Conversation
The bundled guzzlehttp/guzzle 7.8.0 and guzzlehttp/psr7 2.6.1 are affected by several security advisories (fixed in 7.15.2 and 2.12.3), and Guzzle calls curl_close(), which is deprecated since PHP 8.5. - Require guzzlehttp/guzzle ^7.15.2 and guzzlehttp/psr7 ^2.12.3 in src/Client/composer.json and regenerate src/Client/lib/Lib with Mozart. - Since 7.11, Guzzle uses PHP 8.0 functions (get_debug_type(), preg_last_error_msg(), ...), provided on PHP 7.x by symfony/polyfill-php80. Mozart bundles its bootstrap.php, but it's normally loaded through Composer's "files" autoloading, which doesn't apply to the bundled libraries, so src/polyfills.php loads it. - Since 7.15, Utils::jsonEncode(), which the generated API client uses for every request body, calls symfony/deprecation-contracts' trigger_deprecation(). Mozart doesn't bundle it and releases don't ship dev dependencies, so every API request would fatal: src/polyfills.php defines it (a silenced E_USER_DEPRECATED) when it doesn't exist. - Constrain the symfony/deprecation-contracts dev dependency to ^2.5: v3 requires PHP 8.1 and its trigger_deprecation() fatals on PHP 7.4 in CI.
Contributor
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 54 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (2)
📒 Files selected for processing (94)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report❌ Patch coverage is
📢 Thoughts on this report? Let us know! |
# Conflicts: # readme.txt
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates the bundled Guzzle HTTP client (
src/Client/lib/Lib, generated by Mozart) from 7.8.0 to 7.15.5, andguzzlehttp/psr7from 2.6.1 to 2.13.1.Why
curl_close(), which is deprecated since PHP 8.5.Changes
src/Client/composer.json: requireguzzlehttp/guzzle^7.15.2andguzzlehttp/psr7^2.12.3;src/Client/lib/Libregenerated with Mozart (composer update "guzzlehttp/*" -W+mozart composeinsrc/Client). No hand edits inlib/.src/polyfills.php, loaded right after the autoloader. It lives outsidesrc/Client, so Mozart and the OpenAPI generator leave it alone:get_debug_type(),preg_last_error_msg(), …). On PHP 7.x these come fromsymfony/polyfill-php80, whosebootstrap.phpMozart does bundle (pointing at the prefixed class), but which is normally loaded through Composer'sfilesautoloading. Sopolyfills.phploads it. It does nothing on PHP 8.0+.Utils::jsonEncode()(used by the generated API client for every request body) callstrigger_deprecation()fromsymfony/deprecation-contracts. Mozart doesn't bundle it and releases are built without dev dependencies, so without a fallback every API request would fatal.polyfills.phpdefines it (a silencedE_USER_DEPRECATED, like Symfony's) when it doesn't exist.composer.json: constrain thesymfony/deprecation-contractsdev dependency to^2.5. v3 requires PHP 8.1 and itstrigger_deprecation()signature fatals on PHP 7.4, which the CI job for 7.4 would hit now that it's called on every request.Testing
curl_close()deprecation is gone).composer install --no-dev, so withoutsymfony/deprecation-contracts) on PHP 7.4, 8.3 and 8.5: a real API request with a JSON body through the bundled client works, and the deprecation is silenced. Withoutpolyfills.phpthe same request fatals on every version (on 7.4 already onget_debug_type()).