Bump the dependencies group with 2 updates - #2042
Merged
github-actions[bot] merged 1 commit intoAug 31, 2026
Merged
Conversation
Bumps the dependencies group with 2 updates: [vlucas/phpdotenv](https://github.com/vlucas/phpdotenv) and [phpstan/phpstan](https://github.com/phpstan/phpstan-phar-composer-source). Updates `vlucas/phpdotenv` from 5.6.4 to 5.7.0 - [Release notes](https://github.com/vlucas/phpdotenv/releases) - [Commits](vlucas/phpdotenv@v5.6.4...v5.7.0) Updates `phpstan/phpstan` from 2.2.8 to 2.2.9 - [Commits](https://github.com/phpstan/phpstan-phar-composer-source/commits) --- updated-dependencies: - dependency-name: vlucas/phpdotenv dependency-version: 5.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: phpstan/phpstan dependency-version: 2.2.9 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #2042 +/- ##
=========================================
Coverage 92.54% 92.54%
Complexity 2022 2022
=========================================
Files 126 126
Lines 7307 7307
=========================================
Hits 6762 6762
Misses 545 545 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
github-actions
Bot
deleted the
dependabot/composer/dependencies-c9588863d9
branch
August 31, 2026 14:55
Contributor
|
Try the dev build for this PR: https://acquia-cli.s3.amazonaws.com/build/pr/2042/acli.phar |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the dependencies group with 2 updates: vlucas/phpdotenv and phpstan/phpstan.
Updates
vlucas/phpdotenvfrom 5.6.4 to 5.7.0Release notes
Sourced from vlucas/phpdotenv's releases.
Commits
301c079Resolve the remaining static analysis baseline entries (#614)5d0bb3bDocument the real parsing, nesting, comment, escape and validation rules (#609)4426075Stop comments from starting multiline values (#615)eec19eeAdd regression tests for existing behaviour (#608)226b4edImprove diagnostics and messages (#607)4f84f7eStrip a leading UTF-8 byte order mark from string content (#606)4b900c5Resolve nested variables without re-copying the value prefix (#605)dd5b391Remove quadratic value parsing (#604)46d5ce3Skip environment writes and reads for names or values containing a null byte ...8bf174eFix memory-safety crash on invalid UTF-8 variable names (#602)Updates
phpstan/phpstanfrom 2.2.8 to 2.2.9Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions