Skip to content

composer: bump phpunit/phpunit from 13.2.4 to 13.4.0 - #115

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/composer/phpunit/phpunit-13.4.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/composer/phpunit/phpunit-13.4.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps phpunit/phpunit from 13.2.4 to 13.4.0.

Release notes

Sourced from phpunit/phpunit's releases.

PHPUnit 13.4.0

Added

  • #6585: executionOrder attribute values and --order-by token lists that spell the order before defects, for example duration-ascending,defects
  • #6585: pipeline() on the TestSuite\Sorted event for inspecting which reordering stages were applied
  • #6686: Constraint::negatedToString() and Constraint::negatedFailureDescription() for authoring the description of a constraint that is wrapped in LogicalNot
  • #6863: Cache which tests a test file contains
  • #6957: Allow ordering tests by the time their source files were last modified
  • #6958: Select the tests that are in all of several groups
  • #6960: Record the order in which methods of mock objects are invoked
  • #6964: #[RequiresClass] attribute to skip a test if a class does not exist
  • #6995: ChildProcessExtension interface for extensions that need to be bootstrapped in the child process of a test that runs in process isolation
  • --coverage-jsonl CLI option and <jsonl> element for the XML configuration file to write a code coverage report in JSONL format, one JSON object per line, that reports uncovered code rather than every executable line
  • --timeout CLI option to limit the wall-clock time of the entire test run
  • requireCoverageMetadataOnSmallTests, requireCoverageMetadataOnMediumTests, and requireCoverageMetadataOnLargeTests attributes for the XML configuration file to require code coverage metadata depending on the size of a test; these have precedence over requireCoverageMetadata

Changed

  • Output printed by a test is now shown in the compact output as a --- OUTPUT: record that is attributed to the test instead of being passed through unformatted; the record is omitted when beStrictAboutOutputDuringTests or --disallow-test-output already reports the output as risky

Deprecated

  • #6585: Writing defects before the order for --order-by and executionOrder, which will change meaning in PHPUnit 14
  • #6585: depends and no-depends for --order-by and executionOrder
  • #6585: Configuring more than one order for --order-by and executionOrder
  • #6585: Unknown values for the executionOrder XML configuration attribute, which are currently ignored
  • #6686: Constraint::failureDescriptionInContext() and LogicalNot::negate()
  • #6999: Class-level #[Group], #[Ticket], #[Small], #[Medium], and #[Large] on parent classes of test classes

Fixed

  • Issues that are listed in the baseline are not ignored for tests that are run in a separate process
  • A test that is run in process isolation aborts the test run when its result cannot be unserialized, for instance because it returns an object that holds a test double
  • A test that uses #[DataProviderClosure] errors when it is run in process isolation

Learn how to install or update PHPUnit 13.4 in the documentation.

Keep up to date with PHPUnit:

PHPUnit 13.3.6

Fixed

  • The first attempt of a test that is retried is reported as attempt 1 of 1 in events, instead of attempt 1 of the configured maximum number of attempts
  • The class name argument of #[RequiresMethod] is declared as class-string, so static analysis reports an error when it refers to a class that does not exist
  • A #[RequiresMethod] attribute that refers to a class which cannot be loaded, for instance because its parent class does not exist, aborts the test run instead of skipping the test

... (truncated)

Changelog

Sourced from phpunit/phpunit's changelog.

13.4.0 - 2026-10-02

Added

  • #6585: executionOrder attribute values and --order-by token lists that spell the order before defects, for example duration-ascending,defects
  • #6585: pipeline() on the TestSuite\Sorted event for inspecting which reordering stages were applied
  • #6686: Constraint::negatedToString() and Constraint::negatedFailureDescription() for authoring the description of a constraint that is wrapped in LogicalNot
  • #6863: Cache which tests a test file contains
  • #6957: Allow ordering tests by the time their source files were last modified
  • #6958: Select the tests that are in all of several groups
  • #6960: Record the order in which methods of mock objects are invoked
  • #6964: #[RequiresClass] attribute to skip a test if a class does not exist
  • #6995: ChildProcessExtension interface for extensions that need to be bootstrapped in the child process of a test that runs in process isolation
  • --coverage-jsonl CLI option and <jsonl> element for the XML configuration file to write a code coverage report in JSONL format, one JSON object per line, that reports uncovered code rather than every executable line
  • --timeout CLI option to limit the wall-clock time of the entire test run
  • requireCoverageMetadataOnSmallTests, requireCoverageMetadataOnMediumTests, and requireCoverageMetadataOnLargeTests attributes for the XML configuration file to require code coverage metadata depending on the size of a test; these have precedence over requireCoverageMetadata

Changed

  • Output printed by a test is now shown in the compact output as a --- OUTPUT: record that is attributed to the test instead of being passed through unformatted; the record is omitted when beStrictAboutOutputDuringTests or --disallow-test-output already reports the output as risky

Deprecated

  • #6585: Writing defects before the order for --order-by and executionOrder, which will change meaning in PHPUnit 14
  • #6585: depends and no-depends for --order-by and executionOrder
  • #6585: Configuring more than one order for --order-by and executionOrder
  • #6585: Unknown values for the executionOrder XML configuration attribute, which are currently ignored
  • #6686: Constraint::failureDescriptionInContext() and LogicalNot::negate()
  • #6999: Class-level #[Group], #[Ticket], #[Small], #[Medium], and #[Large] on parent classes of test classes

Fixed

  • Issues that are listed in the baseline are not ignored for tests that are run in a separate process
  • A test that is run in process isolation aborts the test run when its result cannot be unserialized, for instance because it returns an object that holds a test double
  • A test that uses #[DataProviderClosure] errors when it is run in process isolation
Commits
  • ef714df Prepare release
  • 6545c10 Update dependency seld/phar-utils to ^1.2.3
  • 1e87210 Increase timeouts
  • 539e81f Use compact/streaming output in CI
  • 5d7d7ee Update dependencies
  • 3c5dd28 Do not put the closure of a #[DataProviderClosure] attribute into the metadat...
  • a1d3b1d Merge branch '12.5' into 13.4
  • 2da7926 Report a test that was run in process isolation as errored when its result ca...
  • fa3d04d Merge branch '12.5' into 13.4
  • 85a8449 Use the baseline in the child process of a test that is run in process isolation
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [phpunit/phpunit](https://github.com/sebastianbergmann/phpunit) from 13.2.4 to 13.4.0.
- [Release notes](https://github.com/sebastianbergmann/phpunit/releases)
- [Changelog](https://github.com/sebastianbergmann/phpunit/blob/13.4.0/ChangeLog-13.4.md)
- [Commits](sebastianbergmann/phpunit@13.2.4...13.4.0)

---
updated-dependencies:
- dependency-name: phpunit/phpunit
  dependency-version: 13.4.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update php code labels Oct 5, 2026
@coderabbitai

coderabbitai Bot commented Oct 5, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 79d1bb53-1b95-45d8-8cc3-1361824721cf

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants