NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #903 most downloaded on Packagist
Flexible and powerful Database abstraction library with a familiar PDO-like API
Last release 5 days ago
03 Oct 2026
Ships fairly regularly
a new release about every 4 weeks
Rarely documented
notes for 6 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
338 releases · first in 2015
Add more clarity Query builder doc strings
Be more clear about which methods are not safe to be used with
user-controlled data.
Thanks to Feei for reporting these gaps via our security process.
Co-authored-by: othercorey corey.taylor.fl@gmail.com
Remove the hardcoded public schema from postgis column reflection. Adding a test seemed more complex than it would provide value.
Remove the hardcoded public schema from postgis column reflection.
Adding a test seemed more complex than it would provide value.
Fixes #19604
One column per quarter.
Document driver-specific function transforms
Document driver-specific function transforms (#19566)
Update split package version constraints and branch aliases to 5.5
Update split package version constraints and branch aliases to 5.5
Nothing published for this version
Nothing published for this version
The postgres driver needs to transforms jsonValue function calls to rename the function and apply postgres specific cast operations. If the current im
The postgres driver needs to transforms jsonValue function calls to
rename the function and apply postgres specific cast operations. If the
current implementation is provided a user-controlled path expression,
the generated query can be manipulated.
Thanks to Himanshu Anand for reporting this
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
The postgres driver needs to transforms jsonValue function calls to rename the function and apply postgres specific cast operations. If the current im
The postgres driver needs to transforms jsonValue function calls to
rename the function and apply postgres specific cast operations. If the
current implementation is provided a user-controlled path expression,
the generated query can be manipulated.
Thanks to Himanshu Anand for reporting this
Fix weakness in FunctionsBuilder
Fix weakness in FunctionsBuilder
Several methods did not explicity label their parameters as unsafe, so
it is possible for an application developer to mistakenly supply user
controlled data into these parameters creating a SQL injection vector.
Thank you to Himanshu Anand for reporting this issue.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
The postgres driver needs to transforms jsonValue function calls to rename the function and apply postgres specific cast operations. If the current im
The postgres driver needs to transforms jsonValue function calls to
rename the function and apply postgres specific cast operations. If the
current implementation is provided a user-controlled path expression,
the generated query can be manipulated.
Thanks to Himanshu Anand for reporting this
Fix weakness in FunctionsBuilder
Fix weakness in FunctionsBuilder
Several methods did not explicity label their parameters as unsafe, so
it is possible for an application developer to mistakenly supply user
controlled data into these parameters creating a SQL injection vector.
Thank you to Himanshu Anand for reporting this issue.
Fix weakness in FunctionsBuilder
Fix weakness in FunctionsBuilder
Several methods did not explicity label their parameters as unsafe, so
it is possible for an application developer to mistakenly supply user
controlled data into these parameters creating a SQL injection vector.
Thank you to Himanshu Anand for reporting this issue.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fix parameter handling in FunctionsBuilder
Fix parameter handling in FunctionsBuilder (#19520)
Fix weakness in FunctionsBuilder
Several methods did not explicity label their parameters as unsafe, so
it is possible for an application developer to mistakenly supply user
controlled data into these parameters creating a SQL injection vector.
Thank you to Himanshu Anand for reporting this issue.
Backport #19520 to 4.x
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →