Skip to content

Bump the production-dependencies group with 2 updates - #54

Merged
ildyria merged 1 commit into
masterfrom
dependabot/composer/production-dependencies-5bfba7f2c2
Sep 29, 2026
Merged

ildyria merged 1 commit into
masterfrom
dependabot/composer/production-dependencies-5bfba7f2c2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 2 updates: phpstan/phpstan and symplify/phpstan-rules.

Updates phpstan/phpstan from 2.2.14 to 2.2.16

Commits

Updates symplify/phpstan-rules from 14.13.1 to 14.17.0

Release notes

Sourced from symplify/phpstan-rules's releases.

PHPStan Rules 14.17

All rule sets are now auto-loaded via phpstan/extension-installer - no includes: needed, just toggle them with a parameter.

New features 🎉

All rule sets auto-loaded, toggle them on/off

Code complexity, configurable, static, Symfony, Symfony config, Doctrine and PHPUnit sets are now registered in extra.phpstan.includes and gated by a symplify.* parameter (#319):

parameters:
    symplify:
        # enabled by default
        naming: true
        complexity: true
        configurable: true
        static: true
        symfony: true
        symfonyConfig: true
        doctrine: true
        phpunit: true
    # disabled by default
    mocks: false
    ctor: false

rector-rules.neon stays opt-in.

⚠️ Drop manual includes of these sets (and symplify-rules.neon) from your phpstan.neon - PHPStan reports duplicated includes.

Bugfixes 🐛

  • [symfony] Skip Symfony\Component\Mailer\Transport in PreferInterfaceInConstructorRule (#320)

PHPStan Rules 14.16

Rule sets are now toggleable from a single symplify parameter, 4 too-narrow Symfony rules are gone, and a batch of false positives is fixed across Symfony, Doctrine, PHPUnit and the ctor rules.

New features 🎉

Toggle whole rule sets on/off

Naming, complexity, configurable and static sets are now auto-loaded via phpstan/extension-installer and gated by a parameter - all on by default, so no behavior change on upgrade (#301, #304):

parameters:
    symplify:
        naming: false
</tr></table> 

... (truncated)

Commits
  • c6a60f1 [symfony] Skip Symfony\Component\Mailer\Transport in PreferInterfaceInConstru...
  • 01ab4a3 Auto-load all rule sets, toggle them via symplify.* parameters (#319)
  • de06599 [symfony] Make NoFindTaggedServiceIdsCallRule context-aware (#317)
  • e10115b [doctrine] skip AsDoctrineListener attribute in NoDoctrineListenerWithoutCont...
  • 4d9f677 Add failing fixture for a parent class that is not first in its file (#292)
  • 4dd9e08 [ctor] add regression test for setter in loop in NewOverSettersRule (#316)
  • 394b2d0 [symfony] remove NoRequiredOutsideClassRule as too narrow (#315)
  • fa3c397 Skip test classes in NewOverSettersRule (#314)
  • 9007956 [ctor] Skip controllers in NewOverSettersRule (#313)
  • f66d025 [doctrine] Skip unconvertible builders in RequireQueryBuilderOnRepositoryRule...
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the production-dependencies group with 2 updates: [phpstan/phpstan](https://github.com/phpstan/phpstan-phar-composer-source) and [symplify/phpstan-rules](https://github.com/symplify/phpstan-rules).


Updates `phpstan/phpstan` from 2.2.14 to 2.2.16
- [Commits](https://github.com/phpstan/phpstan-phar-composer-source/commits)

Updates `symplify/phpstan-rules` from 14.13.1 to 14.17.0
- [Release notes](https://github.com/symplify/phpstan-rules/releases)
- [Commits](symplify/phpstan-rules@14.13.1...14.17.0)

---
updated-dependencies:
- dependency-name: phpstan/phpstan
  dependency-version: 2.2.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: symplify/phpstan-rules
  dependency-version: 14.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update php code labels Sep 29, 2026
@ildyria
ildyria merged commit 532aab6 into master Sep 29, 2026
7 of 8 checks passed
@dependabot
dependabot Bot deleted the dependabot/composer/production-dependencies-5bfba7f2c2 branch September 29, 2026 09:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant