Skip to content

fix(deps): drop the unused Guzzle requirement - #101

Merged
jfrosorio merged 6 commits into
masterfrom
fix-100
Sep 26, 2026
Merged

jfrosorio merged 6 commits into
masterfrom
fix-100

Conversation

@jfrosorio

@jfrosorio jfrosorio commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Description

The package required guzzlehttp/guzzle: ^7.0, although it has not used Guzzle directly since v3.2.0, when the payment classes moved to Laravel's HTTP client. Laravel 13 accepts Guzzle 8, so a new Laravel 13 app installs it, and adding the package then failed unless Composer was allowed to downgrade Guzzle.

  • The Guzzle requirement is removed, leaving the version to Laravel. Laravel 11 and later require the Guzzle range their HTTP client supports (Guzzle 8 only from 13.x, whose client was adapted to it). Laravel 10 leaves Guzzle to the application, whose skeleton requires ^7.2, so the Laravel 10 test rows install it the same way, and the requirements docs say so. The suite passes on Guzzle 8.2.0 with Laravel 13.33 and on Guzzle 7 with Laravel 10.
  • A new CI job installs the package into a new Laravel 10–13 application whose dependencies are already installed, as in a real app. Run against master, it fails on Laravel 13 with the reported conflict; with this change it passes.

Fixes

This fixes #100.

Copilot AI lite review requested due to automatic review settings September 26, 2026 14:53
@jfrosorio jfrosorio self-assigned this Sep 26, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The dependency removal is consistent with the package’s actual requirements, and the added CI job appropriately guards against the reported Composer conflict scenario.

Review effort: Lite
Findings: None

What changed in this PR

This PR removes an unused direct Composer dependency on guzzlehttp/guzzle to prevent installation conflicts in newer Laravel applications (notably Laravel 13, which allows Guzzle 8). It also extends CI to validate real-world installation by adding the package into freshly created Laravel apps across multiple Laravel versions.

Changes:

  • Removed guzzlehttp/guzzle from composer.json requirements (Laravel’s illuminate/http already constrains the appropriate Guzzle version per framework release).
  • Added a GitHub Actions job that creates a Laravel 10–13 app, installs its dependencies first, then requires this package via a local path repository to catch dependency conflicts.
File Description
composer.json Drops the unused direct Guzzle requirement to avoid Composer conflicts with Laravel-supported Guzzle versions.
.github/​workflows/​run-tests.yml Adds an “install into fresh Laravel app” CI job to detect framework/package dependency constraint conflicts.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The change aligns the package’s declared dependencies with actual usage and adds CI coverage for the reported install conflict, with only minor follow-up improvements suggested.

Review effort: Lite
Findings: 1 Medium severity · 1 Low severity

Open (2)
Previously missed (1)

In code that hasn't changed since last review

Low severity Use composer install in install CI job

.github/​workflows/​run-tests.yml:103

The install job aims to mimic a real app with dependencies already installed/locked. Using composer install here more closely matches how a freshly created Laravel app is typically set up (using its shipped lock file) and avoids re-resolving/upgrading dependencies unnecessarily in CI.

Comment thread composer.json
Comment thread docs/requirements.md Outdated
@jfrosorio
jfrosorio merged commit a7e6c2a into master Sep 26, 2026
17 checks passed
@jfrosorio
jfrosorio deleted the fix-100 branch September 26, 2026 15:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Package cannot be installed alongside Guzzle 8

2 participants