Skip to content

Update dependency api-platform/openapi to v5 - #10853

Open
renovate[bot] wants to merge 1 commit into
develfrom
renovate/api-platform-openapi-5.x
Open

renovate[bot] wants to merge 1 commit into
develfrom
renovate/api-platform-openapi-5.x

Conversation

@renovate

@renovate renovate Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
api-platform/openapi (source) 4.4.2 → 5.0.2 age confidence

Release Notes

api-platform/core (api-platform/openapi)

v5.0.2

Compare Source

API Platform 5.0.2 contains every change shipped in v4.4.3, plus the changes below.

Behavior changes
  • 0c0b608f4 fix(openapi): document request body on operations that deserialize (#​8598). An operation with deserialize: true on a method other than POST, PUT or PATCH (for example GET or DELETE) now gets a requestBody and an input JSON Schema in the OpenAPI document. This can change your generated schema, so clients generated from it or snapshot tests of it can differ. It is acceptable in 5.0, but it was reverted from 4.4 because a schema change must not ship in a patch release.
Bug fixes
  • 773c6cca0 fix(doctrine): avoid deprecation with SortFilter (#​8617)
  • 54add936f fix(jsonapi): sparse fieldsets on included resources (#​8584)
  • f590d9438 fix(laravel): don't duplicate the filter interface use statement (#​8593)
  • c092cd0df fix(metadata): use operation shortName for resources without ApiResource (#​8609)
  • d25771aa7 fix: throw exception when an operation is not declared in ApiResource for parameter attributes on properties (#​8552)

v5.0.1

Compare Source

API Platform 5.0.1 contains every change shipped in v4.4.1 and v4.4.2, plus the fixes below.

Bug fixes

v5.0.0

Compare Source

API Platform 5.0 contains every change shipped in v4.4.0, plus the removals and breaking changes below.

Breaking changes
  • 14ce74352 feat(jsonapi)!: default use_iri_as_id to false (#​8512)
  • ce741c851 feat(state)!: drop TranslatorInterface support from DeserializeProvider (#​8514)
  • 906a36dca feat!: drop the Request::getContentType() fallbacks (#​8517)
  • cf1d5a9fc feat(symfony)!: drop the Symfony 6 value resolver shim (#​8516)
  • e22e74464 feat!: remove deprecated APIs scheduled for 5.0 (#​8367)
  • 4a9a14507 feat!: remove legacy PropertyInfo Type system (#​8364)
  • 1e6d13ae1 feat!: core 5.0 cleanups (getProperties interface, json:api status string) (#​8366)
  • Denormalization errors on a property carrying a Symfony Validator constraint now return 422 with a ConstraintViolation payload instead of 400 with a hydra:Error payload (#​8211, #​8389). Properties without constraint metadata still return 400. This shipped in the 4.4 betas and was moved to 5.0; there is no configuration flag, but the behaviour can be disabled by overriding the api_platform.state.denormalization_violation_factory service.
Features
  • edead1f0c feat: HTTP QUERY method support (RFC 10008) (#​8349)
  • 826e847b6 feat(metadata): resolve %param% in yaml/xml and attribute resource config (#​8284)
  • 56c4ae204 feat(symfony): add routePriority to control route matching order (#​8309)
  • c3b6bb41f feat: allow restricting operations for parameter attributes on properties (#​7899)
  • fce2bdfe6 feat(state): apply uri variable provider values (#​8491)
  • 56daf41c4 feat: allow Parameter attributes on properties (#​7870)
  • 24871a9ac feat(symfony): emit a csp nonce on the swagger ui and graphiql scripts (#​8310)
  • a8af8e1b9 feat(doctrine): embed joined/sti relations when a discriminator subclass declares the group (#​8283)
  • 711f00657 feat: extract ApiTestCase in its own api-platform/test package (#​7887)
  • 672d48e25 feat(symfony): map UniqueConstraintViolationException to 422 by default (#​8478)
  • d37a75379 feat(doctrine): standalone Date/Exists filters, ComparisonFilter [between], deprecate RangeFilter (#​8351)
Bug fixes
  • 5ad54c9d9 fix(symfony): separate route priority (#​8529)
  • 239e44c44 fix(symfony): make api-platform/test a dev dependency (#​8527)
  • 7afb7c8a7 fix(test): restore main CI after the ApiTestCase extraction (#​8526)
  • 88f98d961 fix(serializer): read Symfony attributes through their public properties (#​8519)
  • 78151b7d1 fix(mcp): return resource read results for resources (#​8436)
  • 8360186ed fix(serializer): remove dead native-type guards in AbstractItemNormalizerTest
  • 88f458a11 fix(jsonschema): drop removed getBuiltinTypes path in SchemaPropertyMetadataFactory
Dependencies
  • ApiPlatform\Symfony\Bundle\Test\ApiTestCase and its helpers now live in the new api-platform/test package; the classes in the old namespace are deprecated and will be removed in 6.0 (#​7887).
  • Symfony ^7.4 || ^8.0; support for 6.4 is dropped.

v4.4.3

Compare Source

Bug fixes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the renovate label Sep 24, 2026
@renovate

renovate Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: api/composer.lock
Loading composer repositories with package information
Dependency api-platform/json-schema is also a root requirement. Package has not been listed as an update argument, so keeping locked at old version. Use --with-all-dependencies (-W) to include root dependencies.
Dependency api-platform/metadata is also a root requirement. Package has not been listed as an update argument, so keeping locked at old version. Use --with-all-dependencies (-W) to include root dependencies.
Dependency api-platform/state is also a root requirement. Package has not been listed as an update argument, so keeping locked at old version. Use --with-all-dependencies (-W) to include root dependencies.
Dependency symfony/console is also a root requirement. Package has not been listed as an update argument, so keeping locked at old version. Use --with-all-dependencies (-W) to include root dependencies.
Dependency symfony/property-access is also a root requirement. Package has not been listed as an update argument, so keeping locked at old version. Use --with-all-dependencies (-W) to include root dependencies.
Dependency symfony/serializer is also a root requirement. Package has not been listed as an update argument, so keeping locked at old version. Use --with-all-dependencies (-W) to include root dependencies.
Updating dependencies
Your requirements could not be resolved to an installable set of packages.

  Problem 1
    - Root composer.json requires api-platform/openapi 5.0.2 (exact version match: 5.0.2 or 5.0.2.0), found api-platform/openapi[v5.0.2] but these were not loaded, likely because it conflicts with another require.
  Problem 2
    - api-platform/symfony is locked to version v4.4.3 and an update of this package was not requested.
    - api-platform/symfony v4.4.3 requires api-platform/openapi ^4.4 -> found api-platform/openapi[v4.4.0, v4.4.1, v4.4.2, v4.4.3] but it conflicts with your root composer.json require (5.0.2).

Use the option --with-all-dependencies (-W) to allow upgrades, downgrades and removals for packages currently locked to specific versions.

@renovate
renovate Bot force-pushed the renovate/api-platform-openapi-5.x branch from 26df8cf to f4a06e5 Compare September 26, 2026 13:07
@renovate
renovate Bot force-pushed the renovate/api-platform-openapi-5.x branch 8 times, most recently from d0e37d3 to c4c4ab8 Compare October 4, 2026 14:05
@renovate
renovate Bot force-pushed the renovate/api-platform-openapi-5.x branch 2 times, most recently from f5ebe40 to de34364 Compare October 9, 2026 13:20
@renovate
renovate Bot force-pushed the renovate/api-platform-openapi-5.x branch from de34364 to d4878e1 Compare October 9, 2026 14:06

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants