[Security] Bump twig/twig from 1.24.1 to 2.12.5
Bumps twig/twig from 1.24.1 to 2.12.5. This update includes a security fix.
Vulnerabilities fixed
Sourced from The PHP Security Advisories Database.
Sandbox Information Disclosure
Affected versions: =2.0.0, <2.7.0
Changelog
Sourced from twig/twig's changelog.
2.12.5 (2020-02-11)
- Add a check to ensure that iconv() is defined
2.12.4 (2020-02-11)
- Avoid exceptions when an intl resource is not found
- Fix implementation of case-insensitivity for method names
2.12.3 (2019-12-28)
- fixed Symfony 5.0 support for the HTML extra extension
- fixed number formatter in Intl extra extension when using a formatter prototype
2.12.2 (2019-11-11)
- added supported for exponential numbers
2.12.1 (2019-10-17)
- added the String extension in the "extra" repositories: "u" filter
2.12.0 (2019-10-05)
- added the spaceship operator (""), useful when using an arrow function in the "sort" filter
- added support for an "arrow" function on the "sort" filter
- added the CssInliner extension in the "extra" repositories: "inline_css" filter
- added the Inky extension in the "extra" repositories: "inky_to_html" filter
- added Intl extension in the "extra" repositories: "country_name", "currency_name", "currency_symbol", "language_name", "locale_name", "timezone_name", "format_currency", "format_number", "format_*_number", "format_datetime", "format_date", and "format_time" filters, and the "country_timezones" function
- added the Markdown extension in the "extra" repositories: "markdown_to_html", and "html_to_markdown" filters
- added the HtmlExtension extension in the "extra" repositories: "date_uri" filter, and "html_classes" function
- optimized "block('foo') ?? 'bar'"
- fixed the empty test on Traversable instances
- fixed array_key_exists() on objects
- fixed cache when opcache is installed but disabled
- fixed using macros in arrow functions
- fixed split filter on edge case
2.11.3 (2019-06-18)
- display partial output (PHP buffer) when an error occurs in debug mode
- fixed the filter filter (allow the result to be used several times)
- fixed macro auto-import when a template contains only macros
Commits
18772e0Prepare the 2.12.5 release1202869allow null string in StringExtensionf0ccbfcbug #3262 Add a check to ensure that iconv() is defined (fabpot)158a853Add a check to ensure that iconv() is definedd8a22bdMerge branch '1.x' into 2.xc984687Fix 7.4 on Travis71ddeccFix versiona460efcBump version to 2.12.5-DEV822d57ePrepare the 2.12.4 release982f8bdBump version to 1.42.6-DEV- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Note: This repo was added to Dependabot recently, so you'll receive a maximum of 5 PRs for your first few update runs. Once an update run creates fewer than 5 PRs we'll remove that limit.
You can always request more updates by clicking Bump now in your Dependabot dashboard.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) -
@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language -
@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language -
@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language -
@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language -
@dependabot badge mewill comment on this PR with code to add a "Dependabot enabled" badge to your readme
Additionally, you can set the following in your Dependabot dashboard:
- Update frequency (including time of day and day of week)
- Pull request limits (per update run and/or open at any time)
- Automerge options (never/patch/minor, and dev/runtime dependencies)
- Out-of-range updates (receive only lockfile updates, if desired)
- Security updates (receive only security updates, if desired)