Repository navigation
Update dependencies to resolve Dependabot alerts - #2128
Open
kayjoosten wants to merge 3 commits into
Open
kayjoosten wants to merge 3 commits into
kayjoosten wants to merge 3 commits into
Conversation
# If applied, this commit will update the Composer, theme Yarn and Cypress Yarn lock files to the latest versions allowed by the current version constraints. # Why is this change needed? Prior to this change, many Dependabot PRs and security alerts were open (twig, simplesamlphp/saml2, league/flysystem, js-yaml, svgo, fast-uri, postcss, brace-expansion and more). # How does it address the issue? This change runs a constraint-respecting update of all three lock files. Major version bumps (phpunit 13, doctrine-bundle 3, symfony 8, js-yaml 5, webpack-cli 7, babel-loader 10) are left out. The newer stylelint flags valid SCSS @mixin preludes, so at-rule-prelude-no-invalid is disabled in the same way media-query-no-invalid already is. The guzzlehttp/guzzle and guzzlehttp/psr7 fixes remain blocked by the ~2.8.0 psr7 pin in simplesamlphp/assert 1.9.1. This is documented in the CHANGELOG. extract-zip and braces have no patched release yet. # Provide links to any relevant tickets, articles or other resources Refs #2121
johanib
reviewed
Oct 8, 2026
# If applied, this commit will remove the notes about what was not updated from the CHANGELOG entry. # Why is this change needed? Prior to this change, the entry described the major bumps and the guzzle/psr7 blocker that were not part of this change. A changelog should only list what was done. # How does it address the issue? This change keeps a single line describing the dependency update. # Provide links to any relevant tickets, articles or other resources Refs #2121
johanib
reviewed
Oct 8, 2026
| { | ||
| "extends": "stylelint-config-recommended", | ||
| "rules": { | ||
| "at-rule-prelude-no-invalid": null, |
johanib
approved these changes
Oct 8, 2026
# If applied, this commit will keep at-rule-prelude-no-invalid enabled and only skip the SCSS at-rules and the interpolated @media queries in breakpoints.scss. # Why is this change needed? Prior to this change, the rule was disabled for the whole theme to get past false positives on SCSS mixin signatures and interpolation, which would also hide real mistakes in at-rule preludes. # How does it address the issue? This change passes the SCSS-only at-rules (mixin, include, if, each, for, function, return, use, else) through ignoreAtRules, and disables the rule for breakpoints.scss only, where @media uses #{$var} interpolation. # Provide links to any relevant tickets, articles or other resources Refs #2121
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Updates the Composer, theme Yarn and Cypress Yarn lock files to the latest versions allowed by the current version constraints, resolving most open Dependabot alerts (twig, simplesamlphp/saml2, league/flysystem, js-yaml, svgo, fast-uri, postcss, brace-expansion and more).
@mixinpreludes, soat-rule-prelude-no-invalidis disabled intheme/.stylelintrc, likemedia-query-no-invalidalready is.Still open
guzzlehttp/guzzleandguzzlehttp/psr7:simplesamlphp/assert1.9.1 pins psr7 to~2.8.0, while the fixed guzzle 7.15 needs psr7^2.13.simplesamlphp/assert2.x/3.x conflicts withwebmozart/assert^1 required by saml2 4.x. Replacingsimplesamlphp/assertin the two legacy validators would unblock this.extract-zip(Cypress) andbraces(stylelint) have no patched release yet.Testing
PHPUnit (unit, eb4, integration, functional), phpmd, phpcs, docheader, Twig lint, theme build and lint, and the Behat default suite (300 scenarios) all pass.
Refs #2121