Skip to content

chore(deps-dev): bump phpunit/phpunit from 12.5.37 to 13.4.1 in /tools/phpunit - #2675

Open
dependabot[bot] wants to merge 1 commit into
1.xfrom
dependabot/composer/tools/phpunit/phpunit/phpunit-13.4.1
Open

dependabot[bot] wants to merge 1 commit into
1.xfrom
dependabot/composer/tools/phpunit/phpunit/phpunit-13.4.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Bumps phpunit/phpunit from 12.5.37 to 13.4.1.

Release notes

Sourced from phpunit/phpunit's releases.

PHPUnit 13.4.1

Changed

  • The Software Bill of Materials (SBOM) embedded in the PHAR now uses CycloneDX 1.7 and provides the NTIA minimum elements as well as the data fields that BSI TR-03183-2 (version 2.1.0) requires for logical and identified components, including component creators, original, distribution and effective licences, source code URIs, and the PHP runtime and its extensions as external components

Fixed

  • #7029: TestSuite::runTests() doubles garbage collector time when zend.exception_ignore_args is off
  • setUpBeforeClass() and tearDownAfterClass() were run twice for a test class that is the only test class in a test suite of the XML configuration file that has the name of that test class
  • Tests could not be run in process isolation when the path of the bootstrap script, the test file, or the directory for temporary files contained a single quote
  • Arguments in the --ARGS-- section of a PHPT test that start with - were interpreted by PHP instead of being passed to the test when the test also has a --STDIN-- section
  • Recording the tests that passed in a child process copied all tests that had passed so far, which made running many tests in process isolation increasingly slow

Learn how to install or update PHPUnit 13.4 in the documentation.

Keep up to date with PHPUnit:

PHPUnit 13.4.0

Added

  • #6585: executionOrder attribute values and --order-by token lists that spell the order before defects, for example duration-ascending,defects
  • #6585: pipeline() on the TestSuite\Sorted event for inspecting which reordering stages were applied
  • #6686: Constraint::negatedToString() and Constraint::negatedFailureDescription() for authoring the description of a constraint that is wrapped in LogicalNot
  • #6863: Cache which tests a test file contains
  • #6957: Allow ordering tests by the time their source files were last modified
  • #6958: Select the tests that are in all of several groups
  • #6960: Record the order in which methods of mock objects are invoked
  • #6964: #[RequiresClass] attribute to skip a test if a class does not exist
  • #6995: ChildProcessExtension interface for extensions that need to be bootstrapped in the child process of a test that runs in process isolation
  • --coverage-jsonl CLI option and <jsonl> element for the XML configuration file to write a code coverage report in JSONL format, one JSON object per line, that reports uncovered code rather than every executable line
  • --timeout CLI option to limit the wall-clock time of the entire test run
  • requireCoverageMetadataOnSmallTests, requireCoverageMetadataOnMediumTests, and requireCoverageMetadataOnLargeTests attributes for the XML configuration file to require code coverage metadata depending on the size of a test; these have precedence over requireCoverageMetadata

Changed

  • Output printed by a test is now shown in the compact output as a --- OUTPUT: record that is attributed to the test instead of being passed through unformatted; the record is omitted when beStrictAboutOutputDuringTests or --disallow-test-output already reports the output as risky

Deprecated

  • #6585: Writing defects before the order for --order-by and executionOrder, which will change meaning in PHPUnit 14
  • #6585: depends and no-depends for --order-by and executionOrder
  • #6585: Configuring more than one order for --order-by and executionOrder
  • #6585: Unknown values for the executionOrder XML configuration attribute, which are currently ignored
  • #6686: Constraint::failureDescriptionInContext() and LogicalNot::negate()
  • #6999: Class-level #[Group], #[Ticket], #[Small], #[Medium], and #[Large] on parent classes of test classes

... (truncated)

Changelog

Sourced from phpunit/phpunit's changelog.

[13.4.1] - 2026-10-05

Changed

  • The Software Bill of Materials (SBOM) embedded in the PHAR now uses CycloneDX 1.7 and provides the NTIA minimum elements as well as the data fields that BSI TR-03183-2 (version 2.1.0) requires for logical and identified components, including component creators, original, distribution and effective licences, source code URIs, and the PHP runtime and its extensions as external components

Fixed

  • #7029: TestSuite::runTests() doubles garbage collector time when zend.exception_ignore_args is off
  • setUpBeforeClass() and tearDownAfterClass() were run twice for a test class that is the only test class in a test suite of the XML configuration file that has the name of that test class
  • Tests could not be run in process isolation when the path of the bootstrap script, the test file, or the directory for temporary files contained a single quote
  • Arguments in the --ARGS-- section of a PHPT test that start with - were interpreted by PHP instead of being passed to the test when the test also has a --STDIN-- section
  • Recording the tests that passed in a child process copied all tests that had passed so far, which made running many tests in process isolation increasingly slow

[13.4.0] - 2026-10-02

Added

  • #6585: executionOrder attribute values and --order-by token lists that spell the order before defects, for example duration-ascending,defects
  • #6585: pipeline() on the TestSuite\Sorted event for inspecting which reordering stages were applied
  • #6686: Constraint::negatedToString() and Constraint::negatedFailureDescription() for authoring the description of a constraint that is wrapped in LogicalNot
  • #6863: Cache which tests a test file contains
  • #6957: Allow ordering tests by the time their source files were last modified
  • #6958: Select the tests that are in all of several groups
  • #6960: Record the order in which methods of mock objects are invoked
  • #6964: #[RequiresClass] attribute to skip a test if a class does not exist
  • #6995: ChildProcessExtension interface for extensions that need to be bootstrapped in the child process of a test that runs in process isolation
  • --coverage-jsonl CLI option and <jsonl> element for the XML configuration file to write a code coverage report in JSONL format, one JSON object per line, that reports uncovered code rather than every executable line
  • --timeout CLI option to limit the wall-clock time of the entire test run
  • requireCoverageMetadataOnSmallTests, requireCoverageMetadataOnMediumTests, and requireCoverageMetadataOnLargeTests attributes for the XML configuration file to require code coverage metadata depending on the size of a test; these have precedence over requireCoverageMetadata

Changed

  • Output printed by a test is now shown in the compact output as a --- OUTPUT: record that is attributed to the test instead of being passed through unformatted; the record is omitted when beStrictAboutOutputDuringTests or --disallow-test-output already reports the output as risky

Deprecated

  • #6585: Writing defects before the order for --order-by and executionOrder, which will change meaning in PHPUnit 14
  • #6585: depends and no-depends for --order-by and executionOrder
  • #6585: Configuring more than one order for --order-by and executionOrder
  • #6585: Unknown values for the executionOrder XML configuration attribute, which are currently ignored
  • #6686: Constraint::failureDescriptionInContext() and LogicalNot::negate()
  • #6999: Class-level #[Group], #[Ticket], #[Small], #[Medium], and #[Large] on parent classes of test classes

Fixed

  • Issues that are listed in the baseline are not ignored for tests that are run in a separate process
  • A test that is run in process isolation aborts the test run when its result cannot be unserialized, for instance because it returns an object that holds a test double
  • A test that uses #[DataProviderClosure] errors when it is run in process isolation

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [phpunit/phpunit](https://github.com/sebastianbergmann/phpunit) from 12.5.37 to 13.4.1.
- [Release notes](https://github.com/sebastianbergmann/phpunit/releases)
- [Changelog](https://github.com/sebastianbergmann/phpunit/blob/13.4.1/ChangeLog-13.4.md)
- [Commits](sebastianbergmann/phpunit@12.5.37...13.4.1)

---
updated-dependencies:
- dependency-name: phpunit/phpunit
  dependency-version: 13.4.1
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from norberttech as a code owner October 9, 2026 04:32
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update php code labels Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update php code size: L

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants