Skip to content

chore(deps): bump predis/predis from 3.6.0 to 3.6.1 - #1263

Merged
rosalieper merged 1 commit into
mainfrom
dependabot/composer/predis/predis-3.6.1
Oct 5, 2026
Merged

rosalieper merged 1 commit into
mainfrom
dependabot/composer/predis/predis-3.6.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Bumps predis/predis from 3.6.0 to 3.6.1.

Release notes

Sourced from predis/predis's releases.

v3.6.1

Fixed

  • Fixed RESP3 double parsing returning positive INF for -inf payloads (#1716)
  • Fixed client_info connection parameter being ignored (#1722)
  • Fixed Stream::write() and read() leaving a dead connection when a host error handler throws exception (#1725)

Security

  • Deprecated CommandInterface::deserializeCommand() (CVE GHSA-w6f5-v2h6-g786)
  • Fixed CRLF command smuggling and node misrouting in AbstractAggregateConnection::write() and CommandInterface::deserializeCommand() (CVE GHSA-w6f5-v2h6-g786)
Changelog

Sourced from predis/predis's changelog.

v3.6.1 (2026-09-17)

Fixed

  • Fixed RESP3 double parsing returning positive INF for -inf payloads (#1716)
  • Fixed client_info connection parameter being ignored (#1722)
  • Fixed Stream::write() and read() leaving a dead connection when a host error handler throws exception (#1725)

Security

  • Deprecated CommandInterface::deserializeCommand() (CVE GHSA-w6f5-v2h6-g786)
  • Fixed CRLF command smuggling and node misrouting in AbstractAggregateConnection::write() and CommandInterface::deserializeCommand() (CVE GHSA-w6f5-v2h6-g786)
Commits
  • e2db963 tag v3.6.1
  • 3edc442 Fixed CRLF command smuggling and node misrouting in `AbstractAggregateConnect...
  • 3749086 Fixed Stream::write()/read() leaving a dead connection when a host error hand...
  • 3a5b55e Deprecated CommandInterface::deserializeCommand() (CVE GHSA-w6f5-v2h6-g786) (...
  • 401abc4 fix changelog typo
  • e7b89c1 Fixed client_info connection parameter being ignored (#1722)
  • 3a8c350 Bump the github-actions group with 2 updates (#1720)
  • 6759513 Fix RESP3 double parsing returning positive INF for -inf (#1716)
  • 0795d69 bump dev version
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update Php code labels Sep 21, 2026
@rosalieper

Copy link
Copy Markdown
Contributor

@dependabot rebase

Bumps [predis/predis](https://github.com/predis/predis) from 3.6.0 to 3.6.1.
- [Release notes](https://github.com/predis/predis/releases)
- [Changelog](https://github.com/predis/predis/blob/main/CHANGELOG.md)
- [Commits](predis/predis@v3.6.0...v3.6.1)

---
updated-dependencies:
- dependency-name: predis/predis
  dependency-version: 3.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/composer/predis/predis-3.6.1 branch from f46eefe to 364d8b3 Compare October 5, 2026 07:58
@rosalieper
rosalieper merged commit 9ffdf10 into main Oct 5, 2026
4 checks passed
@rosalieper
rosalieper deleted the dependabot/composer/predis/predis-3.6.1 branch October 5, 2026 08:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update Php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant