Skip to content

chore(deps): update all dependencies to latest - #55

Merged
marianogoldman merged 1 commit into
mainfrom
chore/update-dependencies
Sep 2, 2026
Merged

marianogoldman merged 1 commit into
mainfrom
chore/update-dependencies

Conversation

@marianogoldman

@marianogoldman marianogoldman commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

What

Full composer update on top of #54. 1 install, 62 updates, 1 removal.

composer.lock only — all three direct dev requires (laravel/pint ^1.29, orchestra/testbench ^11.0, phpunit/phpunit ^13.0) already admit the new versions, so composer.json is untouched.

⚠️ Majors — read this bit

composer outdated reported these three direct deps as patch/minor only:

Package
laravel/pint 1.29.3 1.30.5
orchestra/testbench 11.1.0 11.2.0
phpunit/phpunit 13.2.1 13.3.2

But the real update brought five transitive majors:

Package From To
guzzlehttp/guzzle 7.15.3 8.1.0
guzzlehttp/promises 2.5.2 3.0.2
guzzlehttp/psr7 2.13.0 3.1.0
guzzlehttp/uri-template 1.0.8 2.0.1
hamcrest/hamcrest-php 2.1.1 3.0.0

Same mechanism as mercadopago — the Laravel bump relaxed the Guzzle constraint:

laravel/framework v13.17.0 requires guzzle: ^7.8.2
laravel/framework v13.30.1 requires guzzle: ^7.8.2 || ^8.0

The one difference from mercadopago is detectability, not exposure: there the majors surfaced only when the update actually ran, whereas here composer outdated (unfiltered) already pre-flagged them with ~. They're still invisible in --direct, which is the part worth knowing about.

Why it matters: src/PayPalApiClient.php routes every call through Illuminate\Support\Facades\Http, which sits on Guzzle. This isn't an inert transitive bump like the commonmark one in #54 — it's under the library's entire API surface. That exposure is not specific to this repo: MercadoPagoApiClient.php uses the same facade over the same Guzzle, so the risk profile of the Guzzle major was identical in both, and in both the real gate was CI running the suite with credentials against the live API.

Two knock-ons from guzzlehttp/psr7 3.x: ralouphie/getallheaders removed, symfony/polyfill-php82 added.

One flagged major did not land: brick/math stays at 0.18.0 (0.20.0 available) because ramsey/uuid 4.9.3 caps it at >=0.8.16 <=0.18.

laravel/framework itself went v13.17.0 → v13.30.1 (minor).

Verification

  • composer audit → No security vulnerability advisories found.
  • composer lint → {"tool":"pint","result":"passed"}
  • composer test → Tests: 9, Assertions: 4, Errors: 4, Skipped: 1 — identical to the pre-update baseline, same pre-existing $apiClientKey ... null given credential errors.

CI is the real gate on this one. The 4 tests that error locally are precisely the ones that make HTTP calls, so the local run cannot exercise Guzzle 8 at all. .github/workflows/php.yml has PAYPAL_API_CLIENT_ID / PAYPAL_API_CLIENT_SECRET; on #54 CI produced OK (9 tests, 11 assertions). Please confirm the check here reports the same full-suite result before merging — that's what actually validates the Guzzle major.

Full `composer update`: 1 install, 62 updates, 1 removal. Lock-only —
all three direct dev requires (laravel/pint ^1.29, orchestra/testbench
^11.0, phpunit/phpunit ^13.0) already admit the new versions, so
composer.json is untouched.

Five major bumps landed, all transitive:

  guzzlehttp/guzzle         7.15.3 => 8.1.0
  guzzlehttp/promises       2.5.2  => 3.0.2
  guzzlehttp/psr7           2.13.0 => 3.1.0
  guzzlehttp/uri-template   1.0.8  => 2.0.1
  hamcrest/hamcrest-php     2.1.1  => 3.0.0

The Guzzle stack moved because laravel/framework v13.17.0 pinned
guzzlehttp/guzzle to ^7.8.2, while v13.30.1 relaxes it to
"^7.8.2 || ^8.0". This matters here: src/PayPalApiClient.php drives
every call through Illuminate's Http facade, which sits on Guzzle.

ralouphie/getallheaders is dropped and symfony/polyfill-php82 added,
both consequences of guzzlehttp/psr7 3.x.

brick/math stays at 0.18.0 despite 0.20.0 being available: ramsey/uuid
caps it at <=0.18.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@marianogoldman
marianogoldman merged commit 448353a into main Sep 2, 2026
1 check passed
@marianogoldman
marianogoldman deleted the chore/update-dependencies branch September 2, 2026 22:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant