- laravel/framework ^12.0 -> ^13.0
- spatie/laravel-backup ^9.2.9 -> ^10.0 (forced: 9.x pins
illuminate/notifications ^12.40, incompatible with L13)
- Drop psalm/plugin-laravel + vimeo/psalm (dev-only static analysis):
the only version chain compatible with L13's testbench-core needs
vimeo/psalm ^7.0.0-beta, which requires narrowing the project's
declared PHP floor (composer platform.php is pinned to 8.3.0 to
keep composer.lock installable on the oldest supported PHP patch;
the psalm 7 betas require specific 8.3.16+/8.4.3+/8.5.0+ floors).
Its CI workflow (.github/workflows/php-psalm.yml) was already
disabled (`on: []`, "too many errors"). Larastan/PHPStan remains
as the project's static analysis tool, unaffected.
- Rename VerifyCsrfToken/ValidateCsrfToken -> PreventRequestForgery
in bootstrap/app.php and config/sanctum.php (the L13 rename; old
classes remain as deprecated aliases but new code should reference
the new name), and validateCsrfTokens() -> preventRequestForgery()
in the middleware config.
Everything else (cache serializable_classes, cache/session/redis key
prefixes, upsert() uniqueBy, JobAttempted/QueueBusy event properties,
pagination view names, Manager::extend bindings, model-boot nested
instantiation) was checked against the app's actual code and found
to be either already handled, already using the new convention, or
not applicable to any pattern in this codebase.
All 715 tests pass (verified against a clean baseline with Redis
available locally via Docker); Pint and Larastan (the project's
configured `composer analyse` scope) are both clean.