NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #3259 most downloaded on Packagist
JWT Bundle of the JWT Framework.
Last release 1 months ago
26 Aug 2026
Release timing varies
gaps range from 4 weeks to 1.6 years
Some releases are documented
notes for 16 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
133 releases · first in 2017
Adds the "keypkcs8" command, the counterpart of "keypkcs1", for the projects that share keys with libraries only able to import PKCS#8 private keys, s
Adds the "key:convert:pkcs8" command, the counterpart of "key:convert:pkcs1",
for the projects that share keys with libraries only able to import PKCS#8
private keys, such as the npm "jose" package.
RSA keys already had a PKCS#8 representation through RSAKey::toPEM(). EC keys
gain ECKey::convertPrivateKeyToPKCS8PEM(), which wraps the RFC 5915 ECPrivateKey
into a PrivateKeyInfo structure and supports every curve of the framework, the
Brainpool ones included. OKP keys gain the OKPKey utility and, with it, their
first JWK to PEM conversion.
As PKCS#8 only covers private keys, public keys are converted into a
SubjectPublicKeyInfo structure.
Closes #661
Adds the "keypkcs8" command, the counterpart of "keypkcs1", for the projects that share keys with libraries only able to import PKCS#8 private keys, s
Adds the "key:convert:pkcs8" command, the counterpart of "key:convert:pkcs1",
for the projects that share keys with libraries only able to import PKCS#8
private keys, such as the npm "jose" package.
RSA keys already had a PKCS#8 representation through RSAKey::toPEM(). EC keys
gain ECKey::convertPrivateKeyToPKCS8PEM(), which wraps the RFC 5915 ECPrivateKey
into a PrivateKeyInfo structure and supports every curve of the framework, the
Brainpool ones included. OKP keys gain the OKPKey utility and, with it, their
first JWK to PEM conversion.
As PKCS#8 only covers private keys, public keys are converted into a
SubjectPublicKeyInfo structure.
Closes #661
One column per quarter.
Adds the "keypkcs8" command, the counterpart of "keypkcs1", for the projects that share keys with libraries only able to import PKCS#8 private keys, s
Adds the "key:convert:pkcs8" command, the counterpart of "key:convert:pkcs1",
for the projects that share keys with libraries only able to import PKCS#8
private keys, such as the npm "jose" package.
RSA keys already had a PKCS#8 representation through RSAKey::toPEM(). EC keys
gain ECKey::convertPrivateKeyToPKCS8PEM(), which wraps the RFC 5915 ECPrivateKey
into a PrivateKeyInfo structure and supports every curve of the framework, the
Brainpool ones included. OKP keys gain the OKPKey utility and, with it, their
first JWK to PEM conversion.
As PKCS#8 only covers private keys, public keys are converted into a
SubjectPublicKeyInfo structure.
Closes #661
Adds the "keypkcs8" command, the counterpart of "keypkcs1", for the projects that share keys with libraries only able to import PKCS#8 private keys, s
Adds the "key:convert:pkcs8" command, the counterpart of "key:convert:pkcs1",
for the projects that share keys with libraries only able to import PKCS#8
private keys, such as the npm "jose" package.
RSA keys already had a PKCS#8 representation through RSAKey::toPEM(). EC keys
gain ECKey::convertPrivateKeyToPKCS8PEM(), which wraps the RFC 5915 ECPrivateKey
into a PrivateKeyInfo structure and supports every curve of the framework, the
Brainpool ones included. OKP keys gain the OKPKey utility and, with it, their
first JWK to PEM conversion.
As PKCS#8 only covers private keys, public keys are converted into a
SubjectPublicKeyInfo structure.
Closes #661
All three QA gates were red on this branch, two of them because a tool config referenced a constant that upstream had removed, so the job died before
All three QA gates were red on this branch, two of them because a tool
config referenced a constant that upstream had removed, so the job died
before analysing anything.
SetList::PHPUNIT and SetList::STRICT, both gone fromOrderedImportsFixer was registered bare, whichclass, function, const order that CLEAN_CODEPHPUnitSetList::PHPUNIT_120, folded upstream into thewithComposerBased(phpunit: true) wasergebnis/phpstan-rules andphpstan-beberlei-assert extensions, matching 4.2.x. ergebnis aloneThe 34 errors PHPStan then reported are fixed rather than baselined,
mostly types tightened by brick/math and Symfony: non-empty-string for
BigInteger::fromBase, positive lengths for random_bytes and
randomBits, crit and key_ops validated as lists of strings.
Two Symfony denormalizer covariance errors remain baselined, as on 4.2.x.
JWKFactory::createOctKey() now rejects sizes below 8 bits, which only
turns an already-broken zero-length secret into an explicit error.
Test results are unchanged: the same 38 pre-existing failures, all in the
bundle configuration tests.
All three QA gates were red on this branch, two of them because a tool config referenced a constant that upstream had removed, so the job died before
All three QA gates were red on this branch, two of them because a tool
config referenced a constant that upstream had removed, so the job died
before analysing anything.
SetList::PHPUNIT and SetList::STRICT, both gone fromOrderedImportsFixer was registered bare, whichclass, function, const order that CLEAN_CODEPHPUnitSetList::PHPUNIT_120, folded upstream into thewithComposerBased(phpunit: true) wasergebnis/phpstan-rules andphpstan-beberlei-assert extensions, matching 4.2.x. ergebnis aloneThe 34 errors PHPStan then reported are fixed rather than baselined,
mostly types tightened by brick/math and Symfony: non-empty-string for
BigInteger::fromBase, positive lengths for random_bytes and
randomBits, crit and key_ops validated as lists of strings.
Two Symfony denormalizer covariance errors remain baselined, as on 4.2.x.
JWKFactory::createOctKey() now rejects sizes below 8 bits, which only
turns an already-broken zero-length secret into an explicit error.
Test results are unchanged: the same 38 pre-existing failures, all in the
bundle configuration tests.
Merge branch '4.0.x' into 4.1.x
Merge branch '4.0.x' into 4.1.x
Add GitHub Action to auto-switch default branch on new tags
Add GitHub Action to auto-switch default branch on new tags
Add GitHub Action to auto-switch default branch on new tags
Add GitHub Action to auto-switch default branch on new tags
Add GitHub Action to auto-switch default branch on new tags
Add GitHub Action to auto-switch default branch on new tags
Add GitHub Action to auto-switch default branch on new tags
Add GitHub Action to auto-switch default branch on new tags
Add GitHub Action to auto-switch default branch on new tags
Add GitHub Action to auto-switch default branch on new tags
Conflicts: phpstan-baseline.neon
Conflicts: phpstan-baseline.neon
3.4.x: Update signature tests for the protected-header "alg" requirement (#651) Merge commit from fork Merge commit from fork Merge commit from fork M
psr/cache v2 (#620)Fix key derivation by removing curve size parameter from openssl_pkey…
Fix key derivation by removing curve size parameter from openssl_pkey…
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →