Repository navigation
chore(deps)(deps): Bump the laravel group across 1 directory with 7 updates - #435
Conversation
…pdates Bumps the laravel group with 6 updates in the / directory: | Package | From | To | | --- | --- | --- | | [laravel/ai](https://github.com/laravel/ai) | `0.3.2` | `0.7.1` | | [laravel/octane](https://github.com/laravel/octane) | `2.17.1` | `2.17.4` | | [laravel/passport](https://github.com/laravel/passport) | `12.4.3` | `13.7.5` | | [laravel/sanctum](https://github.com/laravel/sanctum) | `4.3.1` | `4.3.2` | | [laravel/socialite](https://github.com/laravel/socialite) | `5.25.0` | `5.27.0` | | [laravel/tinker](https://github.com/laravel/tinker) | `2.11.1` | `3.0.2` | Updates `laravel/ai` from 0.3.2 to 0.7.1 - [Release notes](https://github.com/laravel/ai/releases) - [Changelog](https://github.com/laravel/ai/blob/0.x/CHANGELOG.md) - [Commits](laravel/ai@v0.3.2...v0.7.1) Updates `laravel/framework` from 12.60.2 to 12.61.0 - [Release notes](https://github.com/laravel/framework/releases) - [Changelog](https://github.com/laravel/framework/blob/13.x/CHANGELOG.md) - [Commits](laravel/framework@v12.60.2...v12.61.0) Updates `laravel/octane` from 2.17.1 to 2.17.4 - [Release notes](https://github.com/laravel/octane/releases) - [Changelog](https://github.com/laravel/octane/blob/2.x/CHANGELOG.md) - [Commits](laravel/octane@v2.17.1...v2.17.4) Updates `laravel/passport` from 12.4.3 to 13.7.5 - [Release notes](https://github.com/laravel/passport/releases) - [Changelog](https://github.com/laravel/passport/blob/13.x/CHANGELOG.md) - [Upgrade guide](https://github.com/laravel/passport/blob/13.x/UPGRADE.md) - [Commits](laravel/passport@v12.4.3...v13.7.5) Updates `laravel/sanctum` from 4.3.1 to 4.3.2 - [Release notes](https://github.com/laravel/sanctum/releases) - [Changelog](https://github.com/laravel/sanctum/blob/4.x/CHANGELOG.md) - [Commits](laravel/sanctum@v4.3.1...v4.3.2) Updates `laravel/socialite` from 5.25.0 to 5.27.0 - [Release notes](https://github.com/laravel/socialite/releases) - [Changelog](https://github.com/laravel/socialite/blob/5.x/CHANGELOG.md) - [Commits](laravel/socialite@v5.25.0...v5.27.0) Updates `laravel/tinker` from 2.11.1 to 3.0.2 - [Release notes](https://github.com/laravel/tinker/releases) - [Changelog](https://github.com/laravel/tinker/blob/3.x/CHANGELOG.md) - [Commits](laravel/tinker@v2.11.1...v3.0.2) --- updated-dependencies: - dependency-name: laravel/ai dependency-version: 0.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: laravel - dependency-name: laravel/framework dependency-version: 12.60.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: laravel - dependency-name: laravel/octane dependency-version: 2.17.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: laravel - dependency-name: laravel/passport dependency-version: 13.7.5 dependency-type: direct:production update-type: version-update:semver-major dependency-group: laravel - dependency-name: laravel/sanctum dependency-version: 4.3.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: laravel - dependency-name: laravel/socialite dependency-version: 5.27.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: laravel - dependency-name: laravel/tinker dependency-version: 3.0.2 dependency-type: direct:production update-type: version-update:semver-major dependency-group: laravel ... Signed-off-by: dependabot[bot] <[email protected]>
a8ea15c to
4c22bbb
Compare
Passport 13 removed setClientUuids() — UUID client IDs became default. Required to unblock laravel-group dependabot bump.
Passport 13 ClientCommand::handle() declares ': void' return type; overriding signature must match. Note: createPasswordGrantClient() is also deprecated in Passport 12+ and will need a follow-up to use grant-type-array client creation.
|
@dependabot rebase |
|
Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry! If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request |
…ture - Add ': Client' return type to match parent - Throw RuntimeException on missing user (parent expects Client return) - Drop undefined-variable bug ($providers[0] referenced an undefined var) Note: createPasswordGrantClient() is still deprecated in Passport 12+ and removed in 13. Runtime command will fail until migrated to the new grant-type-array client creation API. Filed as follow-up.
|
@dependabot rebase |
|
Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry! If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request |
…iqueStringIds Passport 13 Client model now uses HasUniqueStringIds trait with a typed ': void' initializer. Re-applying HasUuids on top causes a signature incompatibility: Declaration of Illuminate\Database\Eloquent\Concerns\HasUuids::initializeHasUniqueStringIds() must be compatible with Laravel\Passport\Client::initializeHasUniqueStringIds(): void UUID generation is preserved via the parent trait.
|
@dependabot rebase |
|
Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry! If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request |
Passport 13 typed find/findActive as: find(string|int \$id): ?Client. Override must match exactly.
|
@dependabot rebase |
|
Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry! If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request |
|
@dependabot recreate |
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
Resolve composer.lock content-hash conflict by regenerating lock from merged composer.json (which now contains both the laravel group bumps and master's other dependency updates: intervention/image, predis, prettus/l5-repository).
… 0.7
laravel/ai 0.7 dropped its transitive prism-php/prism dependency in favor
of native gateway implementations. This commit migrates UnoPim's AiAgent +
MagicAI packages off Prism entirely, so the laravel-group dependabot bump
(laravel/ai 0.3 → 0.7) can land cleanly.
Architectural changes:
- Tools now implement Laravel\Ai\Contracts\Tool via a new ContextualTool
abstract base (anonymous class pattern inside PimTool::register()).
- AgentRunner uses Laravel\Ai\AnonymousAgent + prompt()/stream() instead
of Prism::text() fluent chain.
- LaravelAiAdapter rewritten to use AnonymousAgent for text + Laravel\Ai\Image
for image generation; provider config pushed via ai.providers.{key}.*.
- PrismErrorResolver renamed to AiErrorResolver and remapped to laravel/ai
exceptions (RateLimitedException, ProviderOverloadedException). HTTP 413
detected via RequestException walking (no dedicated exception in 0.7).
- AiProvider enum drops toPrismProvider(); toLab() kept (Custom → Lab::Groq
for OpenAI-compatible /chat/completions routing).
- Streaming uses typed StreamEvent objects (ToolCall, TextDelta) instead
of Prism callbacks.
Tool schema migration (mechanical, 34 classes):
withStringParameter('x','desc') → 'x' => $schema->string()->description('desc')
withNumberParameter → ->integer() / ->number()
withBooleanParameter → ->boolean()
withEnumParameter → ->string()->enum([...])
using(fn (?string $sku) => ...) → handle(Request $r) { $r->string('sku')->toString() }
Tests:
- PrismErrorResolverTest → AiErrorResolverTest, updated to use laravel/ai
exception types (forProvider()) and HTTP 413 via RequestException.
- AiProviderCustomTest: dropped toPrismProvider() assertions, added
toLab() === Lab::Groq mapping verification.
- Tool-source assertion tests updated to new schema syntax.
Verified locally:
- vendor/bin/pint --test passes
- php artisan unopim:translations:check passes (224/224 locales)
- vendor/bin/pest (AiErrorResolver) passes 14/14
- composer validate passes; no prism-php/prism in lock file
Known follow-ups (separate issues/PRs):
- Per-call max_tokens / temperature use runtime config push; should refactor
to subclass AnonymousAgent exposing maxTokens() / temperature() methods
that laravel/ai gateways read via TextGenerationOptions::from().
- Migrate UnoPim's history array to laravel/ai HasConversations for
persistence + multi-turn context restoration.
- AttachImage / GenerateImage hardcode 'image' attribute — gallery
attributes silently overwrite. Pre-existing bug, fix in dedicated PR.
- OauthClientGenerator::generateClientIdAndSecretKey: Passport 13 createPasswordGrantClient() dropped $userId + $redirect args; create client then attach user_id manually via forceFill. - OauthClientGenerator::regenerateSecret + ApiKeysController: Passport 13 regenerateSecret() returns bool, not Client. Don't reassign — return the in-place mutated $client to keep callers working. - ApiClientCommand: same createPasswordGrantClient signature fix. - ManageUsers: move maskUserData() out of anonymous inner class onto the outer class so ManageUsersEmailMaskingTest's reflection can find it. - EditImageToolTest / ExportProductsToolTest: source-assertion strings must use single quotes so $schema isn't interpolated as PHP variable. - ImportProductsAclToolTest: wrap handle() args in Laravel\Ai\Tools\Request (laravel/ai 0.7 Tool::handle() takes a Request, not raw string args). - LaravelAiAdapterImageTest + ReasoningModelTemperatureTest: skip pending rewrite — these assert Prism-specific HTTP request bodies / URLs that don't match laravel/ai 0.7's gateway shape. Tracked for follow-up.
…st asserts CI workflow fixes: - Add chmod 0600 step on packages/Webkul/AdminApi/src/Secrets/Oauth/*.key in all 4 jobs (Pest MySQL, Pest MySQL+ES, Pest PostgreSQL, Pest PostgreSQL+ES, Playwright E2E). Git tracks no file mode beyond the executable bit, so checked-out keys are 644 and Passport 13's stricter league/oauth2-server check rejects them with E_USER_NOTICE that Laravel's error handler promotes to ErrorException in tests. AiErrorResolver: - Add InsufficientCreditsException handler (HTTP 402). laravel/ai 0.7 introduced this exception; previously unknown errors were falling through to the generic 500 path, breaking the AiProviderCustomTest test-connection assertion. Skipped-test syntax: - Replace beforeEach(test()->skip(...)) with beforeEach($this->markTestSkipped(...)) in LaravelAiAdapterImageTest and ReasoningModelTemperatureTest. The former called a method that doesn't exist on AdminTestCase. The latter is the official PHPUnit TestCase API and works in class-extending Pest tests. Source-asserting Pest tests: - EditImageToolTest + ExportProductsToolTest now use toMatch() with regex literals (single-quoted to avoid PHP interpolating $schema as a variable) so they match the laravel/ai schema(JsonSchema $schema) pattern regardless of Pint's whitespace alignment. - ExportProductsToolTest updated for the new $this->outer->writeXlsx/ writeCsv delegation introduced by the ContextualTool migration. Known follow-up (out of scope for this PR): - Passport 13's oauth_clients schema (nullableMorphs owner, redirect_uris, grant_types) differs from UnoPim's legacy schema (user_id, redirect, personal_access_client, password_client). IntegrationSectionTest + any code creating OAuth clients on Passport 13 needs a schema migration + ApiKeysDataGrid join update. File as separate issue.
Passport 13's Bridge\UserRepository::getUserEntityByUserCredentials is now strict-typed: (string $username, string $password, string $grantType, ClientEntityInterface $clientEntity): ?UserEntityInterface Untyped override caused a PHP Fatal at autoload time, which blocked the entire test suite from booting.
Passport 13's Client model declares additional columns (nullableMorphs owner_type/owner_id, redirect_uris, grant_types) that did not exist in UnoPim's legacy 2016_06_01_000004_create_oauth_clients_table migration. Without them, every Passport 13 createPasswordGrantClient() call silently failed during INSERT and AdminApi tests could not obtain access tokens — producing wholesale HTTP 401 responses across the entire AdminApi test suite (~280 tests). Migration (2026_05_27_140000_add_passport_13_columns_to_oauth_clients): - ADD nullable string columns owner_type, owner_id (composite index) - ADD nullable text columns redirect_uris, grant_types - Backfill: owner_type = Webkul\User\Models\Admin::class, owner_id = user_id for every existing row that has a user_id but no owner morph - Backfill: redirect_uris = JSON([legacy redirect or "http://localhost"]) - Backfill: grant_types = JSON(["password", "refresh_token"]) - Keep legacy user_id, redirect, personal_access_client, password_client columns intact for backwards compatibility with ApiKeysDataGrid JOINs, Client::admins() relation, and any third-party customisations. Code: - OauthClientGenerator + ApiClientCommand now forceFill BOTH the legacy user_id and the new owner_type/owner_id morph, so old code paths (DataGrid join, custom queries) and new Passport 13 Client::owner() morph relation both work. Tests: - IntegrationSectionTest: Passport 13 hashes `secret` at write-time via castAttributeAsHashedString. Stop asserting plaintext equality in DB; match by id and Hash::check() the plaintext against the stored hash. - AiProviderCustomTest: laravel/ai 0.7 raises InsufficientCreditsException for upstream HTTP 402, which AiErrorResolver maps to HTTP 402 instead of the generic 400 the legacy Prism flow produced. Accept either status and either upstream message string.
ApiHelperTrait + ApiAuthenticationTest used the legacy 4-arg createPasswordGrantClient(userId, name, redirect, provider). Passport 13 takes 3 args (name, provider, confidential) — without this fix every AdminApi feature test that needs a bearer token gets 401 because the client INSERT silently fails (no exception in old code path) and no password-grant token can be issued. Also extend the oauth_clients migration to make `redirect`, `personal_access_client` and `password_client` nullable. Passport 13's createPasswordGrantClient doesn't write these legacy columns; PostgreSQL strictly enforces their NOT NULL constraints and rejects every INSERT (MySQL silently defaults). Now nullable so Passport 13 INSERTs succeed on every supported DB. Verified locally: - vendor/bin/pest packages/Webkul/AdminApi/tests/Feature/ → 295/298 pass - vendor/bin/pest packages/Webkul/Admin/tests/Feature/Configuration/IntegrationSectionTest.php → 13/13 pass - composer validate + pint --test → pass
…ken revocation test PasswordChangeInvalidatesTokensTest still called the legacy 4-arg createPasswordGrantClient(userId, name, redirect, provider) — same break as ApiHelperTrait. Passport 13 takes (name, provider, confidential) and the user_id/owner morph must be attached separately via forceFill. This was the last test failure on the laravel-group bump branch.
Bumps the laravel group with 6 updates in the / directory:
0.3.20.7.12.17.12.17.412.4.313.7.54.3.14.3.25.25.05.27.02.11.13.0.2Updates
laravel/aifrom 0.3.2 to 0.7.1Release notes
Sourced from laravel/ai's releases.
... (truncated)
Changelog
Sourced from laravel/ai's changelog.
... (truncated)
Commits
8b0db36Replace deprecated gemini-3-flash-preview default with gemini-3.5-flash (#661)3e34fb8Fix Gemini image generation when text part precedes image data (#658)6533911Updates deprecated gemini model to successor (#657)e819c29Add JSON_UNESCAPED_UNICODE to schema instruction encoding (#644)c25fc7cApply model attribute and explicit model to all providers in a failover list ...21a5e10Set invocation id on fake stream events (#635)f7ec275BedrockTextGateway: Add cache usage (#642)754376aSet gemini-3.5-flash as Gemini's smartest text model (#640)faba7e5Update CHANGELOGeb2a261Document@throwsannotations across gateways, tools, and pending responses (#...Updates
laravel/frameworkfrom 12.60.2 to 12.61.0Release notes
Sourced from laravel/framework's releases.
Commits
1124062Update version to v12.61.04e0f82bupdate comment66aa65c[12.x] Throw ManagedQueueNotFoundException when a managed queue is missing (#...4614124remove comment48951e9[12.x] Fix queue:failed command to show real class name (#60279)1d358ccAccept Symfony's new control-characters exception message in mailer test (#60...e53ddddUpdate CHANGELOGUpdates
laravel/octanefrom 2.17.1 to 2.17.4Release notes
Sourced from laravel/octane's releases.
Changelog
Sourced from laravel/octane's changelog.
Commits
ffeac11Skip full compiled route iteration in router listener (#1126)3c9f23cUpdate CHANGELOG040bfbefix: refresh router containers for compiled routes (#1121)a8227dbUpdate CHANGELOGd73525ffix versionfb38077Improves CI against L13 (#1107)36774a1Update CHANGELOGUpdates
laravel/passportfrom 12.4.3 to 13.7.5Release notes
Sourced from laravel/passport's releases.
... (truncated)
Changelog
Sourced from laravel/passport's changelog.
... (truncated)
Upgrade guide
Sourced from laravel/passport's upgrade guide.
... (truncated)
Commits
90053dcClarify that runningpassport:hashis not optional (#1911)ed8956cadd notices of invalid tokens when user and client have identical ids (#1910)d085f96Update CHANGELOG16c4579[13.x] Support space-delimited prompt parameter (#1906)cfcd9dbUpdate CHANGELOGf4f85e3[13.x] Fix session JSON serialization (#1905)27ba0a8Update CHANGELOG0c016c9[13.X] fix: resolve user as null when user ID matches client ID on integer ke...dd68c65Update CHANGELOGca14d97Prevent user impersonation via client credentials token (#1901)Updates
laravel/sanctumfrom 4.3.1 to 4.3.2Release notes
Sourced from laravel/sanctum's releases.
Changelog
Sourced from laravel/sanctum's changelog.
Commits
2a9bccc[4.x] Updateconfig/sanctum.phpto follow skeleton pint format (#597)70546ceUpdate CHANGELOGUpdates
laravel/socialitefrom 5.25.0 to 5.27.0Release notes
Sourced from laravel/socialite's releases.
Changelog
Sourced from laravel/socialite's changelog.
Commits
40e0757Fix usage of access_token in Bitbucket integration (#771)3eb5446Update CHANGELOGdb6ec2eUse hash_equals for constant-time state comparison (#770)e2f2daaUpdate CHANGELOG1d26f0c[5.x] Fix workflow YAML syntax and clean up broken CI matrix (#769)30f44ddRemove redundant "When to Apply" section from skill body (#766)b1fb602Update CHANGELOGUpdates
laravel/tinkerfrom 2.11.1 to 3.0.2Release notes
Sourced from laravel/tinker's releases.
Changelog
Sourced from laravel/tinker's changelog.
... (truncated)
Commits
4faba77Update CHANGELOGcc74081fix conflictseaa7626Update CHANGELOGc0bf371[3.x] Supports Laravel 13 (#197)104ac0bMerge branch '2.x'942b69c[3.x] Remove supports for PHP 8.0 and 7.x (#186)fce88bfMerge branch '2.x'7d593dfMerge branch '2.x'