enwikipedia-acc / waca

English Wikipedia Account Creation Interface
https://accounts.wmflabs.org/internal.php
The Unlicense
33 stars 43 forks source link

Bump smarty/smarty from 4.3.5 to 4.4.1 #911

Closed dependabot[bot] closed 7 months ago

dependabot[bot] commented 7 months ago

Bumps smarty/smarty from 4.3.5 to 4.4.1.

Release notes

Sourced from smarty/smarty's releases.

v4.4.1

Full Changelog: https://github.com/smarty-php/smarty/compare/v4.4.0...v4.4.1

v4.4.0

What's Changed

Full Changelog: https://github.com/smarty-php/smarty/compare/v4.3.5...v4.4.0

Changelog

Sourced from smarty/smarty's changelog.

[4.4.1] - 2024-02-26

  • Fixed internal release-tooling

[4.4.0] - 2024-02-26

Changed

  • Using the |implode, |json_encode and |substr modifiers does not generate a deprecation warning anymore as they will continue to be supported in v5 #939

Added

  • PHP8.3 support #925

Fixed

  • Incorrect compilation of expressions when escape_html=true #930

[4.3.4] - 2023-09-14

[4.3.3] - 2023-09-14

Fixed

  • |strip_tags does not work if the input is 0 #890
  • Use of negative numbers in {math} equations #895

[4.3.2] - 2023-07-19

Fixed

  • $smarty->muteUndefinedOrNullWarnings() now also mutes PHP8 warnings for undefined properties

[4.3.1] - 2023-03-28

Security

  • Fixed Cross site scripting vulnerability in Javascript escaping. This addresses CVE-2023-28447.

Fixed

  • $smarty->muteUndefinedOrNullWarnings() now also mutes PHP7 notices for undefined array indexes #736
  • $smarty->muteUndefinedOrNullWarnings() now treats undefined vars and array access of a null or false variables equivalent across all supported PHP versions
  • $smarty->muteUndefinedOrNullWarnings() now allows dereferencing of non-objects across all supported PHP versions #831
  • PHP 8.1 deprecation warnings on null strings in modifiers #834

[4.3.0] - 2022-11-22

Added

  • PHP8.2 compatibility #775

Changed

  • Include docs and demo in the releases #799
  • Using PHP functions as modifiers now triggers a deprecation notice because we will drop support for this in the next major release #813
  • Dropped remaining references to removed PHP-support in Smarty 4 from docs, lexer and security class. #816
  • Support umask when writing (template) files and set dir permissions to 777 #548 #819

Fixed

... (truncated)

Commits
  • f4152e9 auto-delete changelog files
  • 5d0dd09 changelog update
  • 9d55982 Merge branch 'release/4.4.1' into support/4.3
  • 5e2a9fb version bump
  • 9614a59 changelog
  • ee58a21 Updated release tooling
  • 29dd621 Add some guidance on upgrading from v3 to v4
  • de1bc77 Prevent deprecation notices for implode, json_encode and substr modifiers
  • 326b2da Fix incorrect compilation of expressions when escape_html=true (#932)
  • See full diff in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)