nelmio/security-bundle
Symfony bundle adding practical security headers and protections: Content Security Policy, X-Frame-Options clickjacking defense, HSTS/HTTPS enforcement, signed cookies, external redirect detection, and content-type sniffing disablement.
Full Changelog: https://github.com/nelmio/NelmioSecurityBundle/compare/v3.8.0...v3.9.0
Full Changelog: https://github.com/nelmio/NelmioSecurityBundle/compare/v3.7.0...v3.8.0
Full Changelog: https://github.com/nelmio/NelmioSecurityBundle/compare/v3.6.0...v3.7.0
Permissions-Policy header support by @silasjoisten in https://github.com/nelmio/NelmioSecurityBundle/pull/373Full Changelog: https://github.com/nelmio/NelmioSecurityBundle/compare/v3.5.1...v3.6.0
Full Changelog: https://github.com/nelmio/NelmioSecurityBundle/compare/v3.5.0...v3.5.1
report-to directive by @martijnc in https://github.com/nelmio/NelmioSecurityBundle/pull/357DirectiveSetBuilderInterface to allow runtime modification of CSP rules by @martijnc in https://github.com/nelmio/NelmioSecurityBundle/pull/348Full Changelog: https://github.com/nelmio/NelmioSecurityBundle/compare/v3.4.2...v3.5.0
Full Changelog: https://github.com/nelmio/NelmioSecurityBundle/compare/v3.4.1...v3.4.2
Full Changelog: https://github.com/nelmio/NelmioSecurityBundle/compare/v3.4.0...v3.4.1
legacy_hash_algo to support backward-compatible hash_algo changes in signed cookies by @martijnc in https://github.com/nelmio/NelmioSecurityBundle/pull/351Full Changelog: https://github.com/nelmio/NelmioSecurityBundle/compare/v3.3.0...v3.4.0
ExternalRedirectResponse by @martijnc in https://github.com/nelmio/NelmioSecurityBundle/pull/331Full Changelog: https://github.com/nelmio/NelmioSecurityBundle/compare/v3.2.0...v3.3.0
Full Changelog: https://github.com/nelmio/NelmioSecurityBundle/compare/v3.1.1...v3.2.0
view-source reports by @fritzmg in https://github.com/nelmio/NelmioSecurityBundle/pull/333Full Changelog: https://github.com/nelmio/NelmioSecurityBundle/compare/v3.1.0...v3.1.1
DoctrineCacheUAFamilyParser (use PsrCacheUAFamilyParser instead)finalWhitelistBasedTargetValidator class to AllowListBasedTargetValidatorCookieSessionHandlerDoctrineCacheUAFamilyParser (use PsrCacheUAFamilyParser instead)finalWhitelistBasedTargetValidator class to AllowListBasedTargetValidatorCookieSessionHandlerNelmio\SecurityBundle\ContentSecurityPolicy\Violation\Event class in favor of
Nelmio\SecurityBundle\ContentSecurityPolicy\Violation\ReportEvent.forced_ssl > redirect_status_code option to allow switching to permanent redirect (301) responsesHow can I help you explore Laravel packages today?