Skip to content

Conversation

@dependabot-preview
Copy link
Contributor

Bumps laravel/framework from 7.14.1 to 7.26.1. This update includes security fixes.

Vulnerabilities fixed

Sourced from The PHP Security Advisories Database.

Guard bypass in Eloquent models

Affected versions: >=5.5.0, =7.0.0, <7.23.2

Sourced from The PHP Security Advisories Database.

RCE vulnerability in "cookie" session driver

Affected versions: >=5.5.0, =7.0.0, <7.22.4

Sourced from The PHP Security Advisories Database.

RCE vulnerability in "cookie" session driver

Affected versions: >=4.1.0, =7.0.0, <7.22.4

Release notes

Sourced from laravel/framework's releases.

v7.26.1

v7.26.1 (2020-08-27)

Fixed

  • Fixed offset error on invalid remember token (#34020)
  • Only prepend scheme to PhpRedis host when necessary (#34017)
  • Fixed whereKey and whereKeyNot in Illuminate\Database\Eloquent\Builder (#34031)

v7.26.0

v7.26.0 (2020-08-25)

Added

  • Added whenHas and whenFilled methods to Illuminate\Http\Concerns\InteractsWithInput class (#33829)
  • Added email validating with custom class (#33835)
  • Added Illuminate\View\ComponentAttributeBag::whereDoesntStartWith() (#33851)
  • Allow setting synchronous_commit for Postgres (#33897)
  • Allow nested errors in Illuminate\Testing\TestResponse::assertJsonValidationErrors() (#33989)
  • Added support for stream reads to FilesystemManager (#34001)

Fixed

  • Fix defaultTimezone not respected in scheduled Events (#33834)
  • Fixed usage of Support Collection#countBy($key) (#33852)
  • Fixed route registerar bug (42ba0ef)
  • Fixed key composition for attribute with dot at validation error messages (#33932)
  • Fixed the dump method for LazyCollection (#33944)
  • Fixed dimension ratio calculation in Illuminate\Validation\Concerns\ValidatesAttributes::failsRatioCheck() (#34003)

Changed

  • Implement LockProvider on DatabaseStore (#33844)
  • Publish resources.stub in stub:publish command (#33862)
  • Handle argon failures robustly (#33856)
  • Normalize scheme in Redis connections (#33892)
  • Cast primary key to string when $keyType is string (#33930)
  • Load anonymous components from packages (#33954)
  • Check no-interaction flag exists and is true for Artisan commands (#33950)

Deprecated

  • Deprecate Illuminate\Database\Eloquent\Model::removeTableFromKey() (#33859)

v7.25.0

v7.25.0 (2020-08-11)

Added

  • Added support to use where in apiResource method (#33790, 3dcc4a6)
  • Support tls:// scheme when using url in Redis config (#33800)
  • Scoped resource routes (#33752)
  • Added Once blade Blocks (#33812)
Changelog

Sourced from laravel/framework's changelog.

v7.26.1 (2020-08-27)

Fixed

  • Fixed offset error on invalid remember token (#34020)
  • Only prepend scheme to PhpRedis host when necessary (#34017)
  • Fixed whereKey and whereKeyNot in Illuminate\Database\Eloquent\Builder (#34031)

v7.26.0 (2020-08-25)

Added

  • Added whenHas and whenFilled methods to Illuminate\Http\Concerns\InteractsWithInput class (#33829)
  • Added email validating with custom class (#33835)
  • Added Illuminate\View\ComponentAttributeBag::whereDoesntStartWith() (#33851)
  • Allow setting synchronous_commit for Postgres (#33897)
  • Allow nested errors in Illuminate\Testing\TestResponse::assertJsonValidationErrors() (#33989)
  • Added support for stream reads to FilesystemManager (#34001)

Fixed

  • Fix defaultTimezone not respected in scheduled Events (#33834)
  • Fixed usage of Support Collection#countBy($key) (#33852)
  • Fixed route registerar bug (42ba0ef)
  • Fixed key composition for attribute with dot at validation error messages (#33932)
  • Fixed the dump method for LazyCollection (#33944)
  • Fixed dimension ratio calculation in Illuminate\Validation\Concerns\ValidatesAttributes::failsRatioCheck() (#34003)

Changed

  • Implement LockProvider on DatabaseStore (#33844)
  • Publish resources.stub in stub:publish command (#33862)
  • Handle argon failures robustly (#33856)
  • Normalize scheme in Redis connections (#33892)
  • Cast primary key to string when $keyType is string (#33930)
  • Load anonymous components from packages (#33954)
  • Check no-interaction flag exists and is true for Artisan commands (#33950)

Deprecated

  • Deprecate Illuminate\Database\Eloquent\Model::removeTableFromKey() (#33859)

v7.25.0 (2020-08-11)

Added

  • Added support to use where in apiResource method (#33790, 3dcc4a6)
  • Support tls:// scheme when using url in Redis config (#33800)
  • Scoped resource routes (#33752)
  • Added Once blade Blocks (#33812)
  • Let mailables accept a simple array of email addresses as cc or bcc (#33810)
  • Added support for PhpRedis 5.3 options parameter (#33799)

Changed

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

@dependabot-preview dependabot-preview bot added dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability labels Aug 28, 2020
@dependabot-preview
Copy link
Contributor Author

Superseded by #50.

@dependabot-preview dependabot-preview bot deleted the dependabot/composer/laravel/framework-7.26.1 branch September 2, 2020 09:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant