NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #1158 most downloaded on Packagist
Extra security-related features for Symfony: signed/encrypted cookies, HTTPS/SSL/HSTS handling, cookie session storage, ...
Last release 7 months ago
23 Feb 2026
Ships unpredictably
gaps range from 2 weeks to 1.7 years
Nearly every release is documented
notes for 53 of 53 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
54 releases · first in 2013
Added PHPUnit assertions for security headers and update testing documentation by @Spomky in #389
Full Changelog: v3.8.0...v3.9.0
Add Cross-Origin Policy feature with configurable headers (COEP, COOP, CORP) by @Spomky in #372
Full Changelog: v3.7.0...v3.8.0
One column per quarter.
Added support for Symfony 8 #386
fix: Make PHPStan green by @silasjoisten in #378
Permissions-Policy header support by @silasjoisten in #373Full Changelog: v3.5.1...v3.6.0
Fixed BC break introduced in 3.5.0 by @martijnc in #370
Full Changelog: v3.5.0...v3.5.1
Added support for the report-to directive by @martijnc in #357
Fix Twig version check to not depend on changing VERSION_ID constant by @glaubinix in #361
Full Changelog: v3.4.1...v3.4.2
Fix twig deprecation warning with twig 3.12 by @pscheit in #359
Full Changelog: v3.4.0...v3.4.1
Deprecated X-Xss-Protection by @maxhelias in #342
legacy_hash_algo to support backward-compatible hash_algo changes in signed cookies by @martijnc in #351Full Changelog: v3.3.0...v3.4.0
Introduce ExternalRedirectResponse by @martijnc in #331
Added support for cookies with null value
* Filter view-source reports
view-source reportsDropped support for Symfony < 5.4
Bump minimal PHP version to 7.4
DoctrineCacheUAFamilyParser (use PsrCacheUAFamilyParser instead)finalWhitelistBasedTargetValidator class to AllowListBasedTargetValidatorCookieSessionHandlerNothing published for this version
Deprecated external_redirects.whitelist option in favor of external_redirects.allow_list
Nelmio\SecurityBundle\ContentSecurityPolicy\Violation\Event class in favor of
Nelmio\SecurityBundle\ContentSecurityPolicy\Violation\ReportEvent.Fixed deprecations warnings using PHP 8.1
Fix Symfony 5 compatibility issues
Fix dependencies (allow installing on PHP 8 and explicitly require symfony/yaml)
Fix ContentSecurityPolicyController
Ensure compatibility with Symfony EventDispatcher 5.x
Show non-deprecated usage of the csp_nonce Twig function
Bump minimal Twig version to 1.38.0
Fixed deprecated/invalid method usage on logger interface
Support more CSP level 3 keywords
Fix deprecation for symfony/config 4.2+
Abort CSP compiler pass when CSP is not enabled
Allows matching the query parameter for clickjacking protection
Deprecate calling ContentSecurityPolicyListener::getNonce without usage ('script' or 'style')
forced_ssl > redirect_status_code option to allow switching to permanent redirect (301) responsesFix arguments for Twig extension
Add support for script-src 'strict-dynamic' (see https://w3c.github.io/webappsec-csp/#strict-dynamic-usage)
Fix exceptions thrown by Report::fromRequest
* Improve CSP filtering
Fix injected script noise detector loading
* Fix dependency on UAParser
* Add CSP report filter * Fix Twig 2 support
Add support for Referrer Policy
Enable manifest-src directive for Chrome, Opera and Firefox
Fix deprecation warning with latest Twig 1.x
Fix typo in the ALLOW-FROM implementation
Fix CookieSessionHandler::open that should return true unless there's an error
Deprecate encrypted cookie support du to high coupling to mcrypt deprecated extension
Added ability to restrict forced_ssl capability to some hostnames only
BugFix: Fix LoggerInterface type hints to support PSR-3 loggers and not only Symfony 2.0 loggers
external_redirects definition can now contains full URL
Added HTTP response's content-type restriction for Clickjacking and CSP headers.
Added a Nelmio\SecurityBundle\ExternalRedirect\TargetValidator interface to implement custom rules for the external_redirects feature. You can overrid
Nelmio\SecurityBundle\ExternalRedirect\TargetValidator interface to implement custom rules for the external_redirects feature. You can override the nelmio_security.external_redirect.target_validator service to change the default.
hosts key in the CSP configuration to restrict CSP-checks to some host namesflexible_ssl where the auth cookie was updated with a wrong expiration time the second time the visitor comes to the site.Added a forced_ssl.hsts_preload flag to allow adding the preload attribute on HSTS headers
forced_ssl.hsts_preload flag to allow adding the preload attribute on HSTS headersAdded ability to have different configs for both reported and enforced CSP rules
Added default controller to log CSP violations
Content-Security-Policy oneAdded support for setting the X-Content-Type-Options header
Added Content-Security-Policy (CSP) 1.0 support
Added a cookie session storage (use only if really needed, and combine it with encrypted_cookie)
encrypted_cookie)
* Initial release
Your coding agent can read these notes before it upgrades. Set up the MCP server →