Skip to content

Bump zircote/swagger-php from 3.3.7 to 6.5.2 - #24

Closed
dependabot[bot] wants to merge 61 commits into
mainfrom
dependabot/composer/zircote/swagger-php-6.5.2
Closed

Bump zircote/swagger-php from 3.3.7 to 6.5.2#24
dependabot[bot] wants to merge 61 commits into
mainfrom
dependabot/composer/zircote/swagger-php-6.5.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 9, 2026

Copy link
Copy Markdown
Contributor

Bumps zircote/swagger-php from 3.3.7 to 6.5.2.

Release notes

Sourced from zircote/swagger-php's releases.

6.5.2

What's Changed

Full Changelog: zircote/swagger-php@6.5.1...6.5.2

6.5.1

What's Changed

Full Changelog: zircote/swagger-php@6.5.0...6.5.1

6.5.0

Spec Pipeline

This version introduces the spec pipeline - a new set of attributes that will replace the current (classic) annotations/attributes. It is using a radically different approach in how the code is organized which makes it a lot easier to maintain.

Right now, the new code is disabled and nothing changes. Key is that in order to try the new code the new OpenApi\Builder needs to be used. Again - using the Builder will, by default, change nothing and the current classic code is used.

The new Builder::setMode() method allows to run the new spec pipeline in two modes:

  • HYBRID: Enables spec support where found and also routes all classic annotations/attributes through the new spec pipeline. Under the hood the classic Generator is used to load/instantiate classic annotations/attributes. Then a custom bridge translates all of those into new thin OpenApi\Spec attributes and adds them to the spec pipeline.
  • SPEC: Only new spec attributes are processed.

HYBRID is a good way to see how compatible things are and also a migration path, as a codebase could be upgrade file by file.

All spec pipeline related commits have been omitted from the change list for clarity and brevity. Going forward these will be marked as feat(Spec): and listed as all other changes.

Testing and Feedback

All current tests pass in HYBRID mode. However, there hasn't been any testing on actual projects yet. Testing the new code in hybrid mode on existing projects and feedback would be greatly appreciated.

What's Changed

... (truncated)

Commits
  • cec9ec9 feat(Spec): nullable summary / description (#2107)
  • 509726b chore(Spec): refactor OpenApi31Compiler: consolidate repetitive patterns (#...
  • 182075b chore(Rector): update config (#2105)
  • fd45d8e Remove redundant description attribute from #[OA\Property] annotation (#2...
  • aeb1d7f feat(Spec): clarify attribute translator lifecycle and add tests (#2100)
  • e59e724 Simplify specification population by replacing foreach loops with unpacking...
  • 56ce65c Add roadmap (#2101)
  • 129e1c8 feat(Spec): simplify sharing of TokenScanner (#2099)
  • ad33057 Cleanup Rector rules and adjust dev dependencies (#2097)
  • cb40919 feat(Spec): improve AttributeTranslatorInterface (#2096)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

WentTheFox and others added 30 commits May 19, 2025 21:28
App fixes:
- Cookie: strip port from HTTP_HOST in cookie domain (RFC 6265; broken
  cookie acceptance in Playwright and curl)
- CGUtils: short-circuit isElasticAvailable() in TEST_MODE to avoid 5s
  connection timeout per page load
- Appearance: skip updateIndex/clearIndex ES calls in TEST_MODE
- CoreUtils: omit ws_server_host from Twig scope in TEST_MODE so the
  socket.io script tag is not rendered (prevented networkidle)
- websocket.js: fix setupDegradedMode() referencing undefined $sidebar
- Appearances.php: guard WHERE id NOT IN () when pinned list is empty
- Event: null-safe getEntryRoleName() fallback and getWinnerHTML() guard
- activerecord.php: route to TEST_DB_NAME when TEST_MODE=true

Test infrastructure:
- reset-test-db.sh: reset PG sequences after seeding so new rows don't
  collide with explicitly-seeded IDs
- Browser/Pest.php: reset test DB in beforeAll hook for clean state
- Correct test URLs (/show, /users/, /account) and assertion values

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Decouples test selectors from CSS classes and form attribute values,
following Playwright's getByTestId() convention. Dialog buttons get
auto-derived testids from their label (dialog-btn-save, etc.), with
explicit overrides for confirm/cancel (dialog-btn-confirm/-cancel)
regardless of display text ("Eeyup"/"Nope").

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Add pnpm-workspace.yaml with a 14-day minimumReleaseAge, update CI
and the deploy post-receive hook to use pnpm, pin GitHub Actions to
commit SHAs, and add Dependabot for npm/composer/actions updates.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Fixes CI failure caused by pnpm/action-setup picking a pnpm version
that doesn't match the lockfile (generated with pnpm 11.5.1).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
eslint.config.js imports @eslint/js directly, but it was only a
transitive dependency of eslint. npm's hoisting masked this; pnpm's
strict node_modules layout does not, causing ESLint to fail with
ERR_MODULE_NOT_FOUND.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
WentTheFox and others added 21 commits June 14, 2026 15:54
The React rewrite of $.Dialog wraps each content block's markup in an
extra container div, so form elements are no longer a direct child of
the #dialogContent content block. Loosen the selector from a direct
child to a descendant so the spacing rules apply again.
The React rewrite of $.Dialog dropped the old jQuery implementation's
behavior of appending new content below the existing dialog content
(with a visual separator) when a dialog is already open, instead
always replacing it. Re-introduce this by tracking a history array of
content blocks: each non-appending-to-request call while a dialog is
open pushes a new block, updates the title (if provided), color, and
buttons, while previous blocks remain visible.
CoreUtils::generateApiSchema() still listed source paths for controllers
that were deleted/moved during the API controller refactor, causing
Symfony Finder to throw on missing directories. Also restores a 404
response annotation on PUT /event/{id} that was dropped during the move.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Missing comma after security={} caused a Doctrine annotation parse
error, silently dropping /about/upcoming from the generated schema.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 4.4.0 to 7.0.0.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@49933ea...8207627)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 4.3.1 to 7.0.1.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@34e1148...3d3c42e)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
…actions/checkout-7.0.1

Bump actions/checkout from 4.3.1 to 7.0.1
…actions/setup-node-7.0.0

Bump actions/setup-node from 4.4.0 to 7.0.0
Bumps [pnpm/action-setup](https://github.com/pnpm/action-setup) from 6.0.8 to 6.0.9.
- [Release notes](https://github.com/pnpm/action-setup/releases)
- [Commits](pnpm/action-setup@0e279bb...0ebf471)

---
updated-dependencies:
- dependency-name: pnpm/action-setup
  dependency-version: 6.0.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
…pnpm/action-setup-6.0.9

Bump pnpm/action-setup from 6.0.8 to 6.0.9
Move restcord/restcord to the v9 dev branch (pinned to a specific
commit) so guzzlehttp/guzzle can update to 7.x - every 6.x release is
now flagged by composer's advisory audit and by roave/security-advisories.

The v9 branch's DiscordClient defaults 'logger' to null while typing it
as non-nullable, and its service description lacks responseTypes for
getGuildMember, so the SDK now returns a raw array-access Result
instead of a typed model with auto-cast DateTimeImmutable fields.
Adjusted DiscordMember::checkServerMembership() accordingly.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
DeviantArt moved app authorization management under Security and
privacy settings; update the URL and pass it to the template directly
instead of via a Twig constant() lookup.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4.6.2 to 7.0.1.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@ea165f8...043fb46)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
…ctions/upload-artifact-7.0.1

Bump actions/upload-artifact from 4.6.2 to 7.0.1
The picker frame page never loaded the react lib, but dialog.jsx (used
for every dialog on that page, including the file-open and
paste-from-clipboard flows) calls ReactDOM.createRoot() at load time.
That threw a ReferenceError which left $.Dialog permanently undefined,
silently breaking both "Open..." and "Open from Clipboard..." with no
visible error to the user.

Also make the ElasticSearch client timeouts configurable via env vars
so the browser test suite doesn't hang for 15s+ per request when ES
is unreachable in the test environment.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
'dialog' depends on ReactDOM at module load time, but pages that opt
out of default-libs (like picker-frame) had to remember to add react
by hand -- exactly the mistake that broke picker-frame's dialogs.
CoreUtils::loadPage now forces react into the resolved libs whenever
'dialog' is requested, so this can't silently regress on future pages.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Bumps [zircote/swagger-php](https://github.com/zircote/swagger-php) from 3.3.7 to 6.5.2.
- [Release notes](https://github.com/zircote/swagger-php/releases)
- [Commits](zircote/swagger-php@3.3.7...6.5.2)

---
updated-dependencies:
- dependency-name: zircote/swagger-php
  dependency-version: 6.5.2
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update php code labels Aug 9, 2026
@WentTheFox WentTheFox closed this Aug 27, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 27, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/composer/zircote/swagger-php-6.5.2 branch August 27, 2026 16:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update php code

Development

Successfully merging this pull request may close these issues.

1 participant