Skip to content

Update non-major-updates - #49

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/non-major-updates
Open

Update non-major-updates#49
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/non-major-updates

Conversation

@renovate

@renovate renovate Bot commented May 25, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Age Confidence
mariadb (source) minor 12.012.3 age confidence
wp-coding-standards/wpcs require-dev minor 3.3.03.4.1 age confidence

Release Notes

WordPress/WordPress-Coding-Standards (wp-coding-standards/wpcs)

v3.4.1

Compare Source

This is a security release and all users are advised to update their WordPressCS install as soon as possible.

Changed
  • The minimum required PHPCSUtils version to 1.2.3 (was 1.2.2). #​2770
  • The minimum required PHPCSExtra version to 1.5.1 (was 1.5.0). #​2770
  • Various housekeeping, including documentation improvements.
Fixed
  • SECURITY FIX: Running the WordPress.WP.EnqueuedResourceParameters sniff over untrusted PHP code, for example, in a CI pipeline that lints pull requests, or on a developer machine reviewing third-party code, could lead to arbitrary command execution on the scanning host. #​2771
    This affects users of the WordPress and WordPress-Extra rulesets. The WordPress-Core ruleset and the WordPress-Docs ruleset are not affected.
    For more details, see the security advisory.
    Thanks to [@​FORIMOC] for responsibly disclosing the vulnerability.

v3.4.0

Compare Source

We're happy to welcome [@​rodrigoprimo] as co-maintainer of WordPressCS as of this release.

Added
Changed
  • The minimum required PHP_CodeSniffer version to 3.13.5 (was 3.13.4). #​2761
  • The minimum required PHPCSUtils version to 1.2.2 (was 1.1.0). #​2761
  • The default value for minimum_wp_version, as used by a number of sniffs detecting usage of deprecated WP features, has been updated to 6.7. #​2757
  • WordPress.NamingConventions.PrefixAllGlobals has been updated to recognize pluggable functions introduced in WP up to WP 7.0.0. #​2747
  • WordPress.WP.ClassNameCase has been updated to recognize classes introduced in WP up to WP 7.0.0. #​2747
  • WordPress.WP.DeprecatedFunctions now detects functions deprecated in WordPress up to WP 7.0.0. #​2747
  • The ConstantsHelper::is_use_of_global_constant() method will no longer flag a constant alias created via an import use statement as it were the use of a global constant. #​2579
  • The ConstantsHelper::is_in_function_call() method will now act fully case-agnostic for the function names being checked. #​2706
    Previously, the $valid_functions parameter would need to be passed with the function names as keys in lowercase.
  • WordPress.PHP.NoSilencedErrors: error silencing is no longer accepted for the parse_url() function. #​2701
  • Improved the wording of the error message for WordPress.Arrays.ArrayDeclarationSpacing.AssociativeArrayFound. #​2688
  • Improved the wording of the error message for WordPress.PHP.RestrictedPHPFunctions. #​2702
  • Various housekeeping, including documentation and test improvements. Includes a contribution by [@​dd32].
Deprecated
  • WordPress.Arrays.ArrayDeclarationSpacing: the allow_single_item_single_line_associative_arrays property has been deprecated in favor of the new allow_single_item_single_line_explicit_key_arrays property. #​2696
    This is a name change only. The functionality of these properties is the same.
Fixed
  • WordPress.DB.PreparedSQL and WordPress.DB.PreparedSQLPlaceholders: false positive for static method calls to a non-global class named wpdb. #​2753
  • WordPress.Security.EscapeOutput: false positive for get_search_query() when the $escaped parameter was passed as fully qualified or non-lowercase true. #​2618
  • WordPress.Security.EscapeOutput: false negative for _deprecated_file() calls when the basename( __FILE__ ) pattern used non-standard casing for either basename() and/or __FILE__. #​2729
  • WordPress.WP.AlternativeFunctions: false negative when class functions/constants/properties use the same name as select global WP constants/functions. #​2617
  • WordPress.WP.AlternativeFunctions: false positive for fully qualified references to the global PHP stream constants \STDIN, \STDOUT, and \STDERR. #​2617
  • WordPress.WP.CronInterval: false positive when the callback function reference used a different case than the function declaration, even though they are in the same file. #​2730

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "after 8am on Monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot changed the title Update mariadb Docker tag to v12.2 Update non-major-updates Jul 19, 2026
@renovate
renovate Bot force-pushed the renovate/non-major-updates branch from c075a81 to 34912f2 Compare July 19, 2026 04:02
@renovate
renovate Bot force-pushed the renovate/non-major-updates branch from 34912f2 to 144ac82 Compare July 27, 2026 14:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants