Skip to content

chore(deps)(deps): bump the laravel group across 1 directory with 2 updates - #731

Open
dependabot[bot] wants to merge 1 commit into
3.xfrom
dependabot/composer/3.x/laravel-7165ad8c17
Open

dependabot[bot] wants to merge 1 commit into
3.xfrom
dependabot/composer/3.x/laravel-7165ad8c17

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the laravel group with 2 updates in the / directory: laravel/framework and laravel/octane.

Updates laravel/framework from 13.30.1 to 13.34.0

Release notes

Sourced from laravel/framework's releases.

v13.34.0

... (truncated)

Changelog

Sourced from laravel/framework's changelog.

v13.34.0 - 2026-09-29

... (truncated)

Commits
  • c829b49 Update version to v13.34.0
  • 322ad9f [13.x] Explicitly enable imagick extension for CI tests (#61756)
  • 1003c6e Add mime type to the files reportable details (#61772)
  • 68b248f Add regression test for QueueManager::createPayloadUsing() (#61773)
  • 4d6522d Fix memoized tagged cache many() returning null for numeric keys (#61780)
  • de11d6d fix dotted key lookup in ArrayStore::touch() (#61777)
  • 57a5c1e pass scheme to compiled routes
  • 4e94d3a Final Mockery cleanup (#61739)
  • a10e706 Fix Builder::with() when a null callback is passed explicitly (#61769)
  • 52d96dc Fix findOrFail() with an array of enum ids (#61765)
  • Additional commits viewable in compare view

Updates laravel/octane from 2.19.1 to 2.20.0

Release notes

Sourced from laravel/octane's releases.

v2.20.0

Changelog

Sourced from laravel/octane's changelog.

v2.20.0 - 2026-08-23

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update php code labels Sep 24, 2026
luis030821 pushed a commit to luis030821/unopim that referenced this pull request Sep 26, 2026
* fix: prevent saving descendant or self as parent category

Adds validation in the category update flow to block assigning a
descendant or the category itself as its parent. Previously this caused
a raw PHP exception from the nested-set library. Now a clear UI error
message is shown and the save is rejected.

* fix: disable current category in parent tree radio selector

* fix: resolve attribute history tab not showing columns (unopim#703)

- Rename v-datagrid-table to v-history-table in history/table.blade.php to
  avoid Vue component registration conflict with the regular datagrid table
  (both shared the same template ID, causing visibleColumns to be undefined)
- Remove unconditional slot forwarding from v-history-datagrid that was
  overriding v-history-table's default slot content with empty content
- Add AttributeHistoryPresenter to translate raw field names and values
  into human-readable labels in the history detail modal

* fix: accept snake_case params in AjaxOptionsController to fix select attribute filter options loading

* fix: add purpose field to text_generation prompts in seeder so both text and image prompts are seeded on fresh install

* fix: reject root category assignment on products (unopim#731)

* fix: make product edit page header sticky so save button is always visible

* fix: unify add-option modal layout for image swatch attributes

* fix: return 403 instead of 401 for authenticated users without permission

* fix: hide edit and delete actions in platform datagrid for users without permission

* fix: align ACL sort values with menu order for data_transfer and ai-agent

* fix: bulk edit attribute list now scoped to the selected products' attribute families

* fix: update ACL tests to assert 403 Forbidden instead of 401 Unauthorized for permission-denied access

* fix: remove dead code accessing non-existent data column and fix parameter name typo in TrackerController

* fix: guard prompt and system-prompt datagrid actions with ACL permission checks

* fix: update security test to assert 403 Forbidden instead of 401 for unauthorized access

* fix: correct undefined variable in ProductValuesValidator channel codes lookup

* fix: update product update test to use non-root category to match category assignment restriction

* fix: fix parameter name typo in ImportController normalizeSummary method

* fix: replace missing translation key with correct tracker datagrid view key and add view translation across all locales

* fix: redirect reset-password route without token to forget-password page instead of 500

* fix: hide AI agent chat widget on anonymous and error pages

* fix: honor server-side default AI platform when session cache holds a stale selection

* fix: prevent marking a disabled AI platform as default with server-side validation

* fix: strip leading tilde from fetched and submitted AI model names to pass validation

* fix: hide Magic AI button in TinyMCE toolbar when text generation is disabled

* fix: render datetime attribute with datetime-local picker in bulk edit and validate on input

* fix: validate numeric attribute values on bulk edit save to reject non-numeric prices

* fix: persist uploaded media file path into product attribute values after upload

* fix: accept both configurable-products and legacy configrable-products URL prefixes for the configurable product API

* feat: add DELETE endpoint for configurable products via REST API

* test: add regression coverage asserting limit query parameter is respected on configurable products endpoint

* test: add regression coverage asserting PATCH and DELETE are rejected on the products listing endpoint

* fix: reject attribute create POST when body is a list of multiple objects

* fix: reject unknown option codes when updating category field options instead of silently creating them

* fix: reject API update requests that include immutable fields for attributes and category fields

* fix: return parent category code when fetching a category by code in REST API

* fix: use clearer page titles for attribute families, Magic AI prompts, and system prompts listing pages

* fix: ignore trailing empty header columns when validating spreadsheet imports

* fix: raise Agentic AI chat CSV/XLSX upload limit from 20MB to 100MB for bulk product imports

* fix: hide edit and delete icons on magic AI platform grid when permission is missing

* fix: forbid deletion of the default magic AI platform regardless of the count of other platforms

* fix: hide Add Platform button for users without ai-agent.platform.create permission

* fix: persist empty value when a core-config field is explicitly cleared so deselected multiselects are saved

* fix: resolve ambiguous name column in attribute search and default suggestion query to empty string

* fix: hide attribute code in manage columns list so only the translated name is shown

* fix: make bulk edit column resize handle larger, persistent, and visible on hover

* fix: place Magic AI before Data Transfer in sidebar and role hierarchy by setting ai-agent sort to 7

* fix: guarantee selected models are posted in Magic AI platform form regardless of DOM binding timing

* fix: revoke Passport tokens on password change and API key secret regeneration

* fix: reject invalid parent filter on products API with 422 instead of silently returning data

* fix: verify Magic AI platform credentials with test-connection before save to block invalid API keys

* fix: auto-fetch Magic AI models on api_key input with a 500ms debounce

* test: align attribute and category field API tests with the immutable-fields 422 policy

* fix: source platform save payload from Vue state so custom multiselect values (provider) reach the server

* chore: pin laravel/pint to 1.29.1 and apply resulting format fixes

CI installs latest pint via aglipanci/laravel-pint-action while lockfile
had v1.29.0; v1.29.1 (PR unopim#432) tightened fixer detection causing CI-only
style failures. Pin exact version to align local + CI, reformat the three
affected controllers.

* ci: run pint via project vendor instead of global install

aglipanci/[email protected] does composer global require and
pulls the latest pint, bypassing composer.lock. Swap to setup-php +
ramsey/composer-install so the lockfile-pinned version is used, keeping
CI and local in lockstep.

* test: fix Magic AI default-requires-enabled spec CSRF handling

Admin layouts don't render a meta[name="csrf-token"] tag, so the old
adminPage.request.post path sent an empty X-CSRF-TOKEN and the request
was rejected (419 locally, 500 in CI shard 2). Switch to the same
in-page fetch pattern as webhook-delivery.spec.js: read the XSRF-TOKEN
cookie and send it as X-XSRF-TOKEN, which the session-backed request
context accepts.

* fix: address Copilot review feedback

- ProductBulkEditController::validateNumericAttributeValues: replace
  break 2 with break so a single bad scalar no longer aborts validation
  of the remaining numeric attributes on the same product.
- ApiResponse::storeExceptionLog: map UnprocessableEntityHttpException
  to 422 instead of 404; keep ModelNotFoundException on 404.
- Tighten API tests: ApiProductInvalidFilterTest asserts 422 exactly,
  ApiProductMethodNotAllowedTest asserts 405 and presence of Allow
  header instead of accepting a loose status set.

* chore: drop accidentally-committed playwright test-results artifact

* refactor: address remaining Copilot review feedback

- MediaFileController::assignMediaToProductAttribute: use the injected
  $attributeRepository instead of an ad-hoc app() lookup.
- tree/radio.blade.php: bind cursor-pointer/cursor-not-allowed on icon
  and label text to isCurrentCategory so the disabled state is
  reflected consistently.
- CoreConfigRepositoryClearValueTest: drop source-string matching and
  replace with behavioral tests that exercise CoreConfigRepository
  against the DB for null-cleared and default-valued fields.
- ImporterEmptyHeadersTest: exercise AbstractImporter::validateData via
  a minimal concrete subclass with a stub source so regressions in
  the trailing-empty-header trim are caught against production code.
- ProductCategoriesValidator: replace the per-validate root-code pluck
  with a closure that does a single indexed whereNull lookup per
  submitted code.

* fix: guard CoreConfigRepository field-type access when field definition is missing

The previous null-to-empty-string change made the code fall through to a
password-type check that assumed $field was an array. Tests that exercise
legacy configuration payloads hit a "Trying to access array offset on
null" error. Use null-coalesce on $field['type'] so the password path
is skipped when the config field is not registered.
@dependabot
dependabot Bot force-pushed the dependabot/composer/3.x/laravel-7165ad8c17 branch 2 times, most recently from 4475a20 to 1646560 Compare October 5, 2026 00:35
…pdates

Bumps the laravel group with 2 updates in the / directory: [laravel/framework](https://github.com/laravel/framework) and [laravel/octane](https://github.com/laravel/octane).


Updates `laravel/framework` from 13.30.1 to 13.34.0
- [Release notes](https://github.com/laravel/framework/releases)
- [Changelog](https://github.com/laravel/framework/blob/13.x/CHANGELOG.md)
- [Commits](laravel/framework@v13.30.1...v13.34.0)

Updates `laravel/octane` from 2.19.1 to 2.20.0
- [Release notes](https://github.com/laravel/octane/releases)
- [Changelog](https://github.com/laravel/octane/blob/2.x/CHANGELOG.md)
- [Commits](laravel/octane@v2.19.1...v2.20.0)

---
updated-dependencies:
- dependency-name: laravel/framework
  dependency-version: 13.32.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: laravel
- dependency-name: laravel/octane
  dependency-version: 2.20.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: laravel
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot
dependabot Bot force-pushed the dependabot/composer/3.x/laravel-7165ad8c17 branch from 1646560 to 032d92b Compare October 7, 2026 07:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants