[10.15.0] chore(deps): bump phpseclib/phpseclib from 3.0.38 to 3.0.39#41276
[10.15.0] chore(deps): bump phpseclib/phpseclib from 3.0.38 to 3.0.39#41276jnweiger merged 2 commits intorelease-10.15.0from
Conversation
Bumps [phpseclib/phpseclib](https://github.com/phpseclib/phpseclib) from 3.0.38 to 3.0.39. - [Release notes](https://github.com/phpseclib/phpseclib/releases) - [Changelog](https://github.com/phpseclib/phpseclib/blob/master/CHANGELOG.md) - [Commits](phpseclib/phpseclib@3.0.38...3.0.39) --- updated-dependencies: - dependency-name: phpseclib/phpseclib dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
|
Note: because of the move of changelog items in a release branch, it will reduce merge-back problems if we apply this change here, and it will end up in master when this branch is merged back to master. For this reason, I have put #41274 into draft mode - we don't want to merge that direct to master and make merge-conflict problems. |
|
|
@jnweiger please have a look. I think that we should do something, not release with 3.0.38 |
|
@jnweiger there are also other dependency bump PRs by dependabot that were created last night: #41280 symfony/console - nothing important in that I will leave those unmerged to reduce the chance of any silly conflict when merging-back release-10.15.0 Where are we up to with the 10.15.0 release process? |
|
@jnweiger ping See comments above. |
* chore(deps): bump phpseclib/phpseclib from 3.0.38 to 3.0.39 Bumps [phpseclib/phpseclib](https://github.com/phpseclib/phpseclib) from 3.0.38 to 3.0.39. - [Release notes](https://github.com/phpseclib/phpseclib/releases) - [Changelog](https://github.com/phpseclib/phpseclib/blob/master/CHANGELOG.md) - [Commits](phpseclib/phpseclib@3.0.38...3.0.39) --- updated-dependencies: - dependency-name: phpseclib/phpseclib dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> * chore(deps): changelog for phpseclib 3.0.39 --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>



Description
Apply dependabot PR #41274 to release-10.15.0
phpseclib/phpseclib#2009 has a fix for an issue introduced in 3.0.38 and 3.0.38 is already in release-10.15.0
IMO we should not release with 3.0.38 - we should move forward to 3.0.39
How Has This Been Tested?
CI
Types of changes
Checklist: