NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #288 most downloaded on Packagist
Provides a tight integration of the Security component into the Symfony full-stack framework
Last release 11 days ago
24 Sep 2026
Ships fairly regularly
a new release about every 4 weeks
Rarely documented
notes for 1 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
15 years old
719 releases · first in 2011
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
The normalization of the cookie names configured in the logout.delete_cookies option is deprecated and will be disabled in Symfony 5.0. This affects t…
auto (recommended), native and sodiumlogout.delete_cookies
option is deprecated and will be disabled in Symfony 5.0. This affects to cookies
with dashes in their names. For example, starting from Symfony 5.0, the my-cookie
name will delete my-cookie (with a dash) instead of my_cookie (with an underscore).Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
…parameters to define the token classes is deprecated. To use custom tokens extend the existing Symfony\Component\Security\Core\Authentication\Token\An…
security.authentication.trust_resolver.anonymous_class and
security.authentication.trust_resolver.rememberme_class parameters to define
the token classes is deprecated. To use custom tokens extend the existing
Symfony\Component\Security\Core\Authentication\Token\AnonymousToken.
or Symfony\Component\Security\Core\Authentication\Token\RememberMeToken.Symfony\Bundle\SecurityBundle\DependencyInjection\Compiler\AddExpressionLanguageProvidersPassjson_login_ldap authentication provider to use LDAP authentication with a REST API.framework.session.cookie_*
and added an "auto" mode to their "secure" config option to make them secure on HTTPS automatically.simple_form and simple_preauth authentication listeners, use Guard instead.SimpleFormFactory and SimplePreAuthenticationFactory classes, use Guard instead.port in access_controlNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
The switch_user.stateless firewall option is deprecated, use the stateless option instead.
switch_user.stateless firewall option is deprecated, use the stateless option instead.logout_on_user_change firewall option is deprecated.SecurityUserValueResolver, use
Symfony\Component\Security\Http\Controller\UserValueResolver instead.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
removed FirewallContext::getContext()
FirewallContext::getContext()FirewallMap::$container and ::$map privateUserPasswordEncoderCommand::_construct() argument mandatoryUserPasswordEncoderCommand does not extend ContainerAwareCommand anymoreVoterInterfaceacl:set along with SetAclCommand classinit:acl along with InitAclCommand classacl configuration key and related services, use symfony/acl-bundle insteadlogout_on_user_change is now always true, which will trigger a logout if the user changes
between requestsswitch_user.stateless firewall option is true for stateless firewallsNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →