Repository navigation
chore(deps)(deps): bump the laravel group across 1 directory with 2 updates - #731
Open
dependabot[bot] wants to merge 1 commit into
Open
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
1 of 6 tasks
luis030821
pushed a commit
to luis030821/unopim
that referenced
this pull request
Sep 26, 2026
* fix: prevent saving descendant or self as parent category Adds validation in the category update flow to block assigning a descendant or the category itself as its parent. Previously this caused a raw PHP exception from the nested-set library. Now a clear UI error message is shown and the save is rejected. * fix: disable current category in parent tree radio selector * fix: resolve attribute history tab not showing columns (unopim#703) - Rename v-datagrid-table to v-history-table in history/table.blade.php to avoid Vue component registration conflict with the regular datagrid table (both shared the same template ID, causing visibleColumns to be undefined) - Remove unconditional slot forwarding from v-history-datagrid that was overriding v-history-table's default slot content with empty content - Add AttributeHistoryPresenter to translate raw field names and values into human-readable labels in the history detail modal * fix: accept snake_case params in AjaxOptionsController to fix select attribute filter options loading * fix: add purpose field to text_generation prompts in seeder so both text and image prompts are seeded on fresh install * fix: reject root category assignment on products (unopim#731) * fix: make product edit page header sticky so save button is always visible * fix: unify add-option modal layout for image swatch attributes * fix: return 403 instead of 401 for authenticated users without permission * fix: hide edit and delete actions in platform datagrid for users without permission * fix: align ACL sort values with menu order for data_transfer and ai-agent * fix: bulk edit attribute list now scoped to the selected products' attribute families * fix: update ACL tests to assert 403 Forbidden instead of 401 Unauthorized for permission-denied access * fix: remove dead code accessing non-existent data column and fix parameter name typo in TrackerController * fix: guard prompt and system-prompt datagrid actions with ACL permission checks * fix: update security test to assert 403 Forbidden instead of 401 for unauthorized access * fix: correct undefined variable in ProductValuesValidator channel codes lookup * fix: update product update test to use non-root category to match category assignment restriction * fix: fix parameter name typo in ImportController normalizeSummary method * fix: replace missing translation key with correct tracker datagrid view key and add view translation across all locales * fix: redirect reset-password route without token to forget-password page instead of 500 * fix: hide AI agent chat widget on anonymous and error pages * fix: honor server-side default AI platform when session cache holds a stale selection * fix: prevent marking a disabled AI platform as default with server-side validation * fix: strip leading tilde from fetched and submitted AI model names to pass validation * fix: hide Magic AI button in TinyMCE toolbar when text generation is disabled * fix: render datetime attribute with datetime-local picker in bulk edit and validate on input * fix: validate numeric attribute values on bulk edit save to reject non-numeric prices * fix: persist uploaded media file path into product attribute values after upload * fix: accept both configurable-products and legacy configrable-products URL prefixes for the configurable product API * feat: add DELETE endpoint for configurable products via REST API * test: add regression coverage asserting limit query parameter is respected on configurable products endpoint * test: add regression coverage asserting PATCH and DELETE are rejected on the products listing endpoint * fix: reject attribute create POST when body is a list of multiple objects * fix: reject unknown option codes when updating category field options instead of silently creating them * fix: reject API update requests that include immutable fields for attributes and category fields * fix: return parent category code when fetching a category by code in REST API * fix: use clearer page titles for attribute families, Magic AI prompts, and system prompts listing pages * fix: ignore trailing empty header columns when validating spreadsheet imports * fix: raise Agentic AI chat CSV/XLSX upload limit from 20MB to 100MB for bulk product imports * fix: hide edit and delete icons on magic AI platform grid when permission is missing * fix: forbid deletion of the default magic AI platform regardless of the count of other platforms * fix: hide Add Platform button for users without ai-agent.platform.create permission * fix: persist empty value when a core-config field is explicitly cleared so deselected multiselects are saved * fix: resolve ambiguous name column in attribute search and default suggestion query to empty string * fix: hide attribute code in manage columns list so only the translated name is shown * fix: make bulk edit column resize handle larger, persistent, and visible on hover * fix: place Magic AI before Data Transfer in sidebar and role hierarchy by setting ai-agent sort to 7 * fix: guarantee selected models are posted in Magic AI platform form regardless of DOM binding timing * fix: revoke Passport tokens on password change and API key secret regeneration * fix: reject invalid parent filter on products API with 422 instead of silently returning data * fix: verify Magic AI platform credentials with test-connection before save to block invalid API keys * fix: auto-fetch Magic AI models on api_key input with a 500ms debounce * test: align attribute and category field API tests with the immutable-fields 422 policy * fix: source platform save payload from Vue state so custom multiselect values (provider) reach the server * chore: pin laravel/pint to 1.29.1 and apply resulting format fixes CI installs latest pint via aglipanci/laravel-pint-action while lockfile had v1.29.0; v1.29.1 (PR unopim#432) tightened fixer detection causing CI-only style failures. Pin exact version to align local + CI, reformat the three affected controllers. * ci: run pint via project vendor instead of global install aglipanci/[email protected] does composer global require and pulls the latest pint, bypassing composer.lock. Swap to setup-php + ramsey/composer-install so the lockfile-pinned version is used, keeping CI and local in lockstep. * test: fix Magic AI default-requires-enabled spec CSRF handling Admin layouts don't render a meta[name="csrf-token"] tag, so the old adminPage.request.post path sent an empty X-CSRF-TOKEN and the request was rejected (419 locally, 500 in CI shard 2). Switch to the same in-page fetch pattern as webhook-delivery.spec.js: read the XSRF-TOKEN cookie and send it as X-XSRF-TOKEN, which the session-backed request context accepts. * fix: address Copilot review feedback - ProductBulkEditController::validateNumericAttributeValues: replace break 2 with break so a single bad scalar no longer aborts validation of the remaining numeric attributes on the same product. - ApiResponse::storeExceptionLog: map UnprocessableEntityHttpException to 422 instead of 404; keep ModelNotFoundException on 404. - Tighten API tests: ApiProductInvalidFilterTest asserts 422 exactly, ApiProductMethodNotAllowedTest asserts 405 and presence of Allow header instead of accepting a loose status set. * chore: drop accidentally-committed playwright test-results artifact * refactor: address remaining Copilot review feedback - MediaFileController::assignMediaToProductAttribute: use the injected $attributeRepository instead of an ad-hoc app() lookup. - tree/radio.blade.php: bind cursor-pointer/cursor-not-allowed on icon and label text to isCurrentCategory so the disabled state is reflected consistently. - CoreConfigRepositoryClearValueTest: drop source-string matching and replace with behavioral tests that exercise CoreConfigRepository against the DB for null-cleared and default-valued fields. - ImporterEmptyHeadersTest: exercise AbstractImporter::validateData via a minimal concrete subclass with a stub source so regressions in the trailing-empty-header trim are caught against production code. - ProductCategoriesValidator: replace the per-validate root-code pluck with a closure that does a single indexed whereNull lookup per submitted code. * fix: guard CoreConfigRepository field-type access when field definition is missing The previous null-to-empty-string change made the code fall through to a password-type check that assumed $field was an array. Tests that exercise legacy configuration payloads hit a "Trying to access array offset on null" error. Use null-coalesce on $field['type'] so the password path is skipped when the config field is not registered.
dependabot
Bot
force-pushed
the
dependabot/composer/3.x/laravel-7165ad8c17
branch
2 times, most recently
from
October 5, 2026 00:35
4475a20 to
1646560
Compare
…pdates Bumps the laravel group with 2 updates in the / directory: [laravel/framework](https://github.com/laravel/framework) and [laravel/octane](https://github.com/laravel/octane). Updates `laravel/framework` from 13.30.1 to 13.34.0 - [Release notes](https://github.com/laravel/framework/releases) - [Changelog](https://github.com/laravel/framework/blob/13.x/CHANGELOG.md) - [Commits](laravel/framework@v13.30.1...v13.34.0) Updates `laravel/octane` from 2.19.1 to 2.20.0 - [Release notes](https://github.com/laravel/octane/releases) - [Changelog](https://github.com/laravel/octane/blob/2.x/CHANGELOG.md) - [Commits](laravel/octane@v2.19.1...v2.20.0) --- updated-dependencies: - dependency-name: laravel/framework dependency-version: 13.32.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: laravel - dependency-name: laravel/octane dependency-version: 2.20.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: laravel ... Signed-off-by: dependabot[bot] <[email protected]>
dependabot
Bot
force-pushed
the
dependabot/composer/3.x/laravel-7165ad8c17
branch
from
October 7, 2026 07:31
1646560 to
032d92b
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the laravel group with 2 updates in the / directory: laravel/framework and laravel/octane.
Updates
laravel/frameworkfrom 13.30.1 to 13.34.0Release notes
Sourced from laravel/framework's releases.
... (truncated)
Changelog
Sourced from laravel/framework's changelog.
... (truncated)
Commits
c829b49Update version to v13.34.0322ad9f[13.x] Explicitly enable imagick extension for CI tests (#61756)1003c6eAdd mime type to the files reportable details (#61772)68b248fAdd regression test for QueueManager::createPayloadUsing() (#61773)4d6522dFix memoized tagged cache many() returning null for numeric keys (#61780)de11d6dfix dotted key lookup in ArrayStore::touch() (#61777)57a5c1epass scheme to compiled routes4e94d3aFinal Mockery cleanup (#61739)a10e706Fix Builder::with() when a null callback is passed explicitly (#61769)52d96dcFix findOrFail() with an array of enum ids (#61765)Updates
laravel/octanefrom 2.19.1 to 2.20.0Release notes
Sourced from laravel/octane's releases.
Changelog
Sourced from laravel/octane's changelog.
Commits
df4c38dMake RoadRunner worker command path configurable and absolute-path safe (#1162)4cdebfbUpdate CHANGELOG