Skip to content

chore(deps): bump jolicode/castor from 1.7.0 to 1.8.1 - #147

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/composer/jolicode/castor-1.8.1
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/composer/jolicode/castor-1.8.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps jolicode/castor from 1.7.0 to 1.8.1.

Release notes

Sourced from jolicode/castor's releases.

Release v1.8.1

What's Changed

Fixes

Full Changelog: jolicode/castor@v1.8.0...v1.8.1

Release v1.8.0

What's Changed

Features

Fixes

Documentation

... (truncated)

Changelog

Sourced from jolicode/castor's changelog.

1.8.1 (2026-09-21)

Fixes

  • Revert passing the script run by run_php() as an argument (1.8.0), and give it back to the Castor process through the CASTOR_PHP_REPLACE environment variable: the argument was removed from argv before the script ran, so the tools restarting themselves by re-executing the PHP binary with their own command line (PHPStan, Rector, composer/xdebug-handler, ...) ran Castor instead of themselves. The environment variable survives such a restart, whatever the command line the tool builds

1.8.0 (2026-09-18)

Features

  • Add self-update command to update Castor to the latest version
  • Publish a snapshot pre-release of the main branch on each push, installable with the installer --version=snapshot option or castor self-update --snapshot
  • Phars and static binaries built from a commit that is not a release now report a snapshot version, like v1.7.0-14-g4531440
  • Add a withTrappedSignals() method on the context, to forward the signals received by Castor (like the SIGINT of a CTRL+C) to the process being run, instead of interrupting Castor itself
  • Publish a static binary for Windows and support --os=windows in castor:compile
  • Allow mount() to mount a remote Composer package (mount('composer://org/repo')), like import() already did, with its own namespace prefix and working directory

Security

  • Publish artifact attestations for the phars and static binaries, and verify them in the installer, in self-update and in castor:repack when the GitHub CLI is installed and authenticated
  • Restrict the file name chosen by the server in http_download(): only the last segment of the Content-Disposition file name (or of the URL path) is kept, so the download always lands in the project directory
  • Never download the remote packages during a shell completion: the packages already installed are used, and the completion goes on without the remote imports when there is none
  • Publish a SHA256SUMS file, attested too, with each release and the snapshot pre-release, and verify the checksum of the downloaded binary in self-update
  • Only accept attestations signed by the Artifacts workflow when verifying the provenance of a binary, and skip the verification with a GitHub CLI too old to know about attestations instead of failing
  • Verify the SHA-256 checksum of the static-php-cli archive downloaded by castor:compile: the checksums of the default --spc-version are known, any other version needs the new --spc-sha256 option
  • Verify the checksum of the binary downloaded by the installer against the SHA256SUMS file of the release, download it to a private temporary file removed whatever happens, and read the whole installer script before running anything
  • Prefer the PHP zip extension over the zip binary in zip() when a password is given: the binary gets the password as a command line argument, readable by every user of the machine while the archive is created. zip_binary() still does, and now warns about it
  • Pass the script run by run_php() to the Castor process as an argument instead of the CASTOR_PHP_REPLACE environment variable, which made any Castor process include an arbitrary file when set in its environment
  • Refuse a Castor phar without provenance attestation in castor:repack, like self-update does, unless the new --allow-unattested option is passed for a release published before attestations existed
  • Derive the key of encrypt_with_password() and encrypt_file_with_password() with the "moderate" limits of libsodium (Argon2id, 3 passes, 256 MiB) instead of the "interactive" ones, and store the limits in the encrypted payload. Content encrypted by previous versions is still decrypted, but content encrypted by this version needs it, or a later one, to be decrypted

Deprecations

  • Not defining the CASTOR_USE_CHDIR constant is deprecated. Add defined('CASTOR_USE_CHDIR') || define('CASTOR_USE_CHDIR', true); at the top of your castor.php to opt in (the guard keeps a mounted or imported castor.php from redefining it): Castor then changes its own current directory to the working directory of the context, so fs(), finder() and the raw PHP functions (mkdir(), unlink(), file_get_contents(), ...) resolve relative paths where run() executes, instead of wherever castor was invoked from. It follows with(workingDirectory: ...) too, and is restored when the block ends. This becomes the default in Castor 2.0. Define the constant to false to keep the current behavior without the deprecation.

    Once enabled, a relative path given as a CLI argument (castor castor:compile foo.phar, task arguments, ...) is resolved from the project root rather than from the directory you invoked castor in, which matters when you run Castor from a subdirectory.

Fixes

  • Resolve the remote packages of castor.composer.json against the packages bundled with Castor, declared to Composer as metapackages standing for the versions Castor ships: a package Castor ships is not installed a second time in .castor/vendor, and a package requiring a version Castor does not ship fails at install time with an explanation, instead of Castor crashing at runtime on a mix of the two versions. In castor.composer.lock, these packages follow the versions of the running Castor, and setting extra.castor.bundled-packages to false in castor.composer.json opts out
  • Quote the remote path of ssh_run(), and reject a host, user, jump_host, path_private_key or multiplexing_control_path containing a shell metacharacter: they end up in a local shell command line, so a value coming from user input could run a command instead of opening a connection
  • Pass the container name of wait_for_docker_container() to docker as an argument instead of building a shell command with it
  • Extract the watcher binary used by watch() in the phar and static builds to the user cache directory, under the Castor version, instead of a fixed path in the system temporary directory shared by all users, and replace it when its content is not the expected one
  • Create the cache directory readable by its owner only (mode 0700), and restrict an existing one, as the cache may hold data written by the tasks; honor XDG_CACHE_HOME for its default location, and fall back to a per-user directory in the system temporary directory, instead of one shared by all users, when the home directory cannot be determined
  • Fix architecture detection on Linux ARM64 (aarch64), which made the watcher and the update hints pick the amd64 binaries
  • Fix run() ignoring the timeout when executed inside parallel(): the process was waited for in its own fiber loop, so Symfony's timeout check never ran and the process could run forever
  • Fix with() leaking its context between fibers running under parallel(): since the current context was tracked globally, a fiber resuming or calling with() while another one was suspended inside its own with() block could make it resume with the wrong context, and the wrong context could even survive parallel() itself
  • Fix import() of a remote Composer package changing the working directory of the tasks it defines: only an explicit mount() should do that
Commits
  • 058fedd Merge pull request #898 from jolicode/release-v1-8-1
  • 28eb23a Prepare v1.8.1
  • 6856d9f Merge pull request #897 from jolicode/revert-run-php
  • f0e7dc4 fix(run-php): revert using arg for run php, it fails on process rexecuting hi...
  • 1ff80e6 Merge pull request #894 from jolicode/fix-release-checksums
  • 2ef402e Fix the checksums check of the release task
  • 83a4ee1 Merge pull request #892 from jolicode/prepare-1-8
  • edbe527 Prepare v1.8.0
  • 44f7c73 Update dependencies
  • 0424744 Merge pull request #893 from jolicode/fix-snapshot-tag-on
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [jolicode/castor](https://github.com/jolicode/castor) from 1.7.0 to 1.8.1.
- [Release notes](https://github.com/jolicode/castor/releases)
- [Changelog](https://github.com/jolicode/castor/blob/main/CHANGELOG.md)
- [Commits](jolicode/castor@v1.7.0...v1.8.1)

---
updated-dependencies:
- dependency-name: jolicode/castor
  dependency-version: 1.8.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update php code labels Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants