Skip to content

Update the bundled Guzzle to 7.15.5 - #328

Open
Dan0sz wants to merge 2 commits into
developfrom
update_guzzle
Open

Dan0sz wants to merge 2 commits into
developfrom
update_guzzle

Conversation

@Dan0sz

@Dan0sz Dan0sz commented Sep 29, 2026

Copy link
Copy Markdown
Collaborator

Updates the bundled Guzzle HTTP client (src/Client/lib/Lib, generated by Mozart) from 7.8.0 to 7.15.5, and guzzlehttp/psr7 from 2.6.1 to 2.13.1.

Why

  • The bundled versions are affected by several security advisories, fixed in Guzzle 7.15.2 and psr7 2.12.3 (e.g. GHSA-v5mv-p594-2x33, GHSA-f7vp-7xgx-4w4r, GHSA-c2w2-prh8-qm98). The plugin only talks to a fixed Plausible API URL without cookies or redirects, so the practical impact is limited, but security scanners flag bundled vulnerable libraries.
  • Guzzle 7.8 calls curl_close(), which is deprecated since PHP 8.5.

Changes

  • src/Client/composer.json: require guzzlehttp/guzzle ^7.15.2 and guzzlehttp/psr7 ^2.12.3; src/Client/lib/Lib regenerated with Mozart (composer update "guzzlehttp/*" -W + mozart compose in src/Client). No hand edits in lib/.
  • New src/polyfills.php, loaded right after the autoloader. It lives outside src/Client, so Mozart and the OpenAPI generator leave it alone:
    • Since 7.11, Guzzle uses PHP 8.0 functions (get_debug_type(), preg_last_error_msg(), …). On PHP 7.x these come from symfony/polyfill-php80, whose bootstrap.php Mozart does bundle (pointing at the prefixed class), but which is normally loaded through Composer's files autoloading. So polyfills.php loads it. It does nothing on PHP 8.0+.
    • Since 7.15, Utils::jsonEncode() (used by the generated API client for every request body) calls trigger_deprecation() from symfony/deprecation-contracts. Mozart doesn't bundle it and releases are built without dev dependencies, so without a fallback every API request would fatal. polyfills.php defines it (a silenced E_USER_DEPRECATED, like Symfony's) when it doesn't exist.
  • Root composer.json: constrain the symfony/deprecation-contracts dev dependency to ^2.5. v3 requires PHP 8.1 and its trigger_deprecation() signature fatals on PHP 7.4, which the CI job for 7.4 would hit now that it's called on every request.
  • Changelog entry under 2.6.2.

Testing

  • Full test suite passes on PHP 7.4, 8.3 and 8.5 (on 8.5 the curl_close() deprecation is gone).
  • Release-build simulation (composer install --no-dev, so without symfony/deprecation-contracts) on PHP 7.4, 8.3 and 8.5: a real API request with a JSON body through the bundled client works, and the deprecation is silenced. Without polyfills.php the same request fatals on every version (on 7.4 already on get_debug_type()).
  • Live site on PHP 7.4 and 8.3: saving the settings (goal, funnel and custom property provisioning against the real API) works without errors and leaves the funnels intact.

The bundled guzzlehttp/guzzle 7.8.0 and guzzlehttp/psr7 2.6.1 are affected
by several security advisories (fixed in 7.15.2 and 2.12.3), and Guzzle
calls curl_close(), which is deprecated since PHP 8.5.

- Require guzzlehttp/guzzle ^7.15.2 and guzzlehttp/psr7 ^2.12.3 in
  src/Client/composer.json and regenerate src/Client/lib/Lib with Mozart.
- Since 7.11, Guzzle uses PHP 8.0 functions (get_debug_type(),
  preg_last_error_msg(), ...), provided on PHP 7.x by
  symfony/polyfill-php80. Mozart bundles its bootstrap.php, but it's
  normally loaded through Composer's "files" autoloading, which doesn't
  apply to the bundled libraries, so src/polyfills.php loads it.
- Since 7.15, Utils::jsonEncode(), which the generated API client uses for
  every request body, calls symfony/deprecation-contracts'
  trigger_deprecation(). Mozart doesn't bundle it and releases don't ship
  dev dependencies, so every API request would fatal: src/polyfills.php
  defines it (a silenced E_USER_DEPRECATED) when it doesn't exist.
- Constrain the symfony/deprecation-contracts dev dependency to ^2.5: v3
  requires PHP 8.1 and its trigger_deprecation() fatals on PHP 7.4 in CI.
@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 54 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 5ba7d8cc-9f2f-47f0-992b-9f8efe3092aa

📥 Commits

Reviewing files that changed from the base of the PR and between 5951eae and ea03bed.

⛔ Files ignored due to path filters (2)
  • composer.lock is excluded by !**/*.lock
  • src/Client/composer.lock is excluded by !**/*.lock
📒 Files selected for processing (94)
  • composer.json
  • plausible-analytics.php
  • readme.txt
  • src/Client/composer.json
  • src/Client/lib/Lib/GuzzleHttp/BodySummarizer.php
  • src/Client/lib/Lib/GuzzleHttp/Client.php
  • src/Client/lib/Lib/GuzzleHttp/ClientInterface.php
  • src/Client/lib/Lib/GuzzleHttp/Cookie/CookieJar.php
  • src/Client/lib/Lib/GuzzleHttp/Cookie/CookieJarInterface.php
  • src/Client/lib/Lib/GuzzleHttp/Cookie/FileCookieJar.php
  • src/Client/lib/Lib/GuzzleHttp/Cookie/SessionCookieJar.php
  • src/Client/lib/Lib/GuzzleHttp/Cookie/SetCookie.php
  • src/Client/lib/Lib/GuzzleHttp/Exception/BadResponseException.php
  • src/Client/lib/Lib/GuzzleHttp/Exception/ConnectException.php
  • src/Client/lib/Lib/GuzzleHttp/Exception/RequestException.php
  • src/Client/lib/Lib/GuzzleHttp/Handler/CurlFactory.php
  • src/Client/lib/Lib/GuzzleHttp/Handler/CurlHandler.php
  • src/Client/lib/Lib/GuzzleHttp/Handler/CurlMultiHandler.php
  • src/Client/lib/Lib/GuzzleHttp/Handler/CurlShareHandleState.php
  • src/Client/lib/Lib/GuzzleHttp/Handler/CurlVersion.php
  • src/Client/lib/Lib/GuzzleHttp/Handler/EasyHandle.php
  • src/Client/lib/Lib/GuzzleHttp/Handler/HeaderProcessor.php
  • src/Client/lib/Lib/GuzzleHttp/Handler/HostValidator.php
  • src/Client/lib/Lib/GuzzleHttp/Handler/MockHandler.php
  • src/Client/lib/Lib/GuzzleHttp/Handler/Proxy.php
  • src/Client/lib/Lib/GuzzleHttp/Handler/ProxyEnvironment.php
  • src/Client/lib/Lib/GuzzleHttp/Handler/StreamHandler.php
  • src/Client/lib/Lib/GuzzleHttp/Handler/TlsVersion.php
  • src/Client/lib/Lib/GuzzleHttp/HandlerStack.php
  • src/Client/lib/Lib/GuzzleHttp/MessageFormatter.php
  • src/Client/lib/Lib/GuzzleHttp/MessageFormatterInterface.php
  • src/Client/lib/Lib/GuzzleHttp/Middleware.php
  • src/Client/lib/Lib/GuzzleHttp/Multiplexing.php
  • src/Client/lib/Lib/GuzzleHttp/Pool.php
  • src/Client/lib/Lib/GuzzleHttp/PrepareBodyMiddleware.php
  • src/Client/lib/Lib/GuzzleHttp/Promise/Coroutine.php
  • src/Client/lib/Lib/GuzzleHttp/Promise/Create.php
  • src/Client/lib/Lib/GuzzleHttp/Promise/Each.php
  • src/Client/lib/Lib/GuzzleHttp/Promise/EachPromise.php
  • src/Client/lib/Lib/GuzzleHttp/Promise/FulfilledPromise.php
  • src/Client/lib/Lib/GuzzleHttp/Promise/Promise.php
  • src/Client/lib/Lib/GuzzleHttp/Promise/PromiseInterface.php
  • src/Client/lib/Lib/GuzzleHttp/Promise/RejectedPromise.php
  • src/Client/lib/Lib/GuzzleHttp/Promise/Utils.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/AppendStream.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/BufferStream.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/CachingStream.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/DroppingStream.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/FnStream.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/Header.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/HttpFactory.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/InflateStream.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/LimitStream.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/Message.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/MessageTrait.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/MimeType.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/MultipartStream.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/NoSeekStream.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/PumpStream.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/Query.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/Request.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/Response.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/Rfc3986.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/Rfc7230.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/ServerRequest.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/Stream.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/StreamDecoratorTrait.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/StreamWrapper.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/UploadedFile.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/Uri.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/UriComparator.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/UriNormalizer.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/UriResolver.php
  • src/Client/lib/Lib/GuzzleHttp/Psr7/Utils.php
  • src/Client/lib/Lib/GuzzleHttp/RedirectMiddleware.php
  • src/Client/lib/Lib/GuzzleHttp/RequestOptions.php
  • src/Client/lib/Lib/GuzzleHttp/RetryMiddleware.php
  • src/Client/lib/Lib/GuzzleHttp/TransferStats.php
  • src/Client/lib/Lib/GuzzleHttp/TransportSharing.php
  • src/Client/lib/Lib/GuzzleHttp/Utils.php
  • src/Client/lib/Lib/GuzzleHttp/functions.php
  • src/Client/lib/Lib/Psr/Http/Message/UploadedFileFactoryInterface.php
  • src/Client/lib/Lib/Symfony/Polyfill/Php80/LICENSE
  • src/Client/lib/Lib/Symfony/Polyfill/Php80/Php80.php
  • src/Client/lib/Lib/Symfony/Polyfill/Php80/PhpToken.php
  • src/Client/lib/Lib/Symfony/Polyfill/Php80/README.md
  • src/Client/lib/Lib/Symfony/Polyfill/Php80/Resources/stubs/Attribute.php
  • src/Client/lib/Lib/Symfony/Polyfill/Php80/Resources/stubs/PhpToken.php
  • src/Client/lib/Lib/Symfony/Polyfill/Php80/Resources/stubs/Stringable.php
  • src/Client/lib/Lib/Symfony/Polyfill/Php80/Resources/stubs/UnhandledMatchError.php
  • src/Client/lib/Lib/Symfony/Polyfill/Php80/Resources/stubs/ValueError.php
  • src/Client/lib/Lib/Symfony/Polyfill/Php80/bootstrap.php
  • src/Client/lib/Lib/Symfony/Polyfill/Php80/composer.json
  • src/polyfills.php
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Sep 29, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 0% with 1 line in your changes missing coverage. Please review.

Files with missing lines Patch % Lines
src/polyfills.php 0.00% 1 Missing ⚠️

📢 Thoughts on this report? Let us know!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant