symfony/dotenv
  dependency-version: 8.1.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: composer
- dependency-name: symfony/framework-bundle
  dependency-version: 8.1.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: composer
- dependency-name: symfony/phpunit-bridge
  dependency-version: 8.1.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: composer
- dependency-name: symfony/property-info
  dependency-version: 8.1.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: composer
- dependency-name: symfony/rate-limiter
  dependency-version: 8.1.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: composer
- dependency-name: symfony/security-bundle
  dependency-version: 8.1.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: composer
- dependency-name: symfony/serializer
  dependency-version: 8.1.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: composer
- dependency-name: symfony/validator
  dependency-version: 8.1.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: composer
- dependency-name: symfony/yaml
  dependency-version: 8.1.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: composer
- dependency-name: web-auth/webauthn-symfony-bundle
  dependency-version: 5.3.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: composer
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump the composer group with 18 updates chore(deps): bump the composer group across 1 directory with 18 updates Sep 10, 2026
@dependabot
dependabot Bot force-pushed the dependabot/composer/composer-aedc6fe12f branch from c694db5 to 2c1e49a Compare September 10, 2026 12:17
@coderabbitai

coderabbitai Bot commented Sep 10, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: de1dcbc9-204c-49bb-a155-6e24a94842e4

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

Copy link
Copy Markdown

@github-actions
github-actions Bot disabled auto-merge September 10, 2026 12:46
@github-actions
github-actions Bot enabled auto-merge September 10, 2026 12:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants