Security fixes are released for the latest version of each maintained release line:
| Version | PHP | Supported |
|---|---|---|
8.5.x |
8.5 | ✅ |
8.4.x |
8.4 | ✅ |
8.3.x |
8.3 | ✅ |
8.2.x |
8.2 | ✅ |
8.1.x |
8.1 | ✅ |
8.0.x |
8.0 | ✅ |
2.x |
8.0 | ❌ |
< 2.0 |
– | ❌ |
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests, and do not disclose them publicly until a fix has been coordinated.
Report them privately through GitHub Security Advisories, or by email to the maintainer listed in composer.json.
Please include:
- The affected package version and PHP version.
- A description of the vulnerability and its impact.
- Steps or code to reproduce it (for example, the input that triggers it).
- Any known workaround.
You will receive a response as soon as possible. Once a fix is released, the vulnerability will be disclosed publicly with credit to the reporter, unless you prefer to stay anonymous.