Skip to content

Bump the composer group with 9 updates - #2600

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/composer/composer-080f2fa9c1
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/composer/composer-080f2fa9c1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 25, 2026

Copy link
Copy Markdown
Contributor

Bumps the composer group with 9 updates:

Package From To
aws/aws-sdk-php 3.395.3 3.395.7
dedoc/scramble 0.13.43 0.13.45
filament/filament 5.8.2 5.8.4
laravel/framework 13.32.0 13.33.0
predis/predis 3.6.0 3.6.1
secondnetwork/blade-tabler-icons 3.46.0 3.47.0
larastan/larastan 3.12.1 3.12.2
laravel/sail 1.67.0 1.68.0
spatie/pest-plugin-snapshots 2.3.1 2.4.0

Updates aws/aws-sdk-php from 3.395.3 to 3.395.7

Release notes

Sourced from aws/aws-sdk-php's releases.

Version 3.395.7

  • Aws\BedrockAgentCore - Amazon Bedrock AgentCore Harness now supports lifecycle hooks for invocations and tool calls, with Lambda, SNS, and EventBridge targets. This release also adds apiBase for custom OpenAI-compatible endpoints.
  • Aws\DocDB - Add support for CopyTagsToSnapshot field in CreateDbCluster, ModifyDbCluster, RestoreDbClusterFromSnapshot and RestoreDbClusterToPointInTime for DocumentDB.
  • Aws\BillingConductor - Launching Auto Billing Transfer Billing Group Creation Preference feature
  • Aws\BedrockAgentCoreControl - Amazon Bedrock AgentCore Harness now supports lifecycle hooks for invocations and tool calls, with Lambda, SNS, and EventBridge targets. This release also adds apiBase for custom OpenAI-compatible endpoints
  • Aws\SageMaker - Add support for r6i, m8i, c8i, r8i instance types in Training and Processing

Version 3.395.6

  • Aws\IVSRealTime - GetParticipant, ListParticipantEvents, ListParticipantReplicas, StartParticipantReplication, and StopParticipantReplication now accept participant IDs containing underscores.
  • Aws\Connect - This release adds the ListSecurityProfileAIAgents API and updates the CreateSecurityProfile and UpdateSecurityProfile APIs to support the AllowedAIAgents field on security profiles, allowing customers to manage the 3P AI agents associated with a security profile for Agent-to-Agent interactions.
  • Aws\QConnect - Amazon Connect AI Agents now support multi-agent orchestration and structured JSON input and output messaging for orchestration agents.
  • Aws\TranscribeService - Amazon Transcribe now lets you encrypt your custom vocabularies, custom vocabulary filters, and custom language models with a customer managed AWS KMS key instead of an AWS owned key, and adds a new UpdateLanguageModel operation to transition CLM encryption to a different KMS key.
  • Aws\AppIntegrationsService - This release adds support for A2A servers via the ApplicationType and AuthConfig fields, allowing customers to register their agent-to-agent servers with API key authentication.
  • Aws\EC2 - This release adds documentation for the T8i instance family to the EC2 ModifyDefaultCreditSpecification and GetDefaultCreditSpecification APIs.
  • Aws\Glue - Introducing AWS Glue Data Quality advanced rule recommendations for faster recommendations. This capability uses Amazon Athena to analyze a sample of table data and Amazon Bedrock to recommend DQDL rules.
  • Aws\SageMaker - Adds support for the hub content resource in SageMaker Search.
  • Aws\DataZone - Adds support for specifying Notebook type

Version 3.395.5

  • Aws\ - Preserved sub-second precision when serializing unixTimestamp and iso8601 request timestamps. Whole-second values and rfc822 timestamps are unchanged.
  • Aws\BedrockAgentCore - Batch evaluation now supports evaluating specific traces within a session. Each session can specify up to 100 trace IDs to evaluate.
  • Aws\SocialMessaging - Add support for WhatsApp Calling APIs.
  • Aws\VPCLattice - Adding support for CIDR Resource Configuration
  • Aws\SNS - SNS API reference documentation update
  • Aws\IoTWireless - Adds Multi-frame GNSS support to the AWS IoT Core Device Location GetPositionEstimate API. The new GnssMultiFrame measurement type improves location accuracy by combining multiple GNSS signal captures (2, 4, 8, 16, or 32) from the same device to estimate its position.
  • Aws\SESv2 - Added support to query the tenant name for BatchGetMetricData and CreateExportJob APIs to filter metrics and messages at the tenant level.
  • Aws\GuardDuty - This change surfaces AI Protection resources on existing public IAM attack sequences. Customers will now see which model was accessed and whether a guardrail intervened as part of the credential-compromise sequence.
  • Aws\Notifications - Added support for attachments on managed notification events. Added support to access and subscribe sensitive managed notification events.
  • Aws\EC2 - Adding support for "Tunnel" VPC Endpoint
  • Aws\Connect - Made the replicaAlias attribute optional in the ReplicateInstance API to support Global routing for Amazon Connect Global Resiliency (ACGR) instances. This change maintains backward compatibility. When onboarding to ACGR without Global routing, you must specify a custom replicaAlias in your API call

Version 3.395.4

  • Aws\Resiliencehubv2 - Next Gen Resilience Hub now supports dependency insights (LLM-based insights about customer's service dependencies) and organization-level policy sharing (provision to share policy with member accounts for an organization)
  • Aws\BedrockAgentCoreControl - Adds support for a new DELETE FAILED status for Bedrock AgentCore Runtimes and Bedrock AgentCore Runtime Endpoints.
  • Aws\ElasticBeanstalk - Adds support to create and manage Elastic Beanstalk Cluster Environments.
  • Aws\Connect - Adds support for ContactAnalysis via ListContactReferences.
  • Aws\EC2 - Releasing new EC2 R9g and R9gd memory-optimized instances powered by AWS Graviton5 processors, with up to 25 percent better compute performance than R8g instances, faster DDR5 memory, and up to 100 Gbps network and 72 Gbps EBS bandwidth. R9gd instances additionally provide local NVMe SSD storage.
  • Aws\MarketplaceCatalog - This release enhances the ListEntities API to support issuerAccountId and SourceAuthorization filter for ResaleAuthorization entity.
  • Aws\CustomerProfiles - This release introduces the SearchRecommendations API, which retrieves recommendations for a profile identified by a search key.
Commits

Updates dedoc/scramble from 0.13.43 to 0.13.45

Release notes

Sourced from dedoc/scramble's releases.

v0.13.45

What's Changed

Full Changelog: dedoc/scramble@v0.13.44...v0.13.45

v0.13.44

What's Changed

New Contributors

Full Changelog: dedoc/scramble@0.13.43...v0.13.44

Commits

Updates filament/filament from 5.8.2 to 5.8.4

Commits
  • b5aad58 Merge remote-tracking branch 'origin/4.x' into 5.x
  • 9fc9ab2 Merge remote-tracking branch 'origin/4.x' into 5.x
  • See full diff in compare view

Updates laravel/framework from 13.32.0 to 13.33.0

Release notes

Sourced from laravel/framework's releases.

v13.33.0

Changelog

Sourced from laravel/framework's changelog.

v13.33.0 - 2026-09-22

Commits
  • 91188a1 Update version to v13.33.0
  • 39faecd [13.x] Add opt-in native Postgres pooling for Laravel Cloud (#61668)
  • 55fc7c4 [13.x] Fix whereValueBetween() binding expression values (#61670)
  • 4f83e2c [13.x] Add createQuietly and createManyQuietly to BelongsToMany (#61669)
  • 0928872 add sole to higher order (#61667)
  • 2c1594b Restore query logging when a pretend callback throws (#61671)
  • 64eb0ab [13.x] Fix ERR invalid cursor returned when calling `$predisClient->scan(null...
  • 5ff93f4 chore(13.x): fix guzzle deprecation by changing bool to string (#61666)
  • 7b300e1 [13.x] Configure Laravel Cloud database read replicas (#61665)
  • 7eb71a3 [13.x] Respect FILESYSTEM_DISK override when configuring Cloud disks (#61664)
  • Additional commits viewable in compare view

Updates predis/predis from 3.6.0 to 3.6.1

Release notes

Sourced from predis/predis's releases.

v3.6.1

Fixed

  • Fixed RESP3 double parsing returning positive INF for -inf payloads (#1716)
  • Fixed client_info connection parameter being ignored (#1722)
  • Fixed Stream::write() and read() leaving a dead connection when a host error handler throws exception (#1725)

Security

  • Deprecated CommandInterface::deserializeCommand() (CVE GHSA-w6f5-v2h6-g786)
  • Fixed CRLF command smuggling and node misrouting in AbstractAggregateConnection::write() and CommandInterface::deserializeCommand() (CVE GHSA-w6f5-v2h6-g786)
Changelog

Sourced from predis/predis's changelog.

v3.6.1 (2026-09-17)

Fixed

  • Fixed RESP3 double parsing returning positive INF for -inf payloads (#1716)
  • Fixed client_info connection parameter being ignored (#1722)
  • Fixed Stream::write() and read() leaving a dead connection when a host error handler throws exception (#1725)

Security

  • Deprecated CommandInterface::deserializeCommand() (CVE GHSA-w6f5-v2h6-g786)
  • Fixed CRLF command smuggling and node misrouting in AbstractAggregateConnection::write() and CommandInterface::deserializeCommand() (CVE GHSA-w6f5-v2h6-g786)
Commits
  • e2db963 tag v3.6.1
  • 3edc442 Fixed CRLF command smuggling and node misrouting in `AbstractAggregateConnect...
  • 3749086 Fixed Stream::write()/read() leaving a dead connection when a host error hand...
  • 3a5b55e Deprecated CommandInterface::deserializeCommand() (CVE GHSA-w6f5-v2h6-g786) (...
  • 401abc4 fix changelog typo
  • e7b89c1 Fixed client_info connection parameter being ignored (#1722)
  • 3a8c350 Bump the github-actions group with 2 updates (#1720)
  • 6759513 Fix RESP3 double parsing returning positive INF for -inf (#1716)
  • 0795d69 bump dev version
  • See full diff in compare view

Updates secondnetwork/blade-tabler-icons from 3.46.0 to 3.47.0

Release notes

Sourced from secondnetwork/blade-tabler-icons's releases.

Release v3.47.0

Features

  • automated change Icons Release v3.47.0 (b4de5fb)
Commits

Updates larastan/larastan from 3.12.1 to 3.12.2

Release notes

Sourced from larastan/larastan's releases.

3.12.2

What's Changed

Fixed

  • Improve unused view detection for mail content, Mail::send(), concatenated view names, and slash-separated Blade view names by @​FeBe95 in #2479
  • Preserve unsigned column types when an integer cast is applied and support them in higher-order collection sum() calls by @​canvural in 6f44183
  • Recognize quiet increment and decrement methods forwarded by models by @​canvural in 0196dee
  • Treat schema dump columns without NOT NULL as nullable by @​canvural in 29c3d08
  • Use Builder<Model> when a relationship path cannot be followed through an unknown model by @​MizouziE in #2549
  • Detect Octane container injection in arrow functions by @​arpitjain099 in #2551

Performance

Internal

New Contributors

Full Changelog: v3.12.1...v3.12.2

Commits
  • c328727 perf: cache Attribute ObjectType instances in ModelPropertyHelper (#2552)
  • 36015ce fix: flag Octane container injection in arrow functions (#2551)
  • becdaa6 fix: don't fall back to the declaring model when a relation path can't be fol...
  • 79091ad test: gate model incrementEach assertions by Laravel version
  • 29c3d08 fix: treat schema dump columns without NOT NULL as nullable
  • 0196dee fix: forward quiet increment and decrement methods on models
  • 6f44183 fix: keep unsigned column types when an integer cast is applied
  • 6b93c1f chore: optimize GHA workflows
  • 91c1a5d [3.x] Improve view name detection for UnusedViewsRule (#2479)
  • See full diff in compare view

Updates laravel/sail from 1.67.0 to 1.68.0

Release notes

Sourced from laravel/sail's releases.

v1.68.0

Changelog

Sourced from laravel/sail's changelog.

v1.68.0 - 2026-09-18

Commits

Updates spatie/pest-plugin-snapshots from 2.3.1 to 2.4.0

Release notes

Sourced from spatie/pest-plugin-snapshots's releases.

2.4.0

Add support for Pest 5.

Pest 5 requires PHP 8.4, so the minimum PHP version is now 8.4. spatie/phpunit-snapshot-assertions is bumped to ^5.4.0 for PHPUnit 13 support.

Changelog

Sourced from spatie/pest-plugin-snapshots's changelog.

2.4.0 - 2026-07-29

Add support for Pest 5.

Pest 5 requires PHP 8.4, so the minimum PHP version is now 8.4. spatie/phpunit-snapshot-assertions is bumped to ^5.4.0 for PHPUnit 13 support.

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the composer group with 9 updates:

| Package | From | To |
| --- | --- | --- |
| [aws/aws-sdk-php](https://github.com/aws/aws-sdk-php) | `3.395.3` | `3.395.7` |
| [dedoc/scramble](https://github.com/dedoc/scramble) | `0.13.43` | `0.13.45` |
| [filament/filament](https://github.com/filamentphp/panels) | `5.8.2` | `5.8.4` |
| [laravel/framework](https://github.com/laravel/framework) | `13.32.0` | `13.33.0` |
| [predis/predis](https://github.com/predis/predis) | `3.6.0` | `3.6.1` |
| [secondnetwork/blade-tabler-icons](https://github.com/secondnetwork/blade-tabler-icons) | `3.46.0` | `3.47.0` |
| [larastan/larastan](https://github.com/larastan/larastan) | `3.12.1` | `3.12.2` |
| [laravel/sail](https://github.com/laravel/sail) | `1.67.0` | `1.68.0` |
| [spatie/pest-plugin-snapshots](https://github.com/spatie/pest-plugin-snapshots) | `2.3.1` | `2.4.0` |


Updates `aws/aws-sdk-php` from 3.395.3 to 3.395.7
- [Release notes](https://github.com/aws/aws-sdk-php/releases)
- [Commits](aws/aws-sdk-php@3.395.3...3.395.7)

Updates `dedoc/scramble` from 0.13.43 to 0.13.45
- [Release notes](https://github.com/dedoc/scramble/releases)
- [Commits](dedoc/scramble@0.13.43...v0.13.45)

Updates `filament/filament` from 5.8.2 to 5.8.4
- [Commits](filamentphp/panels@v5.8.2...v5.8.4)

Updates `laravel/framework` from 13.32.0 to 13.33.0
- [Release notes](https://github.com/laravel/framework/releases)
- [Changelog](https://github.com/laravel/framework/blob/13.x/CHANGELOG.md)
- [Commits](laravel/framework@v13.32.0...v13.33.0)

Updates `predis/predis` from 3.6.0 to 3.6.1
- [Release notes](https://github.com/predis/predis/releases)
- [Changelog](https://github.com/predis/predis/blob/main/CHANGELOG.md)
- [Commits](predis/predis@v3.6.0...v3.6.1)

Updates `secondnetwork/blade-tabler-icons` from 3.46.0 to 3.47.0
- [Release notes](https://github.com/secondnetwork/blade-tabler-icons/releases)
- [Commits](secondnetwork/blade-tabler-icons@v3.46.0...v3.47.0)

Updates `larastan/larastan` from 3.12.1 to 3.12.2
- [Release notes](https://github.com/larastan/larastan/releases)
- [Changelog](https://github.com/larastan/larastan/blob/3.x/RELEASE.md)
- [Commits](larastan/larastan@v3.12.1...v3.12.2)

Updates `laravel/sail` from 1.67.0 to 1.68.0
- [Release notes](https://github.com/laravel/sail/releases)
- [Changelog](https://github.com/laravel/sail/blob/1.x/CHANGELOG.md)
- [Commits](laravel/sail@v1.67.0...v1.68.0)

Updates `spatie/pest-plugin-snapshots` from 2.3.1 to 2.4.0
- [Release notes](https://github.com/spatie/pest-plugin-snapshots/releases)
- [Changelog](https://github.com/spatie/pest-plugin-snapshots/blob/main/CHANGELOG.md)
- [Commits](spatie/pest-plugin-snapshots@2.3.1...2.4.0)

---
updated-dependencies:
- dependency-name: aws/aws-sdk-php
  dependency-version: 3.395.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: composer
- dependency-name: dedoc/scramble
  dependency-version: 0.13.45
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: composer
- dependency-name: filament/filament
  dependency-version: 5.8.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: composer
- dependency-name: laravel/framework
  dependency-version: 13.33.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: composer
- dependency-name: predis/predis
  dependency-version: 3.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: composer
- dependency-name: secondnetwork/blade-tabler-icons
  dependency-version: 3.47.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: composer
- dependency-name: larastan/larastan
  dependency-version: 3.12.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: composer
- dependency-name: laravel/sail
  dependency-version: 1.68.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: composer
- dependency-name: spatie/pest-plugin-snapshots
  dependency-version: 2.4.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: composer
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update php code labels Sep 25, 2026
@coderabbitai

coderabbitai Bot commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: 440e01cf-a063-46ae-874b-4343c551bb6d

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@lancepioch

Copy link
Copy Markdown
Member

Added these changes to #2597

@lancepioch lancepioch closed this Sep 25, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 25, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/composer/composer-080f2fa9c1 branch September 25, 2026 16:21
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 25, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file php Pull requests that update php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant