Öffentliches Register
Software-GesundheitsberichtSchema 0.26.0 · Metriken 1.13.0 · 2026-07-22 17:57 UTC

symfony / security-http

Symfony Security Component - HTTP Integration

PHPMIT★ 1.702 Sterne⑂ 22 Forksseit Sept. 2013Auf GitHub ansehen ↗

symfony/security-http erreicht einen Gesundheitsindex von 65 von 100 und liegt damit im Bereich Mittel. Am stärksten schneidet es bei Vitality (92/100) ab, am schwächsten bei AI Readiness (32/100). Zuletzt vor 13 Tagen aktualisiert. 2 Mitwirkende tragen den Großteil der jüngsten Arbeit.

65
gesamt / 100
Mittel

Software-Gesundheitsindex

Metriken werden auf einer Skala von 1–100 in gewichtete Kategorien gruppiert. Der Gesamtwert beginnt als ihr Mittel; sobald öffentliche Evidenz die Richtlinie für Hochrisikojurisdiktionen auslöst, wird die Bewertung angepasst und erhält die Obergrenze 49 (Gefährdet). AI Readiness liegt außerhalb.

65
Exzellent85-100Vorbildlich; erfüllt im Wesentlichen alle geprüften Kriterien
Gut70-84Gesund; geringfügige Lücken
Mittel50-69Akzeptabel mit deutlichen Lücken; Überprüfung empfohlen
Gefährdet30-49Erhebliche Schwächen; eine Übernahme erfordert Vorsicht
Kritisch1-29Schwerwiegende Probleme (aufgegeben, nur ein Maintainer, keine Hygiene)
VitalitätCommunity &VerbreitungNachhaltigkeit &GovernanceEngineering-QualitätSicherheitAI Readiness

Bewertungsprofil

Jede Achse ist eine Kategorie. Die Form zählt mehr als der Durchschnitt — ein gesundes Projekt füllt die gesamte Fläche, während ein Profil aus Spitzen und Kratern bedeutet, dass Stärke in einer Dimension Risiken in einer anderen verdeckt.

Eigentümerschaft

SymfonyOrganisation
2.169 Follower414 öffentliche Reposseit Okt. 2009

Dieses Repository wird von einer Organisation getragen — geteilte, rechenschaftspflichtige Trägerschaft, die jeden einzelnen Maintainer überdauern kann.

Paket-Ökosysteme

RegistryPaketVersionDownloads / MonatVersionenZuletzt veröffentlicht
Packagistsymfony/security-httpv8.1.14.297.376646vor 25 Tagen

Metriken nach Kategorie

Vitalität

Lebt das Projekt — wird Code geschrieben und werden Releases ausgeliefert?

92Exzellent · 22 % des Gesamtindex
Wie die Bewertung erfolgt
28.8/36Push-Aktualität — letzter Push vor 13 Tagen
30.5/36Commit-Rhythmus — 44/52 Wochen mit Commits
18/18Commit-Volumen — 224 Commits im letzten Jahr
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Verwendete Eingangsdaten
commits_last_year224
human_commit_share1
days_since_last_push13
active_weeks_last_year44

Release-Disziplin

100Exzellent
Wie die Bewertung erfolgt
27/27Liefert Releases aus — 100 Releases veröffentlicht
36/36Release-Aktualität — letztes Release vor 25 Tagen
27/27Release-Rhythmus — ein Release etwa alle 3,4 Tage
0/10OpenSSF Scorecard: Signed-Releases — keine Daten
Verwendete Eingangsdaten
releases_count100
latest_release_tagv8.1.1
releases_from_tagsnein
days_since_latest_release25
mean_days_between_releases3,4
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Signed-Releases. Die verbleibenden Gewichte wurden renormalisiert.

Community & Verbreitung

Hat das Projekt Nutzer, Downloads, Aufmerksamkeit und ein einladendes Umfeld für Beitragende?

81Gut · 18 % des Gesamtindex
Wie die Bewertung erfolgt
52.4/60Stars — 1.702 Stars
11/25Forks — 22 Forks
4.3/15Watcher — 7 Watcher
Verwendete Eingangsdaten
forks22
stars1.702
watchers7
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Wie die Bewertung erfolgt
22.5/22.5README
22.5/22.5Lizenz — anerkannte Lizenz (MIT)
18/18CONTRIBUTING-Leitfaden
13.5/13.5Verhaltenskodex
0/7.2Issue-Vorlage
0/6.3PR-Vorlage
Verwendete Eingangsdaten
has_readmeja
has_licenseja
has_contributingja
has_issue_templatenein
has_code_of_conductja
has_pull_request_templatenein
Wie die Bewertung erfolgt
80/80Downloads pro Monat — 4.297.376 Downloads/Monat über packagist
15.8/20Abhängige in der Registry — 235 Pakete hängen davon ab
Verwendete Eingangsdaten
packagessymfony/security-http
dependents235
ecosystemspackagist
total_downloads180.222.688
monthly_downloads4.297.376

Nachhaltigkeit & Governance

Überdauert das Projekt die Menschen, die es tragen — Bus-Faktor, Reaktionsfähigkeit, Trägerschaft und Paketpflege?

59Mittel · 24 % des Gesamtindex
Wie die Bewertung erfolgt
25.2/54Bus-Faktor — 2 Beitragende decken die Hälfte aller Commits ab
13.6/22.5Commit-Verteilung — wichtigste beitragende Person verfasste 40 % der Commits
13.5/13.5Breite der Beitragenden — 100 Beitragende
10/10OpenSSF Scorecard: Contributors — project has 103 contributing companies or organizations
Verwendete Eingangsdaten
bus_factor2
contributors_sampled100
top_contributor_share0,397
Wie die Bewertung erfolgt
0/46.8Issue-Lösungsquote — keine Issues oder keine Daten
0/38.3PR-Annahme — keine entschiedenen Pull Requests oder keine Daten
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Verwendete Eingangsdaten
merged_prs0
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): Issue-Lösungsquote, PR-Annahme. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
30/30Organisatorische Trägerschaft — im Besitz einer Organisation
0/20Verifizierte Domain
24/25Reichweite des Inhabers — 2.169 Follower von symfony
25/25Kontohistorie — 414 öffentliche Repos, Kontoalter ca. 16 Jahre
Verwendete Eingangsdaten
followers2.169
owner_typeOrganization
is_verified
owner_loginsymfony
public_repos414
account_age_days6.115

Paketpflege

100Exzellent
Wie die Bewertung erfolgt
25/25Veröffentlicht & auflösbar — 1 Paket(e) auf packagist
35/35Veröffentlichungsaktualität — letzte Veröffentlichung vor 25 Tagen
20/20Versionshistorie — 646 veröffentlichte Versionen
20/20Nicht veraltet — aktiv, nicht veraltet oder zurückgezogen
Verwendete Eingangsdaten
packagessymfony/security-http
ecosystemspackagist
any_deprecatednein
min_days_since_publish25

Engineering-Qualität

Sind grundlegende Engineering- und Dokumentationspraktiken vorhanden?

44Gefährdet · 20 % des Gesamtindex
Wie die Bewertung erfolgt
0/24CI-Workflows
24/24Tests vorhanden
0/16Linter-Konfiguration
0/9.6Pre-Commit-Hooks
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — keine Daten
Verwendete Eingangsdaten
has_cinein
has_testsja
has_editorconfignein
has_linter_confignein
has_precommit_confignein
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: CI-Tests. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
30/30README
0/25Dokumentationsverzeichnis
15/15Dokumentations-/Homepage-Site — https://symfony.com/security
10/10Repository-Beschreibung
10/10Topics — 4 Topics
0/10Wiki
Verwendete Eingangsdaten
topicsphp, symfony, component, symfony-component
has_wikinein
homepagehttps://symfony.com/security
has_readmeja
has_docs_dirnein
has_descriptionja

Sicherheit

Sind die sichtbaren Sicherheits- und Lieferkettenpraktiken belastbar, ohne ungeklärte Exposition gegenüber Hochrisikojurisdiktionen?

48Gefährdet · 16 % des Gesamtindex

Sicherheitslage

48Gefährdet
Wie die Bewertung erfolgt
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — keine Daten
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 103 contributing companies or organizations
0/10Dangerous-Workflow — keine Daten
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Lizenz — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — keine Daten
0/5Pinned-Dependencies — keine Daten
0/5SAST — no SAST tool detected
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — keine Daten
0/7.5Token-Permissions — keine Daten
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Verwendete Eingangsdaten
sourceopenssf_scorecard
checks_evaluated12
scorecard_versionv5.5.0
checks_inconclusive6
scorecard_aggregate4,8
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): ci_tests, dangerous_workflow, packaging, pinned_dependencies, signed_releases, token_permissions. Die verbleibenden Gewichte wurden renormalisiert.

AI Readiness

Wie gut ist das Repository dafür ausgestattet, mit KI-Coding-Agenten entwickelt und gepflegt zu werden? Ein unabhängiges, experimentelles Badge — Gewicht 0,0, es wird eigenständig ausgewiesen und verändert den Gesamt-Gesundheitswert nicht.

32Gefährdet · 0 % des Gesamtindex
Wie die Bewertung erfolgt
0/45Agentenanweisungen — keine CLAUDE.md / AGENTS.md / Editor-Regeln
0/15Maschinenlesbare Doku (llms.txt)
32/40Lesbare Commit-Historie — 60 von 100 menschlichen Commits benennen ihre Absicht (strukturierter Betreff oder erläuternder Text)
Verwendete Eingangsdaten
has_llms_txtnein
legible_history_share0,6
agent_instruction_files
agent_instruction_max_bytes
Wie die Bewertung erfolgt
0/18Bootstrap mit einem Befehl
22/22Automatisierte Tests
0/11Lint-/Format-Konfiguration
0/11Statische Typprüfung
0/10Reproduzierbare Umgebung
0/10Belegte Agentenpraxis — keine von Agenten verfassten Commits unter den letzten 100
0/8Automatisierte Wartung — keine automatisierten Abhängigkeits-Updates beobachtet
0/10OpenSSF Scorecard: Pinned-Dependencies — keine Daten
Verwendete Eingangsdaten
has_nixnein
has_testsja
lockfiles
has_dockerfilenein
typed_languagenein
bootstrap_files
has_devcontainernein
has_linter_confignein
typecheck_configs
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
Von der Bewertung ausgeschlossen (keine Daten oder nicht anwendbar): OpenSSF Scorecard: Pinned-Dependencies. Die verbleibenden Gewichte wurden renormalisiert.
Wie die Bewertung erfolgt
0/45Typprüfbarer Code — PHP ohne Typprüfungs-Konfiguration
55/55Handhabbare Dateigrößen — 0/201 Quelldateien über 60 KB
Verwendete Eingangsdaten
primary_languagePHP
largest_source_bytes27.253
source_files_sampled201
oversized_source_files0

Eckdaten

1.702GitHub-Sterne
100Mitwirkende
224Commits, letzte 12 Monate
13Tage seit letztem Push
100Releases
2Bus-Faktor
0offene Issues
PackagistPaket-Ökosysteme

Warnungen zur Datenerhebung

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • No resolved dependencies carried a version and a supported ecosystem

Weitere Details

Stern- und Fork-Verlauf 0 ★ / 22 ⇿
0Sterne
22Forks
96Releases

Wann jeder Stern und Fork hinzugefügt wurde, von GitHub erfasst und nach Tagen gruppiert. Das kumulierte Wachstum steht direkt über den täglichen Zugängen, aus denen es besteht, sodass beide gegeneinander lesbar sind: stetiger organischer Zuwachs sieht ganz anders aus als ein abrupter, kurzlebiger Ausschlag. Wo dieser Unterschied messbar ist, wird er als Wachstumsauthentizität ausgewiesen.

048121620242112015-062020-122026-06
Major 0Minor 5Patch 75

Jeder Punkt umfasst 11 Tage.

OpenSSF Scorecard 4.8 / 10
4.8Gesamtwert

Unabhängige, werkzeugneutrale Sicherheitsbewertung durch das quelloffene OpenSSF Scorecard. Jede Prüfung honoriert eine Sicherheits-Praxis, nicht das Werkzeug eines bestimmten Anbieters. Prüfungen, die Scorecard nicht ermitteln konnte, sind mit k. A. markiert und vom Sicherheitswert ausgeschlossen (nie als null gezählt).Scorecard v5.5.0 · 2026-07-22 17:56 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
k. A.CI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
10Contributorsproject has 103 contributing companies or organizations
k. A.Dangerous-Workflowno workflows found
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
k. A.Packagingpackaging workflow not detected
k. A.Pinned-Dependenciesno dependencies found
0SASTno SAST tool detected
10Security-Policysecurity policy file detected
k. A.Signed-Releasesno releases found
k. A.Token-PermissionsNo tokens found
10Vulnerabilities0 existing vulnerabilities detected
Direkte Abhängigkeiten 7
RegistryPaketVersionsvorgabeManifest
Packagistsymfony/deprecation-contracts^2.5|^3composer.json
Packagistsymfony/http-foundation^7.4|^8.0composer.json
Packagistsymfony/http-kernel^8.1composer.json
Packagistsymfony/polyfill-mbstring^1.0composer.json
Packagistsymfony/property-access^7.4|^8.0composer.json
Packagistsymfony/security-core^7.4|^8.0composer.json
Packagistsymfony/service-contracts^2.5|^3composer.json
Alle Abhängigkeiten 19

Vollständig aufgelöster Abhängigkeitssatz aus dem GitHub-Abhängigkeitsgraphen: 7 direkte und 12 indirekte (transitive) Pakete. Die transitive Hülle ist vollständig, wenn das Repository eine Lockfile eincheckt.

RegistryPaketVersionBeziehung
Packagistsymfony/deprecation-contractsdirekt
Packagistsymfony/http-foundationdirekt
Packagistsymfony/http-kerneldirekt
Packagistsymfony/polyfill-mbstringdirekt
Packagistsymfony/property-accessdirekt
Packagistsymfony/security-coredirekt
Packagistsymfony/service-contractsdirekt
Packagistphpindirekt
Packagistpsr/logindirekt
Packagistsymfony/cacheindirekt
Packagistsymfony/clockindirekt
Packagistsymfony/expression-languageindirekt
Packagistsymfony/http-clientindirekt
Packagistsymfony/http-client-contractsindirekt
Packagistsymfony/rate-limiterindirekt
Packagistsymfony/routingindirekt
Packagistsymfony/security-csrfindirekt
Packagistsymfony/translationindirekt
Packagistweb-token/jwt-libraryindirekt
Abhängigkeits-Advisories nicht bewertet

Der Advisory-Abgleich konnte für diesen Bericht nicht ausgeführt werden: No resolved dependencies carried a version and a supported ecosystem

JSON-Rohbericht maschinenlesbar
{
  "data": {
    "repo": {
      "topics": [
        "php",
        "symfony",
        "component",
        "symfony-component"
      ],
      "is_fork": false,
      "size_kb": 3603,
      "has_wiki": false,
      "homepage": "https://symfony.com/security",
      "languages": {
        "PHP": 792752
      },
      "pushed_at": "2026-07-09T15:18:56Z",
      "created_at": "2013-09-18T14:06:45Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-17T10:04:53Z",
      "description": "Symfony Security Component - HTTP Integration",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "8.2",
      "license_spdx_raw": "MIT",
      "primary_language": "PHP",
      "significant_languages": [
        "PHP"
      ]
    },
    "owner": {
      "blog": "https://symfony.com/",
      "name": "Symfony",
      "type": "Organization",
      "login": "symfony",
      "company": null,
      "location": "The Internet",
      "followers": 2169,
      "avatar_url": "https://avatars.githubusercontent.com/u/143937?v=4",
      "created_at": "2009-10-24T04:05:23Z",
      "is_verified": null,
      "public_repos": 414,
      "account_age_days": 6115
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v8.1.1",
          "kind": "patch",
          "published_at": "2026-06-27T09:30:56Z"
        },
        {
          "tag": "v8.0.14",
          "kind": "patch",
          "published_at": "2026-06-27T09:27:57Z"
        },
        {
          "tag": "v7.4.14",
          "kind": "patch",
          "published_at": "2026-06-27T09:17:03Z"
        },
        {
          "tag": "v6.4.42",
          "kind": "patch",
          "published_at": "2026-06-27T09:14:18Z"
        },
        {
          "tag": "v8.1.0",
          "kind": "minor",
          "published_at": "2026-05-29T08:53:40Z"
        },
        {
          "tag": "v8.1.0-RC1",
          "kind": "prerelease",
          "published_at": "2026-05-27T11:34:48Z"
        },
        {
          "tag": "v8.0.13",
          "kind": "patch",
          "published_at": "2026-05-27T10:31:37Z"
        },
        {
          "tag": "v7.4.13",
          "kind": "patch",
          "published_at": "2026-05-27T08:45:34Z"
        },
        {
          "tag": "v6.4.41",
          "kind": "patch",
          "published_at": "2026-05-27T08:30:01Z"
        },
        {
          "tag": "v5.4.53",
          "kind": "patch",
          "published_at": "2026-05-27T08:20:38Z"
        },
        {
          "tag": "v8.1.0-BETA3",
          "kind": "prerelease",
          "published_at": "2026-05-20T12:11:23Z"
        },
        {
          "tag": "v8.0.12",
          "kind": "patch",
          "published_at": "2026-05-20T10:07:31Z"
        },
        {
          "tag": "v7.4.12",
          "kind": "patch",
          "published_at": "2026-05-20T09:43:44Z"
        },
        {
          "tag": "v6.4.40",
          "kind": "patch",
          "published_at": "2026-05-20T09:02:40Z"
        },
        {
          "tag": "v5.4.52",
          "kind": "patch",
          "published_at": "2026-05-20T08:27:36Z"
        },
        {
          "tag": "v8.1.0-BETA2",
          "kind": "prerelease",
          "published_at": "2026-05-13T18:41:24Z"
        },
        {
          "tag": "v8.0.11",
          "kind": "patch",
          "published_at": "2026-05-13T18:23:18Z"
        },
        {
          "tag": "v7.4.11",
          "kind": "patch",
          "published_at": "2026-05-13T18:05:45Z"
        },
        {
          "tag": "v6.4.39",
          "kind": "patch",
          "published_at": "2026-05-13T17:54:02Z"
        },
        {
          "tag": "v8.1.0-BETA1",
          "kind": "prerelease",
          "published_at": "2026-05-06T14:29:00Z"
        },
        {
          "tag": "v8.0.9",
          "kind": "patch",
          "published_at": "2026-05-01T08:14:52Z"
        },
        {
          "tag": "v7.4.9",
          "kind": "patch",
          "published_at": "2026-05-01T08:00:41Z"
        },
        {
          "tag": "v8.0.8",
          "kind": "patch",
          "published_at": "2026-03-31T21:31:46Z"
        },
        {
          "tag": "v7.4.8",
          "kind": "patch",
          "published_at": "2026-03-31T21:11:23Z"
        },
        {
          "tag": "v8.0.6",
          "kind": "patch",
          "published_at": "2026-02-26T09:14:10Z"
        },
        {
          "tag": "v7.4.6",
          "kind": "patch",
          "published_at": "2026-02-26T08:42:02Z"
        },
        {
          "tag": "v6.4.34",
          "kind": "patch",
          "published_at": "2026-02-26T08:29:03Z"
        },
        {
          "tag": "v8.0.4",
          "kind": "patch",
          "published_at": "2026-01-25T08:31:06Z"
        },
        {
          "tag": "v7.4.4",
          "kind": "patch",
          "published_at": "2026-01-24T22:31:55Z"
        },
        {
          "tag": "v7.3.10",
          "kind": "patch",
          "published_at": "2026-01-24T22:04:14Z"
        },
        {
          "tag": "v8.0.3",
          "kind": "patch",
          "published_at": "2025-12-31T09:44:59Z"
        },
        {
          "tag": "v7.4.3",
          "kind": "patch",
          "published_at": "2025-12-31T09:13:53Z"
        },
        {
          "tag": "v7.3.9",
          "kind": "patch",
          "published_at": "2025-12-31T08:44:49Z"
        },
        {
          "tag": "v6.4.31",
          "kind": "patch",
          "published_at": "2025-12-31T08:35:33Z"
        },
        {
          "tag": "v8.0.1",
          "kind": "patch",
          "published_at": "2025-12-07T17:03:29Z"
        },
        {
          "tag": "v7.4.1",
          "kind": "patch",
          "published_at": "2025-12-07T16:51:24Z"
        },
        {
          "tag": "v7.3.8",
          "kind": "patch",
          "published_at": "2025-12-07T16:19:12Z"
        },
        {
          "tag": "v6.4.30",
          "kind": "patch",
          "published_at": "2025-12-07T16:03:29Z"
        },
        {
          "tag": "v7.4.0",
          "kind": "minor",
          "published_at": "2025-11-27T14:00:10Z"
        },
        {
          "tag": "v8.0.0-RC2",
          "kind": "prerelease",
          "published_at": "2025-11-16T17:46:51Z"
        },
        {
          "tag": "v7.4.0-RC2",
          "kind": "prerelease",
          "published_at": "2025-11-16T17:40:08Z"
        },
        {
          "tag": "v7.4.0-RC1",
          "kind": "prerelease",
          "published_at": "2025-11-13T12:54:10Z"
        },
        {
          "tag": "v7.3.5",
          "kind": "patch",
          "published_at": "2025-10-28T10:34:49Z"
        },
        {
          "tag": "v8.0.0-BETA1",
          "kind": "prerelease",
          "published_at": "2025-10-28T10:10:03Z"
        },
        {
          "tag": "v7.4.0-BETA1",
          "kind": "prerelease",
          "published_at": "2025-10-27T10:53:45Z"
        },
        {
          "tag": "v7.3.4",
          "kind": "patch",
          "published_at": "2025-09-27T12:38:53Z"
        },
        {
          "tag": "v6.4.26",
          "kind": "patch",
          "published_at": "2025-09-27T12:32:38Z"
        },
        {
          "tag": "v7.3.3",
          "kind": "patch",
          "published_at": "2025-08-29T08:29:38Z"
        },
        {
          "tag": "v6.4.25",
          "kind": "patch",
          "published_at": "2025-08-29T08:20:36Z"
        },
        {
          "tag": "v7.3.2",
          "kind": "patch",
          "published_at": "2025-07-31T10:56:58Z"
        },
        {
          "tag": "v7.2.9",
          "kind": "patch",
          "published_at": "2025-07-31T10:46:55Z"
        },
        {
          "tag": "v6.4.24",
          "kind": "patch",
          "published_at": "2025-07-31T09:38:59Z"
        },
        {
          "tag": "v7.3.1",
          "kind": "patch",
          "published_at": "2025-06-28T08:31:18Z"
        },
        {
          "tag": "v7.2.8",
          "kind": "patch",
          "published_at": "2025-06-28T08:25:17Z"
        },
        {
          "tag": "v6.4.23",
          "kind": "patch",
          "published_at": "2025-06-28T08:20:57Z"
        },
        {
          "tag": "v7.3.0",
          "kind": "minor",
          "published_at": "2025-05-29T07:54:25Z"
        },
        {
          "tag": "v7.2.7",
          "kind": "patch",
          "published_at": "2025-05-29T07:39:21Z"
        },
        {
          "tag": "v6.4.22",
          "kind": "patch",
          "published_at": "2025-05-29T07:35:17Z"
        },
        {
          "tag": "v7.3.0-RC1",
          "kind": "prerelease",
          "published_at": "2025-05-25T21:10:26Z"
        },
        {
          "tag": "v7.3.0-BETA2",
          "kind": "prerelease",
          "published_at": "2025-05-10T12:16:37Z"
        },
        {
          "tag": "v7.3.0-BETA1",
          "kind": "prerelease",
          "published_at": "2025-05-02T09:31:17Z"
        },
        {
          "tag": "v7.2.6",
          "kind": "patch",
          "published_at": "2025-05-02T09:14:53Z"
        },
        {
          "tag": "v6.4.21",
          "kind": "patch",
          "published_at": "2025-05-02T09:09:28Z"
        },
        {
          "tag": "v7.2.4",
          "kind": "patch",
          "published_at": "2025-02-26T11:07:14Z"
        },
        {
          "tag": "v6.4.19",
          "kind": "patch",
          "published_at": "2025-02-26T11:02:00Z"
        },
        {
          "tag": "v7.2.3",
          "kind": "patch",
          "published_at": "2025-01-29T07:47:36Z"
        },
        {
          "tag": "v7.1.11",
          "kind": "patch",
          "published_at": "2025-01-29T07:39:09Z"
        },
        {
          "tag": "v6.4.18",
          "kind": "patch",
          "published_at": "2025-01-29T07:34:04Z"
        },
        {
          "tag": "v7.1.10",
          "kind": "patch",
          "published_at": "2024-12-31T15:00:24Z"
        },
        {
          "tag": "v7.2.1",
          "kind": "patch",
          "published_at": "2024-12-11T12:16:26Z"
        },
        {
          "tag": "v7.2.0",
          "kind": "minor",
          "published_at": "2024-11-29T08:49:21Z"
        },
        {
          "tag": "v7.1.8",
          "kind": "patch",
          "published_at": "2024-11-13T14:53:12Z"
        },
        {
          "tag": "v6.4.15",
          "kind": "patch",
          "published_at": "2024-11-13T14:23:32Z"
        },
        {
          "tag": "v5.4.47",
          "kind": "patch",
          "published_at": "2024-11-13T13:55:19Z"
        },
        {
          "tag": "v7.2.0-BETA2",
          "kind": "prerelease",
          "published_at": "2024-11-06T10:06:03Z"
        },
        {
          "tag": "v7.1.7",
          "kind": "patch",
          "published_at": "2024-11-06T10:01:01Z"
        },
        {
          "tag": "v6.4.14",
          "kind": "patch",
          "published_at": "2024-11-06T09:55:16Z"
        },
        {
          "tag": "v5.4.46",
          "kind": "patch",
          "published_at": "2024-11-06T09:38:08Z"
        },
        {
          "tag": "v7.2.0-BETA1",
          "kind": "prerelease",
          "published_at": "2024-10-27T16:16:17Z"
        },
        {
          "tag": "v7.1.6",
          "kind": "patch",
          "published_at": "2024-10-27T15:21:52Z"
        },
        {
          "tag": "v6.4.13",
          "kind": "patch",
          "published_at": "2024-10-27T13:57:08Z"
        },
        {
          "tag": "v5.4.45",
          "kind": "patch",
          "published_at": "2024-10-27T13:02:11Z"
        },
        {
          "tag": "v7.1.5",
          "kind": "patch",
          "published_at": "2024-09-21T06:15:47Z"
        },
        {
          "tag": "v6.4.12",
          "kind": "patch",
          "published_at": "2024-09-21T06:09:25Z"
        },
        {
          "tag": "v5.4.44",
          "kind": "patch",
          "published_at": "2024-09-21T06:03:20Z"
        },
        {
          "tag": "v7.1.4",
          "kind": "patch",
          "published_at": "2024-08-30T17:07:41Z"
        },
        {
          "tag": "v6.4.11",
          "kind": "patch",
          "published_at": "2024-08-30T17:02:42Z"
        },
        {
          "tag": "v5.4.43",
          "kind": "patch",
          "published_at": "2024-08-30T16:57:53Z"
        },
        {
          "tag": "v7.1.3",
          "kind": "patch",
          "published_at": "2024-07-26T15:04:38Z"
        },
        {
          "tag": "v7.1.2",
          "kind": "patch",
          "published_at": "2024-06-28T13:22:48Z"
        },
        {
          "tag": "v7.0.9",
          "kind": "patch",
          "published_at": "2024-06-28T13:14:29Z"
        },
        {
          "tag": "v6.4.9",
          "kind": "patch",
          "published_at": "2024-06-28T11:54:03Z"
        },
        {
          "tag": "v5.4.41",
          "kind": "patch",
          "published_at": "2024-06-28T11:48:38Z"
        },
        {
          "tag": "v7.1.1",
          "kind": "patch",
          "published_at": "2024-06-04T07:37:22Z"
        },
        {
          "tag": "v7.0.8",
          "kind": "patch",
          "published_at": "2024-06-02T18:03:47Z"
        },
        {
          "tag": "v6.4.8",
          "kind": "patch",
          "published_at": "2024-06-02T17:04:03Z"
        },
        {
          "tag": "v5.4.40",
          "kind": "patch",
          "published_at": "2024-06-02T16:04:05Z"
        },
        {
          "tag": "v7.1.0",
          "kind": "minor",
          "published_at": "2024-05-31T08:22:38Z"
        },
        {
          "tag": "v7.1.0-RC1",
          "kind": "prerelease",
          "published_at": "2024-05-17T15:51:04Z"
        },
        {
          "tag": "v7.1.0-BETA1",
          "kind": "prerelease",
          "published_at": "2024-05-02T13:12:52Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "8a899d1a0ee80466911afbae5707a04e0ea65d12",
          "body": null,
          "is_bot": false,
          "headline": "Allow disabling redirect on logout",
          "author_name": "Jérôme Vasseur",
          "author_login": "jvasseur",
          "committed_at": "2026-07-09T13:09:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "096ea90476de2b8852392c3d7b185a7fc5126e85",
          "body": "* 8.1:\n  Bump the github-actions group across 1 directory with 2 updates\n  [Validator] Ukrainian translation update\n  [Validator] reviewed Polish translation unit 146\n  [FrameworkBundle] Fix false positives for _instanceof\n  [Validator] Remove needs-review-translation state from Spanish cron express\n[…]\nill\n  [Validator] Add translated messages for the Cron constraint\n  [Security] Fix PHPDoc of OidcTokenGenerateCommand::addGenerator\n  [Serializer] honor `csv_headers` context when `no_headers` is true",
          "is_bot": false,
          "headline": "Merge branch '8.1' into 8.2",
          "author_name": "Fabien Potencier",
          "author_login": "fabpot",
          "committed_at": "2026-06-27T06:18:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "93f5e8bd49489256e469384e5e408257e8dc3e25",
          "body": "* 8.0:\n  Bump the github-actions group across 1 directory with 2 updates\n  [Validator] Ukrainian translation update\n  [Validator] reviewed Polish translation unit 146\n  [FrameworkBundle] Fix false positives for _instanceof\n  [Validator] Remove needs-review-translation state from Spanish cron express\n[…]\nill\n  [Validator] Add translated messages for the Cron constraint\n  [Security] Fix PHPDoc of OidcTokenGenerateCommand::addGenerator\n  [Serializer] honor `csv_headers` context when `no_headers` is true",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Fabien Potencier",
          "author_login": "fabpot",
          "committed_at": "2026-06-27T06:18:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "982838736e0c0c25059d0dc90d21ca148337a060",
          "body": "* 7.4:\n  Bump the github-actions group across 1 directory with 2 updates\n  [Validator] Ukrainian translation update\n  [Validator] reviewed Polish translation unit 146\n  [FrameworkBundle] Fix false positives for _instanceof\n  [Validator] Remove needs-review-translation state from Spanish cron express\n[…]\nill\n  [Validator] Add translated messages for the Cron constraint\n  [Security] Fix PHPDoc of OidcTokenGenerateCommand::addGenerator\n  [Serializer] honor `csv_headers` context when `no_headers` is true",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Fabien Potencier",
          "author_login": "fabpot",
          "committed_at": "2026-06-27T06:17:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "148e038b91c8cc3e42aee177f8b0117437077c9b",
          "body": null,
          "is_bot": false,
          "headline": "[Security] Fix PHPDoc of OidcTokenGenerateCommand::addGenerator",
          "author_name": "Denys Finchenko",
          "author_login": "dfinchenko",
          "committed_at": "2026-06-19T08:40:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0063980871446676583b07250ddf00dd784cd724",
          "body": "* 8.1:\n  [ObjectMapper] Fix mapping of private properties from parent classes\n  CS fix\n  [ObjectMapper] Fix self-referencing property breaking mapping to readonly targets\n  update from Postgres 10 to 16\n  [ObjectMapper] Handle N targets per source in reverse class map\n  [SecurityBundle] Fix state le\n[…]\nvironments\n  [Form][Validator] Review Hungarian translations\n  Bump the github-actions group across 1 directory with 2 updates\n  [Serializer] Fix denormalization of already-instantiated nested objects",
          "is_bot": false,
          "headline": "Merge branch '8.1' into 8.2",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-16T16:09:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "363cbcec0b60dbb4ac186162d20dff3b2bbbe92e",
          "body": "* 8.0:\n  [ObjectMapper] Fix mapping of private properties from parent classes\n  update from Postgres 10 to 16\n  [SecurityBundle] Fix state leak in LogoutUrlGenerator in async environments\n  [Form][Validator] Review Hungarian translations\n  Bump the github-actions group across 1 directory with 2 upda\n[…]\nrializer] Fix denormalization of already-instantiated nested objects\n\n# Conflicts:\n#\tsrc/Symfony/Component/ObjectMapper/ObjectMapper.php\n#\tsrc/Symfony/Component/ObjectMapper/Tests/ObjectMapperTest.php",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-16T16:07:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "52293be0a1fcf488ef0857fc3bb4ee7e9f4f6220",
          "body": "* 7.4:\n  [ObjectMapper] Fix mapping of private properties from parent classes\n  update from Postgres 10 to 16\n  [SecurityBundle] Fix state leak in LogoutUrlGenerator in async environments\n  [Form][Validator] Review Hungarian translations\n  Bump the github-actions group across 1 directory with 2 updates\n  [Serializer] Fix denormalization of already-instantiated nested objects\n\n# Conflicts:\n#\tsrc/Symfony/Component/Serializer/Normalizer/AbstractObjectNormalizer.php",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-16T16:02:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "60187277833743cb258dcea876d1e19e5244c554",
          "body": "* 6.4:\n  update from Postgres 10 to 16\n  [SecurityBundle] Fix state leak in LogoutUrlGenerator in async environments\n  [Form][Validator] Review Hungarian translations\n  [Serializer] Fix denormalization of already-instantiated nested objects",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-16T15:54:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e107436c107892b1255c3364ec8ff46c141230d1",
          "body": null,
          "is_bot": false,
          "headline": "[SecurityHttp] Make OidcTokenHandler `allowedTimeDrift` configurable",
          "author_name": "jprivet-dev",
          "author_login": "jprivet-dev",
          "committed_at": "2026-06-16T12:43:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c6a3836e6c331503a841f439912939c4e1be480f",
          "body": "…nments",
          "is_bot": false,
          "headline": "[SecurityBundle] Fix state leak in LogoutUrlGenerator in async enviro…",
          "author_name": "Kevin MARTINS",
          "author_login": "KevinMartinsDev",
          "committed_at": "2026-06-16T12:40:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "312c2572476dfb415654dab63ac980a8f6d8e24a",
          "body": "* 8.0:\n  [Mime] Reject \\Stringable in DataPart::__unserialize()\n  [Lock][Form][FrameworkBundle][Mailer][HttpKernel] Harden remaining unserialize trampolines and webhook reject paths\n  Remove review state from Serbian translations\n  Harden __toString trampolines via __unserialize()\n  Remove needs-rev\n[…]\ntion/Bridge/Crowdin/Tests/CrowdinProviderTest.php\n#\tsrc/Symfony/Component/VarExporter/Instantiator.php\n#\tsrc/Symfony/Component/VarExporter/Internal/Exporter.php\n#\tsrc/Symfony/Component/Yaml/Inline.php",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-09T10:54:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6545a813eb53bc29317addfc27f9b83c95c681f1",
          "body": "* 7.4:\n  [Lock][Form][FrameworkBundle][Mailer][HttpKernel] Harden remaining unserialize trampolines and webhook reject paths\n  Remove review state from Serbian translations\n  Harden __toString trampolines via __unserialize()\n  Remove needs-review-translation flag for Russian validators\n  [VarExporte\n[…]\nileLoader.php\n#\tsrc/Symfony/Component/HttpKernel/Tests/DependencyInjection/RegisterControllerArgumentLocatorsPassTest.php\n#\tsrc/Symfony/Component/Security/Core/Authentication/Token/RememberMeToken.php",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-09T10:20:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ee57683f588a075a7a58eb60c80539557eb104ee",
          "body": "* 6.4:\n  Remove review state from Serbian translations\n  Harden __toString trampolines via __unserialize()\n  Remove needs-review-translation flag for Russian validators",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-09T07:51:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "143ad81ca4ea33fece065fa7ca46791f3cd38d90",
          "body": null,
          "is_bot": false,
          "headline": "Harden __toString trampolines via __unserialize()",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-09T07:36:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eaf9dd0e543862e35f235184bc47134dff99e836",
          "body": "* 6.4:\n  [VarExporter] Fix exporting objects that cannot be instantiated empty\n  [Translation] Create Crowdin files before uploading translations\n  [Form] reviewed Polish translation unit 129\n  [Validator] reviewed Polish translation units 143-145\n  Harden TemplatedEmail unserialize and enforce hard\n[…]\nony/Component/Intl/Transliterator/EmojiTransliterator.php\n#\tsrc/Symfony/Component/Translation/Bridge/Crowdin/Tests/CrowdinProviderTest.php\n#\tsrc/Symfony/Component/VarExporter/Tests/VarExporterTest.php",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-08T20:24:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "53b50d5600fa42da6b26fd32e65d99851814ccb1",
          "body": null,
          "is_bot": false,
          "headline": " Unsafe unserialize phpstan rule",
          "author_name": "Jack Worman",
          "author_login": "jack-worman",
          "committed_at": "2026-06-08T07:06:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5fb2de222df56c86a671cede0cf03d8c1d37892a",
          "body": "* 8.0:\n  Make tests compatible with PHPUnit 13.2 and Twig 3.28\n  Fix test\n  [Serializer] Keep collection value type for iterable constructor parameters\n  [AssetMapper] Render an empty import map as a JSON object\n  [Translation] Fix test failing without the intl extension\n  [Mailer] [Mailchimp] Fix tests on low-deps\n  [HttpFoundation] Add RFC6598 Shared Address Space to IpUtils::PRIVATE_SUBNETS\n  Fix Content-Type key in createRequest method",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-06T11:11:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "29c2c1224ab76252a76cdb81b0f80f846242b199",
          "body": "* 7.4:\n  Make tests compatible with PHPUnit 13.2 and Twig 3.28\n  Fix test\n  [Serializer] Keep collection value type for iterable constructor parameters\n  [AssetMapper] Render an empty import map as a JSON object\n  [Translation] Fix test failing without the intl extension\n  [Mailer] [Mailchimp] Fix tests on low-deps\n  [HttpFoundation] Add RFC6598 Shared Address Space to IpUtils::PRIVATE_SUBNETS\n  Fix Content-Type key in createRequest method",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-06T11:11:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4af76885fb0aceb42ed1d7a22fd105b88334769",
          "body": null,
          "is_bot": false,
          "headline": "Make tests compatible with PHPUnit 13.2 and Twig 3.28",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-06T11:10:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1e754937917ae4d9f46591536737036ac5369d6b",
          "body": "* 8.0:\n  Drop PR warning and auto-closing on subtree splits\n  Fix merge\n  [Validator] Support SVG dimensions with units\n  Remove review state from Serbian translations\n  [Translation] Copy domains metadata when moving messages to intl ones\n  [Form] Add missing translation for invalid UUID\n  fix(tran\n[…]\nlation messages\n  [Security][HttpKernel] Add allowed_classes => false to unserialize() in CacheWarmerAggregate, LoggerDataCollector, and HttpCache Store\n  Fix XMLHttpRequest URL handling in toolbar JS",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-05T06:23:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "414e7b5f0b3103d9ebba6403a149155e139447c4",
          "body": "* 7.4:\n  Drop PR warning and auto-closing on subtree splits\n  Fix merge\n  [Validator] Support SVG dimensions with units\n  Remove review state from Serbian translations\n  [Translation] Copy domains metadata when moving messages to intl ones\n  [Form] Add missing translation for invalid UUID\n  fix(tran\n[…]\nlation messages\n  [Security][HttpKernel] Add allowed_classes => false to unserialize() in CacheWarmerAggregate, LoggerDataCollector, and HttpCache Store\n  Fix XMLHttpRequest URL handling in toolbar JS",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-05T06:22:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "67f4b7feb6c188c607f64f7b0896d5c4e25aefb7",
          "body": "* 6.4:\n  Drop PR warning and auto-closing on subtree splits\n  Fix merge\n  Remove review state from Serbian translations\n  [Translation] Copy domains metadata when moving messages to intl ones\n  [Form] Add missing translation for invalid UUID\n  fix(translations): fix sr-Latn validation messages and v\n[…]\nlation messages\n  [Security][HttpKernel] Add allowed_classes => false to unserialize() in CacheWarmerAggregate, LoggerDataCollector, and HttpCache Store\n  Fix XMLHttpRequest URL handling in toolbar JS",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-05T06:22:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8c8ce8f284d34ed514def458e686e0d389bab4af",
          "body": null,
          "is_bot": false,
          "headline": "Drop PR warning and auto-closing on subtree splits",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-05T06:18:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0e6c7b9e80eec37248b92359cbd6938c7086f4b",
          "body": null,
          "is_bot": false,
          "headline": "Add call to backers in README files",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-29T05:06:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7e1ddefc15812654b1897a1676628dd6eb055194",
          "body": "* 8.0:\n  CS fix",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-25T06:14:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ca895c1303cc1d290f190cd7301d48fcef9e73e5",
          "body": "* 7.4:\n  CS fix",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-25T06:08:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "da3c28025a664e6a88e1af104a74457d99301161",
          "body": "* 6.4:\n  CS fix",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-25T06:06:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1a01cd7a6313d5a375480e0d1d4a0ddf834ae12b",
          "body": null,
          "is_bot": false,
          "headline": "CS fix",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-25T06:03:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b0af66c0a540fe5903307d00427e425fae19ff6c",
          "body": "* 8.0:\n  [Security] Don't honor user-supplied _failure_path on failure_forward\n  [Routing] Fix dot-segment encoding for chained \"../\" and \"./\" in generated URLs\n  [HtmlSanitizer] Sanitize URL attributes on <object>, <applet>, <iframe>, <img>, and the URL inside <meta http-equiv=\"refresh\"> content\n  \n[…]\n Pin Mailomat webhook signature algorithm to SHA-256\n  [HttpFoundation] Block IPv6 transition forms in IpUtils::PRIVATE_SUBNETS\n  [HttpClient] Block IPv6 transition forms in NoPrivateNetworkHttpClient",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-24T11:25:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b7e82065c74a23e786ef719c88bde6eaf50f5247",
          "body": "* 7.4:\n  [Security] Don't honor user-supplied _failure_path on failure_forward\n  [Routing] Fix dot-segment encoding for chained \"../\" and \"./\" in generated URLs\n  [HtmlSanitizer] Sanitize URL attributes on <object>, <applet>, <iframe>, <img>, and the URL inside <meta http-equiv=\"refresh\"> content\n  \n[…]\n Pin Mailomat webhook signature algorithm to SHA-256\n  [HttpFoundation] Block IPv6 transition forms in IpUtils::PRIVATE_SUBNETS\n  [HttpClient] Block IPv6 transition forms in NoPrivateNetworkHttpClient",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-24T11:21:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7ea7162bf81996e8e13e3b0621386e1550af2d29",
          "body": "* 6.4:\n  [Security] Don't honor user-supplied _failure_path on failure_forward\n  [Routing] Fix dot-segment encoding for chained \"../\" and \"./\" in generated URLs\n  [HtmlSanitizer] Sanitize URL attributes on <object>, <applet>, <iframe>, <img>, and the URL inside <meta http-equiv=\"refresh\"> content\n  \n[…]\nnt-encoded BiDi marks and Unicode whitespace in URLs\n  [HttpFoundation] Block IPv6 transition forms in IpUtils::PRIVATE_SUBNETS\n  [HttpClient] Block IPv6 transition forms in NoPrivateNetworkHttpClient",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-24T11:20:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b4acd832ca29fc851b14b813187aa6fee2f4c7ab",
          "body": "* 5.4:\n  [Security] Don't honor user-supplied _failure_path on failure_forward\n  [Routing] Fix dot-segment encoding for chained \"../\" and \"./\" in generated URLs\n  [HttpClient] Block IPv6 transition forms in NoPrivateNetworkHttpClient",
          "is_bot": false,
          "headline": "Merge branch '5.4' into 6.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-24T11:18:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "119cc48b2370db276ed5ab81ef0458943645bcf9",
          "body": null,
          "is_bot": false,
          "headline": "[Security] Don't honor user-supplied _failure_path on failure_forward",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-24T10:45:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "692c1ebc88698eccf911e3ddb652186c339e718e",
          "body": "* 8.0:\n  [HttpClient] ntlm regression on authPersistNonNTLM=false connections where reset no longer discards the connection.",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-23T20:26:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "05916f99c11b97bca38a8cf269aa564b3083a387",
          "body": "* 7.4:\n  [HttpClient] ntlm regression on authPersistNonNTLM=false connections where reset no longer discards the connection.",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-23T20:26:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5312b62b04c92c12186505ebdf7fbdcfb4a4da36",
          "body": "* 6.4:\n  [HttpClient] ntlm regression on authPersistNonNTLM=false connections where reset no longer discards the connection.",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-23T20:26:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9f36b71b756102f75e448a47623f3e84360bf59",
          "body": "* 8.0: (49 commits)\n  [Runtime][FrameworkBundle] Trust argv on CLI-like SAPIs in the remaining QUERY_STRING gates\n  Fix tests and merge resolution after merging 6.4 into 7.4\n  [FrameworkBundle] Allow to pass `doctrine_open_transaction_logger`’s entity manager name positionally\n  Remove protectedHead\n[…]\ntion/Loader/YamlFileLoader.php\n#\tsrc/Symfony/Component/HttpClient/CachingHttpClient.php\n#\tsrc/Symfony/Component/HttpClient/Tests/CachingHttpClientTest.php\n#\tsrc/Symfony/Component/HttpKernel/Kernel.php",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-23T18:18:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4b905040548e31e52bae5c39b32b1438b29bb5a3",
          "body": "* 7.4: (46 commits)\n  [Runtime][FrameworkBundle] Trust argv on CLI-like SAPIs in the remaining QUERY_STRING gates\n  Fix tests and merge resolution after merging 6.4 into 7.4\n  [FrameworkBundle] Allow to pass `doctrine_open_transaction_logger`’s entity manager name positionally\n  Remove protectedHead\n[…]\nLOG-8.0.md\n#\tsrc/Symfony/Component/HttpKernel/Kernel.php\n#\tsrc/Symfony/Component/Mime/Part/SMimePart.php\n#\tsrc/Symfony/Component/Mime/Part/TextPart.php\n#\tsrc/Symfony/Component/String/UnicodeString.php",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-23T18:05:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "860286065f54ab4bc6fa4faaddbca4ae8d4ee49e",
          "body": "* [Mime][Routing] Replace @dataProvider annotation with #[DataProvider] attribute\n* [FrameworkBundle] Move webhook request parsers cleanup to after mailer_webhook.php is loaded",
          "is_bot": false,
          "headline": "Fix tests and merge resolution after merging 6.4 into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-23T16:22:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1081160e05f58f9a8f9bb8fa67a2c00e26a16491",
          "body": "* 6.4:\n  [FrameworkBundle] Allow to pass `doctrine_open_transaction_logger`’s entity manager name positionally\n  [Scheduler] Recover pending RecurringMessages after consumer stops midway\n  [SecurityBundle] Fix Security::login() across firewalls\n  [Routing][RateLimiter][Mime][Security] Harden __unser\n[…]\nTests/Generator/MessageGeneratorTest.php\n#\tsrc/Symfony/Component/Security/Http/Tests/Firewall/ContextListenerTest.php\n#\tsrc/Symfony/Component/Translation/Bridge/Lokalise/Tests/LokaliseProviderTest.php",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-23T16:05:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4523a53e4cb33809d715d8dfa494ce22a0baaafe",
          "body": "protectedHeaderOnly is only used by HeaderCheckerManager not ClaimCheckerManager",
          "is_bot": false,
          "headline": "Remove protectedHeaderOnly from claim checkers",
          "author_name": "Samuel Weirich",
          "author_login": "samuelwei",
          "committed_at": "2026-05-23T15:30:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "20636d3115342cf3c94720aa3ab4c8517b03169f",
          "body": null,
          "is_bot": false,
          "headline": "[Security] Initialize lazy users before serializing them in the session",
          "author_name": "Mathieu",
          "author_login": "MatTheCat",
          "committed_at": "2026-05-23T14:34:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c60b7512cc5702513f9ab1cf244495843df02d3",
          "body": "* 8.0:\n  [Runtime] Fix CVE-2024-50340 patch bypass by gating argv on $_SERVER['QUERY_STRING']",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-20T09:18:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d776945b2dc41c0e609c56c1ef69863ab56856ed",
          "body": "* 7.4:\n  [Runtime] Fix CVE-2024-50340 patch bypass by gating argv on $_SERVER['QUERY_STRING']",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-20T07:22:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1fc7ca636cbd2cad29b42cc13c9fd0c681c6efee",
          "body": "* 6.4:\n  [Runtime] Fix CVE-2024-50340 patch bypass by gating argv on $_SERVER['QUERY_STRING']",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-20T07:20:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "816860d96c4fb7ffd7708ae0531ea6e5a1190773",
          "body": "* 5.4:\n  [Mailer] Add end-of-options separator before recipients in SendmailTransport; reject addresses starting with a dash\n  [Yaml] Harden the Parser::cleanup() regexes against catastrophic backtracking\n  [Yaml] Bound collection-alias resolution in the parser\n  [Yaml] Bound recursion depth in the \n[…]\negex to RDN boundary in X509Authenticator\n  [DomCrawler] Fix XXE in addXmlContent() by not enabling `validateOnParse`\n  [Routing] Fix regex alternation anchoring in UrlGenerator requirement validation",
          "is_bot": false,
          "headline": "Merge branch '5.4' into 6.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-19T20:33:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "897674df0d6245b05769fb595d5c6115cad2e8b2",
          "body": "…andler` (alexandre-daubois)\n\nThis PR was merged into the 6.4 branch.",
          "is_bot": false,
          "headline": "security #cve-2026-45069 [Security] Add missing claims in `OidcTokenH…",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-19T20:33:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "04e055ba57676852b6e341cb42b866a32817d4ae",
          "body": "* 8.0:\n  [Messenger] Fix PhpSerializer::getMessageType() when getting payload with Serializable instances\n  [MonologBridge] Fix `interactive_only` not preventing propagation\n  [DomCrawler] Fix `ChoiceFormField::addChoice()` clobbering values on multi-selects\n  [HttpKernel] Preserve named-attribute override on Request/Session value resolvers\n  [Security] Fix impersonation being deauthenticated on every request\n  Remove wrong documentation",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-19T20:01:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d70ddce220c72330bf768cd884da0296f77ea527",
          "body": "* 7.4:\n  [Messenger] Fix PhpSerializer::getMessageType() when getting payload with Serializable instances\n  [MonologBridge] Fix `interactive_only` not preventing propagation\n  [DomCrawler] Fix `ChoiceFormField::addChoice()` clobbering values on multi-selects\n  [HttpKernel] Preserve named-attribute override on Request/Session value resolvers\n  [Security] Fix impersonation being deauthenticated on every request\n  Remove wrong documentation",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-19T19:56:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "46a887c21940aed11edcd74f3c7efd2f8f5e1514",
          "body": null,
          "is_bot": false,
          "headline": "[Security] Various fixes and hardenings",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-19T15:48:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "626a6f32cf0497863b72c4a10fba3aa385e2cdfa",
          "body": "… when using CAS authentication (nicolas-grekas)\n\nThis PR was merged into the 7.4 branch.",
          "is_bot": false,
          "headline": "security #cve-2026-45074 [Security] Require configuring trusted hosts…",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-15T07:14:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2322d5aa6adb4c44600988e27555087448758e6a",
          "body": "…assing methods filter in `IsGranted`, `IsCsrfTokenValid` and `IsSignatureValid` attributes (nicolas-grekas)\n\nThis PR was merged into the 7.4 branch.",
          "is_bot": false,
          "headline": "security #cve-2026-45075 [Security][HttpKernel] Fix HEAD requests byp…",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-15T07:14:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e89d245e47016cb0f06d315d10a536f0a55e36db",
          "body": null,
          "is_bot": false,
          "headline": "[Security] Fix impersonation being deauthenticated on every request",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-15T06:48:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "67abea64ce64f2bc932dc522f2327a0c064d2b70",
          "body": "…ation",
          "is_bot": false,
          "headline": "[Security] Require configuring trusted hosts when using CAS authentic…",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-15T06:45:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bf09203388c5f86fd10f8d2bed891400c0d57349",
          "body": "* 8.0:\n  Allow defining security provider factories without config\n  [FrameworkBundle] Bump Request/Session value resolver priority above EntityValueResolver\n  [Messenger] Ensure SigningSerializer won't decode before verifying the signature\n  [Security] Remove the legacy nested unserialize() call fr\n[…]\n] Warn on missing bare CSS and JSON imports\n  When pushing, run GHA only on \"*.*\" branches\n  [Console] Fix signal handler scoping\n  [Security] Preserve webserver base URL in HttpUtils::createRequest()",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-13T12:23:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3c29d0118c6bc5919ce6f2ef4e9ead24503ca819",
          "body": "* 7.4:\n  Allow defining security provider factories without config\n  [FrameworkBundle] Bump Request/Session value resolver priority above EntityValueResolver\n  [Messenger] Ensure SigningSerializer won't decode before verifying the signature\n  [Security] Remove the legacy nested unserialize() call fr\n[…]\nection/XmlCustomProviderTest.php\n#\tsrc/Symfony/Component/Security/Core/Authentication/Token/RememberMeToken.php\n#\tsrc/Symfony/Component/Security/Core/Tests/Authentication/Token/RememberMeTokenTest.php",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-13T12:07:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2405335470a69e06e549fbb2bb78f96720d52fcc",
          "body": "* 6.4:\n  Allow defining security provider factories without config\n  [FrameworkBundle] Bump Request/Session value resolver priority above EntityValueResolver\n  [Security] Remove the legacy nested unserialize() call from token and exception classes\n  [Yaml] Reject non-stringables when using \"!!binary\n[…]\n] Warn on missing bare CSS and JSON imports\n  When pushing, run GHA only on \"*.*\" branches\n  [Console] Fix signal handler scoping\n  [Security] Preserve webserver base URL in HttpUtils::createRequest()",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-13T12:04:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fc64f2f7cf591db8821bf097e886255da6098a5a",
          "body": null,
          "is_bot": false,
          "headline": "[Security] Preserve webserver base URL in HttpUtils::createRequest()",
          "author_name": "Ousama Ben Younes",
          "author_login": "ousamabenyounes",
          "committed_at": "2026-05-12T06:36:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "57598d9bfbf5033febda6dc41f4e1ac4c07b4361",
          "body": "* 8.0:\n  [DependencyInjection] Relax tests\n  [Scheduler] Make debug:scheduler test independent of terminal width\n  [Messenger] Fix ErrorDetailsStampTest after dropping trace args from normalization\n  [Scheduler] Use stored checkpoint as base date for debug:scheduler\n  [Messenger] Drop trace args fro\n[…]\nG for 7.4.10\n\n# Conflicts:\n#\tsrc/Symfony/Component/HttpKernel/Kernel.php\n#\tsrc/Symfony/Component/Scheduler/Command/DebugCommand.php\n#\tsrc/Symfony/Component/Scheduler/Tests/Command/DebugCommandTest.php",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-11T13:20:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2125459087fd42e3878df3041a01334fc67a3ee1",
          "body": "* 7.4:\n  [DependencyInjection] Relax tests\n  [Scheduler] Make debug:scheduler test independent of terminal width\n  [Messenger] Fix ErrorDetailsStampTest after dropping trace args from normalization\n  [Scheduler] Use stored checkpoint as base date for debug:scheduler\n  [Messenger] Drop trace args fro\n[…]\nrs`\n  [Security] Clarify AbstractToken's role-name decoupling and simplify ContextListener\n  [Notifier] update Slack readme\n  [Dotenv] Don't truncate OS env vars containing $ when $_ENV is unpopulated",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-11T13:06:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "78a03cf62f41f5e5eacbad29425614696998c433",
          "body": "* 6.4:\n  [Scheduler] Make debug:scheduler test independent of terminal width\n  [Messenger] Fix ErrorDetailsStampTest after dropping trace args from normalization\n  [Scheduler] Use stored checkpoint as base date for debug:scheduler\n  [Messenger] Drop trace args from FlattenException normalization\n  [\n[…]\ntry to access `RawMessage::$headers`\n  [Security] Clarify AbstractToken's role-name decoupling and simplify ContextListener\n  [Dotenv] Don't truncate OS env vars containing $ when $_ENV is unpopulated",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-11T13:02:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ceb27a7151ea3b2c25c7f416940778d888b623f7",
          "body": "…ContextListener",
          "is_bot": false,
          "headline": "[Security] Clarify AbstractToken's role-name decoupling and simplify …",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-10T09:44:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f42cdeb2c9dac7f6a59011da943a84ad9a2897c0",
          "body": "…`IsGranted`, `IsCsrfTokenValid` and `IsSignatureValid` attributes",
          "is_bot": false,
          "headline": "[Security][HttpKernel] Fix HEAD requests bypassing methods filter in …",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-08T09:53:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4889312fd4c855735c3476d3998fb23221548cd5",
          "body": "* 8.0:\n  Fix low-deps\n  Fix up\n  [Cache] Ensure compatibility with Relay extension 0.22.0\n  [Yaml] fix flow collection drops `&anchor` and `!!str &anchor` items\n  Fix excludePaths in PHPStan config\n  [Security] Fix typos in method documentations\n  [Messenger] Move --time-limit handling to Worker for proper capping with --sleep\n  [Cache] Remove conflict with dbal<4.3\n  Fix inline attachment contentId for Azure Communication Services mailer",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-05T08:10:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "df93cd314e7ffe827645dbea93a3dfe58ae3ab77",
          "body": "* 7.4:\n  Fix low-deps\n  Fix up\n  [Cache] Ensure compatibility with Relay extension 0.22.0\n  [Yaml] fix flow collection drops `&anchor` and `!!str &anchor` items\n  Fix excludePaths in PHPStan config\n  [Security] Fix typos in method documentations\n  [Messenger] Move --time-limit handling to Worker for proper capping with --sleep\n  Fix inline attachment contentId for Azure Communication Services mailer",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-05T08:10:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fed59f72784e1fce5df0961ce7ed23f6e50f826c",
          "body": "* 6.4:\n  Fix up\n  [Cache] Ensure compatibility with Relay extension 0.22.0\n  [Yaml] fix flow collection drops `&anchor` and `!!str &anchor` items\n  Fix excludePaths in PHPStan config\n  [Security] Fix typos in method documentations\n  [Messenger] Move --time-limit handling to Worker for proper capping with --sleep",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-05T08:01:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9902fac434617310dd5feb6f90d1765e3864d249",
          "body": "…o prevent brute-force attacks (ayyoub-afwallah)\"\n\nThis reverts commit 692ecef8f554f464c1b4c23c842c9e5e11c47621, reversing\nchanges made to 965b0fcc19537fde044ba03b9ce4d36aec910fd0.",
          "is_bot": false,
          "headline": "Revert \"feature #64104 [Security] Add per-username login rate-limit t…",
          "author_name": "Wouter de Jong",
          "author_login": "wouterj",
          "committed_at": "2026-05-04T20:16:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d08c803184bc0696f3ed998c3c95d3145150802",
          "body": null,
          "is_bot": false,
          "headline": "[Security] Fix typos in method documentations",
          "author_name": "Matthias Schmidt",
          "author_login": "mttsch",
          "committed_at": "2026-05-04T18:23:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b1de103a0d84e4966c1f3d0648aa97ae843a615",
          "body": "…t brute-force attacks (ayyoub-afwallah)\n\nThis PR was merged into the 8.1 branch.\n\nDiscussion\n----------\n\n[Security] Add per-username login rate-limit to prevent brute-force attacks\n\n| Q             | A\n| ------------- | ---\n| Branch?       | 8.1\n| Bug fix?      | no\n| New feature?  | yes\n| Deprecat\n[…]\neLimiter as suggested in https://github.com/symfony/symfony/pull/63997#issuecomment-4341549421\n\nCommits\n-------\n\na84ec30c21a [Security] Add per-username login rate-limit to prevent brute-force attacks",
          "is_bot": false,
          "headline": "feature #64104 [Security] Add per-username login rate-limit to preven…",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-04T15:40:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bd42ec6578b84078f9af6118435e604a0665061f",
          "body": "…ttacks",
          "is_bot": false,
          "headline": "[Security] Add per-username login rate-limit to prevent brute-force a…",
          "author_name": "Ayyoub AFW-ALLAH",
          "author_login": "ayyoub-afwallah",
          "committed_at": "2026-05-04T15:40:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "650815fc5c2a9c8a16c96de97ba48c307251e44f",
          "body": "* 8.0:\n  [AssetMapper] Stop baking CSP nonce into the importmap polyfill body\n  [Translation] URL-encode tmp path in XliffUtils::shouldEnableEntityLoader\n  [RateLimiter] Carry over reserved tokens past fixed window resets\n  [Security] Document that AbstractLoginFormAuthenticator::getLoginUrl() must \n[…]\nny version to 7.4.10\n  Update VERSION for 7.4.9\n  Update CHANGELOG for 7.4.9\n  Bump Symfony version to 6.4.38\n  Update VERSION for 6.4.37\n  Update CONTRIBUTORS for 6.4.37\n  Update CHANGELOG for 6.4.37",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-04T13:43:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ef95e76da50c6af01894c15268864e65dcd540e3",
          "body": "* 7.4:\n  [AssetMapper] Stop baking CSP nonce into the importmap polyfill body\n  [Translation] URL-encode tmp path in XliffUtils::shouldEnableEntityLoader\n  [RateLimiter] Carry over reserved tokens past fixed window resets\n  [Security] Document that AbstractLoginFormAuthenticator::getLoginUrl() must \n[…]\nny version to 7.4.10\n  Update VERSION for 7.4.9\n  Update CHANGELOG for 7.4.9\n  Bump Symfony version to 6.4.38\n  Update VERSION for 6.4.37\n  Update CONTRIBUTORS for 6.4.37\n  Update CHANGELOG for 6.4.37",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-04T13:41:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "10ca6afdc347ae771b5f7baea68f655666fe9b0e",
          "body": "* 6.4:\n  [Translation] URL-encode tmp path in XliffUtils::shouldEnableEntityLoader\n  [RateLimiter] Carry over reserved tokens past fixed window resets\n  [Security] Document that AbstractLoginFormAuthenticator::getLoginUrl() must return a path\n  [Ldap] Cast default network_timeout to int\n  Bump Symfony version to 6.4.38\n  Update VERSION for 6.4.37\n  Update CONTRIBUTORS for 6.4.37\n  Update CHANGELOG for 6.4.37",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-04T13:25:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a87eafe04970a043988bb7a37b3463d643bc9569",
          "body": "…) must return a path",
          "is_bot": false,
          "headline": "[Security] Document that AbstractLoginFormAuthenticator::getLoginUrl(…",
          "author_name": "Ousama Ben Younes",
          "author_login": "ousamabenyounes",
          "committed_at": "2026-05-04T12:02:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "de300e6942fe0a23e822338e9e6dfd23f28f8380",
          "body": null,
          "is_bot": false,
          "headline": "[HttpKernel][Security] Type-check evaluated attribute keys",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-30T06:57:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f139d56a79a23169247210bb073ef7cef527fda",
          "body": "* 8.0: (24 commits)\n  [Validator] Drop PHP < 8.4 compat in PropertyMetadata\n  [Form] Preserve collection children added by PRE_SET_DATA listeners\n  [Messenger] Keep deduplication lock when handler throws\n  [Mailer][Postmark] Handle alternate error payload shapes for Payload Too Large\n  CS fix\n  [Ser\n[…]\nests/ObjectMapperTest.php\n#\tsrc/Symfony/Component/Security/Http/Tests/EventListener/IsCsrfTokenValidAttributeListenerTest.php\n#\tsrc/Symfony/Component/Serializer/Normalizer/AbstractObjectNormalizer.php",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-29T15:16:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "51fff88fc8436e42b4d92cae005f86b9233e0f88",
          "body": "* 7.4: (23 commits)\n  [Form] Preserve collection children added by PRE_SET_DATA listeners\n  [Messenger] Keep deduplication lock when handler throws\n  [Mailer][Postmark] Handle alternate error payload shapes for Payload Too Large\n  CS fix\n  [Serializer] Catch TypeError when setting an attribute to co\n[…]\nt/Serializer/Tests/Normalizer/AbstractObjectNormalizerTest.php\n#\tsrc/Symfony/Component/Serializer/Tests/Normalizer/PropertyNormalizerTest.php\n#\tsrc/Symfony/Component/TypeInfo/Tests/TypeFactoryTest.php",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-29T15:02:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a34991b13899de1f953df245395aa2196f9bc113",
          "body": null,
          "is_bot": false,
          "headline": "[7.4] Remove usages of named arguments in tests",
          "author_name": "Robin Chalas",
          "author_login": "chalasr",
          "committed_at": "2026-04-22T15:21:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a185c705f887be995bb11425311e8889c86b9c0",
          "body": null,
          "is_bot": false,
          "headline": "[6.4] Remove usages of named arguments in tests",
          "author_name": "Robin Chalas",
          "author_login": "chalasr",
          "committed_at": "2026-04-20T13:36:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "61b2cdae84864e56bc126e39d45299f3b00c061d",
          "body": "* 8.0:\n  [Security] Throw BadCredentialsException on empty JSON login username/password\n  [Routing] Honor the Request's method in UrlMatcher::matchRequest()\n  [DependencyInjection] Log every build parameter removed during compilation\n  [Serializer] Remove @internal from ClassMetadataInterface and At\n[…]\nake `BackedEnumNormalizer` unconditionally return `null` on invalid value if `allow_invalid_values` is set\n  [Cache] Ensure internal state is cleared in TagAwareAdapter::reset() even on commit failure",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-18T13:52:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ffdf31650eb2b41482d66aca91a31f5f647e1cd3",
          "body": "* 7.4:\n  [Security] Throw BadCredentialsException on empty JSON login username/password\n  [Routing] Honor the Request's method in UrlMatcher::matchRequest()\n  [DependencyInjection] Log every build parameter removed during compilation\n  [Serializer] Remove @internal from ClassMetadataInterface and At\n[…]\nake `BackedEnumNormalizer` unconditionally return `null` on invalid value if `allow_invalid_values` is set\n  [Cache] Ensure internal state is cleared in TagAwareAdapter::reset() even on commit failure",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-18T13:51:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5b1110405842622429e92d2c290fe6f9fc6e728f",
          "body": "…in username/password (ousamabenyounes)\n\nThis PR was merged into the 7.4 branch.\n\nDiscussion\n----------\n\n[Security] Throw BadCredentialsException on empty JSON login username/password\n\n| Q             | A\n| ------------- | ---\n| Branch?       | 7.4\n| Bug fix?      | yes\n| New feature?  | no\n| Deprec\n[…]\nt 11) that all 4 empty/non-string data rows fail on `7.4` before the fix and pass after it.\n\nCommits\n-------\n\ndce79918841 [Security] Throw BadCredentialsException on empty JSON login username/password",
          "is_bot": false,
          "headline": "bug #63983 [Security] Throw BadCredentialsException on empty JSON log…",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-18T13:50:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a43db022814bd5bd6ecf52e3336ab4118ad894f3",
          "body": "…/password",
          "is_bot": false,
          "headline": "[Security] Throw BadCredentialsException on empty JSON login username…",
          "author_name": "Ousama Ben Younes",
          "author_login": "ousamabenyounes",
          "committed_at": "2026-04-18T13:49:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "63e0e4bb91ef4d1a95eb63b31c1bb0cead53bdd9",
          "body": null,
          "is_bot": false,
          "headline": "Update XSD references in phpunit.xml.dist files",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-18T13:18:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "355f32f4318c962842f016eabd0966fde739f6fc",
          "body": "…ator",
          "is_bot": false,
          "headline": "[Security] Anchor emailAddress regex to RDN boundary in X509Authentic…",
          "author_name": "Alexandre Daubois",
          "author_login": "alexandre-daubois",
          "committed_at": "2026-04-17T13:15:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ded4747bc69d692364c0e561530c7d40654ccd9",
          "body": null,
          "is_bot": false,
          "headline": "[Security] Add missing claims in `OidcTokenHandler`",
          "author_name": "Alexandre Daubois",
          "author_login": "alexandre-daubois",
          "committed_at": "2026-04-17T13:11:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8121e9d7817bac8bccbdf34d4d7f838c6c995ad1",
          "body": "* 8.0:\n  [Tests] Fix \"Incomplete version\" PHPUnit warnings\n  chore: Component/String/Resources/data - cleanup header",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-17T05:56:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2749f880dbfbc7c6c7b0b7f3da8c7f2dfc610710",
          "body": "* 7.4:\n  [Tests] Fix \"Incomplete version\" PHPUnit warnings\n  chore: Component/String/Resources/data - cleanup header",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-17T05:56:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5835d0d3f023bce509f56a8a2c5d3a2157cd3eb2",
          "body": null,
          "is_bot": false,
          "headline": "[Tests] Fix \"Incomplete version\" PHPUnit warnings",
          "author_name": "hubert.lenoir",
          "author_login": "Jean-Beru",
          "committed_at": "2026-04-17T05:48:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e8fa5faf8cc28e417fe0ed93ab76daf4534047cc",
          "body": "* 7.4:\n  CS fixes\n  Fix merge\n  More CS fixes",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-13T15:47:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2e151652e4b18e744f6bb0fa54624e003bfc3e82",
          "body": null,
          "is_bot": false,
          "headline": "CS fixes",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-13T15:40:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3913e78fb442d7106dfb68688fa4e9bf753012ab",
          "body": "* 6.4:\n  More CS fixes",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-13T15:32:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0ae423be0cb800fe41214ee5a1e054e5766e0138",
          "body": null,
          "is_bot": false,
          "headline": "More CS fixes",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-13T15:27:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "72b620c2e4799505fa72e4fad8ec70894325bf61",
          "body": "* 7.4:\n  Fix merge",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-13T14:49:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6ced1f456f94688aa586b65ba40c3f4376fbda8",
          "body": "* 7.4:\n  CS fixes - native_function_invocation & static_lambda\n  Backport some CS fixes from 7.4\n  [CS] Back config from 8.1 and apply heredoc_indentation rule\n  [Workflow] Fix HTML escaping in GraphvizDumper labels",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-13T14:34:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "128043f0cd7260c77bbdc34196b9866874f121bb",
          "body": "* 6.4:\n  CS fixes - native_function_invocation & static_lambda\n  Backport some CS fixes from 7.4",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-13T14:28:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f31612626f8e3eb779a0182e2aab141d8b25a146",
          "body": null,
          "is_bot": false,
          "headline": "CS fixes - native_function_invocation & static_lambda",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-13T14:11:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6ce45ef6ebbd7be845edf57e78b1fcdf900718fb",
          "body": null,
          "is_bot": false,
          "headline": "Bump to php >= 8.4.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-07T06:26:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b693cfa2657b7e2881699d27591db72108791627",
          "body": "* 8.0:\n  Add deprecationTrigger ignoreUndefinedTriggers=\"true\" in phpunit.xml.dist files",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-06T11:11:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 100,
      "commits_last_year": 224,
      "latest_release_at": "2026-06-27T09:30:56Z",
      "latest_release_tag": "v8.1.1",
      "releases_from_tags": false,
      "days_since_last_push": 13,
      "active_weeks_last_year": 44,
      "days_since_latest_release": 25,
      "mean_days_between_releases": 3.4
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 75,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "symfony/security-http",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "packagist",
          "matches_repo": true,
          "registry_url": "https://packagist.org/packages/symfony/security-http",
          "is_deprecated": false,
          "latest_version": "v8.1.1",
          "repository_url": "https://github.com/symfony/security-http",
          "versions_count": 646,
          "total_downloads": 180222688,
          "dependents_count": 235,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 4297376,
          "first_published_at": null,
          "latest_published_at": "2026-06-27T06:18:14Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 25
        }
      ]
    },
    "popularity": {
      "forks": 22,
      "stars": 1702,
      "watchers": 7,
      "fork_history": {
        "days": [
          {
            "date": "2015-06-07",
            "count": 1
          },
          {
            "date": "2015-10-07",
            "count": 1
          },
          {
            "date": "2018-08-03",
            "count": 1
          },
          {
            "date": "2019-03-15",
            "count": 1
          },
          {
            "date": "2019-05-07",
            "count": 1
          },
          {
            "date": "2019-06-21",
            "count": 1
          },
          {
            "date": "2020-03-12",
            "count": 1
          },
          {
            "date": "2021-06-24",
            "count": 1
          },
          {
            "date": "2021-09-04",
            "count": 1
          },
          {
            "date": "2022-03-25",
            "count": 1
          },
          {
            "date": "2022-05-12",
            "count": 1
          },
          {
            "date": "2022-12-25",
            "count": 1
          },
          {
            "date": "2023-02-02",
            "count": 1
          },
          {
            "date": "2023-10-24",
            "count": 1
          },
          {
            "date": "2024-02-10",
            "count": 1
          },
          {
            "date": "2024-04-11",
            "count": 1
          },
          {
            "date": "2024-07-29",
            "count": 1
          },
          {
            "date": "2025-06-01",
            "count": 1
          },
          {
            "date": "2025-08-20",
            "count": 1
          },
          {
            "date": "2026-02-13",
            "count": 1
          },
          {
            "date": "2026-06-22",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 21,
        "total_forks": 22
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": 27253,
      "source_files_sampled": 201,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "composer.json"
      ],
      "advisories": {
        "error": "No resolved dependencies carried a version and a supported ecosystem",
        "scope": "repository_graph",
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 19,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "packagist"
      ],
      "dependencies": [
        {
          "name": "symfony/deprecation-contracts",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^2.5|^3"
        },
        {
          "name": "symfony/http-foundation",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^7.4|^8.0"
        },
        {
          "name": "symfony/http-kernel",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^8.1"
        },
        {
          "name": "symfony/polyfill-mbstring",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^1.0"
        },
        {
          "name": "symfony/property-access",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^7.4|^8.0"
        },
        {
          "name": "symfony/security-core",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^7.4|^8.0"
        },
        {
          "name": "symfony/service-contracts",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^2.5|^3"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "symfony/deprecation-contracts",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/http-foundation",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/http-kernel",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/polyfill-mbstring",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/property-access",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/security-core",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/service-contracts",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "php",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "psr/log",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/cache",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/clock",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/expression-language",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/http-client",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/http-client-contracts",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/rate-limiter",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/routing",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/security-csrf",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/translation",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "web-token/jwt-library",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 19,
        "direct_count": 7,
        "indirect_count": 12
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 2,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "nicolas-grekas",
          "commits": 970,
          "avatar_url": "https://avatars.githubusercontent.com/u/243674?v=4"
        },
        {
          "type": "User",
          "login": "fabpot",
          "commits": 578,
          "avatar_url": "https://avatars.githubusercontent.com/u/47313?v=4"
        },
        {
          "type": "User",
          "login": "xabbuh",
          "commits": 201,
          "avatar_url": "https://avatars.githubusercontent.com/u/1957048?v=4"
        },
        {
          "type": "User",
          "login": "chalasr",
          "commits": 110,
          "avatar_url": "https://avatars.githubusercontent.com/u/7502063?v=4"
        },
        {
          "type": "User",
          "login": "derrabus",
          "commits": 105,
          "avatar_url": "https://avatars.githubusercontent.com/u/1506493?v=4"
        },
        {
          "type": "User",
          "login": "wouterj",
          "commits": 104,
          "avatar_url": "https://avatars.githubusercontent.com/u/749025?v=4"
        },
        {
          "type": "User",
          "login": "Tobion",
          "commits": 26,
          "avatar_url": "https://avatars.githubusercontent.com/u/610090?v=4"
        },
        {
          "type": "User",
          "login": "alexandre-daubois",
          "commits": 23,
          "avatar_url": "https://avatars.githubusercontent.com/u/2144837?v=4"
        },
        {
          "type": "User",
          "login": "jderusse",
          "commits": 23,
          "avatar_url": "https://avatars.githubusercontent.com/u/578547?v=4"
        },
        {
          "type": "User",
          "login": "keradus",
          "commits": 16,
          "avatar_url": "https://avatars.githubusercontent.com/u/2716794?v=4"
        }
      ],
      "contributors_sampled": 100,
      "top_contributor_share": 0.397
    },
    "quality_signals": {
      "has_ci": false,
      "has_tests": true,
      "ci_workflows": [],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 103 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": null,
            "reason": "no workflows found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": null,
            "reason": "no dependencies found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": null,
            "reason": "No tokens found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "8a899d1a0ee80466911afbae5707a04e0ea65d12",
        "ran_at": "2026-07-22T17:56:47Z",
        "aggregate_score": 4.8,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": null,
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": null,
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/symfony/security-http",
    "host": "github.com",
    "name": "security-http",
    "owner": "symfony"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 65,
      "inputs": {
        "security": 48,
        "vitality": 92,
        "community": 81,
        "governance": 59,
        "engineering": 44
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 92,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 87,
            "inputs": {
              "commits_last_year": 224,
              "human_commit_share": 1,
              "days_since_last_push": 13,
              "active_weeks_last_year": 44
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 13 days ago",
                "points": 28.8,
                "status": "partial",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 13
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "44/52 weeks with commits",
                "points": 30.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 44
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "224 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 224
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 100,
              "latest_release_tag": "v8.1.1",
              "releases_from_tags": false,
              "days_since_latest_release": 25,
              "mean_days_between_releases": 3.4
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "100 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 100
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 25 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 25
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~3.4 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 3.4
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 13,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 13 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 13
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "good",
        "name": "Community & Adoption",
        "value": 81,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "forks": 22,
              "stars": 1702,
              "watchers": 7,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1,702 stars",
                "points": 52.4,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1702
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "22 forks",
                "points": 11,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 22
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "7 watchers",
                "points": 4.3,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "excellent",
            "name": "Ecosystem adoption (downloads)",
            "note": null,
            "notes": [],
            "value": 96,
            "inputs": {
              "packages": [
                "symfony/security-http"
              ],
              "dependents": 235,
              "ecosystems": "packagist",
              "total_downloads": 180222688,
              "monthly_downloads": 4297376
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "4,297,376 downloads/month across packagist",
                "points": 80,
                "status": "met",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 4297376,
                      "ecosystems": "packagist"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "235 packages depend on it",
                "points": 15.8,
                "status": "partial",
                "details": [
                  {
                    "code": "registry_dependents",
                    "params": {
                      "count": 235
                    }
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 59,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "moderate",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 62,
            "inputs": {
              "bus_factor": 2,
              "contributors_sampled": 100,
              "top_contributor_share": 0.397
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "2 contributor(s) cover half of all commits",
                "points": 25.2,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 40% of commits",
                "points": 13.6,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 40
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "100 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 100
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 103 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution",
                    "pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 79,
            "inputs": {
              "followers": 2169,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "symfony",
              "public_repos": 414,
              "account_age_days": 6115
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "2,169 followers of symfony",
                "points": 24,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 2169,
                      "login": "symfony"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "414 public repos, account ~16 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 414
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 16
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "symfony/security-http"
              ],
              "ecosystems": "packagist",
              "any_deprecated": false,
              "min_days_since_publish": 25
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on packagist",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "packagist"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 25 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 25
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "646 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 646
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "at_risk",
        "name": "Engineering Quality",
        "value": 44,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 30,
            "inputs": {
              "has_ci": false,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [
                "php",
                "symfony",
                "component",
                "symfony-component"
              ],
              "has_wiki": false,
              "homepage": "https://symfony.com/security",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://symfony.com/security",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "4 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 48,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Dangerous-Workflow, Packaging, Pinned-Dependencies, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "dangerous_workflow",
                    "packaging",
                    "pinned_dependencies",
                    "signed_releases",
                    "token_permissions"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 48,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 12,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 6,
              "scorecard_aggregate": 4.8
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 103 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no workflows found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "No tokens found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 31
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "at_risk",
        "name": "AI Readiness",
        "value": 32,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 32,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.6,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "60 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 32,
                "status": "partial",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 60,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "critical",
            "name": "Verify loop (build / test / typecheck)",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Pinned-Dependencies. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_pinned_dependencies"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 24,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "primary_language": "PHP",
              "largest_source_bytes": 27253,
              "source_files_sampled": 201,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "PHP without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "PHP"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/201 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 201,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "No resolved dependencies carried a version and a supported ecosystem"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-22T17:57:04.422694Z",
  "schema_version": "0.26.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/s/symfony/security-http.svg",
  "full_name": "symfony/security-http",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Bewertungen sind Signale, keine Garantien. Sie spiegeln öffentlich sichtbare Praxis auf GitHub wider — kein Code-Audit und keine Sicherheitsgarantie.

Fehlende Daten werden ausgeschlossen und die Gewichte neu normiert, nie als null bewertet. Die Methodik ist versioniert und offen: Metriken v1.13.0, Schema v0.26.0 — vollständige Methodik · Metriken-Wiki.

Wie ein einzelnes Ergebnis im Gesamtregister steht: aggregierte StatistikenPackagist.