Software update: Symfony 4.2.1 / 4.1.9 / 4.0.15 / 3.4.20 / 2.8.49 / 2.7.50

Spread the love

Symfony is a php web application framework and is available under the mit license. In addition to a framework and reusable components offers Symfony a philosophy, methodology and community, supported by SensioLabs. There are also various topics about this on our Forum. The developers released versions 4.2.1, 4.1.9, 4.0.15, 3.4.20, 2.8.49 and 2.7.50 a few days ago with the following announcements:

Symphony 4.2.1 released

Symfony 4.2.1 has just been released. Here is a list of the most important changes:

  • security #cve-2018-19790 [SecurityHttp] detect bad redirect targets using backslashes
  • security #cve-2018-19789 [Form] Filter file uploads out of regular form types
  • bug #29481 [TwigBridge] Deprecating legacy Twig paths in DebugCommand and simplifications
  • bug #29436 [Cache] Fixed Memcached adapter doClear() to call flush()
  • bug #29482 Fixes sprintf(): Too few arguments in MessageFormatter::choiceFormat
  • bug #29461 [Contracts] extract LocaleAwareInterface out of TranslatorInterface
  • bug #29446 [VarExporter] fix dumping private properties from abstract classes
  • bug #29441 [Routing] ignore trailing slash for non-GET requests
  • bug #29445 [FrameworkBundle] Fix empty output for debug:autowiring when reflection-docblock is not installed
  • bug #29444 [Workflow] Fixed BC break for Workflow metadata
  • bug #29432 [DI] dont inline when lazy edges are found
  • bug #29413 [Serializer] fixed DateTimeNormalizer to maintain microseconds when a different timezone required
  • bug #29424 [Routing] fix taking verb into account when redirecting
  • bug #29418 [VarExporter] fix dumping protected property from abstract classes
  • bug #29414 [DI] Fix dumping expressions accessing single-use private services
  • bug #28853 [LDAP] Add TIMEOUT Option to LDAP Connection Options
  • bug #29399 [FrameworkBundle] define doctrine as defaul _pd _provider only if the package is installed
  • bug#29375 [Validator] Allow ConstraintViolation::toString() to expose codes that are not null or emtpy strings
  • bug #29376 [EventDispatcher] Fix eventListener wrapper loop in TraceableEventDispatcher
  • bug #29386 undeprecate the single-colon notation for controllers
  • bug #29393 [DI] fix edge case in InlineServiceDefinitionsPass
  • bug #29394 [Config] fix path exclusion during glob discovery
  • bug #29395 [FrameworkBundle][Messenger] Restore check for messenger serializer default id
  • bug#29380 [Routing] fix greediness or trailing slash
  • security #cve-2018-14774 [HttpKernel] fix trusted headers management in HttpCache and InlineFragmentRenderer
  • security #cve-2018-14773 [HttpFoundation] Remove support for legacy and risky HTTP headers

Symphony 4.1.9 released

Symfony 4.1.9 has just been released. Here is a list of the most important changes:

  • security #cve-2018-19790 [SecurityHttp] detect bad redirect targets using backslashes
  • security #cve-2018-19789 [Form] Filter file uploads out of regular form types
  • bug #29436 [Cache] Fixed Memcached adapter doClear() to call flush()
  • bug #29441 [Routing] ignore trailing slash for non-GET requests
  • bug #29444 [Workflow] Fixed BC break for Workflow metadata
  • bug #29432 [DI] dont inline when lazy edges are found
  • bug #29413 [Serializer] fixed DateTimeNormalizer to maintain microseconds when a different timezone required
  • bug #29424 [Routing] fix taking verb into account when redirecting
  • bug #29414 [DI] Fix dumping expressions accessing single-use private services
  • bug#29375 [Validator] Allow ConstraintViolation::toString() to expose codes that are not null or emtpy strings
  • bug #29376 [EventDispatcher] Fix eventListener wrapper loop in TraceableEventDispatcher
  • bug #29386 undeprecate the single-colon notation for controllers
  • bug #29393 [DI] fix edge case in InlineServiceDefinitionsPass
  • bug#29380 [Routing] fix greediness or trailing slash
  • bug #29343 [Form] Handle all case variants of “nan” when parsing a number
  • bug #29373 [Routing] fix trailing slash redirection
  • bug #29355 [PropertyAccess] calculate cache keys for property setters depending on the value
  • bug #29369 [DI] fix combinatorial explosion when analyzing the service graph
  • bug #29349 [Debug] workaround opcache bug mutating “$this” !?!

Symphony 4.0.15 released

Symfony 4.0.15 has just been released. Here is a list of the most important changes:

  • security #cve-2018-19790 [SecurityHttp] detect bad redirect targets using backslashes
  • security #cve-2018-19789 [Form] Filter file uploads out of regular form types

Symphony 3.4.20 released

Symfony 3.4.20 has just been released. Here is a list of the most important changes:

  • security #cve-2018-19790 [SecurityHttp] detect bad redirect targets using backslashes
  • security #cve-2018-19789 [Form] Filter file uploads out of regular form types
  • bug #29436 [Cache] Fixed Memcached adapter doClear() to call flush()
  • bug #29441 [Routing] ignore trailing slash for non-GET requests
  • bug #29432 [DI] dont inline when lazy edges are found
  • bug #29413 [Serializer] fixed DateTimeNormalizer to maintain microseconds when a different timezone required
  • bug #29424 [Routing] fix taking verb into account when redirecting
  • bug #29414 [DI] Fix dumping expressions accessing single-use private services
  • bug#29375 [Validator] Allow ConstraintViolation::toString() to expose codes that are not null or emtpy strings
  • bug #29376 [EventDispatcher] Fix eventListener wrapper loop in TraceableEventDispatcher
  • bug #29343 [Form] Handle all case variants of “nan” when parsing a number
  • bug #29355 [PropertyAccess] calculate cache keys for property setters depending on the value
  • bug #29369 [DI] fix combinatorial explosion when analyzing the service graph
  • bug #29349 [Debug] workaround opcache bug mutating “$this” !?!

Symphony 2.8.49 released

Symfony 2.8.49 has just been released. Here is a list of the most important changes:

  • security #cve-2018-19790 [SecurityHttp] detect bad redirect targets using backslashes
  • security #cve-2018-19789 [Form] Filter file uploads out of regular form types

Symphony 2.7.50 released

Symfony 2.7.50 has just been released. Here is a list of the most important changes:

  • security #cve-2018-19790 [SecurityHttp] detect bad redirect targets using backslashes
  • security #cve-2018-19789 [Form] Filter file uploads out of regular form types

Version number 4.2.1 / 4.1.9 / 4.0.15
Release status Final
Operating systems script language
Website symphony
Download
License type Conditions (GNU/BSD/etc.)
You might also like