acquia / headless_lightning

A more opinionated flavor of Lightning for building decoupled applications. Support ended on November 2, 2021 and this project is no longer maintained.
https://lightning.acquia.com
GNU General Public License v2.0
58 stars 16 forks source link

Bump composer/composer from 2.1.3 to 2.1.9 #136

Open dependabot[bot] opened 3 years ago

dependabot[bot] commented 3 years ago

Bumps composer/composer from 2.1.3 to 2.1.9.

Release notes

Sourced from composer/composer's releases.

2.1.9

  • Security: Fixed command injection vulnerability on Windows (GHSA-frqg-7g38-6gcf / CVE-2021-41116)
  • Fixed classmap parsing with a new class parser which does not rely on regexes anymore (#10107)
  • Fixed inline git credentials showing up in output in some conditions (#10115)
  • Fixed support for running updates while offline as long as the cache contains enough information (#10116)
  • Fixed show --all foo/bar which as of 2.0.0 was not showing all versions anymore but only the installed one (#10095)
  • Fixed VCS repos ignoring some versions silently when the API rate limit is reached (#10132)
  • Fixed CA bundle to remove the expired Let's Encrypt root CA

2.1.8

  • Fixed regression in 2.1.7 when parsing classmaps in files containing invalid Unicode (#10102)

2.1.7

  • Added many type annotations internally, which may have an effect on CI/static analysis for people using Composer as a dependency. This work will continue in following releases
  • Fixed regression in 2.1.6 when parsing classmaps with empty heredocs (#10067)
  • Fixed regression in 2.1.6 where list command was not showing plugin commands (#10075)
  • Fixed issue handling package updates where the package type changed (#10076)
  • Fixed docker being detected as WSL when run inside WSL (#10094)

2.1.6

  • Updated internal PHAR signatures to be SHA512 instead of SHA1
  • Fixed uncaught exception handler regression (#10022)
  • Fixed more PHP 8.1 deprecation warnings (#10036, #10038, #10061)
  • Fixed corrupted zips in the cache from blocking installs until a cache clear, the bad archives are now deleted automatically on first failure (#10028)
  • Fixed URL sanitizer handling of new github tokens (#10048)
  • Fixed issue finding classes with very long heredocs in classmap autoload (#10050)
  • Fixed proc_open being required for simple installs from zip, as well as diagnose (#9253)
  • Fixed path repository bug causing symlinks to be left behind after a package is uninstalled (#10023)
  • Fixed issue in 7-zip support on windows with certain archives (#10058)
  • Fixed bootstrapping process to avoid loading the composer.json and plugins until necessary, speeding things up slightly (#10064)
  • Fixed lib-openssl detection on FreeBSD (#10046)
  • Fixed support for ircs:// protocol for support.irc composer.json entries

2.1.5

  • Fixed create-project creating a php: directory in the directory it was executed in (#10020, #10021)
  • Fixed curl downloader to respect default_socket_timeout if it is bigger than our default 300s (#10018)

2.1.4

  • Fixed PHP 8.1 deprecation warnings (#10008)
  • Fixed support for working within UNC/WSL paths on Windows (#9993)
  • Fixed 7-zip support to also be looked up on Linux/macOS as 7z or 7zz (#9951)
  • Fixed repositories' only/exclude properties to avoid matching names as sub-strings of full package names (#10001)
  • Fixed open_basedir regression from #9855
  • Fixed schema errors being reported incorrectly in some conditions (#9986)
  • Fixed archive command not working with async archive extraction
  • Fixed init command being able to generate an invalid composer.json (#9986)
Changelog

Sourced from composer/composer's changelog.

[2.1.9] 2021-10-05

  • Security: Fixed command injection vulnerability on Windows (GHSA-frqg-7g38-6gcf / CVE-2021-41116)
  • Fixed classmap parsing with a new class parser which does not rely on regexes anymore (#10107)
  • Fixed inline git credentials showing up in output in some conditions (#10115)
  • Fixed support for running updates while offline as long as the cache contains enough information (#10116)
  • Fixed show --all foo/bar which as of 2.0.0 was not showing all versions anymore but only the installed one (#10095)
  • Fixed VCS repos ignoring some versions silently when the API rate limit is reached (#10132)
  • Fixed CA bundle to remove the expired Let's Encrypt root CA

[2.1.8] 2021-09-15

  • Fixed regression in 2.1.7 when parsing classmaps in files containing invalid Unicode (#10102)

[2.1.7] 2021-09-14

  • Added many type annotations internally, which may have an effect on CI/static analysis for people using Composer as a dependency. This work will continue in following releases
  • Fixed regression in 2.1.6 when parsing classmaps with empty heredocs (#10067)
  • Fixed regression in 2.1.6 where list command was not showing plugin commands (#10075)
  • Fixed issue handling package updates where the package type changed (#10076)
  • Fixed docker being detected as WSL when run inside WSL (#10094)

[2.1.6] 2021-08-19

  • Updated internal PHAR signatures to be SHA512 instead of SHA1
  • Fixed uncaught exception handler regression (#10022)
  • Fixed more PHP 8.1 deprecation warnings (#10036, #10038, #10061)
  • Fixed corrupted zips in the cache from blocking installs until a cache clear, the bad archives are now deleted automatically on first failure (#10028)
  • Fixed URL sanitizer handling of new github tokens (#10048)
  • Fixed issue finding classes with very long heredocs in classmap autoload (#10050)
  • Fixed proc_open being required for simple installs from zip, as well as diagnose (#9253)
  • Fixed path repository bug causing symlinks to be left behind after a package is uninstalled (#10023)
  • Fixed issue in 7-zip support on windows with certain archives (#10058)
  • Fixed bootstrapping process to avoid loading the composer.json and plugins until necessary, speeding things up slightly (#10064)
  • Fixed lib-openssl detection on FreeBSD (#10046)
  • Fixed support for ircs:// protocol for support.irc composer.json entries

[2.1.5] 2021-07-23

  • Fixed create-project creating a php: directory in the directory it was executed in (#10020, #10021)
  • Fixed curl downloader to respect default_socket_timeout if it is bigger than our default 300s (#10018)

[2.1.4] 2021-07-22

  • Fixed PHP 8.1 deprecation warnings (#10008)
  • Fixed support for working within UNC/WSL paths on Windows (#9993)
  • Fixed 7-zip support to also be looked up on Linux/macOS as 7z or 7zz (#9951)
  • Fixed repositories' only/exclude properties to avoid matching names as sub-strings of full package names (#10001)
  • Fixed open_basedir regression from #9855
  • Fixed schema errors being reported incorrectly in some conditions (#9986)

... (truncated)

Commits
  • e558c88 Release 2.1.9
  • cb1e248 Fix type annotation
  • 2f3273b Fix changelog
  • 18e2497 Merge branch '1.10'
  • b67ceb8 Prepare changelog
  • ca5e2f8 Fix escaping issues on Windows which could lead to command injection, fixes G...
  • b3eebeb Merge pull request from GHSA-frqg-7g38-6gcf
  • 532c6e7 Fix show --all showing only the installed version if the package is installed...
  • a7963b7 Fix ComposerRepository handling of offline state to allow resolution as long ...
  • edccad4 VcsRepository: do not continue when receiving 429 rate limit exception (#10132)
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/acquia/headless_lightning/network/alerts).