Skip to content

chore(deps): update dependency friendsofphp/php-cs-fixer to v3.95.27 (stable35) - #2963

Open
renovate[bot] wants to merge 1 commit into
stable35from
renovate/stable35-friendsofphp-php-cs-fixer-3.x
Open

renovate[bot] wants to merge 1 commit into
stable35from
renovate/stable35-friendsofphp-php-cs-fixer-3.x

Conversation

@renovate

@renovate renovate Bot commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
friendsofphp/php-cs-fixer 3.95.15 → 3.95.27 age confidence

Release Notes

PHP-CS-Fixer/PHP-CS-Fixer (friendsofphp/php-cs-fixer)

v3.95.27

Compare Source

  • fix: refuse a symlinked cache path in FileHandler to avoid arbitrary file overwrite (#​9856)
  • fix: validate value types in Cache::fromJson so a corrupt cache rebuilds instead of crashing (#​9855)
  • fix: SimplifiedIfReturnFixer - fix whitespace before ; as well (#​9857)
  • refactor: more moderate permissions for newly created cache file/directory (#​9852)
  • chore: add TODO to split class with too many responsibilities (#​9853)
  • docs: FullyQualifiedStrictTypesFixer - document attribute handling in example (#​9859)

v3.95.26

Compare Source

  • perf: Use dedicated sequence matcher in simplified_if_return (#​9763)
  • DX: add XDEBUG for PHP 8.5 docker build (#​9841)
  • chore: ConfigInterface - document TODO for v4 (#​9845)
  • chore: drop benchmark.sh in favour of phpbench (#​9849)
  • chore: stalebot - exclude RTM labels (#​9843)
  • deps: bump dev-deps (#​9840)
  • deps: explicitly expect PHPUnit 13.3+ over 13.0.x (#​9842)
  • deps: update dev deps (#​9848)
  • docs: do not promote deprecated path argument usage with --path-mode=override (#​9850)
  • docs: simpler docs for parallel execution, as it's default one nowadays (#​9851)

v3.95.25

Compare Source

  • fix: handle missing terminator after ?? in AssignNullCoalescingToCoalesceEqualFixer (#​9831)
  • fix: IsNullFixer - do not fix is_null() calls using argument unpacking (#​9830)
  • fix: IsNullFixer - handle is_null() calls using named arguments (#​9828)
  • UX: init - use outlined messages (#​9826)
  • deps: bump crate-ci/typos from 1.49.0 to 1.50.1 in /.github/workflows in the all group across 1 directory (#​9824)
  • deps: bump phpstan/phpstan from 2.2.9 to 2.2.12 in /dev-tools in the phpstan group (#​9822)
  • deps: bump shipmonk/dead-code-detector from 1.3.3 to 1.4.0 in /dev-tools in the shipmonk group across 1 directory (#​9823)

v3.95.24

Compare Source

  • fix: ControlStructureBracesFixer - do not read a body starting with a parenthesis as a condition (#​9815)
  • UX: init - add handling of .gitignore (#​9813)
  • UX: init - add sections (#​9819)
  • UX: init - command improvements (#​9807)
  • UX: init - fix typos and improve wording (#​9820)
  • UX: init command - suggest php_unit_test_case_static_method_calls rule (#​9810)
  • chore: Fixer name must not be empty (#​9756)
  • chore: DescribeCommand - replace dynamic method calls with explicit ones (#​9817)
  • chore: PhpdocOrderFixer - fix type of duplicated tags passed to naturalLanguageJoin (#​9818)
  • CI: fix warning - Unexpected input(s) 'extensions' (#​9809)
  • CI: introduce PHPBench (#​9755)
  • refactor: init - move content preparation to helper method (#​9812)

v3.95.23

Compare Source

  • fix: FunctionsAnalyzer - detect return type of a closure with a use clause (#​9806)

v3.95.22

Compare Source

  • fix: StaticLambdaFixer - do not make a lambda static when it is the direct subject of bindTo() or call() (#​9802)
  • chore: Implement PHPStan Preg::replaceCallback() extension (#​9799)
  • chore: Utils - fix stableSort() and sortFixers() template types, remove @phpstan-ignore suppressions (#​9798)
  • deps: bump phpstan/phpstan from 2.2.8 to 2.2.9 (#​9797)

v3.95.21

Compare Source

  • fix: StatementIndentationFixer - do not treat ternary colon as block start (#​9795)
  • perf: Introduce new candidate check for transformers (#​9770)
  • perf: Optimize NameQualifiedTransformer token insertion (#​9759)
  • CI: add BC check (#​9791)
  • deps: upgrade dev-tools (#​9793)

v3.95.20

Compare Source

  • fix: PsrAutoloadingFixer - do not throw when the file cannot be resolved on disk (#​9762)
  • refactor: Transformers - move looping over tokens directly into each transformer individually (#​9782)
  • test: drop mikey179/vfsstream (#​9787)
  • test: NoUnusedImportsFixerTest - add new cases around quoted values (#​9784)

v3.95.19

Compare Source

  • fix: binary_operator_spaces alignment for nested single-line arrays in multiline array (#​9654)
  • fix: ClassDefinitionFixer - keep multiline constructor args when anonymous class has both extends and implements (#​9625)
  • fix: SelfStaticAccessorFixer - do not stop fixing a class after a static return type (#​9774)
  • chore: Fix incorrect URL in CommentsAnalyzer.php docblock (#​9772)
  • chore: Runner - ignore coverage of non-deterministic parallel branches (#​9785)
  • CI: fix using PHP_CS_FIXER_FAST_LINT_TEST_CASES (#​9783)
  • deps: bump phpstan/phpstan from 2.2.7 to 2.2.8 in /dev-tools in the phpstan group (#​9779)
  • deps: bump squizlabs/php_codesniffer from 4.0.1 to 4.0.4 in /dev-tools (#​9768)
  • deps: bump the all group across 1 directory with 2 updates (#​9767)
  • test: introduce TestCaseUtils::createTemporaryDirectory() helper (#​9788)
  • test: ProjectCodeTest - restore the duplicate check in data providers (#​9761)
  • test: AbstractFixerTestCase - use spl_object_id() to fix PHP 8.6 deprecations (#​9786)

v3.95.18

Compare Source

  • CI: attach provenance and SBOM attestations to the released image (#​9751)
  • deps: bump the phpstan group in /dev-tools with 2 updates (#​9748)
  • deps: update dev-tools (#​9754)
  • perf: Limit token search in simplified_if_return (#​9747)

v3.95.17

Compare Source

  • perf: Token::equals() - Avoid building intermediary arrays (#​9739)
  • perf: Tokens::findSequence() - improve looping logic (#​9737)

v3.95.16

Compare Source

  • fix: NoSuperfluousPhpdocTagsFixer with multiple hidden params (#​9736)
  • fix: PowToExponentiationFixer - do not produce two consecutive whitespace tokens (#​9735)
  • chore: do not remove ParaUnit for PHPUnit v13, as they are now compatible (#​9579)
  • CI: introduce perf as new PR type (#​9742)
  • deps: update dev deps (#​9743)
  • test: AbstractIntegrationTestCase - externalized FixerFactory creation (#​9744)

Configuration

📅 Schedule: (in timezone Europe/Berlin)

  • Branch creation
    • "before 5am on saturday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added 4. to release dependencies Pull requests that update a dependency file labels Sep 27, 2026
@renovate
renovate Bot enabled auto-merge September 27, 2026 22:03
@renovate

renovate Bot commented Sep 27, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: vendor-bin/cs-fixer/composer.lock
Loading composer repositories with package information
Updating dependencies
Your requirements could not be resolved to an installable set of packages.

  Problem 1
    - Root composer.json requires friendsofphp/php-cs-fixer 3.95.27 (exact version match: 3.95.27 or 3.95.27.0), found friendsofphp/php-cs-fixer[v3.95.27] but these were not loaded, likely because it conflicts with another require.
  Problem 2
    - nextcloud/coding-standard is locked to version v1.5.0 and an update of this package was not requested.
    - nextcloud/coding-standard v1.5.0 requires php-cs-fixer/shim ^3.17 -> found php-cs-fixer/shim[v3.17.0, ..., v3.95.27] but these were not loaded, likely because it conflicts with another require.


Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate
renovate Bot force-pushed the renovate/stable35-friendsofphp-php-cs-fixer-3.x branch from 7c9b894 to 5496b6e Compare September 30, 2026 23:51

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

4. to release dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants