Skip to content

build(deps): bump symfony/var-exporter from 7.1.2 to 7.4.9#234

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/composer/symfony/var-exporter-7.4.9
Open

build(deps): bump symfony/var-exporter from 7.1.2 to 7.4.9#234
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/composer/symfony/var-exporter-7.4.9

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 4, 2026

Bumps symfony/var-exporter from 7.1.2 to 7.4.9.

Release notes

Sourced from symfony/var-exporter's releases.

v7.4.9

Changelog (symfony/var-exporter@v7.4.8...v7.4.9)

v7.4.8

Changelog (symfony/var-exporter@v7.4.7...v7.4.8)

v7.4.0

Changelog (symfony/var-exporter@v7.4.0-RC3...v7.4.0)

  • no significant changes

v7.4.0-RC1

Changelog (symfony/var-exporter@v7.4.0-BETA2...v7.4.0-RC1)

  • no significant changes

v7.4.0-BETA1

Changelog (symfony/var-exporter@v7.3.4...v7.4.0-BETA1)

v7.3.4

Changelog (symfony/var-exporter@v7.3.3...v7.3.4)

v7.3.3

Changelog (symfony/var-exporter@v7.3.2...v7.3.3)

v7.3.2

Changelog (symfony/var-exporter@v7.3.1...v7.3.2)

v7.3.0

Changelog (symfony/var-exporter@v7.3.0-RC1...v7.3.0)

  • no significant changes

v7.3.0-RC1

Changelog (symfony/var-exporter@v7.3.0-BETA2...v7.3.0-RC1)

... (truncated)

Changelog

Sourced from symfony/var-exporter's changelog.

CHANGELOG

8.1

  • Add DeepCloner to deep-clone PHP values while preserving copy-on-write benefits
  • Deprecate Hydrator and Instantiator classes, use deepclone_hydrate() from the deepclone extension instead

8.0

  • Restrict ProxyHelper::generateLazyProxy() to generating abstraction-based lazy decorators; use native lazy proxies otherwise
  • Remove LazyGhostTrait and LazyProxyTrait, use native lazy objects instead
  • Remove ProxyHelper::generateLazyGhost(), use native lazy objects instead

7.4

  • Add support for exporting named closures

7.3

  • Deprecate using ProxyHelper::generateLazyProxy() when native lazy proxies can be used - the method should be used to generate abstraction-based lazy decorators only
  • Deprecate LazyGhostTrait and LazyProxyTrait, use native lazy objects instead
  • Deprecate ProxyHelper::generateLazyGhost(), use native lazy objects instead

7.2

  • Allow reinitializing lazy objects with a new initializer

6.4

  • Deprecate per-property lazy-initializers

6.2

  • Add support for lazy ghost objects and virtual proxies
  • Add Hydrator::hydrate()
  • Preserve PHP references also when using Hydrator::hydrate() or Instantiator::instantiate()
  • Add support for hydrating from native (array) casts

5.1.0

  • added argument array &$foundClasses to VarExporter::export() to ease with preloading exported values

... (truncated)

Commits
  • 22e03a4 Update XSD references in phpunit.xml.dist files
  • 8c34c50 [Tests] Fix "Incomplete version" PHPUnit warnings
  • c337020 Merge branch '6.4' into 7.4
  • 34f6957 bug #63959 [VarExporter] Don't warn for __sleep()-listed uninitialized declar...
  • 68ee500 [VarExporter] Don't warn for __sleep()-listed uninitialized typed properties
  • 6e5ad60 Merge branch '6.4' into 7.4
  • c353bb0 More CS fixes
  • dc41fcd Merge branch '6.4' into 7.4
  • d9a5543 CS fixes - native_function_invocation & static_lambda
  • 94b60a7 [CS] Back config from 8.1 and apply heredoc_indentation rule
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [symfony/var-exporter](https://github.com/symfony/var-exporter) from 7.1.2 to 7.4.9.
- [Release notes](https://github.com/symfony/var-exporter/releases)
- [Changelog](https://github.com/symfony/var-exporter/blob/8.1/CHANGELOG.md)
- [Commits](symfony/var-exporter@v7.1.2...v7.4.9)

---
updated-dependencies:
- dependency-name: symfony/var-exporter
  dependency-version: 7.4.9
  dependency-type: indirect
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update php code labels May 4, 2026
@codacy-production
Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 complexity

Metric Results
Complexity 0

View in Codacy

AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.

Run reviewer

TIP This summary will be updated as you push new changes.

Copy link
Copy Markdown

@codacy-production codacy-production Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR contains critical anomalies in the composer.lock file that must be addressed before merging. While Codacy reports the PR is 'up to standards', the dependency update includes version v7.4.9 for symfony/var-exporter, which does not exist in official repositories, and a release timestamp set in the year 2026.

These findings suggest the lockfile was not generated via a standard composer update command or was generated against a compromised/forged repository. There are also no functional tests included to verify the new features or bug fixes associated with this bump.

About this PR

  • The composer.lock file contains critical metadata inconsistencies. The timestamp for symfony/var-exporter (2026-04-18) is in the future, and version 7.4.9 is not currently a released version of the Symfony component. This strongly suggests that the lockfile may have been manually tampered with or generated in a compromised environment. Please investigate and regenerate the lockfile from official sources.

Test suggestions

  • Verify existing serialization/hydration logic remains functional with the new var-exporter version
  • Verify named closure exporting (new feature in 7.4.0) works as intended if used
  • Verify that uninitialized typed properties no longer trigger warnings during serialization (fix in 7.4.9)
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Verify existing serialization/hydration logic remains functional with the new var-exporter version
2. Verify named closure exporting (new feature in 7.4.0) works as intended if used
3. Verify that uninitialized typed properties no longer trigger warnings during serialization (fix in 7.4.9)

TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback

Comment thread composer.lock
}
],
"time": "2024-06-28T08:00:31+00:00"
"time": "2026-04-18T13:18:21+00:00"
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 HIGH RISK

The composer.lock file contains invalid metadata: the release timestamp 2026-04-18 for symfony/var-exporter is in the future, and version v7.4.9 does not yet exist. This indicates the lockfile was not generated by a standard Composer process against official sources. Please regenerate the lockfile by running composer update to ensure dependency integrity.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants