Skip to content

Conversation

@dependabot-preview
Copy link
Contributor

@dependabot-preview dependabot-preview bot commented Sep 2, 2020

Bumps laravel/framework from 7.14.1 to 7.27.0. This update includes security fixes.

Vulnerabilities fixed

Sourced from The PHP Security Advisories Database.

Guard bypass in Eloquent models

Affected versions: >=5.5.0, =7.0.0, <7.23.2

Sourced from The PHP Security Advisories Database.

RCE vulnerability in "cookie" session driver

Affected versions: >=5.5.0, =7.0.0, <7.22.4

Sourced from The PHP Security Advisories Database.

RCE vulnerability in "cookie" session driver

Affected versions: >=4.1.0, =7.0.0, <7.22.4

Release notes

Sourced from laravel/framework's releases.

v7.26.1

v7.26.1 (2020-08-27)

Fixed

  • Fixed offset error on invalid remember token (#34020)
  • Only prepend scheme to PhpRedis host when necessary (#34017)
  • Fixed whereKey and whereKeyNot in Illuminate\Database\Eloquent\Builder (#34031)

v7.26.0

v7.26.0 (2020-08-25)

Added

  • Added whenHas and whenFilled methods to Illuminate\Http\Concerns\InteractsWithInput class (#33829)
  • Added email validating with custom class (#33835)
  • Added Illuminate\View\ComponentAttributeBag::whereDoesntStartWith() (#33851)
  • Allow setting synchronous_commit for Postgres (#33897)
  • Allow nested errors in Illuminate\Testing\TestResponse::assertJsonValidationErrors() (#33989)
  • Added support for stream reads to FilesystemManager (#34001)

Fixed

  • Fix defaultTimezone not respected in scheduled Events (#33834)
  • Fixed usage of Support Collection#countBy($key) (#33852)
  • Fixed route registerar bug (42ba0ef)
  • Fixed key composition for attribute with dot at validation error messages (#33932)
  • Fixed the dump method for LazyCollection (#33944)
  • Fixed dimension ratio calculation in Illuminate\Validation\Concerns\ValidatesAttributes::failsRatioCheck() (#34003)

Changed

  • Implement LockProvider on DatabaseStore (#33844)
  • Publish resources.stub in stub:publish command (#33862)
  • Handle argon failures robustly (#33856)
  • Normalize scheme in Redis connections (#33892)
  • Cast primary key to string when $keyType is string (#33930)
  • Load anonymous components from packages (#33954)
  • Check no-interaction flag exists and is true for Artisan commands (#33950)

Deprecated

  • Deprecate Illuminate\Database\Eloquent\Model::removeTableFromKey() (#33859)

v7.25.0

v7.25.0 (2020-08-11)

Added

  • Added support to use where in apiResource method (#33790, 3dcc4a6)
  • Support tls:// scheme when using url in Redis config (#33800)
  • Scoped resource routes (#33752)
  • Added Once blade Blocks (#33812)
Changelog

Sourced from laravel/framework's changelog.

Release Notes for 7.x

Unreleased

v7.26.1 (2020-08-27)

Fixed

  • Fixed offset error on invalid remember token (#34020)
  • Only prepend scheme to PhpRedis host when necessary (#34017)
  • Fixed whereKey and whereKeyNot in Illuminate\Database\Eloquent\Builder (#34031)

v7.26.0 (2020-08-25)

Added

  • Added whenHas and whenFilled methods to Illuminate\Http\Concerns\InteractsWithInput class (#33829)
  • Added email validating with custom class (#33835)
  • Added Illuminate\View\ComponentAttributeBag::whereDoesntStartWith() (#33851)
  • Allow setting synchronous_commit for Postgres (#33897)
  • Allow nested errors in Illuminate\Testing\TestResponse::assertJsonValidationErrors() (#33989)
  • Added support for stream reads to FilesystemManager (#34001)

Fixed

  • Fix defaultTimezone not respected in scheduled Events (#33834)
  • Fixed usage of Support Collection#countBy($key) (#33852)
  • Fixed route registerar bug (42ba0ef)
  • Fixed key composition for attribute with dot at validation error messages (#33932)
  • Fixed the dump method for LazyCollection (#33944)
  • Fixed dimension ratio calculation in Illuminate\Validation\Concerns\ValidatesAttributes::failsRatioCheck() (#34003)

Changed

  • Implement LockProvider on DatabaseStore (#33844)
  • Publish resources.stub in stub:publish command (#33862)
  • Handle argon failures robustly (#33856)
  • Normalize scheme in Redis connections (#33892)
  • Cast primary key to string when $keyType is string (#33930)
  • Load anonymous components from packages (#33954)
  • Check no-interaction flag exists and is true for Artisan commands (#33950)

Deprecated

  • Deprecate Illuminate\Database\Eloquent\Model::removeTableFromKey() (#33859)

v7.25.0 (2020-08-11)

Added

  • Added support to use where in apiResource method (#33790, 3dcc4a6)
  • Support tls:// scheme when using url in Redis config (#33800)
  • Scoped resource routes (#33752)
Commits
  • 17777a9 fix version
  • 94a29ca patch
  • 1b9e4fb Merge branch '6.x' into 7.x
  • d541176 Merge branch 'fixing-custom-views-folder' into 7.x
  • b593c62 formatting
  • 4fba87f changed postgres processor (#34055)
  • f07657a Fixed "public static property" in View Components (#34058)
  • cdf19b0 Updating the make commands to use a custom views path
  • 6dd25f4 [7.x] allow to reset forced scheme and root-url (#34039)
  • 6891cb5 [7.x] Introduced basic padding (both, left, right) methods to Str and Stringa...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

@dependabot-preview dependabot-preview bot added dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability labels Sep 2, 2020
@dependabot-preview dependabot-preview bot force-pushed the dependabot/composer/laravel/framework-7.27.0 branch from 6f36e51 to 6f45db9 Compare September 7, 2020 15:42
@CodeDredd CodeDredd merged commit 9724713 into master Sep 7, 2020
@CodeDredd CodeDredd deleted the dependabot/composer/laravel/framework-7.27.0 branch September 7, 2020 15:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants