Skip to content

Update dependency phpunit/phpunit to v13 [SECURITY] - #12

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/packagist-phpunit-phpunit-vulnerability
Open

Update dependency phpunit/phpunit to v13 [SECURITY]#12
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/packagist-phpunit-phpunit-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Jan 28, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
phpunit/phpunit (source) ^4.8^13.0 age confidence

PHPUnit Vulnerable to Unsafe Deserialization in PHPT Code Coverage Handling

CVE-2026-24765 / GHSA-vvj3-c3rp-c85p

More information

Details

Overview

A vulnerability has been discovered involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the cleanupForCoverage() method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious .coverage files are present prior to the execution of the PHPT test.

Technical Details

Affected Component: PHPT test runner, method cleanupForCoverage()
Affected Versions: <= 8.5.51, <= 9.6.32, <= 10.5.61, <= 11.5.49, <= 12.5.7

Vulnerable Code Pattern
if ($buffer !== false) {
    // Unsafe call without restrictions
    $coverage = @unserialize($buffer);
}

The vulnerability occurs when a .coverage file, which should not exist before test execution, is deserialized without the allowed_classes parameter restriction. An attacker with local file write access can place a malicious serialized object with a __wakeup() method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled.

Attack Prerequisites and Constraints

This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through:

  • CI/CD Pipeline Attacks: A malicious pull request that places a .coverage file alongside test files, executed when the CI system runs tests using PHPUnit and collects code coverage information
  • Local Development Environment: An attacker with shell access or ability to write files to the project directory
  • Compromised Dependencies: A supply chain attack inserting malicious files into a package or monorepo

Critical Context: Running test suites from unreviewed pull requests without isolated execution is inherently a code execution risk, independent of this specific vulnerability. This represents a broader class of Poisoned Pipeline Execution (PPE) attacks affecting CI/CD systems.

Proposed Remediation Approach

Rather than just silently sanitizing the input via ['allowed_classes' => false], the maintainer has chosen to make the anomalous state explicit by treating pre-existing .coverage files for PHPT tests as an error condition.

Rationale for Error-Based Approach:
  1. Visibility Over Silence: When an invariant is violated (a .coverage file existing before test execution), the error must be visible in CI/CD output, alerting operators to investigate the root cause rather than proceeding with sanitized input
  2. Operational Security: A .coverage file should never exist before tests run, coverage data is generated by executing tests, not sourced from artifacts. Its presence indicates:
    • A malicious actor placed it intentionally
    • Build artifacts from a previous run contaminated the environment
    • An unexpected filesystem state requiring investigation
  3. Defense-in-Depth Principle: Protecting a single deserialization call does not address the fundamental attack surface. Proper mitigations for PPE attacks lie outside PHPUnit's scope:
    • Isolate CI/CD runners (ephemeral, containerized environments)
    • Restrict code execution on protected branches
    • Scan pull requests and artifacts for tampering
    • Use branch protection rules to prevent unreviewed code execution
Severity Classification
  • Attack Vector (AV): Local (L) — requires write access to the file system where tests execute
  • Attack Complexity (AC): Low (L) — exploitation is straightforward once the malicious file is placed
  • Privileges Required (PR): Low (L) — PR submitter status or contributor role provides sufficient access
  • User Interaction (UI): None (N) — automatic execution during standard test execution
  • Scope (S): Unchanged (U) — impact remains within the affected test execution context
  • Confidentiality Impact (C): High (H) — full remote code execution enables complete system compromise
  • Integrity Impact (I): High (H) — arbitrary code execution allows malicious modifications
  • Availability Impact (A): High (H) — full code execution permits denial-of-service actions
Mitigating Factors (Environmental Context)

Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration:

  • Ephemeral Runners: Use containerized, single-use CI/CD runners that discard filesystem state between runs
  • Code Review Enforcement: Require human review and approval before executing code from pull requests
  • Branch Protection: Enforce branch protection rules that block unreviewed code execution
  • Artifact Isolation: Separate build artifacts from source; never reuse artifacts across independent builds
  • Access Control: Limit file write permissions in CI environments to authenticated, trusted actors
Fixed Behaviour

When a .coverage file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. This ensures:

  • Visibility: The error appears prominently in CI/CD output and test logs
  • Investigation: Operations teams can investigate the root cause (potential tampering, environment contamination)
  • Fail-Fast Semantics: Test execution stops rather than proceeding with an unexpected state
Recommendation

Update to the patched version immediately if a project runs PHPT tests using PHPUnit with coverage instrumentation in any CI/CD environment that executes code from external contributors. Additionally, audit the project's CI/CD configuration to ensure:

  • Pull requests from forks or untrusted sources execute in isolated environments
  • Branch protection rules require human review before code execution
  • CI/CD runners are ephemeral and discarded after each build
  • Build artifacts are not reused across independent runs without validation

Severity

  • CVSS Score: 7.8 / 10 (High)
  • Vector String: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

sebastianbergmann/phpunit (phpunit/phpunit)

v13.3.1

Compare Source

v13.3.0: PHPUnit 13.3.0

Compare Source

Added
  • #​3794: Filesystem-based code coverage targeting
  • #​5758: Make export of objects customizable
  • #​6546: Both property hooks can now be configured on test doubles of virtual hooked properties, even when the doubled property only declares one of them
  • #​6586: Custom code coverage driver support
  • #​6591: Repeated test execution using --repeat CLI option and #[Repeat] attribute
  • #​6701: Allow expectOutputString() and expectOutputRegex() to be combined and repeated
  • #​6710: Deprecation Filters
  • #​6722: Allow #[CoversNothing] on methods
  • #​6742: Retry failing tests up to N times using --retry CLI option #[Retry] attribute
  • #​6827: Customize which deprecation trigger types fail the test run
  • #​6830: Warn when failOnAllIssues="true" is combined with an explicitly disabled fine-grained failOn* setting
  • #​6832: Allow doubling properties that do not declare property hooks
  • #​6853: Optionally warn when PHP is not configured for development
  • phpunit/php-code-coverage #​1140: Class-oriented HTML report
  • phpunit/php-code-coverage #​1141: Improve visualization of branch coverage and path coverage in the HTML report
  • phpunit/php-code-coverage #​1153: Filter HTML code coverage report by test size
  • --record-test-run-history and --do-not-record-test-run-history CLI options as well as the recordTestRunHistory attribute for the XML configuration file to control whether the status and duration of each test are recorded for use by --order-by defects and --order-by duration-*
  • --without-class-view CLI option and classView attribute for the XML configuration file to disable the class-oriented view in the HTML code coverage report
  • --without-file-view CLI option and fileView attribute for the XML configuration file to disable the file-oriented view in the HTML code coverage report
  • {PWD} is now substituted with the directory of the PHPT test file in --ENV-- and --INI-- sections of PHPT test files
  • {TMP} (system directory for temporary files) and {ENV:name} (value of environment variable name) are now substituted in --INI-- sections of PHPT test files
  • A PHPT test whose --INI-- section references an environment variable that is not set is now skipped
  • A --SKIPIF-- section of a PHPT test file that prints xfail <reason> now marks the test as expected to fail, as if the PHPT test file had an --XFAIL-- section with that reason
Changed
  • phpunit/php-code-coverage #​1231: Identify dead code using static analysis
  • phpunit/php-code-coverage #​1259: Degrade gracefully when a source file cannot be parsed
  • The test runner no longer crashes when an attribute cannot be instantiated
  • Improved TestDox HTML report
  • The feature formerly named "test result cache" is now named "test run history"; when a cache directory is configured, the file it is stored in is now named test-run-history instead of test-results
  • The test runner warns now when ordering by defects or duration is configured but recording of the test run history is disabled
  • TestCase no longer captures error_log() output for tests that do not use expectErrorLog(), avoiding the cost of setting up error log redirection for every test
  • error_log() output from tests without an expectation is no longer echoed (date-stripped) to PHPUnit's output; it goes to the configured error log again, as it did before capture was introduced
  • A test running in process isolation that calls error_log() without expectErrorLog() now produces stderr output in the child process, which the test runner reports as a test error
  • A PHPT test that is expected to fail (--XFAIL-- section or xfail output from the --SKIPIF-- section) but passes is now considered risky; this usually means the expected-failure marker is stale and should be removed
  • A PHPT test whose --SKIPIF-- section produces output that is not recognized is now considered risky; this usually means the skip check itself is broken. The keywords understood by PHP's own test runner that have no PHPUnit counterpart (info, warn, xleak, flaky, and nocache) are tolerated and do not make the test risky
  • PHPT tests now run with additional INI defaults for deterministic output (date.timezone=UTC, display_startup_errors=1, fatal_error_backtraces=Off, ignore_repeated_errors=0, precision=14,
    serialize_precision=-1), consistent with PHP's own test runner; all of them can be overridden per test using the --INI-- section
Deprecated
  • --cache-result CLI option, use --record-test-run-history instead
  • --do-not-cache-result CLI option, use --do-not-record-test-run-history instead
  • cacheResult XML configuration attribute, use recordTestRunHistory instead
  • PHPUnit\TextUI\Configuration\Configuration::cacheResult(), use PHPUnit\TextUI\Configuration\Configuration::recordTestRunHistory() instead
  • PHPUnit\TextUI\Configuration\Configuration::testResultCacheFile(), use PHPUnit\TextUI\Configuration\Configuration::testRunHistoryFile() instead
Fixed
  • Doubling a class with a property that declares both a final and a non-final hook no longer triggers a fatal error
  • expectErrorLog() now only considers error_log() output written after it was called; previously, the expectation was also satisfied by output written before expectErrorLog() was called
  • PHPT test files with an unknown section, a duplicated section, more than one of the --FILE--, --FILEEOF--, and --FILE_EXTERNAL-- sections, or more than one expectation section (--EXPECT--, --EXPECTF--, --EXPECTREGEX--, and their _EXTERNAL variants) are now rejected; previously, misspelled sections were silently ignored and duplicated sections silently overwrote each other
  • The regular expression from an --EXPECTREGEX-- section must now match the PHPT test's entire output, and . now matches newline characters, consistent with PHP's own test runner; previously, a match on a substring of the output was sufficient for the test to pass
  • The reason printed by a --SKIPIF-- section of a PHPT test is no longer mangled when it follows the skip <reason> convention used by PHP's own test suite; previously, the first two characters of the reason were stripped unless the skip: <reason> or skip - <reason> convention was used
  • The test runner no longer aborts with an uncaught PHPUnit\Runner\Phpt\InvalidPhptFileException when a PHPT test file has an empty --FILE-- or --FILEEOF-- section or a --FILE_EXTERNAL-- section that references an empty file; such a file is now rejected while it is parsed and reported as an errored test
  • PHPUnit\Runner\Phpt\InvalidPhptFileException now has a message that explains why the PHPT test file was rejected

Learn how to install or update PHPUnit 13.3 in the documentation.

Keep up to date with PHPUnit:

v13.2.6: PHPUnit 13.2.6

Compare Source

Fixed
  • #​6861: Hook methods run twice when a template method is marked with its corresponding attribute
  • Regression that stopped test methods from being sorted by source code location

Learn how to install or update PHPUnit 13.2 in the documentation.

Keep up to date with PHPUnit:

v13.2.5: PHPUnit 13.2.5

Compare Source

Changed
  • Messages for tests that are skipped because of an unsatisfied RequiresPhp, RequiresPhpunit, or RequiresPhpExtension version requirement now include the version that is actually being used
  • Warning messages about incomplete version requirements as well as version requirements without a version comparison operator, and the error message for invalid version requirements, now include the full version requirement and explain what is expected
Fixed
  • #​6825: Forwarding to previous error handler can result in infinite recursion
  • #​6831: PHPUnit's error handler does not respect @ error suppression and forwards suppressed warnings to previous error handler
  • #​6833: assertArrayHasKey() does not accept ArrayAccess implementations with a specific value type when test code is analysed with PHPStan at level 9
  • #​6854: Deprecation triggered in first-party code is wrongly classified as indirect when the first-party code is called from third-party code
  • Test classes were not sorted relative to each other when tests were ordered by duration

Learn how to install or update PHPUnit 13.2 in the documentation.

Keep up to date with PHPUnit:

v13.2.4: PHPUnit 13.2.4

Compare Source

Fixed
  • #​6817: Issue is reported even when previously registered error handler turns the error into an exception
  • #​6818: Issue is reported when custom error handler checks error_reporting() output dynamically

Learn how to install or update PHPUnit 13.2 in the documentation.

Keep up to date with PHPUnit:

v13.2.3

Compare Source

v13.2.2: PHPUnit 13.2.2

Compare Source

Fixed
  • #​6768: Negative priorities for hook methods are rejected by static analysis
  • #​6778: Deprecation triggered outside of tests cannot be ignored

Learn how to install or update PHPUnit 13.2 in the documentation.

Keep up to date with PHPUnit:

v13.2.1: PHPUnit 13.2.1

Compare Source

Fixed
  • #​6741: Test is not run when --filter matches the name of a data set but not the name of the test method
  • #​6743: Improve error message for invalid version constraint in attribute
  • #​6744: Environment variable attributes reject empty-string values since PHPUnit 13.2.0

Learn how to install or update PHPUnit 13.2 in the documentation.

Keep up to date with PHPUnit:

v13.2.0: PHPUnit 13.2.0

Compare Source

Added
  • #​3387: Specify a list of tests to run
  • #​4201: Handle interrupts and display current test results
  • #​4501: Option to mark test as risky when it does not contribute to code coverage
  • #​5757: Add assertions for ignoring whitespace differences in strings
  • #​5810: Do not dump arrays and objects in failure messages of IsTrue, IsFalse, IsNull, IsFinite, IsInfinite, and IsNan constraints
  • #​5838: Inherit #[RunTestsInSeparateProcesses] from parent test classes
  • #​5922: assertContainsEquals() should use sebastian/comparator for element comparison
  • #​6000: Report PHPT test as risky when --SKIPIF-- does not have standard-output side effect
  • #​6075: Support test execution order sorted by descending duration
  • #​6346: Emit warning when conflicting CLI options are used
  • #​6534: Make $_dataName available to #[TestDoxFormatter] callbacks
  • #​6559: Improved API for exception message expectations
  • #​6565: Optional $skipWhenEmpty parameter for #[DataProvider] and #[DataProviderExternal]
  • #​6566: Allow --stop-on-defect, --stop-on-error, etc. to accept an optional threshold
  • #​6567: Make diff context lines configurable
  • #​6574: Improve willReturnMap() with constraint support and strict matching
  • #​6575: --list-test-ids CLI option and enhance --filter CLI option to support test ID syntax
  • #​6577: --run-test-id <test-id> CLI option that accepts a single test ID for exact matching
  • #​6579: Properly handle issues triggered outside of tests
  • #​6597: Compact output (activated through --compact CLI option and PHPUNIT_COMPACT_OUTPUT=1 environment variable)
  • #​6598: --disable-coverage-targeting CLI option
  • #​6602: Separate configuration for branch coverage from path coverage
  • #​6606: Support for partially ordered parameter sets in mock object expectations
  • #​6611: Add CPU time to telemetry
  • #​6681: Comment-aware variants of XML comparison assertions
  • The executionOrder attribute in the XML configuration file now accepts defects combined with any main order, as well as three-way combinations of depends/no-depends, defects, and a main order (for example, depends,defects,duration-ascending)
  • --validate-configuration CLI option to validate an XML configuration file for PHPUnit
  • Report TestDox information in Open Test Reporting XML
  • Report per-test and per-test-suite resource usage (time, memory usage, peak memory usage) in Open Test Reporting XML
  • Report number of assertions performed for each test in Open Test Reporting XML
  • Report structured comparison failure details (expected, actual, diff) in Open Test Reporting XML
  • Report random order seed in Open Test Reporting XML when test execution order is randomised
Changed
  • #​5873: Chain previously registered error handler instead of silently disabling PHPUnit's error handling
  • #​6535: Use sebastian/file-filter in SourceFilter::includes() for issue trigger identification
  • #​6581: Allow #[IgnoreDeprecations] to be repeated
  • #​6609: Skip data providers whose method cannot match --filter
  • #​6685: Generate failure messages for inverse assertions by authoring negations, not by rewriting strings
  • Only errors and failures are now considered for "defect first" test reordering (tests that triggered deprecations, notices, or warnings as well as incomplete, risky, and skipped tests were previous also considered)
  • A warning is now emitted when closures are compared for equality using the IsEqual, IsEqualCanonicalizing, IsEqualIgnoringCase, IsEqualWithDelta, and TraversableContainsEqual constraints or the assertEquals(), assertEqualsCanonicalizing(), assertEqualsIgnoringCase(), assertEqualsWithDelta(), and assertContainsEquals() assertions
Deprecated
  • #​6075: --order-by duration CLI option, use --order-by duration-ascending instead
  • #​6075: --order-by size CLI option, use --order-by size-ascending instead
  • #​6075: executionOrder="duration" XML configuration attribute value, use executionOrder="duration-ascending" instead
  • #​6075: executionOrder="size" XML configuration attribute value, use executionOrder="size-ascending" instead
  • #​6560: Soft-deprecate expectExceptionMessage(), use expectExceptionMessageIsOrContains() instead
Fixed
  • #​5845: Error handlers registered before PHPUnit (e.g. via auto_prepend_file) cause false "risky test" warnings
  • #​5851: Output buffer manipulation in tests causes incorrect capture, hangs, and silent failures
  • #​6582: TestSuiteSorter::cmpSize() does not handle TestSuite objects for TestCase classes

Learn how to install or update PHPUnit 13.2 in the documentation.

Keep up to date with PHPUnit:

v13.1.14: PHPUnit 13.1.14

Compare Source

Fixed
  • #​6683: assertNotEquals() failure message says "is equal to" instead of "is not equal to" when comparing arrays or objects
  • #​6700: expectOutputString() and expectOutputRegex() silently replace themselves and each other

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.13: PHPUnit 13.1.13

Compare Source

Fixed
  • #​6681: XML assertions such as assertXmlStringEqualsXmlString() regressed into treating comments as significant

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.12: PHPUnit 13.1.12

Compare Source

Fixed
  • #​6673: Empty PHP settings from the parent process override per-test -d settings forwarded to child processes (breaks PCOV coverage)

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.11: PHPUnit 13.1.11

Compare Source

Fixed
  • PHP setting values containing = need to be quoted before forwarding via -d

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.10: PHPUnit 13.1.10

Compare Source

Changed
  • Pass configuration options introduced in sebastian/diff 8.3.0

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.9: PHPUnit 13.1.9

Compare Source

Changed
  • A Test or Tests prefix is no longer stripped from class names when they are processed for TestDox output
Fixed
  • #​6605: Data set names and provider values containing Unicode bidirectional control characters distort terminal output
  • #​6610: Per-testsuite bootstrap script not loaded in process isolation
  • TestDox output collapsed separate test classes into a single group when their prettified class names matched

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.8: PHPUnit 13.1.8

Compare Source

Fixed
  • #​6595: Crash when before-class or after-class method fails with assertion failure
  • #​6599: TeamCity logger does not wrap failures in before-test methods with testStarted and testFinished
  • #​6601: Anonymous classes are not rejected with a clear error when creating a test double
  • #​6603: assertArrays*IgnoringOrder() fails on mixed scalar types and on reordered nested associative arrays
  • MockBuilder::setMockClassName() and TestStubBuilder::setStubClassName() now reject values that are not valid unqualified PHP class identifiers, throwing the new InvalidClassNameException
  • The regular expression used by Generator::ensureValidMethods() to validate method names passed to MockBuilder::onlyMethods() and addMethods() was not anchored, so any string containing a valid identifier substring (including strings with parentheses, braces, comments, or newlines) was accepted

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.7: PHPUnit 13.1.7

Compare Source

Changed
  • Pass LIBXML_NONET when parsing/validating XML configuration files to make explicit that no network I/O is performed
  • Verify the result file written by an isolated child process with a random nonce before deserializing it

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.6: PHPUnit 13.1.6

Compare Source

Fixed
  • #​6590: Silent failure when configuration file is invalid
  • #​6592: INI metacharacters ; and " are not preserved when forwarding settings to child processes

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.5: PHPUnit 13.1.5

Compare Source

Fixed
  • #​5860: PHP CLI -d settings are not forwarded to child processes for process isolation
  • #​6451: Incomplete version in RequiresPhp (e.g. <=8.5) is compared against full PHP version, causing unexpected skips
  • #​6589: dataSetAsStringWithData() raises "float is not representable as int" warning for large floats in data sets

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.4: PHPUnit 13.1.4

Compare Source

Fixed
  • #​5993: DefaultJobRunner deadlocks on child processes that write large amounts of stderr output
  • #​6465: SAPI-populated $_SERVER entries leak from parent into child process
  • #​6587: failOnEmptyTestSuite="false" in phpunit.xml is ignored when --group/--filter/--testsuite matches no tests
  • #​6588: Order of issue baseline entries is not canonicalized

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.3: PHPUnit 13.1.3

Compare Source

Fixed
  • Regression in XML configuration migration introduced in PHPUnit 12.5.8

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.2: PHPUnit 13.1.2

Compare Source

Fixed
  • #​4571: No warning when --random-order-seed is used when test execution order is not random
  • #​4975: --filter does not work when filter string starts with #
  • #​5354: JUnit XML logger does not handle TestSuiteSkipped event
  • #​6276: Exit with non-zero exit code when explicit test selection (--filter, --group, --testsuite) yields no tests
  • #​6583: Failing output expectation skips tearDown() and handler restoration, causing subsequent tests to be marked as risky

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.1: PHPUnit 13.1.1

Compare Source

Changed
  • #​3676: Include class/interface name in mock object expectation failure messages
  • #​4793: Exit with non-zero exit code when exit was called from some test
Fixed
  • #​5881: colors="true" in XML configuration file does not unconditionally enable colored output
  • #​6019: --migrate-configuration does not update schema location when XML content already validates against current schema
  • #​6372: Assertion failure inside willReturnCallback() is silently swallowed when code under test catches exceptions
  • #​6464: Process isolation template unconditionally calls set_include_path()
  • #​6571: Static analysis errors for TestDoubleBuilder method chaining

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.0: PHPUnit 13.1.0

Compare Source

Added
  • #​6501: Include unexpected output in Open Test Reporting (OTR) XML logfile
  • #​6517: includeInCodeCoverage attribute for <directory> and <file> children of <source>
  • #​6523: Include #[Group] information in Open Test Reporting (OTR) XML logfile
  • #​6524: Report issues in Open Test Reporting (OTR) XML logfile
  • #​6526: Introduce #[DataProviderClosure] for static closures
  • #​6530: Support for custom issue trigger resolvers that can be configured using <issueTriggerResolvers> in the XML configuration file
  • #​6547: Support for %r...%r in EXPECTF section
  • Support for configuring HTML code coverage report options (colors, thresholds, custom CSS) in XML configuration file without requiring an outputDirectory attribute, allowing the output directory to be specified later with the --coverage-html CLI option
  • Support for configuring dark mode colors, progress bar colors, and breadcrumb colors for HTML code coverage reports in the XML configuration file
Changed
  • #​6557: Improve failure description for StringMatchesFormatDescription constraint which is used by assertFileMatchesFormat(), assertFileMatchesFormatFile(), assertStringMatchesFormat(), assertStringMatchesFormatFile(), and EXPECTF sections of PHPT test files
  • The HTML code coverage report now uses a more colorblind-friendly blue/amber/orange palette by default
  • Extracted PHPUnit\Runner\Extension\Facade from a concrete class to an interface and introduced an internal ExtensionFacade implementation, so that extensions only depend on the Facade interface while PHPUnit internally uses the ExtensionFacade class that also provides query methods
Deprecated
  • #​6515: Deprecate the --log-events-verbose-text <file> CLI option
  • #​6537: Soft-deprecate id() and after() for mock object expectations
Fixed
  • #​6025: FILE_EXTERNAL breaks __DIR__
  • #​6351: No warning when the same test runner extension is configured more than once
  • #​6433: Logic in TestSuiteLoader is brittle and causes "Class FooTest not found" even for valid tests in valid filenames
  • #​6463: Process Isolation fails on non-serializable globals and quietly ignore closures

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.0.6: PHPUnit 13.0.6

Compare Source

Changed
  • #​4440: Improve error when configured code coverage file list is empty
  • #​6549: Allow to stub both hooks of non-virtual properties
Fixed
  • #​6529: Git "detached HEAD state" in Open Test Reporting (OTR) XML logger not handled properly
  • #​6545: Stubbing a class with set property hook leaves property uninitialized by default
  • The RegularExpression and StringMatchesFormatDescription did not handle preg_match() errors such as Compilation failed: regular expression is too large

Learn how to install or update PHPUnit 13.0 in the documentation.

Keep up to date with PHPUnit:

v13.0.5: PHPUnit 13.0.5

Compare Source

Fixed
  • #​6521: Performance regression in PHPUnit 11.5.54, PHPUnit 12.5.13, and PHPUnit 13.0.4

Learn how to install or update PHPUnit 13.0 in the documentation.

Keep up to date with PHPUnit:

v13.0.4: PHPUnit 13.0.4

Compare Source

Fixed
  • #​6489: Classification of self/direct/indirect deprecation triggers is not aligned with Symfony's bridge for PHPUnit

Learn how to install or update PHPUnit 13.0 in the documentation.

Keep up to date with PHPUnit:

v13.0.3: PHPUnit 13.0.3

Compare Source

Fixed
  • #​6511: TestDox variables out of order with named arguments
  • #​6514: <ini /> can silently fail

Learn how to install or update PHPUnit 13.0 in the documentation.

Keep up to date with PHPUnit:

v13.0.2: PHPUnit 13.0.2

Compare Source

Deprecated
  • #​6505: Calling atLeast() with an argument that is not positive
  • #​6507: Support for using with*() without expects()
Fixed
  • #​6503: Temporary file used by SourceMapper may be deleted prematurely when multiple PHPUnit processes run in parallel
  • #​6509: "No expectat

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/packagist-phpunit-phpunit-vulnerability branch from 2647a61 to 18825a8 Compare February 3, 2026 07:08
@renovate renovate Bot changed the title Update dependency phpunit/phpunit to v8 [SECURITY] Update dependency phpunit/phpunit to v12 [SECURITY] Feb 3, 2026
@renovate
renovate Bot force-pushed the renovate/packagist-phpunit-phpunit-vulnerability branch from 18825a8 to ea32f55 Compare February 4, 2026 08:12
@renovate renovate Bot changed the title Update dependency phpunit/phpunit to v12 [SECURITY] Update dependency phpunit/phpunit to v8 [SECURITY] Feb 4, 2026
@renovate
renovate Bot force-pushed the renovate/packagist-phpunit-phpunit-vulnerability branch from ea32f55 to 12f784f Compare February 13, 2026 20:12
@renovate renovate Bot changed the title Update dependency phpunit/phpunit to v8 [SECURITY] Update dependency phpunit/phpunit to v13 [SECURITY] Feb 13, 2026
@renovate
renovate Bot force-pushed the renovate/packagist-phpunit-phpunit-vulnerability branch from 12f784f to 401d9bb Compare February 14, 2026 11:14
@renovate renovate Bot changed the title Update dependency phpunit/phpunit to v13 [SECURITY] Update dependency phpunit/phpunit to v8 [SECURITY] Feb 14, 2026
@renovate
renovate Bot force-pushed the renovate/packagist-phpunit-phpunit-vulnerability branch from 401d9bb to 548f684 Compare February 16, 2026 19:49
@renovate renovate Bot changed the title Update dependency phpunit/phpunit to v8 [SECURITY] Update dependency phpunit/phpunit to v13 [SECURITY] Feb 16, 2026
@renovate
renovate Bot force-pushed the renovate/packagist-phpunit-phpunit-vulnerability branch from 548f684 to f4792b9 Compare February 18, 2026 23:41
@renovate renovate Bot changed the title Update dependency phpunit/phpunit to v13 [SECURITY] Update dependency phpunit/phpunit to v8 [SECURITY] Feb 18, 2026
@renovate
renovate Bot force-pushed the renovate/packagist-phpunit-phpunit-vulnerability branch from f4792b9 to c8f8b53 Compare March 14, 2026 16:52
@renovate renovate Bot changed the title Update dependency phpunit/phpunit to v8 [SECURITY] Update dependency phpunit/phpunit to v13 [SECURITY] Mar 14, 2026
@renovate
renovate Bot force-pushed the renovate/packagist-phpunit-phpunit-vulnerability branch from c8f8b53 to 7481c95 Compare May 2, 2026 15:57
@renovate renovate Bot changed the title Update dependency phpunit/phpunit to v13 [SECURITY] Update dependency phpunit/phpunit to v8 [SECURITY] May 2, 2026
@renovate
renovate Bot force-pushed the renovate/packagist-phpunit-phpunit-vulnerability branch from 7481c95 to 3735364 Compare May 13, 2026 23:13
@renovate renovate Bot changed the title Update dependency phpunit/phpunit to v8 [SECURITY] Update dependency phpunit/phpunit to v13 [SECURITY] May 13, 2026
@renovate
renovate Bot force-pushed the renovate/packagist-phpunit-phpunit-vulnerability branch from 3735364 to afc5b6b Compare May 16, 2026 06:53
@renovate renovate Bot changed the title Update dependency phpunit/phpunit to v13 [SECURITY] Update dependency phpunit/phpunit to v8 [SECURITY] May 16, 2026
@renovate
renovate Bot force-pushed the renovate/packagist-phpunit-phpunit-vulnerability branch from afc5b6b to 0e4ba8f Compare May 22, 2026 00:04
@renovate renovate Bot changed the title Update dependency phpunit/phpunit to v8 [SECURITY] Update dependency phpunit/phpunit to v13 [SECURITY] May 22, 2026
@renovate
renovate Bot force-pushed the renovate/packagist-phpunit-phpunit-vulnerability branch from 0e4ba8f to 18fb5c0 Compare May 24, 2026 07:27
@renovate renovate Bot changed the title Update dependency phpunit/phpunit to v13 [SECURITY] Update dependency phpunit/phpunit to v8 [SECURITY] May 24, 2026
@renovate
renovate Bot force-pushed the renovate/packagist-phpunit-phpunit-vulnerability branch from 18fb5c0 to d53dc3f Compare June 4, 2026 03:46
@renovate renovate Bot changed the title Update dependency phpunit/phpunit to v8 [SECURITY] Update dependency phpunit/phpunit to v13 [SECURITY] Jun 4, 2026
@renovate
renovate Bot force-pushed the renovate/packagist-phpunit-phpunit-vulnerability branch from d53dc3f to a957170 Compare June 6, 2026 15:11
@renovate renovate Bot changed the title Update dependency phpunit/phpunit to v13 [SECURITY] Update dependency phpunit/phpunit to v8 [SECURITY] Jun 6, 2026
@renovate
renovate Bot force-pushed the renovate/packagist-phpunit-phpunit-vulnerability branch from a957170 to 239c981 Compare July 15, 2026 04:04
@renovate renovate Bot changed the title Update dependency phpunit/phpunit to v8 [SECURITY] Update dependency phpunit/phpunit to v13 [SECURITY] Jul 15, 2026
@renovate
renovate Bot force-pushed the renovate/packagist-phpunit-phpunit-vulnerability branch from 239c981 to 183a38d Compare July 18, 2026 11:35
@renovate renovate Bot changed the title Update dependency phpunit/phpunit to v13 [SECURITY] Update dependency phpunit/phpunit to v8 [SECURITY] Jul 18, 2026
@renovate
renovate Bot force-pushed the renovate/packagist-phpunit-phpunit-vulnerability branch from 183a38d to 560ed3a Compare July 24, 2026 07:45
@renovate renovate Bot changed the title Update dependency phpunit/phpunit to v8 [SECURITY] Update dependency phpunit/phpunit to v13 [SECURITY] Jul 24, 2026
@renovate
renovate Bot force-pushed the renovate/packagist-phpunit-phpunit-vulnerability branch from 560ed3a to 1635e87 Compare August 1, 2026 13:03
@renovate renovate Bot changed the title Update dependency phpunit/phpunit to v13 [SECURITY] Update dependency phpunit/phpunit to v8 [SECURITY] Aug 1, 2026
@renovate
renovate Bot force-pushed the renovate/packagist-phpunit-phpunit-vulnerability branch from 1635e87 to 3cb0ef5 Compare August 7, 2026 08:10
@renovate renovate Bot changed the title Update dependency phpunit/phpunit to v8 [SECURITY] Update dependency phpunit/phpunit to v13 [SECURITY] Aug 7, 2026
@renovate
renovate Bot force-pushed the renovate/packagist-phpunit-phpunit-vulnerability branch from 3cb0ef5 to 3000a4d Compare August 8, 2026 15:34
@renovate renovate Bot changed the title Update dependency phpunit/phpunit to v13 [SECURITY] Update dependency phpunit/phpunit to v8 [SECURITY] Aug 8, 2026
@renovate
renovate Bot force-pushed the renovate/packagist-phpunit-phpunit-vulnerability branch from 3000a4d to fd6d5d0 Compare August 15, 2026 11:36
@renovate renovate Bot changed the title Update dependency phpunit/phpunit to v8 [SECURITY] Update dependency phpunit/phpunit to v13 [SECURITY] Aug 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

0 participants