Open dependabot[bot] opened 3 weeks ago
The pull request updates the symfony/polyfill-php80
package from version v1.27.0
to v1.31.0
, which is generally a positive change for application security, but requires reviewing the changelog and performing regression testing to ensure no breaking changes or unintended issues are introduced.
We ran 9 analyzers
against 1 file
and 1 analyzer
had findings. 8 analyzers
had no findings.
Analyzer | Findings |
---|---|
Sensitive Files Analyzer | 1 finding |
:green_circle: Risk threshold not exceeded.
Bumps symfony/process from 6.3.0 to 6.4.14.
Release notes
Sourced from symfony/process's releases.
... (truncated)
Changelog
Sourced from symfony/process's changelog.
... (truncated)
Commits
25214ad
Merge branch '5.4' into 6.40190687
[Process] Fix test88638b9
Merge branch '5.4' into 6.4ee75984
security #cve-2024-51736 [Process] Use %PATH% before %CD% to load the shell o...05c2ccc
[Process] Use %PATH% before %CD% to load the shell on Windows0776b99
Merge branch '5.4' into 6.4d94dda5
[Process] Fix escaping /X arguments on Windows836d34f
Merge branch '5.4' into 6.472baf6b
fix the constant being used81e1a0c
fix the path separator being usedDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show