Skip to content

Conversation

dependabot-preview[bot]
Copy link
Contributor

@dependabot-preview dependabot-preview bot commented Jan 1, 2019

⚠️ Dependabot is rebasing this PR ⚠️

If you make any changes to it yourself then they will take precedence over the rebase.


Bumps phpunit/phpunit from 5.5.4 to 6.0.8. This update includes security fixes.

Vulnerabilities fixed

Sourced from The PHP Security Advisories Database.

RCE vulnerability in phpunit

Affected versions: >=5.0.10, <5.6.3; >=4.8.19, <4.8.28

Changelog

Sourced from phpunit/phpunit's changelog.

[6.0.8] - 2017-03-02

Changed

  • The --check-version commandline option is now also available when PHPUnit is installed using Composer

Fixed

  • Fixed #1999: Handler is inherited from previous custom option with handler
  • Fixed #2149: assertCount() does not handle generators properly
  • Fixed #2478: Tests that take too long are not reported as risky test
  • Fixed #2527: Output of --check-version suggests removed --self-upgrade

[6.0.7] - 2017-02-19

Fixed

  • Fixed #2489: processUncoveredFilesFromWhitelist is not handled correctly
  • Fixed default values for addUncoveredFilesFromWhitelist and processUncoveredFilesFromWhitelist in phpunit.xsd

[6.0.6] - 2017-02-08

Fixed

  • Fixed #2474: --globals-backup commandline option is not recognized
  • Fixed #2475: Defining a test suite with only one file does not work
  • Fixed #2487: Wrong default values for backupGlobals and beStrictAboutTestsThatDoNotTestAnything in phpunit.xsd

[6.0.5] - 2017-02-05

Fixed

  • Deprecation errors when used with PHP 7.2

[6.0.4] - 2017-02-04

Fixed

  • Fixed #2470: PHPUnit 6.0 does not work with PHP 7.0.0-7.0.12

[6.0.3] - 2017-02-04

Fixed

  • Fixed #2460: Strange error in tests after update to PHPUnit 6
  • Fixed #2467: Process Isolation does not work when using PHPUnit from PHAR

[6.0.2] - 2017-02-03

Fixed

... (truncated)
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

Dependabot will not automatically merge this PR because it includes an out-of-range update to a development dependency.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot ignore this [patch|minor|major] version will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Automerge options (never/patch/minor, and dev/runtime dependencies)
  • Pull request limits (per update run and/or open at any time)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

Finally, you can contact us by mentioning @dependabot.

@dependabot-preview dependabot-preview bot added dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability labels Jan 1, 2019
Bumps [phpunit/phpunit](https://github.com/sebastianbergmann/phpunit) from 5.5.4 to 6.0.8. **This update includes security fixes.**
- [Release notes](https://github.com/sebastianbergmann/phpunit/releases)
- [Changelog](https://github.com/sebastianbergmann/phpunit/blob/6.0.8/ChangeLog-6.0.md)
- [Commits](https://github.com/sebastianbergmann/phpunit/commits/6.0.8)

Signed-off-by: dependabot[bot] <support@dependabot.com>
@dependabot-preview dependabot-preview bot force-pushed the dependabot/composer/phpunit/phpunit-6.0.8 branch from 4cd8298 to 9c7095e Compare January 4, 2019 20:28
@WyriHaximus WyriHaximus merged commit aa15694 into master Jan 4, 2019
@dependabot-preview dependabot-preview bot deleted the dependabot/composer/phpunit/phpunit-6.0.8 branch January 4, 2019 20:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants