This week, Symfony 6.4.47, 7.4.20, and 8.1.8 were released, along with Symfony Reprise 1.3.0. Meanwhile, we continued introducing Symfony 8.2 features, including OpenID Connect login, PGP/MIME signed and encrypted emails, sudo mode, more flexible serialization groups, and performance improvements. Finally, we announced more talks for SymfonyCon Warsaw 2026.

Symfony development highlights

This week, 364 pull requests were merged (191 in code, 63 in docs, 101 in UX and 9 in AI) and 92 issues were closed (33 in code, 47 in docs, 8 in UX and 4 in AI). Excluding merges, 67 authors made additions and deletions. See details for code, docs, UX and AI.

6.4 changelog:

  • 7a9b164: [Serializer] fix the cache key of MetadataAwareNameConverter when the context can't be serialized
  • a7fe780: [FrameworkBundle] disable HTTP/2 push on the default HTTP client
  • 410b9c3: [HttpKernel] fix the log level of exceptions mapped to an HTTP status code
  • 7e59fe0: [Serializer] don't include the debug trace id in the attributes cache key
  • 243d173: [DoctrineBridge] never claim an object as a collection key type
  • 2b7cf91: [WebProfilerBundle] escape the workflow diagram source and listener map in the profiler
  • cfbee39: [DoctrineBridge] don't map the uuid and ulid type names to uid classes in DoctrineExtractor
  • 983d5a5: [Cache] escape glob characters when clearing Redis namespaces
  • 35f513e: [DependencyInjection] export the service id when sharing a circular wither service
  • f8e2d14: [FrameworkBundle] fix the description of an empty webhook routing secret
  • 60cf683: [DependencyInjection, Routing] escape identifiers in generated PHP
  • ce086d4: [DependencyInjection] track env placeholders reused after a previous extension dropped them
  • b530685: [String] update wcswidth data with Unicode 18
  • 3172f3f: [String] fix the width of emoji sequences and conjoining Hangul jamo
  • be608ca: [Messenger] fix decoding ErrorDetailsStamp with Serializer::create()
  • af9e4e4: [HttpClient] cap the timeout passed to curl_multi_select()
  • 6ad469d: [Messenger] fix decoding ErrorDetailsStamp with the XML format
  • 6aa5b27: [Messenger] don't send handler results to transports
  • db66f78: [Messenger] turn any error thrown while decoding into a MessageDecodingFailedException
  • c588108: [Messenger] fix decoding in XML an ErrorDetailsStamp that has no FlattenException
  • fe8998a: [Messenger] fix decoding in XML a ValidationStamp that has one group or none
  • fff4db5: [Messenger] fix recognizing a repeated error when its code does not keep its type in XML
  • 82fab8a: [Messenger] fix decoding a ValidationStamp that holds a GroupSequence
  • 983971e: [HttpFoundation] fix HeaderUtils::split() when a separator is a whitespace character
  • c2aee89: [String] fix width() of skin tones on keycap and text-default bases, and of format characters
  • 7a5c6a7: [Messenger] fix moving a message between transports that use different serialization formats
  • e465d45: [String] fix width() of OSC sequences terminated by BEL
  • 16c8fdb: [String] fix width() of escape sequences with an intermediate or a digit final byte
  • 2a5c8f7: [Yaml] fix round-tripping literal blocks that start with spaces-only lines
  • 32d3f8e: [PhpUnitBridge] remove silencing of __sleep/wakeup() deprecations
  • 4800ae8: [Messenger] reject decoded messages that carry non-sendable stamps and validate the stamps of unserialized envelopes
  • f4d6d8b: [Messenger] recommend not decoding non-sendable stamps in SerializerInterface::decode()
  • 47ec709: [HttpFoundation] keep the session ID when the session handler fails to read
  • e763561: [Yaml] fix dumping tagged multi-line literal blocks
  • 513e96d: [Messenger] fix losing delayed messages when retrying the message that dispatched them
  • 3614876: [Messenger] fix the Doctrine transport masking commit failures
  • beb4c9c: [Security] pass only stringable request attributes to the URL generator in HttpUtils
  • 68051a6: [FrameworkBundle] don't list aliases of abstract services in debug:autowiring
  • ec54b1e: [Yaml] quote .inf and .nan strings when dumping
  • 132867d: [String] fix wordwrap() with $cut when the string ends with the break

7.4 changelog:

  • 30802f4: [JsonStreamer] fix generic types replacement in array shapes
  • ad7c073: [TypeInfo] fix accepts() of union and intersection types
  • 03654e1: [TypeInfo] fix quoted strings resolution with phpstan/phpdoc-parser 1.x
  • 489d20d: [Serializer, Validator] fix compile-time discovery of attributes on non-public members
  • bb5fdd6: [HtmlSanitizer] fix sanitizeFor() with table-related, image and plaintext contexts
  • f25ca4f: [HtmlSanitizer] don't render comments as elements when the default action is Allow
  • 21e5e2a: [TypeInfo] fix printing array shape keys that contain quotes or backslashes
  • c462177: [JsonStreamer] fix replacing templates by mixed in union types
  • c2e593d: [ObjectMapper] construct nested lazy-ghost targets when the mapper is decorated
  • 94e5b55: [TypeInfo] fix Type::union() with mixed as the only non-null type
  • 0c4996e: [PropertyInfo] fix quoted strings resolution in PhpStanExtractor with phpstan/phpdoc-parser 1.x
  • 6321df0: [TypeInfo] fix infinite recursion on recursive type aliases
  • fb7d2b3: [Security] give each role its own node in the Mermaid dump
  • 3571209: [JsonStreamer] fix generated readers and writers for names holding quotes
  • a3f66cc: [Cache] bind namespaces in PDO-based cache invalidation
  • 7dcbcde: [Security] bind discovered OIDC keys to issuers
  • 43dce2d: [JsonStreamer] escape types in generated PHP comments
  • 41e11de: [Messenger] prevent PhpSerializer::getMessageType() from autoloading classes
  • ee2ab09: [Mailer, Sweego] send the Reply-To address through the dedicated API field
  • 9ef2936: use full setting name in deprecation message for consistency
  • d6f029e: [Messenger] fix workers stopping on messages that fail signature verification
  • 722eb74: [Mailer, Sweego] accept fractional seconds in webhook timestamps
  • 8d7dadc: [Lock] fix denormalizing in XML a Key that has no expiring time or no state
  • 78b2cea: [Messenger] fix skipping a message that has no original transport in messenger:failed:retry
  • d8cb531: [FrameworkBundle, Messenger, Scheduler] require a signature for RedispatchMessage and ServiceCallMessage
  • 6d25294: [Mailer, MicrosoftGraph] only forward headers that Graph can accept
  • 990636b: [HttpClient] fix using HTTP/3 with CurlHttpClient
  • ffc1b79: [JsonPath] fix index and slice selectors dropping null array elements
  • 8881c9c: [JsonPath] fix anchoring and slash escaping in match() and search()
  • 6b8537d: [Scheduler] fix processOnlyLastMissedRun() skipping every missed run after a restart

8.1 changelog:

  • c505a39: [DependencyInjection, FrameworkBundle] fix describing services that have env closure arguments
  • 6dc4600: [TypeInfo] fix object shape keys resolution in StringTypeResolver
  • 963994d: [TypeInfo] fix printing object shape keys that contain quotes or backslashes
  • abce89e: [JsonStreamer] fix generic types replacement in object shapes
  • 739581a: [FrameworkBundle] require symfony/dependency-injection ^8.1.8
  • 82c3ec2: [Tui] repaint the viewport without clearing the screen when overflowing content shrinks
  • 335148d: [Tui] paint lines already in the scrollback in place when overflowing content grows back
  • 55d26ca: [JsonStreamer] export the type as a literal in the generated encoding error message
  • 2e56795: [Tui] fix slicing counting a combining mark as a column
  • 0c3f6ee: [Messenger] keep the signature of signed messages that fail to decode
  • ccfe5b6: [Messenger] don't retry messages rejected for their signature
  • a6d9000: [Tui] measure an emoji ZWJ, modifier or tag sequence as two columns
  • 6fd896e: [Messenger] fix acking messages that InMemoryTransport fails to decode
  • 42952ca: [Messenger] fix endless retries of messages with an empty body or an undecodable stamp header
  • 0eef6c7: [Messenger] fix duplicated stamps when a message that failed to decode is decoded on replay
  • bba9ddb: [Messenger] fix losing the payload of a message without a type header when it is retried
  • 00d18e6: [Messenger] fix ack/reject of Redis messages listed by the failed messages commands
  • 1cf261c: [Messenger] route a message that PhpSerializer fails to decode to its own bus
  • d060748: [Tui] fix wrapLineIntoChunks() returning a chunk wider than the width after wrapping at a space
  • fc6822c: [Tui] give no width to format characters and lone combining marks
  • 3217edf: [Messenger] add the default stamps of a message to its replayed decoding failure
  • 1db8c7c: [Tui] fix parse() and matches() of modified function keys
  • 6cebc11: [Tui] match a modified escape that parse() names

8.2 changelog:

  • 296470b: [PropertyInfo] create the inflector and the type resolver of ReflectionExtractor on first use
  • 91cdb3d: [TypeInfo] parse the class docblock once when creating a type context
  • 7d66574: [Cache] clone the calls of CacheDataCollector once per profile
  • 8c4eb68: [AssetMapper] load each cached asset once per request and from a single file
  • 720a5ef: [TwigBundle] skip templates already warmed up under another name
  • 343fa46: [HttpKernel] compute the cURL command of RequestDataCollector in lateCollect()
  • 245ca50: [AssetMapper, FrameworkBundle, WebProfilerBundle] build neither the profiler nor Twig when the dev server serves an asset
  • 8d581ad: [FrameworkBundle] build the configuration trees once for reference.php and schema.json
  • b73db07: [PropertyInfo] parse the constructor docblock once per class
  • 8823b6f: [Serializer] reduce the per-attribute overhead of normalizing objects
  • f606ec9: [Serializer] speed up name conversion when normalizing objects
  • 1248d08: [PropertyInfo, Serializer, Validator] warm up property info for the classes mapped by the serializer and the validator
  • 590ba12: [HtmlSanitizer] skip parsing plain text
  • 9b9212a: [Serializer] aggregate nested calls in SerializerDataCollector as they happen
  • 0ffd5b3: [HttpKernel] log client errors at the warning level instead of error
  • d827566: [HttpKernel] log exceptions without flattening them
  • 69cf483: [Validator] reuse the IntlDateFormatter of ConstraintValidator::formatValue()
  • 93a532a: [PropertyAccess] reduce the overhead of reading properties
  • 7020f70: [Serializer] look up constructor parameters before property info when denormalizing
  • c43fb8c: [Serializer] don't read class files when resolving the types of constructor parameters
  • ae2f63b: [HttpKernel] collect the static data of ConfigDataCollector in lateCollect()
  • c0bc6eb: [SecurityBundle] move the static work of SecurityDataCollector to lateCollect()
  • f5e38b5: conflict with outdated Symfony UX packages when requiring symfony/symfony
  • 659cd62: [TwigBundle] warm up only reachable form themes
  • 0447e59: [FrameworkBundle, HttpKernel] skip resolving the runtime mode on web requests
  • d3b022a: [DependencyInjection] skip encoding plain ASCII values in XmlDumper
  • d49cb69: [Serializer] don't create a property accessor per denormalized object
  • 6686941: [TypeInfo, Serializer, JsonStreamer] add Type::map()
  • 1eba7ce: [KeyManagement] record the key ARN returned by AWS KMS in ciphertexts
  • 9c6ba22: [Translation] extract messages from match expressions, interpolated strings, variables and method return values
  • f212f28: [HttpClient] allow repeating fields in the query and body options
  • df1286f: [Validator] make Constraint objects invokable
  • 3b94fb1: [SecurityBundle] fix the role hierarchy diagram in the profiler
  • 0a71f5f: [Messenger] allow using a named serializer for messenger.transport.symfony_serializer
  • 775c1c2: [FrameworkBundle] allow using a named serializer for #[MapRequestPayload], #[MapQueryString] & #[Serialize]
  • a4916cb: [Mailer, Scaleway] bind webhook requests to the configured topic ARN
  • a1bff76: [String] skip the per-character width measurement for printable ASCII
  • 7eaf80c: [KeyManagement] reject empty column values in the DBAL type
  • 4732193: [Messenger] fix redispatching a message that failed to decode
  • 977b90b: [Messenger] retry a claim that could not be retrieved with its original reference
  • a6d7e84: [Security] let voters tell which denials a re-authentication can cure
  • 616a19c: [Security, SecurityBundle] let the discovery endpoints of the oidc token handler be pinned to their issuer
  • fec3f91: [Messenger] fix unverified decoding failures putting their stamps on signed messages
  • e661238: [Messenger] fix endless retries of a claim that cannot be retrieved
  • d1659d2: [Security] start a re-authentication for a check made by an allow_if expression or an #[IsGranted] closure
  • 494d536: [Mime] keep the explicit encoding of parts in FormDataPart
  • feb08ca: [Messenger] route a claim that cannot be retrieved to the bus of its message
  • 3bf30ac: [Messenger] reject an unverified decoding failure that runs on another bus than its signed message
  • 7cc98e4: [TwigBundle] skip checking known template directories on each request
  • 7384daa: [Security] make FormLoginAuthenticator a re-authentication entry point
  • 7614f74: [Messenger, Scheduler] replace RedispatchMessageHandler by a non-sendable RedispatchStamp
  • fa61c64: [Messenger] let a flow carry its context in stamps: propagation, handler arguments and identity
  • f9cce70: [Messenger] keep an application-defined message id generator when symfony/uid is missing
  • 13a9950: [Messenger] merge the identity and propagation middlewares into FlowContextMiddleware and track delayed messages
  • 9917e11: [Messenger, Scheduler] add a sign option to transports to sign every message
  • 95b3e61: [Messenger] make SyncTransport trust the messages dispatched in this process
  • 515f227: [Messenger] stop forwarding a redispatched message again once it was sent
  • d547b96: [Messenger] refuse to call handlers that require a signature for untrusted envelopes
  • 0520527: [FrameworkBundle, RateLimiter] register RateLimitAttributeListener in FrameworkBundle
  • 37457db: [Tui] add the super, hyper and meta modifiers to key ids
  • e130143: [Messenger] fix sending stamps and trust to parallel workers
  • 1b33dca: [Messenger] fix delaying acks until after the idle sleep with --concurrency
  • e469e86: [Tui] reject a key id naming an unknown key when creating Keybindings
  • b024412: [HttpClient] use HTTP/2 with prior knowledge when http_version is 2.0
  • d56d793: [Messenger] add ChainStamp to dispatch messages one after another
  • 8318c76: [Messenger] add DispatchOnFailureStamp to dispatch a message when another one fails
  • 77b7797: [KeyManagement] bind a stored data key to its reference and scope
  • be05acb: [Tui] add Tui::getWidgetRect()
  • e9a0f11: [Form] add the sort_choices option to ChoiceType
  • 24809fd: [FrameworkBundle, HttpFoundation, Messenger, Security, SecurityBundle] allow rotating the secrets that sign URIs, remember-me cookies, login links and messages
  • ed4c60b: [FrameworkBundle] improve the hints shown by debug:autowiring
  • de96277: [JsonStreamer, Mailer, Notifier, SecurityBundle, Webhook] deprecate autowiring aliases named after implementations
  • 5a5cd5b: [DependencyInjection] move PriorityTaggedServiceUtil to its own file so that it can be autoloaded
  • cb263b0: [Config, DependencyInjection] add NodeDefinition::inlineEnvVars() to inline env vars while the container is compiled
  • cb53c82: [DependencyInjection] add within and around constraints to order decorators
  • 08829a1: [Config] fix enum nodes and validation rules that inline env vars

Symfony UX development highlights

3.x changelog:

  • 683b467: [Image] add the UX Image package and its Cloudflare and KeyCDN bridges
  • 865e532: [Toolkit] ship kit preview assets and add a preview app
  • 19c7ad8: [Toolkit] add visual tests for recipes
  • e7e7f1b: [Toolkit, Shadcn] fix the popover not focusing its content on a busy browser
  • 27da043: [Toolkit] shard the browser tests and keep the server logs out of the CI output
  • 402afd1: [Toolkit, Flowbite] fix the modal having no accessible name
  • dd302b3: [Toolkit, Flowbite] fix inactive tabs being unreadable in dark mode
  • cdc2878: [Toolkit, Shadcn] fix the arrow keys getting stuck before a disabled accordion item
  • 01b3ed4: [Toolkit, Shadcn] fix alert dialogs opening on page load
  • db56b43: [Toolkit, Shadcn] fix a closed drawer staying reachable with the keyboard
  • 8d2b82f: [Toolkit, Shadcn] fix the combobox list not lining up with its trigger
  • 3ebdfa0: [Toolkit, Shadcn] fix the radio indicator of the dropdown menu being a ring instead of a dot
  • 183536e: [Toolkit, Shadcn] fix dropdown submenus wrapping their labels
  • 99e0def: [Toolkit, Shadcn] fix the date picker focusing "Previous month" instead of a day
  • 3e74e95: [Toolkit, Shadcn] fix the radio indicator of the menubar being a ring instead of a dot
  • b2d63a8: [Toolkit, Shadcn] fix menubar submenus wrapping long labels
  • fb844e7: [Toolkit, Shadcn] fix the dialog trigger's aria-expanded getting out of sync
  • 4fd09a2: [Toolkit, Shadcn] fix Tab skipping the panels of the navigation menu
  • e5896b1: [Toolkit, Shadcn] fix the resizable handle missing its separator state
  • 9525e93: [Toolkit, Shadcn] fix a closed sheet staying reachable with the keyboard
  • a2e0e03: [Toolkit, Shadcn] fix a disabled slider still reacting to the keyboard
  • 893bd57: [Toolkit, Shadcn] fix the slider losing the focus after a click on its track
  • c3f8aa5: [Toolkit, Shadcn] fix the close button and the action of a toast ignoring mouse clicks
  • b505c4c: [Toolkit, Shadcn] fix the bookmark icon not filling in the toggle examples
  • cf264f6: [Toolkit, Shadcn] fix the tooltip of the disabled button example never opening
  • 07052f9: [Toolkit] fix ux:install not overwriting a file newer than the recipe
  • 9becbdd: [Image] add presets
  • 4cfdb08: [Icons] warm local icons on cache:warmup
  • 7d06bf1: [TwigComponent] copy plain text in one go when pre-lexing templates
  • cfae61f: [Toolkit, Shadcn] align combobox with the upstream Shadcn UI component
  • 0297127: [Toolkit, Shadcn] align input-group with the upstream Shadcn InputGroup
  • 41789ce: [Toolkit, Shadcn] fix data-slot being shadowed when forwarded to a child component
  • 1ece7c6: [Toolkit, Shadcn] align select with the upstream Shadcn Select
  • f23c899: [Toolkit] show a diff when ux:install asks to overwrite a file
  • e396086: [Toolkit, Shadcn] keep the tooltip inside the viewport and fit it to its text
  • ee36b37: [Toolkit, Shadcn] fix resizable handle moving twice as far once moved in the DOM
  • 0e54cdf: [Toolkit, Shadcn] fix sonner losing its toasts once moved in the DOM
  • 06803d9: [Toolkit, Shadcn] fix dialog no longer being modal once moved in the DOM
  • c57118a: [Toolkit, Flowbite] fix modal no longer being modal once moved in the DOM
  • 30ae785: [Toolkit, Shadcn] fix navigation-menu never opening again once moved in the DOM
  • 8ae6aef: [Toolkit, Shadcn] fix alert-dialog no longer being modal once moved in the DOM
  • 9be2122: [Toolkit, Shadcn] fix questionnaire freeform answer losing its name once moved in the DOM
  • 49ab9cc: [LiveComponent] fix AssertDispatchedEvent::withPayloadSubset() crashing on non-scalar payload values
  • b8d4038: [Pagination] fix Cursor pagination with DATETIMETZ_MUTABLE columns
  • 5ef8a78: [Turbo] support the Mercure protocol 1.0 in turbo_stream_from()
  • c19924f: [Turbo] only trigger the TurboStreamListenRenderer deprecation when the service is used
  • dcbeef0: [LiveComponent] add the render:started hook to the ComponentHooks type
  • 40eaad0: [LiveComponent] fix child components lost inside a data-skip-morph element
  • 9613d13: [LiveComponent] finish the loading state when a request fails

Symfony Jobs

These are some of the most recent Symfony job offers:

  • Symfony Developer at Steward
    Part-time / Temporary - $8,700 – $13,000 / month
    Full remote
    View details
  • Symfony Developer at ATH
    Contract / Freelance - €25 – €50 / hour
    Full remote
    View details

You can publish a Symfony job offer for free on symfony.com.

SymfonyCasts Updates

SymfonyCasts is the official way to learn Symfony. Select a track for a guided path through 100+ video tutorial courses about Symfony, PHP and JavaScript.

This week, SymfonyCasts published the following updates:

Upcoming Symfony Events

Call to Action

Published in #A week of symfony