Fixed symfony/console requirement to exclude 7.x as Composer 2.6 is not compatible, 2.7 will be (#11741)
Fixed libpq parsing to use the global constant if available (#11684)
Fixed error output when updating with a temporary constraint fails (#11692)
2.6.5
Fixed error when vendor dir contains broken symlinks (#11670)
Fixed composer.lock missing from Composer's zip archives (#11674)
Fixed AutoloadGenerator::dump() non-BC signature change in 2.6.4 (cb363b0e8)
2.6.4
Security: Fixed possible remote code execution vulnerability if composer.phar is publicly accessible, executable as PHP, and register_argc_argv is enabled in php.ini (GHSA-jm6m-4632-36hf / CVE-2023-43655)
Fixed json output of abandoned packages in audit command (#11647)
Fixed autoloader suffix to reuse the content-hash from lock file if available to make for more reproducible builds by default (#11663)
Performance improvement in pool optimization step (#11638)
Performance improvement in show -a <packagename> (#11659)
Security: Fixed code execution and possible privilege escalation via compromised vendor dir contents (GHSA-7c6p-848j-wh5h / CVE-2024-24821)
Changed the default of the audit.abandoned config setting to fail, set it to report or ignore if you do not want this, or set it via COMPOSER_AUDIT_ABANDONED env var (#11643)
Added --minimal-changes (-m) flag to update/require/remove commands to perform partial update with --with-dependencies while changing only what is absolutely necessary in transitive dependencies (#11665)
Added --sort-by-age (-A) flag to outdated/show commands to allow sorting by and displaying the release date (most outdated first) (#11762)
Added support for --self combined with --installed or --locked in show command, to add the root package to the package list being output (#11785)
Added severity information to audit command output (#11702)
Added scripts-aliases top level key in composer.json to define aliases for custom scripts you defined (#11666)
Added IPv4 fallback on connection timeout, as well as a COMPOSER_IPRESOLVE env var to force IPv4 or IPv6, set it to 4 or 6 (#11791)
Added support for wildcards in outdated's --ignore arg (#11831)
Added support for bump command bumping * to >=current version (#11694)
Added detection of constraints that cannot possibly match anything to validate command (#11829)
Added package source information to the output of install when running in very verbose (-vv) mode (#11763)
Added audit of Composer's own bundled dependencies in diagnose command (#11761)
Added GitHub token expiration date to diagnose command output (#11688)
Added non-zero status code to why/why-not commands (#11796)
Added error when calling show --direct <package> with an indirect/transitive dependency (#11728)
Added COMPOSER_FUND=0 env var to hide calls for funding (#11779)
Fixed bump command not bumping packages required with a v prefix (#11764)
Fixed automatic disabling of plugins when running non-interactive as root
Fixed update --lock not keeping the dist reference/url/checksum pinned (#11787)
Fixed require command crashing at the end if no lock file is present (#11814)
Fixed root aliases causing problems when auditing locked dependencies (#11771)
Fixed handling of versions with 4 components in require command (#11716)
Fixed compatibility issues with Symfony 7
Fixed composer.json remaining behind after a --dry-run of the require command (#11747)
Fixed warnings being shown incorrectly under some circumstances (#11786, #11760, #11803)
[2.6.6] 2023-12-08
Fixed symfony/console requirement to exclude 7.x as Composer 2.6 is not compatible, 2.7 will be (#11741)
Fixed libpq parsing to use the global constant if available (#11684)
Fixed error output when updating with a temporary constraint fails (#11692)
[2.6.5] 2023-10-06
Fixed error when vendor dir contains broken symlinks (#11670)
Fixed composer.lock missing from Composer's zip archives (#11674)
Fixed AutoloadGenerator::dump() non-BC signature change in 2.6.4 (cb363b0e8)
[2.6.4] 2023-09-29
Security: Fixed possible remote code execution vulnerability if composer.phar is publicly accessible, executable as PHP, and register_argc_argv is enabled in php.ini (GHSA-jm6m-4632-36hf / CVE-2023-43655)
Fixed json output of abandoned packages in audit command (#11647)
Performance improvement in pool optimization step (#11638)
Performance improvement in show -a <packagename> (#11659)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Bumps composer/composer from 2.6.3 to 2.7.0.
Release notes
Sourced from composer/composer's releases.
Changelog
Sourced from composer/composer's changelog.
Commits
96d107e
Release 2.7.0eea73da
Update changelog64e4eb3
Merge pull request from GHSA-7c6p-848j-wh5h7442981
Add flag alias to docs7a6bb18
Adds a test for no dev (#11833)67d80e1
Fix php7.2df8f9f0
Update tests754f286
Add non-zero return codes when why-not finds a reason a package is not instal...7cb92a9
Introduce COMPOSER_AUDIT_ABANDONED env var (#11794)e0807d3
Diagnose command: Add GitHub OAuth token expiration date information (#11688)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show