Skip to content

Bump symfony/cache from 5.1.4 to 5.4.53 - #4

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/composer/symfony/cache-5.4.53
Open

Bump symfony/cache from 5.1.4 to 5.4.53#4
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/composer/symfony/cache-5.4.53

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 17, 2026

Copy link
Copy Markdown
Contributor

Bumps symfony/cache from 5.1.4 to 5.4.53.

Release notes

Sourced from symfony/cache's releases.

v5.4.53

Changelog (symfony/cache@v5.4.52...v5.4.53)

v5.4.52

Changelog (symfony/cache@v5.4.46...v5.4.52)

v5.4.46

Changelog (symfony/cache@v5.4.45...v5.4.46)

v5.4.45

Changelog (symfony/cache@v5.4.44...v5.4.45)

v5.4.44

Changelog (symfony/cache@v5.4.43...v5.4.44)

Changelog

Sourced from symfony/cache's changelog.

CHANGELOG

8.0

  • Remove CouchbaseBucketAdapter, use CouchbaseCollectionAdapter instead

7.4

  • Bump ext-redis to 6.1 and ext-relay to 0.12 minimum

7.3

  • Add support for \Relay\Cluster in RedisAdapter
  • Add support for valkey: / valkeys: schemes
  • Add support for namespace-based invalidation
  • Rename options "redis_cluster" and "redis_sentinel" to "cluster" and "sentinel" respectively

7.2

  • igbinary_serialize() is no longer used instead of serialize() by default when the igbinary extension is installed, due to behavior compatibilities between the two
  • Add optional Psr\Clock\ClockInterface parameter to ArrayAdapter

7.1

  • Add option sentinel_master as an alias for redis_sentinel
  • Deprecate CouchbaseBucketAdapter, use CouchbaseCollectionAdapter
  • Add support for URL encoded characters in Couchbase DSN
  • Add support for using DSN with PDOAdapter
  • The algorithm for the default cache namespace changed from SHA256 to XXH128

7.0

  • Add parameter $isSameDatabase to DoctrineDbalAdapter::configureSchema()
  • Drop support for Postgres < 9.5 and SQL Server < 2008 in DoctrineDbalAdapter

6.4

  • EarlyExpirationHandler no longer implements MessageHandlerInterface, rely on AsMessageHandler instead

6.3

... (truncated)

Commits
  • bf58147 [Cache] skip tests for adapters that cannot clear by prefix
  • 4acd37c [Cache] Accept '_' and ':' in prefix passed to AbstractAdapter::clear()
  • 03b191d [Cache] Validate the prefix given to AbstractAdapter::clear()
  • 0fe08ee [Cache] Fix clear() when using Predis
  • 12b03e3 Revert "bug #58661 [Cache] Initialize RedisAdapter cursor to 0 (thomas-hiron)"
  • e135eb8 initialize RedisAdapter cursor to 0
  • c2b90da do not skip tests from data providers
  • 6cf23ad drop existing schema if tests create it explicitly
  • 7050072 do not mix named and positional arguments in data provider definitions
  • 911f2bc do not use TestCase::getName() when possible
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [symfony/cache](https://github.com/symfony/cache) from 5.1.4 to 5.4.53.
- [Release notes](https://github.com/symfony/cache/releases)
- [Changelog](https://github.com/symfony/cache/blob/8.2/CHANGELOG.md)
- [Commits](symfony/cache@v5.1.4...v5.4.53)

---
updated-dependencies:
- dependency-name: symfony/cache
  dependency-version: 5.4.53
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update php code labels Jul 17, 2026
@private-packagist

Copy link
Copy Markdown

composer.lock

Package changes

Package Operation From To About
psr/container upgrade 1.0.0 1.1.2 diff
psr/log upgrade 1.1.3 1.1.4 diff
symfony/cache upgrade v5.1.4 ⚠️ v5.4.53 ✅ diff
symfony/cache-contracts upgrade v2.1.3 v2.5.4 diff
symfony/deprecation-contracts upgrade v2.5.3 v2.5.4 diff
symfony/polyfill-php73 upgrade v1.18.1 v1.37.0 diff
symfony/polyfill-php80 upgrade v1.31.0 v1.37.0 diff
symfony/service-contracts upgrade v2.1.3 v2.5.4 diff
symfony/var-exporter upgrade v5.1.4 v5.4.45 diff

Settings · Docs · Powered by Private Packagist

@joostfaassen

Copy link
Copy Markdown
Member

🤖 Dependabot PR processing skill — risk assessment

Acting on behalf of Joost Faassen.

Decision

Do not merge automatically — assessed risk: medium

What changed

Title Bump symfony/cache from 5.1.4 to 5.4.53
Semver minor (5.1.45.4.53)
Files (1) composer.lock
Diff size +144 / −110

Why this was not merged automatically

  1. This is a minor bump of a framework/runtime package.
  2. Minor upgrades can still change defaults or deprecations in ways that affect apps.
  3. Left open for human review.

Checks considered

  • Pull request is mergeable with a clean merge state
  • No failing / timed-out / cancelled required checks observed
  • Diff inspected for manifests/lockfiles only vs unexpected paths
  • Package/path screened against sensitive dependency patterns

Automated assessment by the Dependabot PR processing skill. Detail stays in this comment; the merge commit message is kept short on purpose.

4 similar comments
@joostfaassen

Copy link
Copy Markdown
Member

🤖 Dependabot PR processing skill — risk assessment

Acting on behalf of Joost Faassen.

Decision

Do not merge automatically — assessed risk: medium

What changed

Title Bump symfony/cache from 5.1.4 to 5.4.53
Semver minor (5.1.45.4.53)
Files (1) composer.lock
Diff size +144 / −110

Why this was not merged automatically

  1. This is a minor bump of a framework/runtime package.
  2. Minor upgrades can still change defaults or deprecations in ways that affect apps.
  3. Left open for human review.

Checks considered

  • Pull request is mergeable with a clean merge state
  • No failing / timed-out / cancelled required checks observed
  • Diff inspected for manifests/lockfiles only vs unexpected paths
  • Package/path screened against sensitive dependency patterns

Automated assessment by the Dependabot PR processing skill. Detail stays in this comment; the merge commit message is kept short on purpose.

@joostfaassen

Copy link
Copy Markdown
Member

🤖 Dependabot PR processing skill — risk assessment

Acting on behalf of Joost Faassen.

Decision

Do not merge automatically — assessed risk: medium

What changed

Title Bump symfony/cache from 5.1.4 to 5.4.53
Semver minor (5.1.45.4.53)
Files (1) composer.lock
Diff size +144 / −110

Why this was not merged automatically

  1. This is a minor bump of a framework/runtime package.
  2. Minor upgrades can still change defaults or deprecations in ways that affect apps.
  3. Left open for human review.

Checks considered

  • Pull request is mergeable with a clean merge state
  • No failing / timed-out / cancelled required checks observed
  • Diff inspected for manifests/lockfiles only vs unexpected paths
  • Package/path screened against sensitive dependency patterns

Automated assessment by the Dependabot PR processing skill. Detail stays in this comment; the merge commit message is kept short on purpose.

@joostfaassen

Copy link
Copy Markdown
Member

🤖 Dependabot PR processing skill — risk assessment

Acting on behalf of Joost Faassen.

Decision

Do not merge automatically — assessed risk: medium

What changed

Title Bump symfony/cache from 5.1.4 to 5.4.53
Semver minor (5.1.45.4.53)
Files (1) composer.lock
Diff size +144 / −110

Why this was not merged automatically

  1. This is a minor bump of a framework/runtime package.
  2. Minor upgrades can still change defaults or deprecations in ways that affect apps.
  3. Left open for human review.

Checks considered

  • Pull request is mergeable with a clean merge state
  • No failing / timed-out / cancelled required checks observed
  • Diff inspected for manifests/lockfiles only vs unexpected paths
  • Package/path screened against sensitive dependency patterns

Automated assessment by the Dependabot PR processing skill. Detail stays in this comment; the merge commit message is kept short on purpose.

@joostfaassen

Copy link
Copy Markdown
Member

🤖 Dependabot PR processing skill — risk assessment

Acting on behalf of Joost Faassen.

Decision

Do not merge automatically — assessed risk: medium

What changed

Title Bump symfony/cache from 5.1.4 to 5.4.53
Semver minor (5.1.45.4.53)
Files (1) composer.lock
Diff size +144 / −110

Why this was not merged automatically

  1. This is a minor bump of a framework/runtime package.
  2. Minor upgrades can still change defaults or deprecations in ways that affect apps.
  3. Left open for human review.

Checks considered

  • Pull request is mergeable with a clean merge state
  • No failing / timed-out / cancelled required checks observed
  • Diff inspected for manifests/lockfiles only vs unexpected paths
  • Package/path screened against sensitive dependency patterns

Automated assessment by the Dependabot PR processing skill. Detail stays in this comment; the merge commit message is kept short on purpose.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant