chore(deps): update dependency twig/twig to v3.30.0 - #64
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/twig-monorepo
branch
from
May 2, 2025 15:33
7d6b49a to
dc5d82f
Compare
renovate
Bot
force-pushed
the
renovate/twig-monorepo
branch
from
May 3, 2025 10:10
dc5d82f to
c735178
Compare
renovate
Bot
force-pushed
the
renovate/twig-monorepo
branch
from
October 31, 2025 00:04
c735178 to
1f42e95
Compare
renovate
Bot
force-pushed
the
renovate/twig-monorepo
branch
from
November 30, 2025 14:04
1f42e95 to
9d01894
Compare
renovate
Bot
force-pushed
the
renovate/twig-monorepo
branch
from
December 15, 2025 10:42
9d01894 to
8055303
Compare
renovate
Bot
force-pushed
the
renovate/twig-monorepo
branch
from
January 23, 2026 22:08
8055303 to
16cf8fa
Compare
renovate
Bot
force-pushed
the
renovate/twig-monorepo
branch
from
March 18, 2026 01:29
16cf8fa to
0a0230e
Compare
renovate
Bot
force-pushed
the
renovate/twig-monorepo
branch
from
May 17, 2026 09:00
0a0230e to
4e17b79
Compare
renovate
Bot
force-pushed
the
renovate/twig-monorepo
branch
from
May 20, 2026 09:52
4e17b79 to
cefa5ca
Compare
renovate
Bot
force-pushed
the
renovate/twig-monorepo
branch
from
May 27, 2026 14:45
cefa5ca to
c819557
Compare
renovate
Bot
force-pushed
the
renovate/twig-monorepo
branch
from
May 30, 2026 21:28
c819557 to
3290875
Compare
renovate
Bot
force-pushed
the
renovate/twig-monorepo
branch
from
July 3, 2026 21:25
3290875 to
80d4236
Compare
renovate
Bot
force-pushed
the
renovate/twig-monorepo
branch
from
September 20, 2026 02:49
80d4236 to
d383d64
Compare
renovate
Bot
force-pushed
the
renovate/twig-monorepo
branch
from
September 25, 2026 13:58
d383d64 to
202c567
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.8.0→3.30.0Release Notes
twigphp/Twig (twig/twig)
v3.30.0Compare Source
split,random, andshufflemerging a trailing newline into the last character of a stringsplit,random, andshuffleIntlExtensionletting the pattern derived from a date formatter prototype override an explicit localeIntlExtensionnot honoring the locale of a date formatter prototype configured with no date and time stylesTemplateWrapper::unwrap()failing when called without arguments, which is now deprecatedTemplateWrapper::getDefaultEscapeStrategy()to know the escaping strategy a template was compiled withrandom,reverse,shuffle, andsplitreceive a string that is not valid UTF-8Twig\EnvironmentinstanceStringablekey on subclasses ofArrayObjectandArrayIteratorv3.29.0Compare Source
{% cache %}always missing in the Symfony bundle whenframework.cache.appuses a natively tag aware adapterusetrait templates before checking that theusetag is allowedhtml_attrdroppingstyledeclarations whose value is0,0.0or'0'defaultfilter fallback emitting an undefined variable warning when it uses the null-safe operatormatchesoperator silently treating PCRE execution errors as non-matches; it now throws aRuntimeErrorTemplateWrapper::streamBlock(),TemplateWrapper::hasBlock(), andTemplateWrapper::getBlockNames()omitting environment globalsBlockChainclass to compose blocks from multiple templates without using template internalsTemplateWrapper::hasBlock()andTemplateWrapper::getBlockNames()losing theextendsline when the parent template does not existHtmlExtension::htmlAttrValue()method to resolve a single HTML attribute value the way thehtml_attrfunction renders ithtml_attrJSON encoding aStringablevalue in adata-*attribute instead of using its string representationSyntaxErrorTypeErrorMissingExtensionSuggestornot suggesting thetwig/*-extrapackage to install for somehtml-extra,intl-extra, andstring-extrafilters and functionsTempestMarkdownto usetempest/markdownas themarkdown_to_htmlconverterinclude_onlyfunction to render a template without giving it access to the current contextTwig\Sandbox\SandboxInterfaceinterface andTwig\Sandbox\Sandboxclass to render untrusted templates through a dedicated, always-sandboxed environment crafted for itTemplateWrapperinstances created by anotherEnvironmentTwig\Extension\SandboxBridgeExtensionto render sandboxed templates from trusted templates with an explicit output escaping strategyTwig\Sandbox\SecurityCheckerclass used by compiled templates andCoreExtensionSandboxExtensionas internal, useTwig\Sandbox\Sandboxinsteadsandboxedargument of theincludefunction, useTwig\Sandbox\SandboxinsteadSandboxExtension::enableSandbox(),disableSandbox(), andisSandboxedGlobally()IntlExtensionignoring explicit date/time formats and configured calendars when using a date formatter prototypeformat_listfilter toIntlExtensionto format a list of strings using PHP 8.5'sIntlListFormatterStringablekey forArrayObjectandArrayIteratorwhile preserving object keys forSplObjectStorageSyntaxErrorTemplateVariableandAssignTemplateVariable; useMacroVariableandAssignMacroVariableinsteadSyntaxErrorin 4.0definedtest; it will throw aSyntaxErrorin 4.0{% macro foo(a, ...rest) %})macro_-prefixed PHP methodsTwig\Node\MacroNodeas@final; it will be final in Twig 4.0MacrosNodeinstance as the macros of aModuleNodeconstructorMacroReferenceExpressionto take the bare macro name instead of amacro_-prefixed method namemacro_-prefixed name; pass the bare macro name toMacroReferenceExpressionv3.28.0Compare Source
html_attrfunctionchr()deprecation when decoding an octal string escape sequence larger than\377(such as"\777")Twig\Markupas@final; it will be final in Twig 4.0forloopsmacros.(name)(args))Error::getTemplateColumn()Token::getOffset()block()calls to resolve against the overriding template when a block rendered throughblock(name, template)callsparent()blocktag within a capture node (likeset)blocktag within a capture node (likeset) in child templatesmacro,extends, orusetag outside the root of a templateIntegrationTestCasewhen there is no legacy test to runmarkdown_to_htmlto strip the indentation shared by all lines instead of mangling content that starts with a blank lineIntegrationTestCaseandNodeTestCasetest helpers compatible with PHPUnit 11Stringableobjects, ...) report a usable stack trace at the print locationinclude()function return aMarkupobject so an assigned result is not re-escaped when printed__toStringcheck on arguments whose PHP parameter type cannot implicitly coerce to stringalways_allowed_in_sandboxoption for filters, functions, and tests, and anisAlwaysAllowedInSandbox()method for token parsers, to let authors mark callables and tags that are always allowed in sandbox mode without explicit allow-listingTwig\Sandbox\SecurityPolicy, with the safe built-in tests flagged as always allowed so they keep working without allow-listingv3.27.1Compare Source
Stringablekey to coerce the key to string consistently instead of throwing in the optimized pathIteratorAggregatearguments (e.g. Symfony'sFormView) by a plain arrayv3.27.0Compare Source
Twig\Sandbox\SecurityPolicyto opt-in to the 4.0 behavior for theextends/usetags and theparent/block/attributefunctions, which are otherwise still implicitly allowed in a sandboxparent,block, andattributefunctions are always allowed in a sandboxed templateTemplateinstanceArrayAccessattribute access with a float keyTwig\Profiler\Profile::unserialize()to prevent arbitrary class instantiationHtmlDumpertwig_array_some(),twig_array_every(), andtwig_check_arrow_in_sandbox()(src/Resources/core.php)Twig\Sandbox\SourcePolicyInterfaceinterface with no replacementSourcePolicyInterface__toStringbypass viaTraversablearguments to thejoinandreplacefilters (also covers containers that implement bothStringableandTraversable)__toStringbypass via theinandnot inoperatorsSandboxExtension::ensureToStringAllowed()when a self-referencing iterable is passed to a sandboxed template__toStringpolicy bypass via dynamic mapping keysv3.26.0Compare Source
template_from_stringcaveats when used in a sandboxed environmentMarkupabout the goal of this class in the context of a sandboxspacelessfilterinline_cssandinky_to_htmlfiltersis_safeannotation on HTML-emitting filtersHtmlDumperIntlDateFormatter/NumberFormatter{% sandbox %}tag when including a preloaded template{% use %}template name_self/ import macro referenceSourcetocheckArrowfor source-policy sandboxing\x27inCompiler::string()as a defense-in-depth measure__toStringbypassesTwig\Node\CoercesChildrenToStringInterfaceto let nodes declare which of their child nodes will be string-coerced at runtime so the sandbox wraps them with a__toStringcheckv3.25.0Compare Source
needs_is_sandboxedoption for filters, functions, and testsEscaperRuntimeinEscaperExtensionv3.24.0Compare Source
getOperatorTokens()method inExpressionParserInterfaceimplementationsAbstractExpressionnode toTwig\Node\Expression\Binary\MatchesBinaryconstructorAbstractExpressionnode toParser::setParent(){name: userName} = user)html_attr_relaxedescaping strategy that preserves :, @, [, and ] for front-end framework attribute nameshtml_attrfunction andhtml_attr_mergeas well ashtml_attr_typefiltersv3.23.0Compare Source
=assignment operator (allows to set variables in expression or to replace the short-form of the set tag)?.null-safe operator===and!==operators (equivalent to thesame asandnot same astests)v3.22.2Compare Source
v3.22.1Compare Source
v3.22.0Compare Source
Environment::registerUndefinedTestCallback()v3.21.1Compare Source
v3.21.0Compare Source
Template::loadTemplate()MarkupReturnPrimitiveTypeInterface(and sub-interfaces for number, boolean, string, and array)SupportDefinedTestInterfacefor expression nodes supporting thedefinedtest|operator in an expression with+or-without using parentheses to clarify precedenceinstead of arrays (it comes with many deprecations that are documented in
the
deprecateddocumentation chapter)Twig\ExpressionParser, andTwig\OperatorPrecedenceChangeclassesAsTwigFilter,AsTwigFunction, andAsTwigTestto ease extension developmentv3.20.0Compare Source
ForElseNodev3.19.0Compare Source
??Token::getType(), useToken::test()insteadToken::toEnglish()ForElseNodeTwig\ExpressionParser::parseOnlyArguments()andTwig\ExpressionParser::parseArguments()(useTwig\ExpressionParser::parseNamedArguments()instead)constant()behavior when used with??invokefilter{}optional for thetypestagLastModifiedExtensionInterfaceand implementation inAbstractExtensionto track modification of runtime classesv3.18.0Compare Source
SyntaxErrorexceptions from undefined handlers when using theguardtagTemplateWrapper::stream()andTemplateWrapper::streamBlock())v3.17.1Compare Source
v3.17.0Compare Source
ConditionalExpressionandNullCoalesceExpression(useConditionalTernaryandNullCoalesceBinaryinstead)v3.16.0Compare Source
InlinePrintSourceinstance toTokenStreamnullfromTwigFilter::getSafe()andTwigFunction::getSafe(), return[]insteadv3.15.0Compare Source
this can be a BC break if you don't use UPPERCASE constant names
pluralandsingularfilters in the String extensionTempNameExpressionin favor ofLocalVariableNameExpressionin favor ofContextVariableAssignNameExpressionin favor ofAssignContextVariableMacroAutoImportNodeVisitorMethodCallExpressionin favor ofMacroReferenceExpression_self.xxx(auto-imported) macrosfoo.bar(some: arg))guardtag that allows to test if some Twig callables are available at compilation time\Closure)notunary operator in an expression with*,/,//, or%without using explicit parentheses to clarify precedence??binary operator without explicit parentheses~binary operator in an expression with+or-without using parentheses to clarify precedenceAbstractExpressionargs to most constructor arguments for classes extendingAbstractExpressionpowerexpressions with a negative number in parenthesis ((-1) ** 2)Nodedirectly. UseEmptyNodeorNodesinstead.Profile::getStartTime()andProfile::getEndTime()They were automatically converted to snake-cased before
attributefunction; use the.notation and wrap the name with parenthesis insteadsandboxtagdeprecation_infoinstead of the other callable options)enumfunctionxoroperatorv3.14.2Compare Source
v3.14.1Compare Source
They are now checked via the property policy
toString()under some circumstances on an object even if the
__toString()method is not allowed by the security policyv3.14.0Compare Source
Environment::resetGlobals()Environment::mergeGlobals()v3.13.0Compare Source
typestag (experimental)Twig\Test\NodeTestCase::getTests()data provider, overrideprovideTests()instead.Twig\Test\NodeTestCase::getEnvironment()as final, overridecreateEnvironment()instead.Twig\Test\NodeTestCase::getVariableGetter(), callcreateVariableGetter()instead.Twig\Test\NodeTestCase::getAttributeGetter(), callcreateAttributeGetter()instead.Twig\Test\IntegrationTestCase::getFixturesDirectory(), this method will be abstract in 4.0Twig\Test\IntegrationTestCase::getTests()andgetLegacyTests()as finalv3.12.0Compare Source
extendsandusetags are always allowed in a sandboxed template.This behavior will change in 4.0 where these tags will need to be explicitly allowed like any other tag.
spacelessfilterParser:getBlockStack(),hasBlock(),getBlock(),hasMacro(),hasTraits(),getParent()nulltoTwig\Parser::setParent()Node::__toString()to include the node tag if setTwig\Node\Nodethat take a Node nameBodyNodeinstance as the body of aModuleNodeorMacroNodeconstructorOptimizerNodeVisitor::OPTIMIZE_TEXT_NODESuse_yieldisfalse(which is the default)use_yieldisfalse(as extensions still usingechowill work as is):) in addition to equals (=) to separate argument names and values in named argumentshtml_cvafunction (in the HTML extra package)blockandattributefunctionsCallableArgumentsExtractorclassFunctionExpression,FilterExpression, andTestExpression;pass a
TwigFunction,TwigFilter, orTestFilterinsteadFunctionExpression,FilterExpression, andTestExpressionfilternode ofFilterExpressionenum_casesfunctionv3.11.3Compare Source
v3.11.2Compare Source
They are now checked via the property policy
toString()under some circumstances on an object even if the
__toString()method is not allowed by the security policyv3.11.1Compare Source
v3.11.0Compare Source
OptimizerNodeVisitor::OPTIMIZE_RAW_FILTERTwig\Cache\ChainCacheandTwig\Cache\ReadOnlyFilesystemCacheNodedeprecatedtagConstantExpressionas being@finalfindfilterOptimizerNodeVisitorPrintNodeshufflefiltersingularandpluralfilters inStringExtensionTwig\Node\Expression\CallExpression::compileArguments()Twig\ExpressionParser\parseHashExpression()in favor ofTwig\ExpressionParser::parseMappingExpression()Twig\ExpressionParser\parseArrayExpression()in favor ofTwig\ExpressionParser::parseSequenceExpression()sequenceandmappingtestsTwig\Node\Expression\NameExpression::isSimple()andTwig\Node\Expression\NameExpression::isSpecial()v3.10.3Compare Source
v3.10.2Compare Source
v3.10.1Compare Source
v3.10.0Compare Source
Make
CoreExtension::formatDate,CoreExtension::convertDate, andCoreExtension::formatNumberpart of the public APIAdd
needs_charsetoption for filters and functionsExtract the escaping logic from the
EscaperExtensionclass to a newEscaperRuntimeclass.The following methods from
Twig\\Extension\\EscaperExtensionaredeprecated:
setEscaper(),getEscapers(),setSafeClasses,addSafeClasses(). Use the same methods on theTwig\\Runtime\\EscaperRuntimeclass instead.Fix capturing output from extensions that still use echo
Fix a PHP warning in the Lexer on malformed templates
Fix blocks not available under some circumstances
Synchronize source context in templates when setting a Node on a Node
v3.9.3Compare Source
twig_escape_filter_is_safedeprecated functionv3.9.2Compare Source
v3.9.1Compare Source
$blocksvariable inCaptureNodev3.9.0Compare Source
Node implementations that use "echo" or "print" should use "yield" instead;
all Node implementations should be flagged with
#[YieldReady]once they've been made ready for "yield";the "use_yield" Environment option can be turned on when all nodes have been made
#[YieldReady];"yield" will be the only strategy supported in the next major version
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.