NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #693 most downloaded on Packagist
Build a fully-featured hypermedia or GraphQL API in minutes!
Last release 4 days ago
02 Oct 2026
Release timing varies
gaps range from 8 days to 2 months
Nearly every release is documented
notes for 56 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
395 releases · first in 2015
0d9a44bef fix(laravel): allow custom error handler for non-api operations
stale-while-revalidate and stale-if-error cache headers via config file (#7606)One column per quarter.
01fd0b578 fix(symfony): do not redeclare object_mapper
502c0e2de fix(symfony): skip argument resolver when context is not api platform
Nothing published for this version
44af80c43 fix(symfony): disable Swagger UI and keep openapi.json
53d3f8481 fix(state): object mapper flag
57fe3d1 fix(state): class existence check for ObjectMapperAwareInterface
20f288959 fix: multiple :property template operations on a single resource
9416083f7 fix(state): object mapper aware interface
Parameters (#7492)member property out of HydraCollectionBaseSchema (#7456)mixed properties to string|null instead of null (#7489)0b8237918 fix(state): object mapper with input different
@id and @type properties required only in the JSON-LD schema for output (#7397)KernelBrowser::loginUser() (#7446)059e6a09e fix(symfony): remove suggest ocramius/package-versions
pagination_maximum_items_per_page same as Laravel version (#7396)Also includes v4.1.25 bug fixes
4f0864c1a fix(symfony): remove deprecation about jsonopenapi
#[ApiResource] attribute (#6943)TypeInfo's Type (#7100)TypeInfo type (#7097)TypeInfo's Type (#7099)Type of TypeInfo instead of PropertyInfo (#6979)TypeInfo type (#7098)TypeInfo's Type (#7096)TypeInfo's Type (#7101)ParameterExtension context more generic (#7389)4f0864c1a fix(symfony): remove deprecation about jsonopenapi
Also includes patches from v4.1.24 and v4.2.0-alpha fixes
f010fd456 fix(serializer): deprecate SerializerAwareProviderInterface and SerializableProvider
partial query parameter to OpenAPI when pagination_client_enabled is true (#7295)Link (#7342)#[ApiResource] attribute (#6943)JSON Streamer:
Object Mapper:
TypeInfo:
TypeInfo's Type (#7099)Type of TypeInfo instead of PropertyInfo (#6979)TypeInfo type (#7098)TypeInfo's Type (#7096)TypeInfo's Type (#7101)TypeInfo's Type (#7100)TypeInfo type (#7097)76c80a67c fix: command name deprecation
partial query parameter to OpenAPI when pagination_client_enabled is true (#7295)Link (#7342)#[ApiResource] attribute (#6943)JSON Streamer:
Object Mapper:
TypeInfo:
TypeInfo's Type (#7099)Type of TypeInfo instead of PropertyInfo (#6979)TypeInfo type (#7098)TypeInfo's Type (#7096)TypeInfo's Type (#7101)TypeInfo's Type (#7100)TypeInfo type (#7097)76c80a67c fix: command name deprecation
Introducing new Symfony components!
#[ApiResource] attribute (#6943)Object Mapper:
TypeInfo:
TypeInfo's Type (#7099)Type of TypeInfo instead of PropertyInfo (#6979)TypeInfo type (#7098)TypeInfo's Type (#7096)TypeInfo's Type (#7101)TypeInfo's Type (#7100)TypeInfo type (#7097)Nothing published for this version
9f5d0e020 fix(serializer): gate cache_key in JsonApi and Hal with isCacheKeySafe
dfe42b385 fix(symfony): skip argument resolver when context is not api platform
3df65aa86 fix(symfony): allow disabling PHPStan PhpDocParser
4fa6d3fa2 fix(laravel): groups with input/output
54352d853 fix(jsonld): hydra context w3.org updates
07112a27d fix(laravel): remove duplication code exception
Laravel compatibility with api-platform/http-cache:
254cbdd00 fix(symfony): only set name_converter for the default serializer
11bba62c2 fix(laravel): serialization issue with camelCase relation
04414e4fc fix(serializer): improve #7270 by reducing inconsistencies
Link (#7342)c41a0bca4 fix(jsonld): child class @type shortName
2c06a22e2 fix(validation): moving dependency from require-dev to require
partial query parameter to OpenAPI when pagination_client_enabled is true (#7295)d3e73f09a fix(metadata): read every OpenApiOperation attributes in Xml instead of only "deprecated"
InputOption::VALUE_REQUIRED) (#7266)@id property when genId is false (#7162) (#7251)34a0d54b1 fix(jsonld): genId false should work with embeded resources
LinksHandler to handle polymorphic relationships (#7231)4a99a5f6e fix(laravel): persist HasMany and MorphMany relationships
Notes:
Two providers are now available on parameters (query parameters, header and uri variables Link):
ReadLinkParameterProvider previously used for link security (renamed from Symfony\Security\State\LinkedReadProvider)IriConverterParameterProvider this allows you to read a resource from an IRI usefull for filters (eg ?author=/authors/1)Previous tests on link security were left untouched we removed the experimental class Symfony\Security\State\LinkAccessCheckerProvider as well as the LinkedReadProvider as they're not used anymore.
There was an issue with the subtree split as we attempted to test lower dependencies on the subtree split, some components where wrongly tagged.
There was an issue with the subtree split as we attempted to test lower dependencies on the subtree split, some components where wrongly tagged.
The proper fix is at: https://github.com/api-platform/core/pull/7196
example and default with nullable value not being shownNothing published for this version
Nothing published for this version
b14a463a9 fix(laravel): register error handler without graphql
329acf21e fix(metadata): infer parameter string type from schema
4dd0cdfc4 fix(doctrine): support integer-backed enums in BackedEnumFilter
0ff950f37 fix: type info deprecations to baseline
40c09d1c0 fix(metadata): yaml link security
44e560839 fix(laravel): undefined variable app
60747cc8c fix(graphql): access to unauthorized resource using node Relay CVE-2025-31481
eaf007536 fix(state): support filter interface on serializer filter parameter provider
8a2265041 fix(laravel): defer "filters" dependent services
42f25cf04 fix: react@18 for UMD + add Laravel support in update-js.sh
2771363b0 fix(validation): deprecate string message for ValidationException constructor
alwaysBootKernel property for BC layer (#7007)Also contains v4.0.20 changes.
2e2debb94 feat(mongodb): Replace usage of deprecated method AggregationBuilder::execute()
show_webby parameter in Laravel config (#6741)AggregationBuilder::execute() (#6933)da37ca91c fix(laravel): default to file cache instead of cache.default
2e2debb94 feat(mongodb): Replace usage of deprecated method AggregationBuilder::execute()
01fd74268 fix(laravel): restore accidentally removed BooleanFilter
The hydra patch changes default hydra:title and uses the resource shortname. Previously the hydra:title information was duplicating the hydra:description.
The rdfs:label got removed from the hydra:Class as it was used instead of the hydra:title.
On hydra:property rdfs:label got renamed to label as the rdfs namespace is available in the context.
The ApiPlatform\Metadata\ErrorResource and the ConstraintViolation (ValidationException class) are now generated directly from your PHP classes, only our ConstraintViolationList is hard-written and documents the ConstraintViolation::violation property. Therefore, your own error resources are also documented. On top of that, we now set the rdfs:subClassOf to hydra:Error.
#[ApiProperty(hydra: false)] allows you to skip a documented hydra:supportedProperty on a class.
On write operations, we added the expectsHeader field.
67fbe51c5 fix: reintroduce the show_webby parameter in Laravel config
show_webby parameter in Laravel config (#6741)60747cc8c fix(graphql): access to unauthorized resource using node Relay CVE-2025-31481
7cb5a6db8 fix: allow parameter provider as object
284937039 fix(doctrine): mapping ArrayAccess deprecation
1dfefda5e fix(laravel): add middleware granularity
7007dcca8 fix(laravel): duplicate middleware in routes
5124d8c57 fix(laravel): Prevent overwriting existing routes on the router
To save some time during cache warmup we recommend to define uri variables such as: uriVariables: ['id']. More details at #6954.
dc4fc84ba fix(graphql): securityAfterResolver not called
36cee399c fix(state): skip Content-Location header for GET requests
Also contains v3.4.15 changes.
97cdb6b3f fix(state): remove ProcessorInterface laravel specific type
Also contains v3.4.14 changes.
3a694624b fix(laravel): eloquent BelongsToMany relation
Also contains v3.4.10 changes.
Your coding agent can read these notes before it upgrades. Set up the MCP server →