Skip to content

[Renovate] Update dependency phpunit/phpunit to v13 [SECURITY] [HIGH] - #21

Open
appsec-renovate-bot[bot] wants to merge 1 commit into
masterfrom
renovate/major-composer-security-fixes
Open

[Renovate] Update dependency phpunit/phpunit to v13 [SECURITY] [HIGH]#21
appsec-renovate-bot[bot] wants to merge 1 commit into
masterfrom
renovate/major-composer-security-fixes

Conversation

@appsec-renovate-bot

@appsec-renovate-bot appsec-renovate-bot Bot commented Aug 27, 2026

Copy link
Copy Markdown

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change
phpunit/phpunit (source) require-dev major ~4.0|~5.013.3.2

PHPUnit Vulnerable to Unsafe Deserialization in PHPT Code Coverage Handling

CVE-2026-24765 / GHSA-vvj3-c3rp-c85p

More information

Details

Overview

A vulnerability has been discovered involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the cleanupForCoverage() method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious .coverage files are present prior to the execution of the PHPT test.

Technical Details

Affected Component: PHPT test runner, method cleanupForCoverage()
Affected Versions: <= 8.5.51, <= 9.6.32, <= 10.5.61, <= 11.5.49, <= 12.5.7

Vulnerable Code Pattern
if ($buffer !== false) {
    // Unsafe call without restrictions
    $coverage = @unserialize($buffer);
}

The vulnerability occurs when a .coverage file, which should not exist before test execution, is deserialized without the allowed_classes parameter restriction. An attacker with local file write access can place a malicious serialized object with a __wakeup() method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled.

Attack Prerequisites and Constraints

This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through:

  • CI/CD Pipeline Attacks: A malicious pull request that places a .coverage file alongside test files, executed when the CI system runs tests using PHPUnit and collects code coverage information
  • Local Development Environment: An attacker with shell access or ability to write files to the project directory
  • Compromised Dependencies: A supply chain attack inserting malicious files into a package or monorepo

Critical Context: Running test suites from unreviewed pull requests without isolated execution is inherently a code execution risk, independent of this specific vulnerability. This represents a broader class of Poisoned Pipeline Execution (PPE) attacks affecting CI/CD systems.

Proposed Remediation Approach

Rather than just silently sanitizing the input via ['allowed_classes' => false], the maintainer has chosen to make the anomalous state explicit by treating pre-existing .coverage files for PHPT tests as an error condition.

Rationale for Error-Based Approach:
  1. Visibility Over Silence: When an invariant is violated (a .coverage file existing before test execution), the error must be visible in CI/CD output, alerting operators to investigate the root cause rather than proceeding with sanitized input
  2. Operational Security: A .coverage file should never exist before tests run, coverage data is generated by executing tests, not sourced from artifacts. Its presence indicates:
    • A malicious actor placed it intentionally
    • Build artifacts from a previous run contaminated the environment
    • An unexpected filesystem state requiring investigation
  3. Defense-in-Depth Principle: Protecting a single deserialization call does not address the fundamental attack surface. Proper mitigations for PPE attacks lie outside PHPUnit's scope:
    • Isolate CI/CD runners (ephemeral, containerized environments)
    • Restrict code execution on protected branches
    • Scan pull requests and artifacts for tampering
    • Use branch protection rules to prevent unreviewed code execution
Severity Classification
  • Attack Vector (AV): Local (L) — requires write access to the file system where tests execute
  • Attack Complexity (AC): Low (L) — exploitation is straightforward once the malicious file is placed
  • Privileges Required (PR): Low (L) — PR submitter status or contributor role provides sufficient access
  • User Interaction (UI): None (N) — automatic execution during standard test execution
  • Scope (S): Unchanged (U) — impact remains within the affected test execution context
  • Confidentiality Impact (C): High (H) — full remote code execution enables complete system compromise
  • Integrity Impact (I): High (H) — arbitrary code execution allows malicious modifications
  • Availability Impact (A): High (H) — full code execution permits denial-of-service actions
Mitigating Factors (Environmental Context)

Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration:

  • Ephemeral Runners: Use containerized, single-use CI/CD runners that discard filesystem state between runs
  • Code Review Enforcement: Require human review and approval before executing code from pull requests
  • Branch Protection: Enforce branch protection rules that block unreviewed code execution
  • Artifact Isolation: Separate build artifacts from source; never reuse artifacts across independent builds
  • Access Control: Limit file write permissions in CI environments to authenticated, trusted actors
Fixed Behaviour

When a .coverage file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. This ensures:

  • Visibility: The error appears prominently in CI/CD output and test logs
  • Investigation: Operations teams can investigate the root cause (potential tampering, environment contamination)
  • Fail-Fast Semantics: Test execution stops rather than proceeding with an unexpected state
Recommendation

Update to the patched version immediately if a project runs PHPT tests using PHPUnit with coverage instrumentation in any CI/CD environment that executes code from external contributors. Additionally, audit the project's CI/CD configuration to ensure:

  • Pull requests from forks or untrusted sources execute in isolated environments
  • Branch protection rules require human review before code execution
  • CI/CD runners are ephemeral and discarded after each build
  • Build artifacts are not reused across independent runs without validation

Severity

  • CVSS Score: 7.8 / 10 (High)
  • Vector String: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


PHPUnit Vulnerable to Unsafe Deserialization in PHPT Code Coverage Handling

CVE-2026-24765 / GHSA-vvj3-c3rp-c85p

More information

Details

Overview

A vulnerability has been discovered involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the cleanupForCoverage() method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious .coverage files are present prior to the execution of the PHPT test.

Technical Details

Affected Component: PHPT test runner, method cleanupForCoverage()
Affected Versions: <= 8.5.51, <= 9.6.32, <= 10.5.61, <= 11.5.49, <= 12.5.7

Vulnerable Code Pattern
if ($buffer !== false) {
    // Unsafe call without restrictions
    $coverage = @unserialize($buffer);
}

The vulnerability occurs when a .coverage file, which should not exist before test execution, is deserialized without the allowed_classes parameter restriction. An attacker with local file write access can place a malicious serialized object with a __wakeup() method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled.

Attack Prerequisites and Constraints

This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through:

  • CI/CD Pipeline Attacks: A malicious pull request that places a .coverage file alongside test files, executed when the CI system runs tests using PHPUnit and collects code coverage information
  • Local Development Environment: An attacker with shell access or ability to write files to the project directory
  • Compromised Dependencies: A supply chain attack inserting malicious files into a package or monorepo

Critical Context: Running test suites from unreviewed pull requests without isolated execution is inherently a code execution risk, independent of this specific vulnerability. This represents a broader class of Poisoned Pipeline Execution (PPE) attacks affecting CI/CD systems.

Proposed Remediation Approach

Rather than just silently sanitizing the input via ['allowed_classes' => false], the maintainer has chosen to make the anomalous state explicit by treating pre-existing .coverage files for PHPT tests as an error condition.

Rationale for Error-Based Approach:
  1. Visibility Over Silence: When an invariant is violated (a .coverage file existing before test execution), the error must be visible in CI/CD output, alerting operators to investigate the root cause rather than proceeding with sanitized input
  2. Operational Security: A .coverage file should never exist before tests run, coverage data is generated by executing tests, not sourced from artifacts. Its presence indicates:
    • A malicious actor placed it intentionally
    • Build artifacts from a previous run contaminated the environment
    • An unexpected filesystem state requiring investigation
  3. Defense-in-Depth Principle: Protecting a single deserialization call does not address the fundamental attack surface. Proper mitigations for PPE attacks lie outside PHPUnit's scope:
    • Isolate CI/CD runners (ephemeral, containerized environments)
    • Restrict code execution on protected branches
    • Scan pull requests and artifacts for tampering
    • Use branch protection rules to prevent unreviewed code execution
Severity Classification
  • Attack Vector (AV): Local (L) — requires write access to the file system where tests execute
  • Attack Complexity (AC): Low (L) — exploitation is straightforward once the malicious file is placed
  • Privileges Required (PR): Low (L) — PR submitter status or contributor role provides sufficient access
  • User Interaction (UI): None (N) — automatic execution during standard test execution
  • Scope (S): Unchanged (U) — impact remains within the affected test execution context
  • Confidentiality Impact (C): High (H) — full remote code execution enables complete system compromise
  • Integrity Impact (I): High (H) — arbitrary code execution allows malicious modifications
  • Availability Impact (A): High (H) — full code execution permits denial-of-service actions
Mitigating Factors (Environmental Context)

Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration:

  • Ephemeral Runners: Use containerized, single-use CI/CD runners that discard filesystem state between runs
  • Code Review Enforcement: Require human review and approval before executing code from pull requests
  • Branch Protection: Enforce branch protection rules that block unreviewed code execution
  • Artifact Isolation: Separate build artifacts from source; never reuse artifacts across independent builds
  • Access Control: Limit file write permissions in CI environments to authenticated, trusted actors
Fixed Behaviour

When a .coverage file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. This ensures:

  • Visibility: The error appears prominently in CI/CD output and test logs
  • Investigation: Operations teams can investigate the root cause (potential tampering, environment contamination)
  • Fail-Fast Semantics: Test execution stops rather than proceeding with an unexpected state
Recommendation

Update to the patched version immediately if a project runs PHPT tests using PHPUnit with coverage instrumentation in any CI/CD environment that executes code from external contributors. Additionally, audit the project's CI/CD configuration to ensure:

  • Pull requests from forks or untrusted sources execute in isolated environments
  • Branch protection rules require human review before code execution
  • CI/CD runners are ephemeral and discarded after each build
  • Build artifacts are not reused across independent runs without validation

Severity

  • CVSS Score: 7.8 / 10 (High)
  • Vector String: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

sebastianbergmann/phpunit (phpunit/phpunit)

v13.3.2: PHPUnit 13.3.2

Compare Source

Fixed
  • #​6904: SourceMap is built in child process even though identifyIssueTrigger is disabled
  • #​6924: #[CoversFile] attribute is not considered for risky test check

Learn how to install or update PHPUnit 13.3 in the documentation.

Keep up to date with PHPUnit:

v13.3.1: PHPUnit 13.3.1

Compare Source

Changed
  • Invoking a static hook method such as setUpBeforeClass() no longer triggers a deprecation warning on PHP 8.6

Learn how to install or update PHPUnit 13.3 in the documentation.

Keep up to date with PHPUnit:

v13.3.0: PHPUnit 13.3.0

Compare Source

Added
  • #​3794: Filesystem-based code coverage targeting
  • #​5758: Make export of objects customizable
  • #​6546: Both property hooks can now be configured on test doubles of virtual hooked properties, even when the doubled property only declares one of them
  • #​6586: Custom code coverage driver support
  • #​6591: Repeated test execution using --repeat CLI option and #[Repeat] attribute
  • #​6701: Allow expectOutputString() and expectOutputRegex() to be combined and repeated
  • #​6710: Deprecation Filters
  • #​6722: Allow #[CoversNothing] on methods
  • #​6742: Retry failing tests up to N times using --retry CLI option #[Retry] attribute
  • #​6827: Customize which deprecation trigger types fail the test run
  • #​6830: Warn when failOnAllIssues="true" is combined with an explicitly disabled fine-grained failOn* setting
  • #​6832: Allow doubling properties that do not declare property hooks
  • #​6853: Optionally warn when PHP is not configured for development
  • phpunit/php-code-coverage #​1140: Class-oriented HTML report
  • phpunit/php-code-coverage #​1141: Improve visualization of branch coverage and path coverage in the HTML report
  • phpunit/php-code-coverage #​1153: Filter HTML code coverage report by test size
  • --record-test-run-history and --do-not-record-test-run-history CLI options as well as the recordTestRunHistory attribute for the XML configuration file to control whether the status and duration of each test are recorded for use by --order-by defects and --order-by duration-*
  • --without-class-view CLI option and classView attribute for the XML configuration file to disable the class-oriented view in the HTML code coverage report
  • --without-file-view CLI option and fileView attribute for the XML configuration file to disable the file-oriented view in the HTML code coverage report
  • {PWD} is now substituted with the directory of the PHPT test file in --ENV-- and --INI-- sections of PHPT test files
  • {TMP} (system directory for temporary files) and {ENV:name} (value of environment variable name) are now substituted in --INI-- sections of PHPT test files
  • A PHPT test whose --INI-- section references an environment variable that is not set is now skipped
  • A --SKIPIF-- section of a PHPT test file that prints xfail <reason> now marks the test as expected to fail, as if the PHPT test file had an --XFAIL-- section with that reason
Changed
  • phpunit/php-code-coverage #​1231: Identify dead code using static analysis
  • phpunit/php-code-coverage #​1259: Degrade gracefully when a source file cannot be parsed
  • The test runner no longer crashes when an attribute cannot be instantiated
  • Improved TestDox HTML report
  • The feature formerly named "test result cache" is now named "test run history"; when a cache directory is configured, the file it is stored in is now named test-run-history instead of test-results
  • The test runner warns now when ordering by defects or duration is configured but recording of the test run history is disabled
  • TestCase no longer captures error_log() output for tests that do not use expectErrorLog(), avoiding the cost of setting up error log redirection for every test
  • error_log() output from tests without an expectation is no longer echoed (date-stripped) to PHPUnit's output; it goes to the configured error log again, as it did before capture was introduced
  • A test running in process isolation that calls error_log() without expectErrorLog() now produces stderr output in the child process, which the test runner reports as a test error
  • A PHPT test that is expected to fail (--XFAIL-- section or xfail output from the --SKIPIF-- section) but passes is now considered risky; this usually means the expected-failure marker is stale and should be removed
  • A PHPT test whose --SKIPIF-- section produces output that is not recognized is now considered risky; this usually means the skip check itself is broken. The keywords understood by PHP's own test runner that have no PHPUnit counterpart (info, warn, xleak, flaky, and nocache) are tolerated and do not make the test risky
  • PHPT tests now run with additional INI defaults for deterministic output (date.timezone=UTC, display_startup_errors=1, fatal_error_backtraces=Off, ignore_repeated_errors=0, precision=14,
    serialize_precision=-1), consistent with PHP's own test runner; all of them can be overridden per test using the --INI-- section
Deprecated
  • --cache-result CLI option, use --record-test-run-history instead
  • --do-not-cache-result CLI option, use --do-not-record-test-run-history instead
  • cacheResult XML configuration attribute, use recordTestRunHistory instead
  • PHPUnit\TextUI\Configuration\Configuration::cacheResult(), use PHPUnit\TextUI\Configuration\Configuration::recordTestRunHistory() instead
  • PHPUnit\TextUI\Configuration\Configuration::testResultCacheFile(), use PHPUnit\TextUI\Configuration\Configuration::testRunHistoryFile() instead
Fixed
  • Doubling a class with a property that declares both a final and a non-final hook no longer triggers a fatal error
  • expectErrorLog() now only considers error_log() output written after it was called; previously, the expectation was also satisfied by output written before expectErrorLog() was called
  • PHPT test files with an unknown section, a duplicated section, more than one of the --FILE--, --FILEEOF--, and --FILE_EXTERNAL-- sections, or more than one expectation section (--EXPECT--, --EXPECTF--, --EXPECTREGEX--, and their _EXTERNAL variants) are now rejected; previously, misspelled sections were silently ignored and duplicated sections silently overwrote each other
  • The regular expression from an --EXPECTREGEX-- section must now match the PHPT test's entire output, and . now matches newline characters, consistent with PHP's own test runner; previously, a match on a substring of the output was sufficient for the test to pass
  • The reason printed by a --SKIPIF-- section of a PHPT test is no longer mangled when it follows the skip <reason> convention used by PHP's own test suite; previously, the first two characters of the reason were stripped unless the skip: <reason> or skip - <reason> convention was used
  • The test runner no longer aborts with an uncaught PHPUnit\Runner\Phpt\InvalidPhptFileException when a PHPT test file has an empty --FILE-- or --FILEEOF-- section or a --FILE_EXTERNAL-- section that references an empty file; such a file is now rejected while it is parsed and reported as an errored test
  • PHPUnit\Runner\Phpt\InvalidPhptFileException now has a message that explains why the PHPT test file was rejected

Learn how to install or update PHPUnit 13.3 in the documentation.

Keep up to date with PHPUnit:

v13.2.6: PHPUnit 13.2.6

Compare Source

Fixed
  • #​6861: Hook methods run twice when a template method is marked with its corresponding attribute
  • Regression that stopped test methods from being sorted by source code location

Learn how to install or update PHPUnit 13.2 in the documentation.

Keep up to date with PHPUnit:

v13.2.5: PHPUnit 13.2.5

Compare Source

Changed
  • Messages for tests that are skipped because of an unsatisfied RequiresPhp, RequiresPhpunit, or RequiresPhpExtension version requirement now include the version that is actually being used
  • Warning messages about incomplete version requirements as well as version requirements without a version comparison operator, and the error message for invalid version requirements, now include the full version requirement and explain what is expected
Fixed
  • #​6825: Forwarding to previous error handler can result in infinite recursion
  • #​6831: PHPUnit's error handler does not respect @ error suppression and forwards suppressed warnings to previous error handler
  • #​6833: assertArrayHasKey() does not accept ArrayAccess implementations with a specific value type when test code is analysed with PHPStan at level 9
  • #​6854: Deprecation triggered in first-party code is wrongly classified as indirect when the first-party code is called from third-party code
  • Test classes were not sorted relative to each other when tests were ordered by duration

Learn how to install or update PHPUnit 13.2 in the documentation.

Keep up to date with PHPUnit:

v13.2.4: PHPUnit 13.2.4

Compare Source

Fixed
  • #​6817: Issue is reported even when previously registered error handler turns the error into an exception
  • #​6818: Issue is reported when custom error handler checks error_reporting() output dynamically

Learn how to install or update PHPUnit 13.2 in the documentation.

Keep up to date with PHPUnit:

v13.2.3: PHPUnit 13.2.3

Compare Source

Changed
  • #​6797: Adapt code generated for test double of interface with constructor for PHP 8.6

Learn how to install or update PHPUnit 13.2 in the documentation.

Keep up to date with PHPUnit:

v13.2.2: PHPUnit 13.2.2

Compare Source

Fixed
  • #​6768: Negative priorities for hook methods are rejected by static analysis
  • #​6778: Deprecation triggered outside of tests cannot be ignored

Learn how to install or update PHPUnit 13.2 in the documentation.

Keep up to date with PHPUnit:

v13.2.1: PHPUnit 13.2.1

Compare Source

Fixed
  • #​6741: Test is not run when --filter matches the name of a data set but not the name of the test method
  • #​6743: Improve error message for invalid version constraint in attribute
  • #​6744: Environment variable attributes reject empty-string values since PHPUnit 13.2.0

Learn how to install or update PHPUnit 13.2 in the documentation.

Keep up to date with PHPUnit:

v13.2.0: PHPUnit 13.2.0

Compare Source

Added
  • #​3387: Specify a list of tests to run
  • #​4201: Handle interrupts and display current test results
  • #​4501: Option to mark test as risky when it does not contribute to code coverage
  • #​5757: Add assertions for ignoring whitespace differences in strings
  • #​5810: Do not dump arrays and objects in failure messages of IsTrue, IsFalse, IsNull, IsFinite, IsInfinite, and IsNan constraints
  • #​5838: Inherit #[RunTestsInSeparateProcesses] from parent test classes
  • #​5922: assertContainsEquals() should use sebastian/comparator for element comparison
  • #​6000: Report PHPT test as risky when --SKIPIF-- does not have standard-output side effect
  • #​6075: Support test execution order sorted by descending duration
  • #​6346: Emit warning when conflicting CLI options are used
  • #​6534: Make $_dataName available to #[TestDoxFormatter] callbacks
  • #​6559: Improved API for exception message expectations
  • #​6565: Optional $skipWhenEmpty parameter for #[DataProvider] and #[DataProviderExternal]
  • #​6566: Allow --stop-on-defect, --stop-on-error, etc. to accept an optional threshold
  • #​6567: Make diff context lines configurable
  • #​6574: Improve willReturnMap() with constraint support and strict matching
  • #​6575: --list-test-ids CLI option and enhance --filter CLI option to support test ID syntax
  • #​6577: --run-test-id <test-id> CLI option that accepts a single test ID for exact matching
  • #​6579: Properly handle issues triggered outside of tests
  • #​6597: Compact output (activated through --compact CLI option and PHPUNIT_COMPACT_OUTPUT=1 environment variable)
  • #​6598: --disable-coverage-targeting CLI option
  • #​6602: Separate configuration for branch coverage from path coverage
  • #​6606: Support for partially ordered parameter sets in mock object expectations
  • #​6611: Add CPU time to telemetry
  • #​6681: Comment-aware variants of XML comparison assertions
  • The executionOrder attribute in the XML configuration file now accepts defects combined with any main order, as well as three-way combinations of depends/no-depends, defects, and a main order (for example, depends,defects,duration-ascending)
  • --validate-configuration CLI option to validate an XML configuration file for PHPUnit
  • Report TestDox information in Open Test Reporting XML
  • Report per-test and per-test-suite resource usage (time, memory usage, peak memory usage) in Open Test Reporting XML
  • Report number of assertions performed for each test in Open Test Reporting XML
  • Report structured comparison failure details (expected, actual, diff) in Open Test Reporting XML
  • Report random order seed in Open Test Reporting XML when test execution order is randomised
Changed
  • #​5873: Chain previously registered error handler instead of silently disabling PHPUnit's error handling
  • #​6535: Use sebastian/file-filter in SourceFilter::includes() for issue trigger identification
  • #​6581: Allow #[IgnoreDeprecations] to be repeated
  • #​6609: Skip data providers whose method cannot match --filter
  • #​6685: Generate failure messages for inverse assertions by authoring negations, not by rewriting strings
  • Only errors and failures are now considered for "defect first" test reordering (tests that triggered deprecations, notices, or warnings as well as incomplete, risky, and skipped tests were previous also considered)
  • A warning is now emitted when closures are compared for equality using the IsEqual, IsEqualCanonicalizing, IsEqualIgnoringCase, IsEqualWithDelta, and TraversableContainsEqual constraints or the assertEquals(), assertEqualsCanonicalizing(), assertEqualsIgnoringCase(), assertEqualsWithDelta(), and assertContainsEquals() assertions
Deprecated
  • #​6075: --order-by duration CLI option, use --order-by duration-ascending instead
  • #​6075: --order-by size CLI option, use --order-by size-ascending instead
  • #​6075: executionOrder="duration" XML configuration attribute value, use executionOrder="duration-ascending" instead
  • #​6075: executionOrder="size" XML configuration attribute value, use executionOrder="size-ascending" instead
  • #​6560: Soft-deprecate expectExceptionMessage(), use expectExceptionMessageIsOrContains() instead
Fixed
  • #​5845: Error handlers registered before PHPUnit (e.g. via auto_prepend_file) cause false "risky test" warnings
  • #​5851: Output buffer manipulation in tests causes incorrect capture, hangs, and silent failures
  • #​6582: TestSuiteSorter::cmpSize() does not handle TestSuite objects for TestCase classes

Learn how to install or update PHPUnit 13.2 in the documentation.

Keep up to date with PHPUnit:

v13.1.14: PHPUnit 13.1.14

Compare Source

Fixed
  • #​6683: assertNotEquals() failure message says "is equal to" instead of "is not equal to" when comparing arrays or objects
  • #​6700: expectOutputString() and expectOutputRegex() silently replace themselves and each other

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.13: PHPUnit 13.1.13

Compare Source

Fixed
  • #​6681: XML assertions such as assertXmlStringEqualsXmlString() regressed into treating comments as significant

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.12: PHPUnit 13.1.12

Compare Source

Fixed
  • #​6673: Empty PHP settings from the parent process override per-test -d settings forwarded to child processes (breaks PCOV coverage)

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.11: PHPUnit 13.1.11

Compare Source

Fixed
  • PHP setting values containing = need to be quoted before forwarding via -d

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.10: PHPUnit 13.1.10

Compare Source

Changed
  • Pass configuration options introduced in sebastian/diff 8.3.0

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.9: PHPUnit 13.1.9

Compare Source

Changed
  • A Test or Tests prefix is no longer stripped from class names when they are processed for TestDox output
Fixed
  • #​6605: Data set names and provider values containing Unicode bidirectional control characters distort terminal output
  • #​6610: Per-testsuite bootstrap script not loaded in process isolation
  • TestDox output collapsed separate test classes into a single group when their prettified class names matched

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.8: PHPUnit 13.1.8

Compare Source

Fixed
  • #​6595: Crash when before-class or after-class method fails with assertion failure
  • #​6599: TeamCity logger does not wrap failures in before-test methods with testStarted and testFinished
  • #​6601: Anonymous classes are not rejected with a clear error when creating a test double
  • #​6603: assertArrays*IgnoringOrder() fails on mixed scalar types and on reordered nested associative arrays
  • MockBuilder::setMockClassName() and TestStubBuilder::setStubClassName() now reject values that are not valid unqualified PHP class identifiers, throwing the new InvalidClassNameException
  • The regular expression used by Generator::ensureValidMethods() to validate method names passed to MockBuilder::onlyMethods() and addMethods() was not anchored, so any string containing a valid identifier substring (including strings with parentheses, braces, comments, or newlines) was accepted

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.7: PHPUnit 13.1.7

Compare Source

Changed
  • Pass LIBXML_NONET when parsing/validating XML configuration files to make explicit that no network I/O is performed
  • Verify the result file written by an isolated child process with a random nonce before deserializing it

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.6: PHPUnit 13.1.6

Compare Source

Fixed
  • #​6590: Silent failure when configuration file is invalid
  • #​6592: INI metacharacters ; and " are not preserved when forwarding settings to child processes

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.5: PHPUnit 13.1.5

Compare Source

Fixed
  • #​5860: PHP CLI -d settings are not forwarded to child processes for process isolation
  • #​6451: Incomplete version in RequiresPhp (e.g. <=8.5) is compared against full PHP version, causing unexpected skips
  • #​6589: dataSetAsStringWithData() raises "float is not representable as int" warning for large floats in data sets

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.4: PHPUnit 13.1.4

Compare Source

Fixed
  • #​5993: DefaultJobRunner deadlocks on child processes that write large amounts of stderr output
  • #​6465: SAPI-populated $_SERVER entries leak from parent into child process
  • #​6587: failOnEmptyTestSuite="false" in phpunit.xml is ignored when --group/--filter/--testsuite matches no tests
  • #​6588: Order of issue baseline entries is not canonicalized

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.3: PHPUnit 13.1.3

Compare Source

Fixed
  • Regression in XML configuration migration introduced in PHPUnit 12.5.8

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

v13.1.2: PHPUnit 13.1.2

Compare Source

Fixed
  • #​4571: No warning when --random-order-seed is used when test execution order is not random
  • #​4975: --filter does not work when filter string starts with #
  • #​5354: JUnit XML logger does not handle TestSuiteSkipped event
  • #​6276: Exit with non-zero exit code when explicit test selection (--filter, --group, --testsuite) yields no tests
  • #​6583: Failing output expectation skips tearDown() and handler restoration, causing subsequent tests to be marked as risky

Learn how to install or update PHPUnit 13.1 in the documentation.

Keep up to date with PHPUnit:

[v13.1.1](https://redirect.github.com/sebastianbergmann/phpunit/releas

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@appsec-renovate-bot
appsec-renovate-bot Bot force-pushed the renovate/major-composer-security-fixes branch 2 times, most recently from fdf2f1f to 8334e61 Compare August 30, 2026 06:09
@appsec-renovate-bot appsec-renovate-bot Bot changed the title [Renovate] Update dependency phpunit/phpunit to v13 [SECURITY] [HIGH] [Renovate] Update dependency phpunit/phpunit to v8 [SECURITY] [HIGH] Aug 30, 2026
@appsec-renovate-bot
appsec-renovate-bot Bot force-pushed the renovate/major-composer-security-fixes branch from 8334e61 to bd9f4c3 Compare September 3, 2026 06:12
@appsec-renovate-bot appsec-renovate-bot Bot changed the title [Renovate] Update dependency phpunit/phpunit to v8 [SECURITY] [HIGH] [Renovate] Update dependency phpunit/phpunit to v13 [SECURITY] [HIGH] Sep 3, 2026
@appsec-renovate-bot
appsec-renovate-bot Bot force-pushed the renovate/major-composer-security-fixes branch from bd9f4c3 to cd7cbe6 Compare September 6, 2026 06:07
@appsec-renovate-bot appsec-renovate-bot Bot changed the title [Renovate] Update dependency phpunit/phpunit to v13 [SECURITY] [HIGH] [Renovate] Update dependency phpunit/phpunit to v8 [SECURITY] [HIGH] Sep 6, 2026
@appsec-renovate-bot
appsec-renovate-bot Bot force-pushed the renovate/major-composer-security-fixes branch from cd7cbe6 to 0846f6f Compare September 7, 2026 06:10
@appsec-renovate-bot appsec-renovate-bot Bot changed the title [Renovate] Update dependency phpunit/phpunit to v8 [SECURITY] [HIGH] [Renovate] Update dependency phpunit/phpunit to v13 [SECURITY] [HIGH] Sep 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants