Skip to content

Update phpstan/phpstan requirement from 1.5.4 to 1.7.6#69

Closed
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/composer/phpstan/phpstan-1.7.6
Closed

Update phpstan/phpstan requirement from 1.5.4 to 1.7.6#69
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/composer/phpstan/phpstan-1.7.6

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot bot commented on behalf of github May 31, 2022

Updates the requirements on phpstan/phpstan to permit the latest version.

Release notes

Sourced from phpstan/phpstan's releases.

1.7.6

Bugfixes 🐛

  • Rewrite the located identifier name with class aliases in mind (#1369), #7308
  • Class definition from autoloader should be preferred over PhpStorm stubs, #7357, #3634
Commits
  • 1af9271 PHPStan 1.7.6
  • 98728f7 Regression test
  • abe5fa9 Updated PHPStan to commit 9df114220b3688bc5a2921fa7b9f1db41aaec237
  • cf3736b Fix
  • f894334 Regression test
  • dfb81bf PHPStan 1.7.5
  • c5b2802 Updated PHPStan to commit 1a176987e15757a18815ba09d430b236b654ca50
  • 63cbdad Updated PHPStan to commit eab4542c4b8877c5f7e85d31d9aa688212f77a77
  • 6f9ffc0 Regression test
  • 7b2cf45 Improve regression test
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Updates the requirements on [phpstan/phpstan](https://github.com/phpstan/phpstan) to permit the latest version.
- [Release notes](https://github.com/phpstan/phpstan/releases)
- [Changelog](https://github.com/phpstan/phpstan/blob/1.7.x/CHANGELOG.md)
- [Commits](phpstan/phpstan@1.5.4...1.7.6)

---
updated-dependencies:
- dependency-name: phpstan/phpstan
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label May 31, 2022
@dependabot @github
Copy link
Copy Markdown
Author

dependabot bot commented on behalf of github Jun 1, 2022

Superseded by #70.

@dependabot dependabot bot closed this Jun 1, 2022
@dependabot dependabot bot deleted the dependabot/composer/phpstan/phpstan-1.7.6 branch June 1, 2022 11:31
lchrusciel pushed a commit that referenced this pull request Jul 29, 2024
This PR was merged into the 1.12 branch.

Discussion
----------

| Q               | A
| --------------- | -----
| Branch?         | 1.12
| Bug fix?        | yes
| New feature?    | no
| BC breaks?      | no
| Deprecations?   | no
| Related tickets | n/a
| License         | MIT

Fixes CVE-2024-29376. Reported here: https://github.com/r2tunes/Reports/blob/main/Sylius.md


Commits
-------

0a7fe9e Add js sanitizeInput function
89880cd Add sanitizer function to UIBundle
19cea9a Use function from UIBundle
3d66fb0 [AddressBook] Add scenario for preventing from a potential XSS attack
9255540 [Checkout] Add scenario for preventing from a potential XSS attack
30de6ff [Behat] Minor scenarios improvements after code review
lchrusciel pushed a commit that referenced this pull request Jul 29, 2024
…t, Address Book and Admin Panel (GSadee)

This PR was merged into the 1.12 branch.

Discussion
----------

| Q               | A
|-----------------|-----
| Branch?         | 1.12
| Bug fix?        | yes
| New feature?    | no
| BC breaks?      | no
| Deprecations?   | no
| Related tickets | 
| License         | MIT

This PR aims to solve 2 issues:

- Potential Cross Site Scripting (XSS) via the "Province" field in the Checkout and Address Book (https://github.com/r2tunes/Reports/blob/main/Sylius.md)
- Potential Cross Site Scripting (XSS) via the "Name" field (Taxons, Products, Options, Variants) in the Admin Panel


Commits
-------
  Fix potential xss in admin panel
  Use function from UIBundle
  Fix product-auto-complete
  Add js sanitizeInput function
  Add sanitizer function to UIBundle
  Use function from UIBundle
  [AddressBook] Add scenario for preventing from a potential XSS attack
  [Checkout] Add scenario for preventing from a potential XSS attack
  [Behat] Minor scenarios improvements after code review
  Test adding new taxon
  Test adding new simple product
  Test adding similar products
  Fixes after CR
  bug #69 Fix potential xss in AdressBook and Checkout (mpysiak, GSadee)
  bug #76 Fix potential xss in admin panel (mpysiak)
  [Behat] Minor scenarios improvements
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants