Update Composer and npm dependencies to latest
Composer: ~40 Symfony 7.4.x packages patched to 7.4.17, plus four majors - doctrine/dbal 3->4, phpdocumentor/reflection-docblock 5->6, symfony/mercure-bundle 0.3->0.5, symfony/monolog-bundle 3->4. Removed two doctrine.yaml keys (use_savepoints, report_fields_where_declared) that DBAL 4 deprecated in favor of fixed defaults. npm: @symfony/webpack-encore 4->6, which required bumping its peers webpack-cli 5->6 and sass-loader 14->16 together, plus babel-loader 9->10. Fixes the one high-severity audit finding (RCE in serialize-javascript, via the old css-minimizer-webpack-plugin). One moderate finding remains in webpack-notifier's dev-only notification chain - audit's suggested fix would downgrade it, so left alone; it's build tooling only, never shipped to users. Verified: full test suite green, lint:container clean, both `encore dev` and `npm run build` compile without errors, and the production CSS output was inspected byte-for-byte to confirm the new SVG-minifier warnings (on Bootstrap's pre-encoded icon data-URIs) don't corrupt anything. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -15,11 +15,9 @@ doctrine:
|
||||
#server_version: '16'
|
||||
|
||||
profiling_collect_backtrace: '%kernel.debug%'
|
||||
use_savepoints: true
|
||||
orm:
|
||||
auto_generate_proxy_classes: true
|
||||
enable_lazy_ghost_objects: true
|
||||
report_fields_where_declared: true
|
||||
validate_xml_mapping: true
|
||||
naming_strategy: doctrine.orm.naming_strategy.underscore_number_aware
|
||||
auto_mapping: true
|
||||
|
||||
Reference in New Issue
Block a user