S

Symfony

S
Symfony Web v8.1.3

v8.1.3

Changelog (v8.1.2...v8.1.3) minor #65046 [VarExporter] Detect the null byte rendering instead of pinning a PHP version (@nicolas-grekas) minor #65042 [Serializer] Relax PropertyAccess version constraint (@derrabus) bug #65036 [HttpClient] Revert " Strip Proxy-Authorization on cross-authority redirects" (@GrahamCampbell)

S
Symfony Web v8.0.16

v8.0.16

Changelog (v8.0.15...v8.0.16) minor #65046 [VarExporter] Detect the null byte rendering instead of pinning a PHP version (@nicolas-grekas) bug #65036 [HttpClient] Revert " Strip Proxy-Authorization on cross-authority redirects" (@GrahamCampbell)

S
Symfony Web v8.1.2

v8.1.2

Changelog (v8.1.1...v8.1.2) bug #65029 [JsonPath] Add limits for filter expression length and depth in JsonCrawler (@alexandre-daubois) bug #65028 [HttpClient] Fail when an https proxy is configured but libcurl cannot use it (@nicolas-grekas) bug #65026 [JsonStreamer] Drop the unbounded process-global key cache in Splitter (@nicolas-grekas) bug #65025 [Serializer] Check the denormalized class is a…

S
Symfony Web v8.0.15

v8.0.15

Changelog (v8.0.14...v8.0.15) bug #65029 [JsonPath] Add limits for filter expression length and depth in JsonCrawler (@alexandre-daubois) bug #65028 [HttpClient] Fail when an https proxy is configured but libcurl cannot use it (@nicolas-grekas) bug #65026 [JsonStreamer] Drop the unbounded process-global key cache in Splitter (@nicolas-grekas) bug #65025 [Serializer] Check the denormalized class is…

S
Symfony Web v7.4.15

v7.4.15

Changelog (v7.4.14...v7.4.15) bug #65029 [JsonPath] Add limits for filter expression length and depth in JsonCrawler (@alexandre-daubois) bug #65028 [HttpClient] Fail when an https proxy is configured but libcurl cannot use it (@nicolas-grekas) bug #65026 [JsonStreamer] Drop the unbounded process-global key cache in Splitter (@nicolas-grekas) bug #65025 [Serializer] Check the denormalized class is…

S
Symfony Web v6.4.43

v6.4.43

Changelog (v6.4.42...v6.4.43) bug #65028 [HttpClient] Fail when an https proxy is configured but libcurl cannot use it (@nicolas-grekas) bug #65025 [Serializer] Check the denormalized class is a Mime part in MimeMessageNormalizer (@nicolas-grekas) bug #65024 [SecurityBundle] Always constrain redirect targets to the current host, even without sessions (@nicolas-grekas) bug #65023 [HttpFoundation] V…

S
Symfony Web v8.1.1

v8.1.1

Changelog (v8.1.0...v8.1.1) data #64731 Release v8.1.1 bug #64718 [Serializer] Fix GetSetMethodNormalizer denormalization of constructor only objects (@mtarld) minor #64721 [Finder] Update tests to pass on Windows (@MatTheCat) minor #64717 Bump actions/checkout from 6.0.3 to 7.0.0 in the github-actions group (@dependabot[bot]) minor #64715 Bump the github-actions group across 1 directory with 2 up…

S
Symfony Web v8.0.14

v8.0.14

Changelog (v8.0.13...v8.0.14) data #64730 Release v8.0.14 bug #64718 [Serializer] Fix GetSetMethodNormalizer denormalization of constructor only objects (@mtarld) minor #64721 [Finder] Update tests to pass on Windows (@MatTheCat) minor #64717 Bump actions/checkout from 6.0.3 to 7.0.0 in the github-actions group (@dependabot[bot]) minor #64715 Bump the github-actions group across 1 directory with 2…

S
Symfony Web v7.4.14

v7.4.14

Changelog (v7.4.13...v7.4.14) data #64729 Release v7.4.14 bug #64718 [Serializer] Fix GetSetMethodNormalizer denormalization of constructor only objects (@mtarld) minor #64721 [Finder] Update tests to pass on Windows (@MatTheCat) minor #64717 Bump actions/checkout from 6.0.3 to 7.0.0 in the github-actions group (@dependabot[bot]) minor #64715 Bump the github-actions group across 1 directory with 2…

S
Symfony Web v6.4.42

v6.4.42

Changelog (v6.4.41...v6.4.42) data #64728 Release v6.4.42 bug #64718 [Serializer] Fix GetSetMethodNormalizer denormalization of constructor only objects (@mtarld) minor #64721 [Finder] Update tests to pass on Windows (@MatTheCat) minor #64715 Bump the github-actions group across 1 directory with 2 updates (@dependabot[bot]) data #64692 [Validator] Remove needs-review-translation state from Spanish…

S
Symfony Web v8.1.0

v8.1.0

Changelog (v8.1.0-RC1...v8.1.0) data #64399 Release v8.1.0 feature #64398 Shopware is backing Symfony 8.1, thanks to them! (@nicolas-grekas) feature #64397 Mailtrap is backing Ssymfony 8.1, thanks to them! (@nicolas-grekas) feature #64396 Les-Tilleuls.coop is backing Symfony 8.1, thanks to them! (@nicolas-grekas) feature #64395 TYPO3 is backing Symfony 8.1, thanks to them! (@nicolas-grekas) bug #6…

S
Symfony Web v8.1.0-RC1

v8.1.0-RC1

Changelog (v8.1.0-BETA3...v8.1.0-RC1) data #64377 Release v8.1.0-RC1 security #cve-2026-48747 [Mailer] Pin Mailomat webhook signature algorithm to SHA-256 (@nicolas-grekas) security #cve-2026-48761 [HtmlSanitizer] Sanitize URL attributes on , , <iframe>, , and the URL inside content (@nicolas-grekas) security #cve-2026-48760 [HtmlSanitizer] Reject percent-encoded BiDi marks and Unicode whitespace…

S
Symfony Web v8.0.13

v8.0.13

Changelog (v8.0.12...v8.0.13) data #64374 Release v8.0.13 security #cve-2026-48747 [Mailer] Pin Mailomat webhook signature algorithm to SHA-256 (@nicolas-grekas) security #cve-2026-48761 [HtmlSanitizer] Sanitize URL attributes on , , <iframe>, , and the URL inside content (@nicolas-grekas) security #cve-2026-48760 [HtmlSanitizer] Reject percent-encoded BiDi marks and Unicode whitespace in URLs (@n…

S
Symfony Web v7.4.13

v7.4.13

Changelog (v7.4.12...v7.4.13) data #64372 Release v7.4.13 security #cve-2026-48747 [Mailer] Pin Mailomat webhook signature algorithm to SHA-256 (@nicolas-grekas) security #cve-2026-48761 [HtmlSanitizer] Sanitize URL attributes on , , <iframe>, , and the URL inside content (@nicolas-grekas) security #cve-2026-48760 [HtmlSanitizer] Reject percent-encoded BiDi marks and Unicode whitespace in URLs (@n…

S
Symfony Web v6.4.41

v6.4.41

Changelog (v6.4.40...v6.4.41) data #64371 Release v6.4.41 security #cve-2026-48761 [HtmlSanitizer] Sanitize URL attributes on , , <iframe>, , and the URL inside content (@nicolas-grekas) security #cve-2026-48760 [HtmlSanitizer] Reject percent-encoded BiDi marks and Unicode whitespace in URLs (@nicolas-grekas) security #cve-2026-48736 [HttpFoundation] Block IPv6 transition forms in IpUtils::PRIVATE…

S
Symfony Web v5.4.53

v5.4.53

Changelog (v5.4.52...v5.4.53) data #64370 Release v5.4.53 security #cve-2026-48736 [HttpClient] Block IPv6 transition forms in NoPrivateNetworkHttpClient (@nicolas-grekas) security #cve-2026-48489 [Security] Don't honor user-supplied _failure_path on failure_forward (@nicolas-grekas) security #cve-2026-48784 [Routing] Fix dot-segment encoding for chained "../" and "./" in generated URLs (@nicolas-…