Skip to content

[SECURITY] Update phpunit/phpunit from 8.3.4 to 8.5.54 - #196

Open
violinist-bot wants to merge 1 commit into
matthijsthoolen:masterfrom
violinist-dev:phpunitphpunit8348554
Open

violinist-bot wants to merge 1 commit into
matthijsthoolen:masterfrom
violinist-dev:phpunitphpunit8348554

Conversation

@violinist-bot

@violinist-bot violinist-bot commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

User description

If you have a high test coverage index, and your tests for this pull request are passing, it should be both safe and recommended to merge this update.

Updated packages

Some times an update also needs new or updated dependencies to be installed. Even if this branch is for updating one dependency, it might contain other installs or updates. All of the updates in this branch can be found here:

  • phpdocumentor/reflection-common 1.0.1 (package was removed)
  • phpdocumentor/reflection-docblock 4.3.1 (package was removed)
  • phpdocumentor/type-resolver 0.4.0 (package was removed)
  • phpspec/prophecy 1.8.1 (package was removed)
  • webmozart/assert 1.4.0 (package was removed)
  • doctrine/instantiator: 1.5.0 (updated from 1.2.0)
  • myclabs/deep-copy: 1.13.4 (updated from 1.9.3)
  • phar-io/manifest: 2.0.4 (updated from 1.0.3)
  • phar-io/version: 3.2.1 (updated from 2.0.1)
  • phpunit/php-code-coverage: 7.0.17 (updated from 7.0.7)
  • phpunit/php-file-iterator: 2.0.6 (updated from 2.0.2)
  • phpunit/php-timer: 2.1.4 (updated from 2.1.2)
  • phpunit/php-token-stream: 3.1.3 (updated from 3.1.0)
  • phpunit/phpunit: 8.5.54 (updated from 8.3.4)
  • sebastian/code-unit-reverse-lookup: 1.0.3 (updated from 1.0.1)
  • sebastian/comparator: 3.0.7 (updated from 3.0.2)
  • sebastian/diff: 3.0.6 (updated from 3.0.2)
  • sebastian/environment: 4.2.5 (updated from 4.2.2)
  • sebastian/exporter: 3.1.9 (updated from 3.1.1)
  • sebastian/global-state: 3.0.6 (updated from 3.0.0)
  • sebastian/object-enumerator: 3.0.5 (updated from 3.0.3)
  • sebastian/object-reflector: 1.1.3 (updated from 1.1.1)
  • sebastian/recursion-context: 3.0.4 (updated from 3.0.0)
  • sebastian/resource-operations: 2.0.3 (updated from 2.0.1)
  • sebastian/type: 1.1.5 (updated from 1.1.3)
  • theseer/tokenizer: 1.3.1 (updated from 1.1.3)

Working with this branch

If you find you need to update the codebase to be able to merge this branch (for example update some tests or rebuild some assets), please note that violinist will force push to this branch to keep it up to date. This means you should not work on this branch directly, since you might lose your work. Read more about branches created by violinist.io here.


This is an automated pull request from Violinist: Continuously and automatically monitor and update your composer dependencies. Have ideas on how to improve this message? All violinist messages are open-source, and can be improved here.


CodeAnt-AI Description

Update PHPUnit to a security-maintained 8.5 release

What Changed

  • Development and test tooling now uses PHPUnit 8.5.54 instead of 8.3.4
  • Test dependencies are refreshed to versions compatible with the updated PHPUnit release

Impact

✅ Security updates for test tooling
✅ More reliable test execution

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

Summary by CodeRabbit

  • Chores
    • Updated the development testing framework to version 8.5.54.

@codeant-ai

codeant-ai Bot commented Aug 11, 2026

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Reviewed your PR c8d2dd4 Aug 11, 2026 · 09:23 09:23

@codeant-ai

codeant-ai Bot commented Aug 11, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@coderabbitai

coderabbitai Bot commented Aug 11, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: b919f271-18ef-4493-bd71-53c949f59685

📥 Commits

Reviewing files that changed from the base of the PR and between 0041136 and c8d2dd4.

⛔ Files ignored due to path filters (1)
  • composer.lock is excluded by !**/*.lock
📒 Files selected for processing (1)
  • composer.json

📝 Walkthrough

Walkthrough

The pull request updates the development PHPUnit dependency from 8.3.4 to 8.5.54 in composer.json.

Changes

PHPUnit dependency update

Layer / File(s) Summary
Update PHPUnit development dependency
composer.json
The development dependency changes from PHPUnit 8.3.4 to 8.5.54.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the security update to phpunit/phpunit from version 8.3.4 to 8.5.54.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codeant-ai codeant-ai Bot added the size:XS This PR changes 0-9 lines, ignoring generated files label Aug 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS This PR changes 0-9 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant