Skip to content

chore(deps): bump easycorp/easyadmin-bundle from 4.29.5 to 4.29.10 in /apps/back - #115

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/composer/apps/back/easycorp/easyadmin-bundle-4.29.10
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/composer/apps/back/easycorp/easyadmin-bundle-4.29.10

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 2, 2026

Copy link
Copy Markdown
Contributor

Bumps easycorp/easyadmin-bundle from 4.29.5 to 4.29.10.

Release notes

Sourced from easycorp/easyadmin-bundle's releases.

4.29.10

This is a security release that contains a fix for this issue:

[565064b9f] Path traversal and reflected XSS in Flag and Icon Twig components

Full security advisory information: GHSA-2wwr-9x6f-88gp

4.29.9

Bug fixes

[3f979b6ff] Call embedded controller's createEntity() for CollectionField entries (@​lacatoire) [16f3e86cc] Harden the security of the sort feature (@​javiereguiluz) [6e16ad9ce] Avoid formatting collection items when a custom formatting is used (@​javiereguiluz) [9c964aa50] Fix browser <title> tag is not rendered when overriding content_title in custom templates (@​matixxd1999)

4.29.8

Bug fixes

[2f8b89392] Fix filter labels not translated with correct domain (@​Amoifr) [3f9a759b9] Render HTML attributes on form fieldset wrapper (@​lacatoire) [b41a56061] Skip CollectionField entry-type setup on INDEX/DETAIL pages (@​lacatoire) [fe2f4b2d5] Fix CrudTestSelectors::getActionSelector() not matching grouped actions (@​lacatoire) [ecf31cc1e] Allow defining custom CSS class for index rows with default actions (@​javiereguiluz) [67fa76026] Fix translation issues (@​Seb33300)

4.29.7

Bug fixes

[ba934ab71] Fix TextEditorField layout breaking under strict CSP (@​lacatoire) [f74c13489] Allow buttons to grow and wrap with long or multi-line content (@​lacatoire) [f71eee4cb] Fix filter to use translated labels for enums implementing TranslatableInterface (@​lacatoire) [080ae900f] Fix the disabling of text editor fields (@​javiereguiluz) [29bf7ec2f] Prevent TextEditor modal clicks from triggering row action redirect (@​lacatoire) [5e00ba3c4] Add choice_label support to CrudAutocompleteType (@​Amoifr) [0d158f00b] Apply DefaultColumns to ChoiceField regardless of widget type (@​lacatoire) [4e39c0df7] Fix filter label translation when field is hidden via hideOnIndex (@​Amoifr)

Misc fixes

[538ff879f] Improve the docs about field configurators (@​lacatoire)

4.29.6

This release mostly focuses on fixing security issues identified during an AI-assisted security audit.

Bug fixes

[4c36ff818] Fix RepeatedType fields not inheriting Bootstrap column classes (@​Mozoou) [1a0153c12] Translate header in ItemGroup (@​Ishadijcks) [66fe61831] Fix a deprecation related to Url constraint (@​javiereguiluz) [13aa46219] Use formattedValue consistently in UrlField on index and detail pages (@​lacatoire)

... (truncated)

Commits
  • a483631 Prepare 4.29.10 release
  • 565064b [Security] Fix a security issue
  • 9c9daa4 Bump development version
  • 3c592a5 Prepare 4.29.9 release
  • 9c964aa bug #7619 Fix: Browser <title> tag is not rendered when overriding content_ti...
  • 6e16ad9 bug #7618 Avoid formatting collection items when a custom formatting is used ...
  • 16f3e86 bug #7621 Harden the security of the sort feature (javiereguiluz)
  • 4d37165 Harden the security of the sort feature
  • a6a9a23 Fix: Browser <title> tag is not rendered when overriding content_title in cus...
  • 9b01b13 Avoid formatting collection items when a custom formatting is used
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [easycorp/easyadmin-bundle](https://github.com/EasyCorp/EasyAdminBundle) from 4.29.5 to 4.29.10.
- [Release notes](https://github.com/EasyCorp/EasyAdminBundle/releases)
- [Commits](EasyCorp/EasyAdminBundle@v4.29.5...v4.29.10)

---
updated-dependencies:
- dependency-name: easycorp/easyadmin-bundle
  dependency-version: 4.29.10
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update php code labels Jul 2, 2026
@vercel

vercel Bot commented Jul 2, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
apuntate Ready Ready Preview Jul 2, 2026 1:40am

Request Review

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants