paragonie/csp-builder
Easily add and update Content-Security-Policy headers for your project
v3.1.0
3.2M downloads/mo
#2647 most downloaded on Packagist
paragonie/csp-builder
What this package is like to depend on
Last release 5 days ago
18 Aug 2026
Ships fairly regularly
a new release about every 8 months
Some releases are documented
notes for 10 of 28 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
28 releases · first in 2015
1 release in the last 12 months
see the full history below
Release timeline
28 releases · Jun 2015 to Aug 2026Releases
latest 28-
v3.1.018 Aug 2026Release notes
Open source →What's Changed
- Add getPolicies method to CSPBuilder class by @jahidulpabelislam in #80
- Upgrade actions/checkout to 7.x by @jahidulpabelislam in #82
- add "wasm-unsafe-eval" directive to CSPBuilder by @cliffordvickrey in #81
- Fix CI, add PHP 8.5 to build matrix by @paragonie-security in #83
New Contributors
- @jahidulpabelislam made their first contribution in #80
Full Changelog: v3.0.2...v3.1.0
-
v3.0.203 Jan 2025Release notes
Open source →What's Changed
- add updates for PHP 8.4 by @cliffordvickrey in #78
New Contributors
- @cliffordvickrey made their first contribution in #78
Full Changelog: v3.0.1...v3.0.2
-
v3.0.108 May 2024 -
v3.0.018 Dec 2023Release notes
Open source →What's Changed
- PHP <7.4 is not supported in this new major version!
- The changes in #70 created a dependency conflict with PHP <7.4.
- Add a CSP header parser (
CSPBuilder::fromHeader) by @fritzmg in #74 - un-deprecate
frame-srcby @fritzmg in #76 - Generate nonce also when only
default-srcpolicy is applied by @fritzmg in #65 - Add PoC of report-to header by @Firesphere in #70
Full Changelog: v2.9.0...v3.0.0
- PHP <7.4 is not supported in this new major version!
-
v2.9.024 May 2023Release notes
Open source →What's Changed
- Add support for
psr/http-messagev2 by @internalsystemerror in #73 - Fix support for script-src-{elem|attr}, Add support for style-src-{elem|attr} by @internalsystemerror in #71
New Contributors
- @internalsystemerror made their first contribution in #73
Full Changelog: v2.8.1...v2.9.0
- Add support for
-
v2.8.126 Mar 2023Release notes
Open source →What's Changed
- Add 'url' type value for report-uri by @danieltott in #61
- Fix
plugin-typesgeneration by @fritzmg in #69 - report-uri should not be encoded at all by @Firesphere in #64
- Ignore PHPUnit result cache by @fritzmg in #67
- Allow 'unsafe-hashed-attributes' to be set by @fritzmg in #68
- Remove trailing semicolon by @fritzmg in #66
New Contributors
- @danieltott made their first contribution in #61
- @fritzmg made their first contribution in #69
- @Firesphere made their first contribution in #64
Full Changelog: v2.8.0...v2.8.1
-
v2.8.015 Dec 2022Release notes
Open source →Prevent semicolon or CLRF injection. See 1a1a85f for details.
CSP-Builder is a developer tool. It is not meant to be used with user input.
However, the ability to inject CSP directives or additional headers violates the principle of least astonishment.
This was reported via user demonia on HackerOne.
-
v2.7.001 Oct 2022 -
v2.6.007 Sep 2021 -
v2.5.002 Sep 2020Release notes
Open source →- Consistently invalidate the compiled CSP cache.
- Update PHPUnit, etc.
- Dropped support for PHP 7.0. You can continue to install 2.4.0, but we will not be backporting patches into the old version. PHP 7.0 is EOL, please upgrade to 7.4 or newer.
-
v2.4.019 Oct 2019Nothing published for this version
-
v2.3.103 Jan 2019Nothing published for this version
-
v2.3.020 Nov 2017Nothing published for this version
-
v2.2.008 Nov 2017Nothing published for this version
-
v2.1.024 Jul 2017Nothing published for this version
-
v2.0.101 Nov 2016Nothing published for this version
-
v2.0.009 Apr 2016Nothing published for this version
-
v1.4.009 Nov 2017Nothing published for this version
-
v1.3.301 Nov 2016Nothing published for this version
-
v1.3.117 Feb 2016Nothing published for this version
-
v1.3.001 Feb 2016Nothing published for this version
-
v1.2.430 Jan 2016Nothing published for this version
-
v1.2.329 Jan 2016Nothing published for this version
-
v1.2.220 Jan 2016Nothing published for this version
-
v1.2.113 Jan 2016Nothing published for this version
-
v1.2.003 Jan 2016Nothing published for this version
-
v1.1.002 Jan 2016Nothing published for this version
-
1.0.016 Jun 2015Nothing published for this version