Skip to content
Permalink
Branch: master
Commits on Apr 16, 2019
  1. [VarDumper] fix tests with ICU 64.1

    nicolas-grekas committed Apr 16, 2019
  2. [VarDumper][Ldap] relax some locally failing tests

    nicolas-grekas committed Apr 16, 2019
  3. Merge branch '4.2'

    nicolas-grekas committed Apr 16, 2019
    * 4.2:
      [DI] Check service IDs are valid
  4. Merge branch '3.4' into 4.2

    nicolas-grekas committed Apr 16, 2019
    * 3.4:
      [DI] Check service IDs are valid
  5. security #cve-2019-10910 [DI] Check service IDs are valid (nicolas-gr…

    nicolas-grekas committed Apr 16, 2019
    …ekas)
    
    * di-sec-34:
      [DI] Check service IDs are valid
  6. Merge branch '4.2'

    nicolas-grekas committed Apr 16, 2019
    * 4.2:
      Fix XSS issues in the form theme of the PHP templating engine
  7. Merge branch '3.4' into 4.2

    nicolas-grekas committed Apr 16, 2019
    * 3.4:
      Fix XSS issues in the form theme of the PHP templating engine
  8. security #cve-2019-10909 [FrameworkBundle][Form] Fix XSS issues in th…

    nicolas-grekas committed Apr 16, 2019
    …e form theme of the PHP templating engine (stof)
    
    This PR was merged into the 3.4 branch.
    
    Discussion
    ----------
    
    [FrameworkBundle][Form] Fix XSS issues in the form theme of the PHP templating engine
    
    Based on #88
    
    Commits
    -------
    
    ab4d053 Fix XSS issues in the form theme of the PHP templating engine
  9. Merge branch '4.2'

    nicolas-grekas committed Apr 16, 2019
    * 4.2:
      Prevent destructors with side-effects from being unserialized
  10. Merge branch '3.4' into 4.2

    nicolas-grekas committed Apr 16, 2019
    * 3.4:
      Prevent destructors with side-effects from being unserialized
  11. security #cve-2019-10912 [Cache][PHPUnit Bridge] Prevent destructors …

    nicolas-grekas committed Apr 16, 2019
    …with side-effects from being unserialized (nicolas-grekas)
    
    This PR was merged into the 3.4 branch.
    
    Discussion
    ----------
    
    [Cache][PHPUnit Bridge] Prevent destructors with side-effects from being unserialized
    
    | Q             | A
    | ------------- | ---
    | Branch?       | 3.4
    | Bug fix?      | yes
    | New feature?  | no
    | BC breaks?    | no
    | Deprecations? | no
    | Tests pass?   | yes
    | Fixed tickets | -
    | License       | MIT
    | Doc PR        | -
    
    Reported for `FilesystemCommonTrait` at https://www.intigriti.com/company/submission/CfDJ8Pja6NZvkpNCmx5vVyiGSn7yW8c1j4H0-cnAhIk6fbstOMm028X-XD1kmSuQkGB2n0cRyyVrA2yAiLN_I0EVilaKVLSiSa0UXZJGfN1h85vmk5c2dBBpu619r1YQEIjcXA
    
    Commits
    -------
    
    4fb9752 Prevent destructors with side-effects from being unserialized
  12. Merge branch '4.2'

    nicolas-grekas committed Apr 16, 2019
    * 4.2:
      [Security] Add a separator in the remember me cookie hash
  13. Merge branch '3.4' into 4.2

    nicolas-grekas committed Apr 16, 2019
    * 3.4:
      [Security] Add a separator in the remember me cookie hash
  14. security #cve-2019-10911 [Security] Add a separator in the remember m…

    nicolas-grekas committed Apr 16, 2019
    …e cookie hash (pborreli)
    
    This PR was merged into the 3.4 branch.
    
    Discussion
    ----------
    
    [Security] Add a separator in the remember me cookie hash
    
    Based on #89
    
    Commits
    -------
    
    a29ce28 [Security] Add a separator in the remember me cookie hash
  15. Merge branch '4.2'

    nicolas-grekas committed Apr 16, 2019
    * 4.2:
      [HttpFoundation] reject invalid method override
  16. Merge branch '3.4' into 4.2

    nicolas-grekas committed Apr 16, 2019
    * 3.4:
      [HttpFoundation] reject invalid method override
  17. security #cve-2019-10913 [HttpFoundation] reject invalid method overr…

    nicolas-grekas committed Apr 16, 2019
    …ide (nicolas-grekas)
    
    This PR was merged into the 3.4 branch.
    
    Discussion
    ----------
    
    [HttpFoundation] reject invalid method override
    
    Based on #86
    
    Commits
    -------
    
    944e60f [HttpFoundation] reject invalid method override
  18. Merge branch '4.2'

    nicolas-grekas committed Apr 16, 2019
    * 4.2:
      bumped Symfony version to 4.2.7
      updated VERSION for 4.2.6
      updated CHANGELOG for 4.2.6
      bumped Symfony version to 3.4.26
      updated VERSION for 3.4.25
      update CONTRIBUTORS for 3.4.25
      updated CHANGELOG for 3.4.25
      Workaround for \DateInterval::createFromDateString()
      [DoctrineBridge] [DX] Update exception text in ManagerRegistry::resetService to avoid confusion.
      Missing Lithuanian translations added to validator component.
  19. Merge branch '3.4' into 4.2

    nicolas-grekas committed Apr 16, 2019
    * 3.4:
      bumped Symfony version to 3.4.26
      updated VERSION for 3.4.25
      update CONTRIBUTORS for 3.4.25
      updated CHANGELOG for 3.4.25
      Workaround for \DateInterval::createFromDateString()
      Missing Lithuanian translations added to validator component.
Commits on Apr 15, 2019
  1. minor #31118 [HttpClient] fix too high timeout in test (nicolas-grekas)

    nicolas-grekas committed Apr 15, 2019
    This PR was merged into the 4.3-dev branch.
    
    Discussion
    ----------
    
    [HttpClient] fix too high timeout in test
    
    | Q             | A
    | ------------- | ---
    | Branch?       | master
    | Bug fix?      | no
    | New feature?  | no
    | BC breaks?    | no
    | Deprecations? | no
    | Tests pass?   | yes
    | Fixed tickets | -
    | License       | MIT
    | Doc PR        | -
    
    This makes tests pass without waiting for no reasons.
    
    Commits
    -------
    
    8f69954 [HttpClient] fix too high timeout in test
  2. [HttpClient] fix too high timeout in test

    nicolas-grekas committed Apr 15, 2019
  3. minor #31115 [Form] Workaround for \DateInterval::createFromDateStrin…

    nicolas-grekas committed Apr 15, 2019
    …g() (renanbr)
    
    This PR was merged into the 3.4 branch.
    
    Discussion
    ----------
    
    [Form] Workaround for \DateInterval::createFromDateString()
    
    | Q             | A
    | ------------- | ---
    | Branch?       | master
    | Bug fix?      | no
    | New feature?  | no
    | BC breaks?    | no
    | Deprecations? | no
    | Tests pass?   | yes
    | Fixed tickets | n/a
    | License       | MIT
    | Doc PR        | n/a
    
    This patch makes test `Symfony\Component\Form\Tests\Extension\Core\Type\DateIntervalTypeTest::testSubmitNullUsesDateEmptyData()` pass in PHP 7.2.17 and 7.3.4
    
    PHP bug reference : https://bugs.php.net/bug.php?id=77896
    
    See also : https://3v4l.org/sQjh2
    
    Commits
    -------
    
    54247ec Workaround for \DateInterval::createFromDateString()
  4. feature #30717 [Serializer] Use name converter when normalizing const…

    nicolas-grekas committed Apr 15, 2019
    …raint violation list (norkunas)
    
    This PR was merged into the 4.3-dev branch.
    
    Discussion
    ----------
    
    [Serializer] Use name converter when normalizing constraint violation list
    
    | Q             | A
    | ------------- | ---
    | Branch?       | master <!-- see below -->
    | Bug fix?      | no
    | New feature?  | yes <!-- don't forget to update src/**/CHANGELOG.md files -->
    | BC breaks?    | no     <!-- see https://symfony.com/bc -->
    | Deprecations? | no <!-- don't forget to update UPGRADE-*.md and src/**/CHANGELOG.md files -->
    | Tests pass?   | yes    <!-- please add some, will be required by reviewers -->
    | Fixed tickets | #...   <!-- #-prefixed issue number(s), if any -->
    | License       | MIT
    | Doc PR        | symfony/symfony-docs#... <!-- required for new features -->
    
    When using name converter with serializer and the default ConstraintViolationListNormalizer, returned propertyPaths was not converted to the same format.
    
    <!--
    Write a short README entry for your feature/bugfix here (replace this comment block.)
    This will help people understand your PR and can be used as a start of the Doc PR.
    Additionally:
     - Bug fixes must be submitted against the lowest branch where they apply
       (lowest branches are regularly merged to upper ones so they get the fixes too).
     - Features and deprecations must be submitted against the master branch.
    -->
    
    Commits
    -------
    
    dd93b70 Use name converter when normalizing constraint violation list
  5. minor #31047 [DoctrineBridge] [DX] Update exception text in ManagerRe…

    nicolas-grekas committed Apr 15, 2019
    …gistry to avoid confusion. (Simperfit)
    
    This PR was submitted for the master branch but it was merged into the 4.2 branch instead (closes #31047).
    
    Discussion
    ----------
    
    [DoctrineBridge] [DX] Update exception text in ManagerRegistry to avoid confusion.
    
    | Q             | A
    | ------------- | ---
    | Branch?       | master
    | Bug fix?      | no
    | New feature?  | yesish <!-- don't forget to update src/**/CHANGELOG.md files -->
    | BC breaks?    | no     <!-- see https://symfony.com/bc -->
    | Deprecations? | no <!-- don't forget to update UPGRADE-*.md and src/**/CHANGELOG.md files -->
    | Tests pass?   | yes    <!-- please add some, will be required by reviewers -->
    | Fixed tickets | #29659   <!-- #-prefixed issue number(s), if any -->
    | License       | MIT
    | Doc PR        |
    
    <!--
    Write a short README entry for your feature/bugfix here (replace this comment block.)
    This will help people understand your PR and can be used as a start of the Doc PR.
    Additionally:
     - Bug fixes must be submitted against the lowest branch where they apply
       (lowest branches are regularly merged to upper ones so they get the fixes too).
     - Features and deprecations must be submitted against the master branch.
    -->
    
    Since the last PR was closed and the ticket is still open, taking it since it was already done by Nicolas in the comments.
    
    Commits
    -------
    
    9ade232 [DoctrineBridge] [DX] Update exception text in ManagerRegistry::resetService to avoid confusion.
Commits on Apr 14, 2019
  1. [FrameworkBundle] decorate the ValidatorBuilder's translator with Leg…

    nicolas-grekas committed Apr 14, 2019
    …acyTranslatorProxy
Commits on Apr 12, 2019
  1. Merge branch '4.2'

    nicolas-grekas committed Apr 12, 2019
    * 4.2:
      Skip testing the phpunit-bridge on not-master branches when $deps is empty
      more tests
      [DI] Fixes: #28326 - Overriding services autowired by name under _defaults bind not working
      [DI] fix removing non-shared definition while inlining them
  2. Merge branch '3.4' into 4.2

    nicolas-grekas committed Apr 12, 2019
    * 3.4:
      Skip testing the phpunit-bridge on not-master branches when $deps is empty
      more tests
      [DI] Fixes: #28326 - Overriding services autowired by name under _defaults bind not working
  3. minor #31095 Skip testing the phpunit-bridge on not-master branches w…

    nicolas-grekas committed Apr 12, 2019
    …hen $deps is empty (nicolas-grekas)
    
    This PR was merged into the 3.4 branch.
    
    Discussion
    ----------
    
    Skip testing the phpunit-bridge on not-master branches when $deps is empty
    
    | Q             | A
    | ------------- | ---
    | Branch?       | 3.4
    | Bug fix?      | no
    | New feature?  | no
    | BC breaks?    | no
    | Deprecations? | no
    | Tests pass?   | yes
    | Fixed tickets | -
    | License       | MIT
    | Doc PR        | -
    
    Tests are not in sync with the autoloaded code on these jobs.
    The bridge is still tested on deps=low/high jobs + master
    
    Commits
    -------
    
    b0ee192 Skip testing the phpunit-bridge on not-master branches when $deps is empty
  4. [PhpUnitBridge] fix PHP 5.5 support

    nicolas-grekas committed Apr 12, 2019
  5. Skip testing the phpunit-bridge on not-master branches when $deps is …

    nicolas-grekas committed Apr 12, 2019
    …empty
  6. [PhpUnitBridge] CS fix

    nicolas-grekas committed Apr 12, 2019
Older
You can’t perform that action at this time.