grasmash/yaml-expander
Expands internal property references in a yaml file.
4.0.0
33M downloads/mo
#2083 most downloaded on Packagist
grasmash/yaml-expander
What this package is like to depend on
Last release 2 months ago
11 Jun 2026
Release timing varies
gaps range from 6 weeks to 2.1 years
Some releases are documented
notes for 9 of 18 stable releases
Nothing withdrawn
no release was ever pulled
10 years old
18 releases · first in 2017
1 release in the last 12 months
see the full history below
Release timeline
18 releases · Jan 2017 to Jun 2026Releases
latest 18-
4.0.011 Jun 2026Release notes
Open source →Breaking changes
- Requires PHP >= 8.1 (previously no PHP constraint).
symfony/yaml4.x and 5.x (EOL) are no longer supported; allowed versions are^6.4.40 || ^7.4.12 || ^8.0.12.grasmash/expander1.x and 2.x are no longer supported; requires^3.0.1.- Native parameter and return types on the public API (
parse(),expandArrayProperties()). Passing non-string YAML or a non-array reference array now throwsTypeError. parse()now returns[]for empty YAML and throwsUnexpectedValueExceptionwhen YAML parses to a non-array value (previously both surfaced as an opaqueTypeError).
Security
symfony/yamlconstraint excludes versions vulnerable to CVE-2026-45304 (YAML parser "Billion Laughs" memory exhaustion).- PHPUnit dev constraint excludes versions vulnerable to CVE-2026-24765.
- Dropped
php-coveralls, which pulled in vulnerableguzzlehttpreleases at lowest versions; coverage is now uploaded withcoverallsapp/github-action. - All GitHub Actions are pinned to commit SHAs.
- New README guidance: only parse YAML from trusted sources.
Improvements
- The constructor logger is now optional and defaults to
NullLogger:new YamlExpander(). declare(strict_types=1)throughout.- 100% test coverage; new tests for empty input, scalar input, invalid YAML, and unresolved-placeholder behavior.
- Test suite modernized to PHPUnit 10–13 (attributes, static data providers).
- CI now tests PHP 8.1–8.4, including a working lowest-dependencies job (the previous prefer-lowest job silently never ran), with Dependabot enabled for composer and GitHub Actions.
- README examples rewritten to match the actual API; CONTRIBUTING.md and RELEASE.md now contain accurate instructions.
squizlabs/php_codesniffer4.x allowed for development.
Full Changelog: 3.0.3...4.0.0
🤖 Generated with Claude Code
-
3.0.304 May 2024Release notes
Open source →What's Changed
- #27: Allow 7.x release of symfony/yaml. by @vishalkhode1 in #28
New Contributors
- @vishalkhode1 made their first contribution in #28
Full Changelog: 3.0.2...3.0.3
-
3.0.210 May 2022Release notes
Open source →- Switch to GitHub Actions
- Allow grasmash/expander 3.x
Full Changelog: 3.0.1...3.0.2
-
3.0.128 Mar 2022Release notes
Open source →What's Changed
- Update dflydev/dot-access-data to 3.x by @joelpittet in #24
- Fixes #25 to allow grasmash/expander ^2. by @mikemadison13 in #26
New Contributors
- @joelpittet made their first contribution in #24
- @mikemadison13 made their first contribution in #26
Full Changelog: 3.0.0...3.0.1
-
3.0.024 Feb 2020Release notes
Open source →- Changing Symfony requirement to ^4 | ^5
- Updating PHPUnit dev requirement to ^8.2
- Removing testing for PHP 7.0 and 7.1.
-
2.0.017 Aug 2019Release notes
Open source →The 2.x is much lighter weight and relies on grasmash/expander for most expansion logic.
- This library is now a simple yaml-specific wrapper around grasmash/expander.
- It is backwards in compatible due to class renaming.
- Support for PHP 5.4 and 5.5 has been dropped.
-
1.4.016 Dec 2017 -
1.3.008 Dec 2017 -
1.2.026 Sep 2017Release notes
Open source →This release adds support for expanding placeholders that reference arrays.
-
1.1.101 Aug 2017Nothing published for this version
-
1.1.024 Mar 2017Nothing published for this version
-
1.0.521 Mar 2017Nothing published for this version
-
1.0.417 Jan 2017Nothing published for this version
-
1.0.316 Jan 2017Nothing published for this version
-
1.0.216 Jan 2017Nothing published for this version
-
1.0.116 Jan 2017Nothing published for this version
-
1.0.013 Jan 2017Nothing published for this version
-
0.1.013 Jan 2017Nothing published for this version