Symfony 7.1.5 has just been released.
Here is the list of the most important changes since 7.1.4:
Symfony 7.1.5 has just been released.
Here is the list of the most important changes since 7.1.4:
Symfony 6.4.12 has just been released.
Here is the list of the most important changes since 6.4.11:
Symfony 5.4.44 has just been released.
Here is the list of the most important changes since 5.4.43:
This week, Symfony development activity focused on fixing bugs on existing branches: we provided a workaround for a parse_url() bug, updated the wcswidth data in the String component to Unicode 16, and updated ICU data to version 75.1.
Affected Versions
Twig >1.0.0,<=1.44.7 || >2.0.0,<=2.16.0 || >3.0.0,<=3.11.0 || >=3.12.0,<3.14.0 versions are affected by this security issue.
Even if twig 1.x and 2.x are not maintained anymore, we've released new versions with the security fix.
This issue has been fixed in Twig 1.44.8, 2.16.1, and 3.14.0.
Description
Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions.
The security issue happens when all these conditions are met:
This week, the upcoming Symfony 7.2 version focused on adding compatibility with Twig 4 and updating tests to support PHPUnit 10 and later versions.
This week, Symfony 5.4.43, 6.4.11, and 7.1.4 maintenance versions were released. Meanwhile, the upcoming Symfony 7.2 version continued tweaking and polishing some of its new features.
Symfony 7.1.4 has just been released.
Here is the list of the most important changes since 7.1.3:
Symfony 6.4.11 has just been released.
Here is the list of the most important changes since 6.4.10:
Symfony 5.4.43 has just been released.
Here is the list of the most important changes since 5.4.42: