Bump symfony/cache from 7.4.7 to 8.0.13#55
Conversation
Bumps [symfony/cache](https://github.com/symfony/cache) from 7.4.7 to 8.0.13. - [Release notes](https://github.com/symfony/cache/releases) - [Changelog](https://github.com/symfony/cache/blob/8.1/CHANGELOG.md) - [Commits](symfony/cache@v7.4.7...v8.0.13) --- updated-dependencies: - dependency-name: symfony/cache dependency-version: 8.0.13 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 66964bb. Configure here.
| }, | ||
| "require": { | ||
| "php": ">=8.2", | ||
| "php": ">=8.4", |
There was a problem hiding this comment.
Major version bump breaks PHP 8.3 CI pipeline
High Severity
The bump from symfony/cache v7.4.7 to v8.0.13 introduces a php >= 8.4 requirement, but the project's CI pipeline in .github/workflows/quality.yml runs on PHP 8.3. The composer install step will fail because the locked symfony/cache and symfony/var-exporter packages refuse to install on PHP versions below 8.4. This is a major version bump (7.x → 8.x) disguised as a security patch that silently raises the minimum PHP version.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit 66964bb. Configure here.


Bumps symfony/cache from 7.4.7 to 8.0.13.
Release notes
Sourced from symfony/cache's releases.
... (truncated)
Changelog
Sourced from symfony/cache's changelog.
... (truncated)
Commits
75f9223Merge branch '7.4' into 8.04c09e18Merge branch '6.4' into 7.45490a57Merge branch '5.4' into 6.4bf58147[Cache] skip tests for adapters that cannot clear by prefix62ee88dMerge branch '7.4' into 8.0f796e47Ignore Doctrine DBAL deprecations that can't be worked around12cc026Merge branch '7.4' into 8.0bf9d30fMerge branch '6.4' into 7.403472b6[Cache] Fix strlen(null) deprecation on RelayCluster path in RedisTrait::doCl...8602405Merge branch '5.4' into 6.4Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.
Note
Medium Risk
Major-version cache dependency with PHP 8.4+ requirement affects dev-tooling paths; low production surface if cache is dev-only, but CI/runtime PHP version mismatch is the main failure mode.
Overview
Updates
composer.lockonly: bumpssymfony/cachefrom 7.4.7 to 8.0.13 (major) and pulls aligned Symfony contract / support packages (symfony/cache-contracts,symfony/deprecation-contracts,symfony/service-contracts,symfony/var-exporter).The resolved
symfony/cachetree now requires PHP >= 8.4 (was >= 8.2) andsymfony/var-exporter^7.4|^8.0 at v8.0.9. Dependency metadata in the lockfile reflects Symfony 8 constraints (e.g. trimmed conflicts, dev deps pinned to ^7.4|^8.0). No application source files change—verify CI/dev environments run PHP 8.4+ and that dev tooling (e.g. phplint) still passes after the upgrade.Reviewed by Cursor Bugbot for commit 66964bb. Bugbot is set up for automated code reviews on this repo. Configure here.