Skip to content

Bump webonyx/graphql-php from 15.30.2 to 15.33.1#3712

Draft
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/composer/webonyx/graphql-php-15.32.3
Draft

Bump webonyx/graphql-php from 15.30.2 to 15.33.1#3712
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/composer/webonyx/graphql-php-15.32.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 4, 2026

Copy link
Copy Markdown
Contributor

Bumps webonyx/graphql-php from 15.30.2 to 15.33.1.

Release notes

Sourced from webonyx/graphql-php's releases.

v15.33.1

Fixed

v15.33.0

Added

v15.32.3

Fixed

  • Denial of Service via stack overflow from deeply nested queries in the parser GHSA-r7cg-qjjm-xhqq

v15.32.2

Fixed

  • Denial of Service via quadratic complexity in OverlappingFieldsCanBeMerged validation through inline fragments GHSA-fc86-6rv6-2jpm

v15.32.1

Fix "Cannot traverse an already closed generator" in Schema::getTypeMap() webonyx/graphql-php#1903

v15.32.0

Added

v15.31.5

Fixed

  • Denial of Service via quadratic complexity in OverlappingFieldsCanBeMerged validation GHSA-68jq-c3rv-pcrr

v15.31.4

Changed

v15.31.3

Fixed

v15.31.2

Changed

Fixed

... (truncated)

Changelog

Sourced from webonyx/graphql-php's changelog.

v15.33.1

Fixed

v15.33.0

Added

v15.32.3

Fixed

  • Denial of Service via stack overflow from deeply nested queries in the parser GHSA-r7cg-qjjm-xhqq

v15.32.2

Fixed

  • Denial of Service via quadratic complexity in OverlappingFieldsCanBeMerged validation through inline fragments GHSA-fc86-6rv6-2jpm

v15.32.1

Fixed

v15.32.0

Added

v15.31.5

Fixed

  • Denial of Service via quadratic complexity in OverlappingFieldsCanBeMerged validation GHSA-68jq-c3rv-pcrr

v15.31.4

Changed

v15.31.3

... (truncated)

Commits
  • e0f40ce v15.33.1
  • fa402b1 Merge pull request #1930 from webonyx/fix-single-field-subscription-spec-comp...
  • 60dcb2f Check @skip/@​include directives on fragment-contributed root fields
  • 5bd0575 Update dependency friendsofphp/php-cs-fixer to v3.95.8 (#1932)
  • 4bed264 Document spec compliance status in README and docs
  • 76af9e1 Revert trailing slash removal from Directive.php
  • d6dd273 Document @​see it(...) convention for graphql-js test references
  • 7342712 Fix @​see annotations to match graphql-js test names exactly
  • c903727 Autofix
  • 1910986 Remove trailing slashes from URLs
  • Additional commits viewable in compare view

@williamjallen williamjallen added this pull request to the merge queue May 13, 2026
@github-merge-queue github-merge-queue Bot removed this pull request from the merge queue due to failed status checks May 13, 2026
@williamjallen williamjallen added this pull request to the merge queue May 13, 2026
@github-merge-queue github-merge-queue Bot removed this pull request from the merge queue due to failed status checks May 13, 2026
@williamjallen williamjallen added this pull request to the merge queue May 13, 2026
@github-merge-queue github-merge-queue Bot removed this pull request from the merge queue due to failed status checks May 13, 2026
@williamjallen williamjallen added this pull request to the merge queue May 13, 2026
@github-merge-queue github-merge-queue Bot removed this pull request from the merge queue due to failed status checks May 13, 2026
@williamjallen williamjallen added this pull request to the merge queue May 13, 2026
@github-merge-queue github-merge-queue Bot removed this pull request from the merge queue due to failed status checks May 13, 2026
@williamjallen williamjallen added this pull request to the merge queue May 13, 2026
@github-merge-queue github-merge-queue Bot removed this pull request from the merge queue due to failed status checks May 13, 2026
@williamjallen

Copy link
Copy Markdown
Collaborator

Converting to draft for further investigation.

@williamjallen williamjallen marked this pull request as draft May 13, 2026 15:55
@williamjallen

Copy link
Copy Markdown
Collaborator

@dependabot rebase

@dependabot dependabot Bot force-pushed the dependabot/composer/webonyx/graphql-php-15.32.3 branch from 3d1224b to 88c1f46 Compare May 14, 2026 14:48
@williamjallen

Copy link
Copy Markdown
Collaborator

@dependabot rebase

@dependabot dependabot Bot force-pushed the dependabot/composer/webonyx/graphql-php-15.32.3 branch from 88c1f46 to f9cd447 Compare May 14, 2026 15:25
@williamjallen

Copy link
Copy Markdown
Collaborator

@dependabot recreate

Bumps [webonyx/graphql-php](https://github.com/webonyx/graphql-php) from 15.30.2 to 15.33.1.
- [Release notes](https://github.com/webonyx/graphql-php/releases)
- [Changelog](https://github.com/webonyx/graphql-php/blob/master/CHANGELOG.md)
- [Commits](webonyx/graphql-php@v15.30.2...v15.33.1)

---
updated-dependencies:
- dependency-name: webonyx/graphql-php
  dependency-version: 15.32.3
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump webonyx/graphql-php from 15.30.2 to 15.32.3 Bump webonyx/graphql-php from 15.30.2 to 15.33.1 Jun 24, 2026
@dependabot dependabot Bot force-pushed the dependabot/composer/webonyx/graphql-php-15.32.3 branch from f9cd447 to 79c8beb Compare June 24, 2026 21:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant