Repository navigation
chore(deps): update all dependencies to latest - #55
Merged
Merged
Conversation
Full `composer update`: 1 install, 62 updates, 1 removal. Lock-only — all three direct dev requires (laravel/pint ^1.29, orchestra/testbench ^11.0, phpunit/phpunit ^13.0) already admit the new versions, so composer.json is untouched. Five major bumps landed, all transitive: guzzlehttp/guzzle 7.15.3 => 8.1.0 guzzlehttp/promises 2.5.2 => 3.0.2 guzzlehttp/psr7 2.13.0 => 3.1.0 guzzlehttp/uri-template 1.0.8 => 2.0.1 hamcrest/hamcrest-php 2.1.1 => 3.0.0 The Guzzle stack moved because laravel/framework v13.17.0 pinned guzzlehttp/guzzle to ^7.8.2, while v13.30.1 relaxes it to "^7.8.2 || ^8.0". This matters here: src/PayPalApiClient.php drives every call through Illuminate's Http facade, which sits on Guzzle. ralouphie/getallheaders is dropped and symfony/polyfill-php82 added, both consequences of guzzlehttp/psr7 3.x. brick/math stays at 0.18.0 despite 0.20.0 being available: ramsey/uuid caps it at <=0.18. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Full
composer updateon top of #54. 1 install, 62 updates, 1 removal.composer.lockonly — all three direct dev requires (laravel/pint ^1.29,orchestra/testbench ^11.0,phpunit/phpunit ^13.0) already admit the new versions, socomposer.jsonis untouched.composer outdatedreported these three direct deps as patch/minor only:But the real update brought five transitive majors:
Same mechanism as mercadopago — the Laravel bump relaxed the Guzzle constraint:
The one difference from mercadopago is detectability, not exposure: there the majors surfaced only when the update actually ran, whereas here
composer outdated(unfiltered) already pre-flagged them with~. They're still invisible in--direct, which is the part worth knowing about.Why it matters:
src/PayPalApiClient.phproutes every call throughIlluminate\Support\Facades\Http, which sits on Guzzle. This isn't an inert transitive bump like the commonmark one in #54 — it's under the library's entire API surface. That exposure is not specific to this repo:MercadoPagoApiClient.phpuses the same facade over the same Guzzle, so the risk profile of the Guzzle major was identical in both, and in both the real gate was CI running the suite with credentials against the live API.Two knock-ons from
guzzlehttp/psr73.x:ralouphie/getallheadersremoved,symfony/polyfill-php82added.One flagged major did not land:
brick/mathstays at 0.18.0 (0.20.0 available) becauseramsey/uuid 4.9.3caps it at>=0.8.16 <=0.18.laravel/frameworkitself went v13.17.0 → v13.30.1 (minor).Verification
composer audit→ No security vulnerability advisories found.composer lint→{"tool":"pint","result":"passed"}composer test→Tests: 9, Assertions: 4, Errors: 4, Skipped: 1— identical to the pre-update baseline, same pre-existing$apiClientKey ... null givencredential errors.CI is the real gate on this one. The 4 tests that error locally are precisely the ones that make HTTP calls, so the local run cannot exercise Guzzle 8 at all.
.github/workflows/php.ymlhasPAYPAL_API_CLIENT_ID/PAYPAL_API_CLIENT_SECRET; on #54 CI producedOK (9 tests, 11 assertions). Please confirm the check here reports the same full-suite result before merging — that's what actually validates the Guzzle major.