chore(deps): bump the composer group with 15 updates - #672
Merged
github-actions[bot] merged 1 commit intoAug 13, 2026
Conversation
Bumps the composer group with 15 updates: | Package | From | To | | --- | --- | --- | | [doctrine/orm](https://github.com/doctrine/orm) | `3.6.7` | `3.6.8` | | [sentry/sentry-symfony](https://github.com/getsentry/sentry-symfony) | `5.11.0` | `5.12.0` | | [symfony/console](https://github.com/symfony/console) | `8.1.2` | `8.1.4` | | [symfony/framework-bundle](https://github.com/symfony/framework-bundle) | `8.1.2` | `8.1.4` | | [symfony/object-mapper](https://github.com/symfony/object-mapper) | `8.1.2` | `8.1.4` | | [symfony/property-access](https://github.com/symfony/property-access) | `8.1.0` | `8.1.4` | | [symfony/property-info](https://github.com/symfony/property-info) | `8.1.2` | `8.1.4` | | [symfony/rate-limiter](https://github.com/symfony/rate-limiter) | `8.1.1` | `8.1.4` | | [symfony/serializer](https://github.com/symfony/serializer) | `8.1.3` | `8.1.4` | | [symfony/translation](https://github.com/symfony/translation) | `8.1.1` | `8.1.4` | | [symfony/validator](https://github.com/symfony/validator) | `8.1.2` | `8.1.4` | | [phpstan/phpstan](https://github.com/phpstan/phpstan-phar-composer-source) | `2.2.7` | `2.2.8` | | [phpunit/phpunit](https://github.com/sebastianbergmann/phpunit) | `13.2.6` | `13.3.0` | | [symfony/phpunit-bridge](https://github.com/symfony/phpunit-bridge) | `8.1.2` | `8.1.4` | | [symfony/web-profiler-bundle](https://github.com/symfony/web-profiler-bundle) | `8.1.2` | `8.1.4` | Updates `doctrine/orm` from 3.6.7 to 3.6.8 - [Release notes](https://github.com/doctrine/orm/releases) - [Commits](doctrine/orm@3.6.7...3.6.8) Updates `sentry/sentry-symfony` from 5.11.0 to 5.12.0 - [Release notes](https://github.com/getsentry/sentry-symfony/releases) - [Changelog](https://github.com/getsentry/sentry-symfony/blob/master/CHANGELOG.md) - [Commits](getsentry/sentry-symfony@5.11.0...5.12.0) Updates `symfony/console` from 8.1.2 to 8.1.4 - [Release notes](https://github.com/symfony/console/releases) - [Changelog](https://github.com/symfony/console/blob/8.2/CHANGELOG.md) - [Commits](symfony/console@v8.1.2...v8.1.4) Updates `symfony/framework-bundle` from 8.1.2 to 8.1.4 - [Release notes](https://github.com/symfony/framework-bundle/releases) - [Changelog](https://github.com/symfony/framework-bundle/blob/8.2/CHANGELOG.md) - [Commits](symfony/framework-bundle@v8.1.2...v8.1.4) Updates `symfony/object-mapper` from 8.1.2 to 8.1.4 - [Release notes](https://github.com/symfony/object-mapper/releases) - [Changelog](https://github.com/symfony/object-mapper/blob/8.2/CHANGELOG.md) - [Commits](symfony/object-mapper@v8.1.2...v8.1.4) Updates `symfony/property-access` from 8.1.0 to 8.1.4 - [Release notes](https://github.com/symfony/property-access/releases) - [Changelog](https://github.com/symfony/property-access/blob/8.2/CHANGELOG.md) - [Commits](symfony/property-access@v8.1.0...v8.1.4) Updates `symfony/property-info` from 8.1.2 to 8.1.4 - [Release notes](https://github.com/symfony/property-info/releases) - [Changelog](https://github.com/symfony/property-info/blob/8.2/CHANGELOG.md) - [Commits](symfony/property-info@v8.1.2...v8.1.4) Updates `symfony/rate-limiter` from 8.1.1 to 8.1.4 - [Release notes](https://github.com/symfony/rate-limiter/releases) - [Changelog](https://github.com/symfony/rate-limiter/blob/8.2/CHANGELOG.md) - [Commits](symfony/rate-limiter@v8.1.1...v8.1.4) Updates `symfony/serializer` from 8.1.3 to 8.1.4 - [Release notes](https://github.com/symfony/serializer/releases) - [Changelog](https://github.com/symfony/serializer/blob/8.2/CHANGELOG.md) - [Commits](symfony/serializer@v8.1.3...v8.1.4) Updates `symfony/translation` from 8.1.1 to 8.1.4 - [Release notes](https://github.com/symfony/translation/releases) - [Changelog](https://github.com/symfony/translation/blob/8.2/CHANGELOG.md) - [Commits](symfony/translation@v8.1.1...v8.1.4) Updates `symfony/validator` from 8.1.2 to 8.1.4 - [Release notes](https://github.com/symfony/validator/releases) - [Changelog](https://github.com/symfony/validator/blob/8.2/CHANGELOG.md) - [Commits](symfony/validator@v8.1.2...v8.1.4) Updates `phpstan/phpstan` from 2.2.7 to 2.2.8 - [Commits](https://github.com/phpstan/phpstan-phar-composer-source/commits) Updates `phpunit/phpunit` from 13.2.6 to 13.3.0 - [Release notes](https://github.com/sebastianbergmann/phpunit/releases) - [Changelog](https://github.com/sebastianbergmann/phpunit/blob/13.3.0/ChangeLog-13.3.md) - [Commits](sebastianbergmann/phpunit@13.2.6...13.3.0) Updates `symfony/phpunit-bridge` from 8.1.2 to 8.1.4 - [Release notes](https://github.com/symfony/phpunit-bridge/releases) - [Changelog](https://github.com/symfony/phpunit-bridge/blob/8.2/CHANGELOG.md) - [Commits](symfony/phpunit-bridge@v8.1.2...v8.1.4) Updates `symfony/web-profiler-bundle` from 8.1.2 to 8.1.4 - [Release notes](https://github.com/symfony/web-profiler-bundle/releases) - [Changelog](https://github.com/symfony/web-profiler-bundle/blob/8.2/CHANGELOG.md) - [Commits](symfony/web-profiler-bundle@v8.1.2...v8.1.4) --- updated-dependencies: - dependency-name: doctrine/orm dependency-version: 3.6.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: composer - dependency-name: sentry/sentry-symfony dependency-version: 5.12.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: composer - dependency-name: symfony/console dependency-version: 8.1.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: composer - dependency-name: symfony/framework-bundle dependency-version: 8.1.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: composer - dependency-name: symfony/object-mapper dependency-version: 8.1.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: composer - dependency-name: symfony/property-access dependency-version: 8.1.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: composer - dependency-name: symfony/property-info dependency-version: 8.1.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: composer - dependency-name: symfony/rate-limiter dependency-version: 8.1.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: composer - dependency-name: symfony/serializer dependency-version: 8.1.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: composer - dependency-name: symfony/translation dependency-version: 8.1.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: composer - dependency-name: symfony/validator dependency-version: 8.1.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: composer - dependency-name: phpstan/phpstan dependency-version: 2.2.8 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: composer - dependency-name: phpunit/phpunit dependency-version: 13.3.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: composer - dependency-name: symfony/phpunit-bridge dependency-version: 8.1.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: composer - dependency-name: symfony/web-profiler-bundle dependency-version: 8.1.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: composer ... Signed-off-by: dependabot[bot] <support@github.com>
|
CybotTM
added a commit
that referenced
this pull request
Aug 14, 2026
## Root cause The scheduled run [31767912809](https://github.com/netresearch/timetracker/actions/runs/31767912809) failed `e2e/date-format.spec.ts:22` identically on all three attempts. The failure artifact's `error-context.md` shows the page state at failure time: the worklog row's customer cell already holds **`E2EInline_1786679426486_746937-draft`** — a throwaway customer created by `admin-inline-edit.spec.ts` ("the Edit button opens the modal seeded with the in-progress inline value", which ran 03:50:24–03:50:36 in the same shard; the name's embedded timestamp `1786679426486` = 03:50:26 UTC) — and the open Projekt combobox shows **"Keine Treffer"**. That throwaway customer is created Global and owns no projects; its `finally`-block delete is explicitly best-effort (failures swallowed), and in this run it leaked. `CustomerRepository::getCustomersByUser` orders by name ASC, so `E2EInline_*` sorts before the seeded bookable customer `Freizeit` — and `createWorklogEntry`'s `pickFirstOption(page, row, 'customer')` blindly picks the first option. Result: a customer without projects is booked, the dependent project combobox is empty, and `await expect(option).toBeVisible({ timeout: 8000 })` fails. The leaked row persists in db-e2e for the rest of the shard, which is why all three in-run attempts failed identically — and why the next day's fresh stack was green again. ## Not a composer regression The framing "the only diff to the last green run is composer.lock ([PR #672](#672))" turned out to be a red herring: PR #672's own CI ran all four E2E shards green (run [31696793473](https://github.com/netresearch/timetracker/actions/runs/31696793473)), and the **byte-identical failure** (same spec, same locator, same three-attempt pattern, same trailing `page.waitForResponse: Test ended`) already occurred in scheduled run [29629898230](https://github.com/netresearch/timetracker/actions/runs/29629898230) on 2026-07-18 at SHA `8bee8881` — a month before #672 merged. In that run the admin customer test had visibly flaked right before date-format failed. This is a cross-test data-pollution race, present whenever an admin spec's throwaway customer outlives its best-effort cleanup within a shard. ## Change - `e2e/helpers/worklog.ts`: new `SEEDED_BOOKABLE_CUSTOMER` constant (`Freizeit`, the one seeded customer both e2e users can book, per `e2e/AGENTS.md` / `sql/testdata.sql`) and a `pickOptionByText` helper that filters the combobox by name before picking. `createWorklogEntry` now selects the customer by name; project/activity keep first-option picks because they are scoped to that customer and therefore deterministic. - `e2e/worklog-grid-editing.spec.ts`: the three remaining blind customer picks (two `arrowEnter()` guided-flow closures and the focus-retention test at line 236) filter to `SEEDED_BOOKABLE_CUSTOMER` before `ArrowDown` — the focus-retention test provably fails the same way under a leaked customer (verified locally, see below). No app code changed; the timing/waiting logic of the helpers is unchanged. Leaks can still happen (the admin cleanup remains best-effort by design), but they can no longer redirect the worklog specs onto a project-less customer. ## Verification Local e2e stack at `e5533522` (CI-equivalent: `ghcr.io/netresearch/timetracker:e2e` image, compose profile e2e, fresh seed). Injected the pollution the artifact shows (`INSERT INTO customers (name, active, global) VALUES ('E2EInline_9999999999_123456-draft', 1, 1)`), then ran `npx playwright test e2e/date-format.spec.ts:22` on the **unmodified** tree: reproduced the CI failure byte-for-byte (`locator('.combobox-content .combobox-item').first()` → `element(s) not found`, then `page.waitForResponse: Test ended`). With the fix applied and the pollution **still in the database**: `e2e/date-format.spec.ts:22` passed 3/3 single runs, and the full consumer set (`worklog-grid-editing`, `worklog-crud`, `session-expiry`, `date-format` — every spec using `createWorklogEntry`) passed 17/17 with CI-like `--workers=2 --retries=2`. The same polluted-DB run also exposed and confirmed the focus-retention test as a second victim of the same class before its fix. ## Evidence links - Failing scheduled run: https://github.com/netresearch/timetracker/actions/runs/31767912809 - Identical pre-#672 failure (2026-07-18): https://github.com/netresearch/timetracker/actions/runs/29629898230 - Dependency PR whose CI was green on E2E: #672 (run https://github.com/netresearch/timetracker/actions/runs/31696793473) - Last green scheduled run before the failure: https://github.com/netresearch/timetracker/actions/runs/31292785770
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Bumps the composer group with 15 updates:
3.6.73.6.85.11.05.12.08.1.28.1.48.1.28.1.48.1.28.1.48.1.08.1.48.1.28.1.48.1.18.1.48.1.38.1.48.1.18.1.48.1.28.1.42.2.72.2.813.2.613.3.08.1.28.1.48.1.28.1.4Updates
doctrine/ormfrom 3.6.7 to 3.6.8Release notes
Sourced from doctrine/orm's releases.
Commits
a4d13edMerge pull request #12545 from greg0ire/3.6.x0254bc7Merge remote-tracking branch 'origin/2.20.x' into 3.6.x6544249Merge pull request #12491 from demiankatz/fix-issue-11418d9923c2Merge pull request #12516 from ruudk/fix-lock-mode8c15dcdRename variable as per review.2bae808Merge pull request #12534 from greg0ire/mocks-stubs1cebc45Use stubs when appropriate0314881Merge pull request #12532 from greg0ire/towards-phpunit-126e78e5dRemove deprecated attribute4656213Address deprecation about argument count mismatchUpdates
sentry/sentry-symfonyfrom 5.11.0 to 5.12.0Release notes
Sourced from sentry/sentry-symfony's releases.
Changelog
Sourced from sentry/sentry-symfony's changelog.
Commits
20786d4release: 5.12.0c11ac68Prepare 5.12.0 (#1052)9aa3ec6build(deps): bump getsentry/craft from 2.26.6 to 2.28.0 (#1049)75cae0bAdd support for guzzlehttp/psr7 3.x (Guzzle 8 compatibility) (#1046)c85e8fbci: Remove disabled changelog-preview workflow (#1051)5270407fix: start runtime context before the router and security firewall (#1043)6313bd6Merge branch 'release/5.11.0'Updates
symfony/consolefrom 8.1.2 to 8.1.4Release notes
Sourced from symfony/console's releases.
Commits
68efa2eMerge branch '7.4' into 8.1f4c69c9Merge branch '6.4' into 7.44b3cf1f[Console] Fix column widths when a row spans columnsUpdates
symfony/framework-bundlefrom 8.1.2 to 8.1.4Release notes
Sourced from symfony/framework-bundle's releases.
Commits
780a466Merge branch '7.4' into 8.1fa9c816Merge branch '6.4' into 7.4265ff3c[FrameworkBundle] Fix "cache:clear" failing when the cache dir is rebuilt con...a430728[FrameworkBundle] Fix test failing on narrow terminalsUpdates
symfony/object-mapperfrom 8.1.2 to 8.1.4Release notes
Sourced from symfony/object-mapper's releases.
Commits
3889e64Merge branch '7.4' into 8.138f9183[ObjectMapper] Honor the target property #[Map] for the same-name copy when t...5213708[ObjectMapper] Skip nested mapping when no target fits the destination proper...204cf8c[ObjectMapper] Fix the class-level mapping of another target being appliedUpdates
symfony/property-accessfrom 8.1.0 to 8.1.4Release notes
Sourced from symfony/property-access's releases.
Commits
1a41232Merge branch '7.4' into 8.1c3dce76Merge branch '6.4' into 7.457793e8[PropertyAccess] Fix caching of null read info5c442ccMerge branch '8.0' into 8.1440aa25Merge branch '7.4' into 8.06648c37Merge branch '6.4' into 7.4782a962Drop PR warning and auto-closing on subtree splitsf4fbdeaRevert "[PropertyAccess] Add InvalidTypeException thrown on type mismatch"d15851f[PropertyAccess] Add InvalidTypeException thrown on type mismatch0624342[7.4] Remove usages of named arguments in testsUpdates
symfony/property-infofrom 8.1.2 to 8.1.4Release notes
Sourced from symfony/property-info's releases.
Commits
d3b1ba3Merge branch '7.4' into 8.1c79afdbMerge branch '6.4' into 7.4078d645[PropertyInfo] Do not report a non-public mutator as writable6cac06eRevert "bug #64990 [PropertyInfo] Do not trigger legacy Type deprecation on g...fce3f4d[PropertyInfo] Do not trigger legacy Type deprecation on getType()Updates
symfony/rate-limiterfrom 8.1.1 to 8.1.4Release notes
Sourced from symfony/rate-limiter's releases.
Commits
dee2fc9Merge branch '7.4' into 8.16703d04Merge branch '6.4' into 7.4882bf96[RateLimiter] Fix the overflow test on 32-bit platforms2d09e63Merge branch '7.4' into 8.1c5fc078Merge branch '6.4' into 7.46432742[RateLimiter] Cap the burst size and the duration computed from itUpdates
symfony/serializerfrom 8.1.3 to 8.1.4Release notes
Sourced from symfony/serializer's releases.
Commits
ec3ae77Merge branch '7.4' into 8.13c69b84[Serializer] Align union member order between the legacy and TypeInfo paths8d76b34[Serializer] Fix FILTER_BOOL breaking union type denormalizationUpdates
symfony/translationfrom 8.1.1 to 8.1.4Release notes
Sourced from symfony/translation's releases.
Commits
c0955ebMerge branch '7.4' into 8.1501e0ffMerge branch '6.4' into 7.436b8f86[Translation] Fix fuzzy translations and message context in PO files3fc3fb6[Translation] Do not split ICU messages on pipes in PoFileDumperf0aa2d6[FrameworkBundle][Translation] Fix translator tests colliding on a shared cac...Updates
symfony/validatorfrom 8.1.2 to 8.1.4Release notes
Sourced from symfony/validator's releases.
Commits
1642533Merge branch '7.4' into 8.13aee773Merge branch '6.4' into 7.4c72ea15[Form][Validator] Added missing Slovak translationsdefa059Merge branch '7.4' into 8.1f1bfab9Merge branch '6.4' into 7.4b6df2c3[Form][Validator] Review Lithuanian (lt) translationsfd7cd9eMerge branch '7.4' into 8.15883928Merge branch '6.4' into 7.4a0c07e2minor #65055 [Validator] Review Serbian (sr_Latn) translations (milanqtx)806434aminor #65054 [Validator] Review Serbian (sr_Cyrl) translations (milanqtx)Updates
phpstan/phpstanfrom 2.2.7 to 2.2.8Commits
Updates
phpunit/phpunitfrom 13.2.6 to 13.3.0Release notes
Sourced from phpunit/phpunit's releases.
... (truncated)
Changelog
Sourced from phpunit/phpunit's changelog.
... (truncated)
Commits
346fcbaPrepare release77af2e2Update dependencies828d62cRestore PCRE backtrack limit so that it does not affect PHPUnit's own regular...f121d56Update dependencies17ac9f6Only run test that requires PHP 8.5 syntax on PHP 8.551ece9dDisable PCRE JIT compiler so that the backtrack limit is actually exhausted88e68d1Ignore (maybe too) defensive code from coverage that cannot be reachedfdcc32aAdd tests1193213Ignore (maybe too) defensive code from coverage that cannot be reached4d35bebAdd testsUpdates
symfony/phpunit-bridgefrom 8.1.2 to 8.1.4Release notes
Sourced from symfony/phpunit-bridge's releases.
Commits
98adc9cMerge branch '7.4' into 8.149757f7Merge branch '6.4' into 7.4426ba57[PhpUnitBridge] Don't return a non-callable from getPhpUnitErrorHandler()Updates
symfony/web-profiler-bundlefrom 8.1.2 to 8.1.4Release notes
Sourced from symfony/web-profiler-bundle's releases.
Commits
6c45bb4Merge branch '7.4' into 8.187b90c1[WebProfilerBundle] Avoid a flash of unstyled content in the debug toolbar99f196cMerge branch '7.4' into 8.125dfae8Merge branch '6.4' into 7.4028277a[TwigBridge][WebProfilerBundle] Fix compatibility with Twig 4b234de9Merge branch '6.4' into 7.4eb91675minor #64816 Allow Twig 4 (xabbuh)96194e8Merge branch '6.4' into 7.4a5ecc06[WebProfilerBundle] Move mailer panel macros to template root for Twig 3.27+8ac247callow Twig 4Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions