Skip to content

chore(deps-dev): update google/recaptcha requirement from ^1.5 to ^2.1 - #49

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot-composer-master-google-recaptcha-tw-2.1
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot-composer-master-google-recaptcha-tw-2.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on google/recaptcha to permit the latest version.

Release notes

Sourced from google/recaptcha's releases.

2.1.0

Overview

2.1.0 is a backwards-compatible minor release in the 2.x series (PHP >=8.4) introducing immutable with*() builder methods on ReCaptcha, \JsonSerializable support on Response, configurable transport timeouts, ReCaptcha::SITE_VERIFY_URL_ALTERNATIVE, cURL handle connection reuse, unified HTTP status validation across all transports, and validation/security hardening.

What's Changed

  • Immutable with*() Builder Methods (ReCaptcha):
    • Added withExpectedHostname(), withExpectedApkPackageName(), withExpectedAction(), withScoreThreshold(), and withChallengeTimeout() methods that return a cloned ReCaptcha instance instead of mutating the instance in place—making ReCaptcha safe to share as a singleton in dependency injection containers and persistent worker runtimes (FrankenPHP, RoadRunner, Swoole, Laravel Octane) (#637).
  • Response implements \JsonSerializable:
    • Implemented \JsonSerializable (jsonSerialize()) on ReCaptcha\Response so response objects can be passed directly to json_encode() (#636).
  • Configurable Transport Timeouts & Alternative Global Endpoint:
    • Added an optional int $timeout = 60 constructor parameter to CurlPost, Post, and SocketPost, and added CURLOPT_CONNECTTIMEOUT to CurlPost (#636).
    • Added ReCaptcha::SITE_VERIFY_URL_ALTERNATIVE (https://www.recaptcha.net/recaptcha/api/siteverify) for environments where www.google.com is not accessible (#636).
  • Connection Reuse & Transport Hardening:
    • CurlPost now lazily initializes and reuses its CurlHandle across submit() calls for TLS session resumption and HTTP keep-alive (#637).
    • Unified HTTP 200 status validation across CurlPost (CURLINFO_HTTP_CODE), Post (http_get_last_response_headers() with ignore_errors), and SocketPost so non-200 HTTP responses consistently return ReCaptcha::E_BAD_RESPONSE (#637).
    • SocketPost now loops fwrite() to handle partial TLS socket writes and closes the socket handle cleanly on write failures (#637).
  • Security Hardening:
    • Added #[\SensitiveParameter] to $secret in ReCaptcha::__construct() and RequestParameters::__construct() to prevent secret exposure in stack traces (#636).
    • Hardened examples/ against DOM XSS, added server-side action allowlisting in examples/recaptcha-v3-verify.php, updated CSP connect-src, and added examples/recaptcha-v3-immutable.php (#636, #637).

Bug Fixes

  • Fixed setScoreThreshold(0.0) null-coercion bypass when score is omitted (null) from the API response so it properly fails with ReCaptcha::E_SCORE_THRESHOLD_NOT_MET (#637).
  • Fixed setChallengeTimeout() failing open when challenge_ts is empty or unparseable; it now fails closed with ReCaptcha::E_CHALLENGE_TIMEOUT (#637).
  • Filtered error-codes in Response::fromJson() to ensure only string elements are retained (#636).

Compatibility & Upgrade Guide

  • 100% Backwards-Compatible with 2.0.0: Verified via roave/backward-compatibility-check.
  • Upgrade via Composer:
    composer update google/recaptcha

Full Changelog: google/recaptcha@2.0.0...2.1.0

Commits
  • 05a576b chore: prepare 2.1.0 release (#638)
  • a6df771 feat: harden validation edge cases, add immutable with*() builders, and unify...
  • 50a03db feat: harden HTTP/socket transports, add JsonSerializable to Response, and se...
  • 09814c8 chore: upgrade dependencies, harden static analysis/test strictness, and add ...
  • 81700ff Prepare 2.0.0 release with strict types, readonly DTOs, and PHP 8.5 fixes
  • ee4352f Harden transport TLS/timeouts, accept HTTP/1.1 in SocketPost, and bump to 1.5.2
  • 1fb3b1a Merge branch 'pr-634'
  • a373090 Version bump to 1.5.1
  • 9a04f83 ci: pin actions to commit hashes
  • 1a8b966 ci: install the BC check from composer instead of the stale docker image
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Updates the requirements on [google/recaptcha](https://github.com/google/recaptcha) to permit the latest version.
- [Release notes](https://github.com/google/recaptcha/releases)
- [Commits](google/recaptcha@1.5...2.1.0)

---
updated-dependencies:
- dependency-name: google/recaptcha
  dependency-version: 2.1.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, php. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@sonarqubecloud

sonarqubecloud Bot commented Oct 1, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants