Weave Code
Code Weaver
Helps Laravel developers discover, compare, and choose open-source packages. See popularity, security, maintainers, and scores at a glance to make better decisions.
Feedback
Share your thoughts, report bugs, or suggest improvements.
Subject
Message

Security Bundle Laravel Package

nelmio/security-bundle

Symfony bundle adding practical security headers and protections: Content Security Policy, X-Frame-Options clickjacking defense, HSTS/HTTPS enforcement, signed cookies, external redirect detection, and content-type sniffing disablement.

View on GitHub
Deep Wiki
Context7
v3.9.0

What's Changed

Full Changelog: https://github.com/nelmio/NelmioSecurityBundle/compare/v3.8.0...v3.9.0

v3.8.0

What's Changed

Full Changelog: https://github.com/nelmio/NelmioSecurityBundle/compare/v3.7.0...v3.8.0

v3.7.0

What's Changed

Full Changelog: https://github.com/nelmio/NelmioSecurityBundle/compare/v3.6.0...v3.7.0

v3.5.0

What's Changed

Full Changelog: https://github.com/nelmio/NelmioSecurityBundle/compare/v3.4.2...v3.5.0

v3.4.2

What's Changed

New Contributors

Full Changelog: https://github.com/nelmio/NelmioSecurityBundle/compare/v3.4.1...v3.4.2

v3.4.1
v3.4.0

What's Changed

Full Changelog: https://github.com/nelmio/NelmioSecurityBundle/compare/v3.3.0...v3.4.0

v3.3.0
v3.1.0
  • Fixed overriding CSP header
  • Dropped support for Symfony < 5.4
  • Added support for Symfony 7
v3.0.0
  • Bump minimal PHP version to 7.4
  • Dropped support for Symfony < 4.4
  • Dropped support for Twig 1
  • Removed DoctrineCacheUAFamilyParser (use PsrCacheUAFamilyParser instead)
  • All classes have been marked as final
  • Renamed WhitelistBasedTargetValidator class to AllowListBasedTargetValidator
  • Removed CookieSessionHandler
  • Allowed to define host restriction for clickjacking protection
v3.0.0-alpha.1
  • Bump minimal PHP version to 7.4
  • Dropped support for Symfony < 4.4
  • Dropped support for Twig 1
  • Removed DoctrineCacheUAFamilyParser (use PsrCacheUAFamilyParser instead)
  • All classes have been marked as final
  • Renamed WhitelistBasedTargetValidator class to AllowListBasedTargetValidator
  • Removed CookieSessionHandler
  • Allowed to define host restriction for clickjacking protection
v2.12.0
  • Filter moz-extension reports
  • Log user agent along with CSP report
  • Deprecated external_redirects.whitelist option in favor of external_redirects.allow_list
  • Deprecated forced_ssl.whitelist option in favor of forced_ssl.allow_list
  • Deprecated Nelmio\SecurityBundle\ContentSecurityPolicy\Violation\Event class in favor of Nelmio\SecurityBundle\ContentSecurityPolicy\Violation\ReportEvent.
v2.11.0
  • Added support for CSP "prefetch-src" directive
  • Added support for CSP "wasm-unsafe-eval" keyword
  • Added support for Symfony 6
  • Fixed deprecations warnings using PHP 8.1
v2.10.3
  • Fixed Symfony 5 compatibility issues
v2.10.2
  • Fixed dependencies (allow installing on PHP 8 and explicitly require symfony/yaml)
v2.10.1
  • Fix ContentSecurityPolicyController
v2.10.0
  • Ensure compatibility with Symfony EventDispatcher 5.x
v2.9.1
  • Ensure passing the correct type to UAParser::parse
    • Use Symfony DI Reference instead of Definition
    • Optimize regular expressions in the sha computer
    • Show non-deprecated usage of the csp_nonce Twig function
v2.9.0
  • Symfony 5 compatibility added
    • Bump minimal Twig version to 1.38.0
v2.8.0
  • Fixed deprecated/invalid method usage on logger interface
    • Drop tests for PHP 5.4
2.7.0
  • Use base64 for encoding nonces
    • Support more CSP level 3 keywords
    • Allow configuring a report URI for XSS
2.6.0
  • Support random_compat v9.99.99
    • Don't ship unneeded files for composer installs
    • Change controller action reference
    • Add worker-src directive
    • Fix deprecation for symfony/config 4.2+
2.5.1
  • Abort CSP compiler pass when CSP is not enabled
2.5.0
  • Allows matching the query parameter for clickjacking protection
  • Cleanup content type restrictable listener
  • Added Symfony 4 support
  • Added support for 'worker-src' CSP directive
  • Removed PHP 5.3 support guarantees F- ix CSP noise filter compiler pass registration
2.4.0
  • Deprecate calling ContentSecurityPolicyListener::getNonce without usage ('script' or 'style')
    • Added forced_ssl > redirect_status_code option to allow switching to permanent redirect (301) responses
    • Fixed HSTS header being sent even in non-secure responses unnecessarily
    • Fixed URLs with whitespace prefix not being seen as external redirects
2.3.1
  • Fix arguments for Twig extension
Weaver

How can I help you explore Laravel packages today?

Conversation history is not saved when not logged in.
Prompt
Add packages to context
No packages found.
besmartand-pro/php-quality-config
sentix/ai-chatbot
terminal42/code-quality-tools
codifyo/ts-generator-bundle
testo/fiber
mintobit/jobqueue
a4sex/maintenance-bundle
a4sex/entity-date-update
a4sex/client-identifier
a4sex/base-utilites
a4sex/key-value-storage
a4sex/micro-status
chilldev/dependency-injection-extra
datinglibre/datinglibre-app-api
biberltd/corebundle
bricre/symfony-bundle-test
biberltd/logbundle
dominium/http-adapter-bundle
dominium/google-analytics
a4sex/auto-clean-entity