Bump guzzlehttp/psr7 from 2.5.0 to 2.12.3 in /libs/wordpress-plugin/plugin/trunk - #1573
Conversation
Bumps [guzzlehttp/psr7](https://github.com/guzzle/psr7) from 2.5.0 to 2.12.3. - [Release notes](https://github.com/guzzle/psr7/releases) - [Changelog](https://github.com/guzzle/psr7/blob/2.12/CHANGELOG.md) - [Commits](guzzle/psr7@2.5.0...2.12.3) --- updated-dependencies: - dependency-name: guzzlehttp/psr7 dependency-version: 2.12.3 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
PR SummaryMedium Risk Overview The newer Reviewed by Cursor Bugbot for commit 8ff44d2. Bugbot is set up for automated code reviews on this repo. Configure here. |
|
Superseded by #1583. |
Bumps guzzlehttp/psr7 from 2.5.0 to 2.12.3.
Release notes
Sourced from guzzlehttp/psr7's releases.
... (truncated)
Changelog
Sourced from guzzlehttp/psr7's changelog.
... (truncated)
Commits
7ec62dcRelease 2.12.3ddd64f1Validate the URI host sogetHost()matches the URI authority (#811)5ec8b15Release 2.12.25cfb193Fail closed on validation PCRE errors (#803)9e21236Report message parser PCRE failures (#802)45ae7e8Report URI PCRE failures (#801)7af66b9Bump minimum PHP 8.0 polyfill version (#800)172ef2fRelease 2.12.1f3f94b4Mitigate CRLF Injection in HTTP Start-Line Serialization (#798)9b38012Release 2.12.0Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.