Skip to content

Bump monolog/monolog from 2.11.0 to 3.11.0 - #36

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/composer/monolog/monolog-3.11.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/composer/monolog/monolog-3.11.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 6, 2026

Copy link
Copy Markdown
Contributor

Bumps monolog/monolog from 2.11.0 to 3.11.0.

Release notes

Sourced from monolog/monolog's releases.

3.11.0

  • Security: Fixed potential XSS in BrowserConsoleHandler when logging user provided content
  • Added RedactingFormatter to automatically redact sensitive data from records, based on key names, #[SensitiveParameter] constructor params and/or regex patterns (#2041)
  • Added FrankenPhpHandler to log records via FrankenPHP's frankenphp_log() function (#2056)
  • Added LogMonsterHandler which complains if the code did not log enough records before the process/request ends, like a dead man's switch for logs (#2039)
  • Added FILE_PER_HOUR rotation mode to RotatingFileHandler (#2040)
  • Added ErrorHandler::captureStackTraces() to attach the stack trace of PHP errors to the records it generates (#2060)
  • Added NormalizerFormatter::setMaxTraceLength() to limit how many stack trace frames are included when normalizing exceptions (#2015)
  • Added extension points to TelegramBotHandler to change the API URL (e.g. for a self-hosted Bot API server) and to send extra curl headers (#2029)
  • Added ability to override IntrospectionProcessor's SKIP_FUNCTIONS in subclasses (#2050)
  • Added $maxLength param to SyslogUdpHandler/UdpSocket to keep datagrams below the path MTU, as fragmented UDP packets are often dropped (#2049)
  • Fixed StreamHandler truncating writes on non-blocking streams, it now loops until the whole record is written (#2016)
  • Fixed stack trace frames without file/line being skipped, they are now reported as internal[function] entries so traces are not truncated or empty (#2061)
  • Fixed RotatingFileHandler cleanup not finding files behind stream wrappers (e.g. private://) as glob() cannot see through those (#2058)
  • Fixed RotatingFileHandler not using the configured timezone when computing the next rotation time (#2022)
  • Fixed scalars being replaced by the "Over N levels deep" message instead of being output when the max normalization depth is reached (#2042)
  • Fixed DeduplicationHandler failing with an undefined array key error when the store file is written to concurrently (#2020)
  • Fixed TelegramBotHandler swallowing errors when the API returns a non-JSON response (#2030)
  • Fixed AbstractProcessingHandler::handle() reading $bubble directly instead of calling getBubble(), so overrides of it were ignored (#2031)
  • Fixed warning on PHP 8.5 when ErrorHandler sets the HTTP response code and a status line was already registered (#2027)

Full Changelog: Seldaek/monolog@3.10.0...3.11.0

3.10.0

  • Added automatic directory cleanup in RotatingFileHandler (#2000)
  • Added timezone-aware file rotation to RotatingFileHandler (#1982)
  • Added support for mongodb/mongodb 2.0+ (#1998)
  • Added NoDiscard attribute to TestHandler methods to ensure the result is used (#2013)
  • Fixed JsonFormatter crashing if __toString throws while normalizing data (#1968)
  • Fixed PHP 8.5 deprecation warnings (#1997, #2009)
  • Fixed DeduplicatingHandler collecting duplicate logs if the file cannot be locked (2e97231)
  • Fixed GelfMessageFormatter to use integers instead of bool for gelf 1.1 support (#1973)
  • Fixed empty stack traces being output anyway (#1979)
  • Fixed StreamHandler not reopening the file if the inode changed (#1963)
  • Fixed TelegramBotHandler sending empty messages (#1992)
  • Fixed file paths in stack traces containing backslashes on windows, always using / now to unify logs (#1980)
  • Fixed RotatingFileHandler unlink errors not being suppressed correctly (#1999)

Full Changelog: Seldaek/monolog@3.9.0...3.10.0

3.9.0

  • BC Warning: Fixed SendGridHandler to use the V3 API as V2 is now shut down, but this requires a new API key (#1952)
  • Deprecated Monolog\Test\TestCase in favor of Monolog\Test\MonologTestCase (#1953)
  • Added extension point for NativeMailerHandler::mail (#1948)
  • Added setHandler method to BufferHandler to modify the nested handler at runtime (#1946)
  • Fixed date format in ElasticsearchFormatter to use +00:00 vs +0000 tz identifiers (#1942)
  • Fixed GelfMessageFormatter handling numeric context/extra keys (#1932)

Full Changelog: Seldaek/monolog@3.8.1...3.9.0

... (truncated)

Changelog

Sourced from monolog/monolog's changelog.

3.11.0 (2026-09-02)

  • Security: Fixed potential XSS in BrowserConsoleHandler when logging user provided content
  • Added RedactingFormatter to automatically redact sensitive data from records, based on key names, #[SensitiveParameter] constructor params and/or regex patterns (#2041)
  • Added FrankenPhpHandler to log records via FrankenPHP's frankenphp_log() function (#2056)
  • Added LogMonsterHandler which complains if the code did not log enough records before the process/request ends, like a dead man's switch for logs (#2039)
  • Added FILE_PER_HOUR rotation mode to RotatingFileHandler (#2040)
  • Added ErrorHandler::captureStackTraces() to attach the stack trace of PHP errors to the records it generates (#2060)
  • Added NormalizerFormatter::setMaxTraceLength() to limit how many stack trace frames are included when normalizing exceptions (#2015)
  • Added extension points to TelegramBotHandler to change the API URL (e.g. for a self-hosted Bot API server) and to send extra curl headers (#2029)
  • Added ability to override IntrospectionProcessor's SKIP_FUNCTIONS in subclasses (#2050)
  • Added $maxLength param to SyslogUdpHandler/UdpSocket to keep datagrams below the path MTU, as fragmented UDP packets are often dropped (#2049)
  • Fixed StreamHandler truncating writes on non-blocking streams, it now loops until the whole record is written (#2016)
  • Fixed stack trace frames without file/line being skipped, they are now reported as internal[function] entries so traces are not truncated or empty (#2061)
  • Fixed RotatingFileHandler cleanup not finding files behind stream wrappers (e.g. private://) as glob() cannot see through those (#2058)
  • Fixed RotatingFileHandler not using the configured timezone when computing the next rotation time (#2022)
  • Fixed scalars being replaced by the "Over N levels deep" message instead of being output when the max normalization depth is reached (#2042)
  • Fixed DeduplicationHandler failing with an undefined array key error when the store file is written to concurrently (#2020)
  • Fixed TelegramBotHandler swallowing errors when the API returns a non-JSON response (#2030)
  • Fixed AbstractProcessingHandler::handle() reading $bubble directly instead of calling getBubble(), so overrides of it were ignored (#2031)
  • Fixed warning on PHP 8.5 when ErrorHandler sets the HTTP response code and a status line was already registered (#2027)

3.10.0 (2026-01-02)

  • Added automatic directory cleanup in RotatingFileHandler (#2000)
  • Added timezone-aware file rotation to RotatingFileHandler (#1982)
  • Added support for mongodb/mongodb 2.0+ (#1998)
  • Added NoDiscard attribute to TestHandler methods to ensure the result is used (#2013)
  • Fixed JsonFormatter crashing if __toString throws while normalizing data (#1968)
  • Fixed PHP 8.5 deprecation warnings (#1997, #2009)
  • Fixed DeduplicatingHandler collecting duplicate logs if the file cannot be locked (2e97231)
  • Fixed GelfMessageFormatter to use integers instead of bool for gelf 1.1 support (#1973)
  • Fixed empty stack traces being output anyway (#1979)
  • Fixed StreamHandler not reopening the file if the inode changed (#1963)
  • Fixed TelegramBotHandler sending empty messages (#1992)
  • Fixed file paths in stack traces containing backslashes on windows, always using / now to unify logs (#1980)
  • Fixed RotatingFileHandler unlink errors not being suppressed correctly (#1999)

3.9.0 (2025-03-24)

  • BC Warning: Fixed SendGridHandler to use the V3 API as V2 is now shut down, but this requires a new API key (#1952)
  • Deprecated Monolog\Test\TestCase in favor of Monolog\Test\MonologTestCase (#1953)
  • Added extension point for NativeMailerHandler::mail (#1948)
  • Added setHandler method to BufferHandler to modify the nested handler at runtime (#1946)
  • Fixed date format in ElasticsearchFormatter to use +00:00 vs +0000 tz identifiers (#1942)
  • Fixed GelfMessageFormatter handling numeric context/extra keys (#1932)

3.8.1 (2024-12-05)

  • Deprecated Monolog\DateTimeImmutable in favor of Monolog\JsonSerializableDateTimeImmutable (#1928)

... (truncated)

Upgrade guide

Sourced from monolog/monolog's upgrade guide.

4.0.0

Overall / notable changes:

  • Monolog\DateTimeImmutable has been removed in favor of Monolog\JsonSerializableDateTimeImmutable.

3.0.0

Overall / notable changes:

  • The minimum supported PHP version is now 8.1.0.
  • Monolog\Logger::API can be used to distinguish between a Monolog 3, 2 or 1 install when writing integration code.
  • Log records have been converted from an array to a Monolog\LogRecord object with public (and mostly readonly) properties. e.g. instead of doing $record['context'] use $record->context. In formatters or handlers if you rather need an array to work with you can use $record->toArray() to get back a Monolog 1/2 style record array. This will contain the enum values instead of enum cases in the level and level_name keys to be more backwards compatible and use simpler data types.
  • FormatterInterface, HandlerInterface, ProcessorInterface, etc. changed to contain LogRecord $record instead of array $record parameter types. If you want to support multiple Monolog versions this should be possible by type-hinting nothing, or array|LogRecord if you support PHP 8.0+. You can then code against the $record using Monolog 2 style as LogRecord implements ArrayAccess for BC. The interfaces do not require a LogRecord return type even where it would be applicable, but if you only support Monolog 3 in integration code I would recommend you use LogRecord return types wherever fitting to ensure forward compatibility as it may be added in Monolog 4.
  • Log levels are now stored as an enum Monolog\Level
  • All properties have had types added, which may require you to do so as well if you extended a Monolog class and declared the same property.

Logger

  • Logger::DEBUG, Logger::ERROR, etc. are now deprecated in favor of the Level enum. e.g. instead of Logger::WARNING use Level::Warning if you need to pass the enum case to Monolog or one of its handlers, or Level::Warning->value if you need the integer value equal to what Logger::WARNING was giving you.
  • Logger::$levels has been removed.
  • Logger::getLevels has been removed in favor of Monolog\Level::VALUES or Monolog\Level::cases().
  • setExceptionHandler now requires a Closure instance and not just any callable.

HtmlFormatter

  • If you redefined colors in the $logLevels property you must now override the getLevelColor method instead.

NormalizerFormatter

  • A new normalizeRecord method is available as an extension point which is called only when converting the LogRecord to an array. You may need this if you overrode format previously as parent::format now needs to receive a LogRecord still

... (truncated)

Commits
  • 147f303 Update changelog
  • 7bbffd0 Report stack trace frames that have no file/line instead of skipping them (#2...
  • 567b630 Bump zizmorcore/zizmor-action from 0.6.1 to 0.6.2 (#2063)
  • a3a2046 Align FrankenPhpHandler's level scale with OpenTelemetry's mapping (#2062)
  • d1d7def Fix warning when setting the http response code in case a status has already ...
  • 6949404 Add a way to turn on stack traces for ErrorHandler-generated records (#2060)
  • a4c5f65 Add LogMonsterHandler that requires at least some amount of logging or it log...
  • e7508d8 Replace glob() with RecursiveDirectoryIterator in RotatingFileHandler cleanup...
  • 9435605 Add RedactingFormatter to automatically redact keys/sensitive data before log...
  • fde8b93 Add FrankenPhpHandler (#2056)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [monolog/monolog](https://github.com/Seldaek/monolog) from 2.11.0 to 3.11.0.
- [Release notes](https://github.com/Seldaek/monolog/releases)
- [Changelog](https://github.com/Seldaek/monolog/blob/main/CHANGELOG.md)
- [Upgrade guide](https://github.com/Seldaek/monolog/blob/main/UPGRADE.md)
- [Commits](Seldaek/monolog@2.11.0...3.11.0)

---
updated-dependencies:
- dependency-name: monolog/monolog
  dependency-version: 3.11.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update php code labels Sep 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update php code

Development

Successfully merging this pull request may close these issues.

0 participants