Skip to content

chore(deps-dev): update google/recaptcha requirement from ^1.5 to ^2.0 - #48

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot-composer-master-google-recaptcha-tw-2.0
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot-composer-master-google-recaptcha-tw-2.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on google/recaptcha to permit the latest version.

Release notes

Sourced from google/recaptcha's releases.

2.0.0

google/recaptcha — 2.0.0

Major release introducing strict PHP 8.4+ typing, immutable (readonly) response and parameter value objects, simplified transport constructors, and full PHP 8.5 compatibility.

Upgrading from 1.x? If you cannot yet adopt the breaking API changes below, remain on the ^1.5 release line (1.5.2), which preserves full 1.4.2 public API compatibility alongside recent transport security fixes.

Improvements

  • Strict Type Safety: Added declare(strict_types=1) and native scalar parameter, property, and return type declarations across ReCaptcha, Response, RequestParameters, and RequestMethod.
  • Immutable Value Objects (Response & RequestParameters): Converted Response and RequestParameters to readonly classes with promoted constructor properties.
  • Streamlined Transport Constructors: Simplified CurlPost and SocketPost to accept ?string $siteVerifyUrl = null directly without intermediate wrapper objects.
  • Transport Hardening & Proxy Compatibility: Enforced OpenSSL verify_peer / verify_peer_name in Post, added 60-second request timeouts, and enabled HTTP/1.1 response status parsing in SocketPost.

Bug Fixes

  • PHP 8.5 Compatibility: Removed deprecated curl_close() call in CurlPost so no deprecation notices are emitted on PHP 8.5 (#630, #632).
  • Socket Handle Cleanup: Fixed an early-return path in SocketPost::submit() to ensure the open socket is closed if stream_set_timeout() fails.
  • Non-Empty '0' Handling: Fixed ReCaptcha secret and response validation so the string '0' is treated as a non-empty input rather than discarded by empty().

Breaking Changes

  • Minimum PHP Version (>=8.4): Requires PHP 8.4 or newer.
  • RequestMethod::submit() Return Type: Custom implementations of ReCaptcha\RequestMethod must declare the native : string return type: public function submit(RequestParameters $params): string.
  • Strict Scalar Parameter Types: Public methods such as ReCaptcha::verify(string $response, ?string $remoteIp = null): Response require string rather than null for $response (coalesce nullable framework request inputs via $token ?? '').
  • readonly DTOs (Response & RequestParameters): Because PHP forbids non-readonly subclasses of readonly classes, PHPUnit::createMock(Response::class) cannot be used. In unit tests, instantiate new Response(true, ...) directly or mock the RequestMethod interface.
  • Removed RequestMethod\Curl & RequestMethod\Socket Wrappers: The Curl and Socket wrapper classes have been removed; new CurlPost($siteVerifyUrl) and new SocketPost($siteVerifyUrl) now take ?string $siteVerifyUrl = null as their first parameter.

Full Changelog: google/recaptcha@1.5.2...2.0.0

Commits
  • 81700ff Prepare 2.0.0 release with strict types, readonly DTOs, and PHP 8.5 fixes
  • ee4352f Harden transport TLS/timeouts, accept HTTP/1.1 in SocketPost, and bump to 1.5.2
  • 1fb3b1a Merge branch 'pr-634'
  • a373090 Version bump to 1.5.1
  • 9a04f83 ci: pin actions to commit hashes
  • 1a8b966 ci: install the BC check from composer instead of the stale docker image
  • 1b8958c ci: detect backward compatibility breaks automatically
  • cf664d8 fix: restore the 1.4.2 public API
  • 6721ab8 Remove /phpstan.neon from the vendor tarball (#626)
  • 5450db3 Include PHPStan in suggested scripts for contributors
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Updates the requirements on [google/recaptcha](https://github.com/google/recaptcha) to permit the latest version.
- [Release notes](https://github.com/google/recaptcha/releases)
- [Commits](google/recaptcha@1.5...2.0.0)

---
updated-dependencies:
- dependency-name: google/recaptcha
  dependency-version: 2.0.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, php. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants