NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #1382 most downloaded on Packagist
Tools to manage HTTP caching proxies with PHP
Last release 7 months ago
04 Mar 2026
Release timing varies
gaps range from 9 days to 11 months
Nearly every release is documented
notes for 56 of 60 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
70 releases · first in 2014
Added support for prefix invalidation, a special case of banning for cloudflare enterprise.
Compatible with Symfony 8. Testing with PHP 8.5.
One column per quarter.
Fixed banPath to escape array of host names to be a correct regular expression.
banPath to escape array of host names to be a correct regular expression.Add events PRE_FORWARD and POST_FORWARD to allow event listeners to alter the request before and after it is sent to the backend.
PRE_FORWARD and POST_FORWARD to allow event listeners to alterPOST_FORWARD event instead ofPRE_STORE. Using PRE_STORE, requests that are not considered cacheable byfallbackToSmaxage to CustomTtlListener to allow controllings-maxage if custom TTL header is not defined on the response.s-maxage, this bug might have led to caching responses that should notSwitched to PSR-17 message factories
TagCapable::invalidateTags so you don't need to check if there are tags or not.The new EventDispatchingHttpCache::forward method added in 2.16.0 was not compatible with Symfony 4.4. Adjusted the signature to make it compatible.
EventDispatchingHttpCache::forward method added in 2.16.0 was not(Mistake, same as 2.16.0)
Add events PRE_FORWARD and POST_FORWARD to allow event listeners to alter the request before and after it is sent to the backend.
PRE_FORWARD and POST_FORWARD to allow event listeners to alterPOST_FORWARD event instead ofPRE_STORE. Using PRE_STORE, requests that are not considered cacheable byfallbackToSmaxage to CustomTtlListener to allow controllings-maxage if custom TTL header is not defined on the response.s-maxage, this bug might have led to caching responses that should notAvoid deprecated RequestMatcher in favor of IpsRequestMatcher .
RequestMatcher in favor of IpsRequestMatcher.Declare incompatibility with Symfony 7 because it removes RequestMatcher .
RequestMatcher.Directly require php-http/message-factory to keep working with the legacy factories.
php-http/message-factory to keep working with the legacy factories.Provide a TagHeaderParser that can split up a tag header into the list of tags. This allows to correctly handle non-default tag separators in all plac
TagHeaderParser that can split up a tag header into the list of tags.
This allows to correctly handle non-default tag separators in all places.Fixed varnish configuration examples to say Authorization and not Autorization.
Authorization and not Autorization.Fixed dummy interface name for code scanners to match the expected name.
Removed the internal BaseEvent class and extend our events from the Symfony contracts class directly.
HttpKernelInterface::fetch - if you implement the method in your application,
you need to adjust when upgrading to Symfony 6.Allow installation with Symfony 6 components
Do not extend the wrong Event class when installed with legacy Symfony but the Symfony contracts happen to be installed
Added Cloudflare ProxyClient Adapter with ClearCapable, PurgeCapable and TagCapable. This allows to use FOSHttpCache to invalidate caches on Cloudflar
fos_user_context_hash method to be called in vcl_hash when using the user context
hash mechanism. This can avoid performance problems Varnish can run into when the hash Varys on
the basic authentication or session cookie.
If you use the user context, read the updated documentation and call fos_user_context_hash in
your vcl_hash function.Added flag on CustomTtlListener to allow keeping the custom TTL header on the response
@internal constants in FOS\HttpCache\ProxyClient\Fastly as privateFix how we create exceptions to get the expected exception rather than a PHP error
Raised minimal PHP version to 7.2
Fix: Preserve inline credentials when multiplexing to the proxy servers.
Allow to use inline credentials for the caching proxy URL in the format http://user:pass@1.2.3.4
Raised minimal PHP version to 7.1
PurgeTagsListener and Symfony 5Use LegacyEventDispatcherProxy for Symfony >= 4.3 to avoid deprecation messages.
LegacyEventDispatcherProxy for Symfony >= 4.3 to avoid deprecation messages.Added request type to the CacheEvent.
Added: ClearCapable to clear the whole cache in one efficient call. Currently supported only by the Symfony HttpCache.
Fixed: Avoid regression of 2.5.3: If there are no messages to be dispatched, do not throw an exception if the HttpCache is not set.
Fixed: Handle HttpCache not available in KernelDispatcher and fix return type annotations - if HttpCache is not set, it can't be returned.
Fixed: Remove the xkey header in vcl_deliver if we are not in debug mode
Fixed: MaxHeaderValueLengthFormatter::getTagsHeaderName now actually returns the value.
MaxHeaderValueLengthFormatter::getTagsHeaderName now actually returns the value.Added: MaxHeaderValueLengthFormatter to allow splitting cache tag headers into multiple headers.
MaxHeaderValueLengthFormatter to allow splitting cache tag headers into
multiple headers.Added: CleanupCacheTagsListener to remove the cache tags header from the final response that is sent to the client. Add this listener to your cache ke
CleanupCacheTagsListener to remove the cache tags header from the final
response that is sent to the client. Add this listener to your cache kernel.ResponseTagger does now remove duplicate tags.Fixed: Do not preg_quote tags when using xkey. Quoting is only used for BAN requests that expect a regular expression. This bug only affected you if y
preg_quote tags when using xkey. Quoting is only used for BAN
requests that expect a regular expression. This bug only affected you if you
use xkey and used characters in your tags that are changed by preg_quote.The HttpProxyClient now accepts an instance of the new Dispatcher interface instead of the concrete HttpDispatcher, allowing for more flexibility.
HttpProxyClient now accepts an instance of the new Dispatcher interface
instead of the concrete HttpDispatcher, allowing for more flexibility.KernelDispatcher for the Symfony proxy that calls the application
kernel directly instead of executing a full HTTP request.The provided VCL for custom TTL no longer provides import std; because each import may only exist once.
import std; because each
import may only exist once.Added support for the more efficient xkey cache tag system. BAN remains the default cache tagging system, but if you can install the varnish modules i
std.duration() instead.Authorization, HTTP_AUTHORIZATION and
PHP_AUTH_USER.Fixed bug in Symfony tag invalidation. Do not check if host is missing in request creation.
Fixed issue with detection if toflar psr6 store is available.
Updated X-Cache-Tags regex to prevent matching partial tags
Updated X-Cache-Tags regex to prevent matching partial tags
Invalidating objects with a tag of 'bar' would have previously also have invalidated objects with a tag that ends in 'bar', eg. 'foobar'. Now when invalidating an object the tag name must match in full.
Upgraded phpunit to 5.7 / 6. If you use anything from the FOS\HttpCache\Test namespace you need to update your project to use PHPUnit 6 (or 5.7, if yo
FOS\HttpCache\Test namespace you need to update your project to use
PHPUnit 6 (or 5.7, if you are using PHP 5.6).Cache tagging support for Symfony HttpCache
Added a PurgeTagsListener for tag based invalidation with the Symfony
HttpCache reverse caching proxy. This requires the newly created
Toflar Psr6Store
built on PSR-6 cache and supporting pruning expired cache entries.
Using Request::isMethodCacheable rather than Request::isMethodSafe to correctly handle OPTIONS and TRACE requests.
Avoid warning about count(null) in PHP 7.2.
Support PHP 7.2
Avoid warning about count(null) in PHP 7.2.
Ban requests now work even when no base URI is configured.
Raised minimum PHP version to 5.6.
Interface suffix from all interfaces.HashGenerator to DefaultHashGenerator.HashGenerator interface.LogSubscriber to
LogListener.Ban, Purge, Refresh and Tag interfaces to
BanCapable, PurgeCapable, RefreshCapable and TagCapable.CacheInvalidator, and renamed
TagHandler to ResponseTagger.TagCapable for ProxyClients.strict option to ResponseTagger that throws an exception when empty
tags are added. By default, empty tags are ignored.TagHeaderFormatter interface that is used within the ResponseTagger
to provide the header name and for formatting the tags header value.resources/config/varnish-4/
to resources/config/varnish/.setPurgeLocation().XxListener instead of
XxSubscriber.PurgeListener and RefreshListener now use
an options array for customization.EventDispatchingHttpCache to a trait, which now provides the addSubscriber
and addListener methods. In your AppCache, replace
AppCache extends EventDispatchingHttpInterface with a
use EventDispatchingHttpCache; statement.ProxyTestCase; use the traits CacheAssertions and HttpCaller instead.HttpCaller::getResponse().BC break: The ResponseTagger no longer expects an instance of TagCapable as first argument. To adjust the tag header name or the way the tags are form
ResponseTagger no longer expects an instance of
TagCapable as first argument. To adjust the tag header name or the way the
tags are formatted, use the new header_formatter option with a
TagHeaderFormatter.Nothing published for this version
Nothing published for this version
Nothing published for this version
[Symfony HttpCache] Added a neutral "Bad Request" body to user hash mismatch response to have something searchable in the code when debugging.
Symfony user context: You can now also specify which headers are used for authentication to detect anonymous requests. By default, the headers are the
Authorization, HTTP_AUTHORIZATION and
PHP_AUTH_USER.Avoid problem with http_method_override.
Avoid warning about count(null) in PHP 7.2.
count(null) in PHP 7.2.The TagHandler constructor now accepts a headerLength argument which will cause its invalidateTags function to invalidate in batches if the header len
headerLength argument which will
cause its invalidateTags function to invalidate in batches if the header
length exceeds this value.* Support for Symfony 3.
Added symfony/http-kernel HttpCache client.
Added TagHandler->hasTags() method.
TagHandler->hasTags() method.Fixed usage of deprecated Guzzle subtree splits.
Deprecated CacheInvalidator::addSubscriber in favor of either using the event dispatcher instance you inject or doing getEventDispatcher()->addSubscri…
CacheInvalidator::addSubscriber in favor of either using the event
dispatcher instance you inject or doing getEventDispatcher()->addSubscriber($subscriber).Added support for the symfony/http-kernel component reverse proxy HttpCache.
Fixed documentation for user context varnish configuration to also work when client omits the Accept HTTP header.
Accept HTTP header.Your coding agent can read these notes before it upgrades. Set up the MCP server →