Skip to content

Update dependency composer/composer to v2.10.0 (Latest)#426

Merged
alcohol merged 1 commit into
mainfrom
renovate/latest-composer-composer-2.x
May 28, 2026
Merged

Update dependency composer/composer to v2.10.0 (Latest)#426
alcohol merged 1 commit into
mainfrom
renovate/latest-composer-composer-2.x

Conversation

@renovate

@renovate renovate Bot commented May 28, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
composer/composer minor 2.9.82.10.0

Release Notes

composer/composer (composer/composer)

v2.10.0

Compare Source

  • BC Break / Security: Disabled automatic fallback to source checkout if dist/zip install fails, we have introduced a new source-fallback config option as a temporary way to restore the old behavior, but if you need this talk to us as we plan to remove it entirely in 2.11 (#​12885)
    • BC Break: Minor break for audit consumers, the exit code is now always 0 (success) or 1 if anything failed the audit (#​12881)
    • Security: Hardened output filtering of URLs to reduce chances of token leaks (#​12882, #​12886)
    • Security: Fixed handling of uppercase schemes in URL validation that might have allowed https requirement bypass (#​12884)
    • Fixed audit command returning a success code when the vendor dir was not present (#​12880)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@alcohol alcohol merged commit aba41a2 into main May 28, 2026
11 checks passed
@alcohol alcohol deleted the renovate/latest-composer-composer-2.x branch May 28, 2026 17:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant