Registro público
Informe de salud del softwareesquema 0.26.0 · métricas 1.13.0 · 2026-07-22 17:57 UTC

symfony / security-http

Symfony Security Component - HTTP Integration

PHPMIT★ 1702 estrellas⑂ 22 forksdesde sept 2013Ver en GitHub ↗

symfony/security-http tiene un índice de salud de 65 sobre 100, lo que lo sitúa en la banda Moderado. Su puntuación más alta es Vitality (92/100) y la más baja, AI Readiness (32/100). Se actualizó por última vez hace 13 días. 2 personas concentran la mayor parte del trabajo reciente.

65
global / 100
Moderado

Índice de salud del software

Las métricas se agrupan en categorías ponderadas sobre una escala de 1 a 100. El resultado global parte de su media; cuando la evidencia pública activa la Política de Jurisdicciones de Alto Riesgo, la calificación se ajusta y recibe el límite 49 (En riesgo). Preparación para IA queda fuera.

65
Excelente85-100Ejemplar; cumple prácticamente todos los criterios evaluados
Bueno70-84Saludable; carencias menores
Moderado50-69Aceptable con carencias notables; se recomienda revisión
En riesgo30-49Debilidades significativas; su adopción exige cautela
Crítico1-29Problemas graves (proyecto abandonado, un solo mantenedor, sin higiene)
VitalidadComunidad yAdopciónSostenibilidady GobernanzaCalidad deIngenieríaSeguridadPreparaciónpara IA

Perfil de puntuación

Cada eje es una categoría. La forma importa más que la media: un proyecto sano llena toda la figura, mientras que un perfil de picos y cráteres indica que la fortaleza en una dimensión enmascara el riesgo en otra.

Titularidad

SymfonyOrganización
2169 seguidores414 repositorios públicosdesde oct 2009

Este repositorio está respaldado por una organización: una custodia compartida y responsable que puede sobrevivir a cualquier mantenedor individual.

Ecosistemas de paquetes

RegistroPaqueteVersiónDescargas / mesVersionesÚltima publicación
Packagistsymfony/security-httpv8.1.14.297.376646hace 25 días

Métricas por categoría

Vitalidad

¿Está vivo el proyecto: se escribe código y se publican versiones?

92Excelente · 22% del índice global
Cómo se puntúa
28.8/36Recencia de push — último push hace 13 días
30.5/36Cadencia de commits — 44/52 semanas con commits
18/18Volumen de commits — 224 commits en el último año
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Datos de entrada utilizados
commits_last_year224
human_commit_share1
days_since_last_push13
active_weeks_last_year44
Cómo se puntúa
27/27Publica versiones — 100 versiones publicadas
36/36Recencia de las versiones — última versión hace 25 días
27/27Cadencia de publicación — una versión cada ~3,4 días
0/10OpenSSF Scorecard: Signed-Releases — sin datos
Datos de entrada utilizados
releases_count100
latest_release_tagv8.1.1
releases_from_tagsno
days_since_latest_release25
mean_days_between_releases3,4
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: Signed-Releases. Los pesos restantes se han renormalizado.

Comunidad y Adopción

¿Tiene el proyecto usuarios, descargas, atención y unas condiciones acogedoras para quienes contribuyen?

81Bueno · 18% del índice global
Cómo se puntúa
52.4/60Estrellas — 1702 estrellas
11/25Forks — 22 forks
4.3/15Observadores — 7 observadores
Datos de entrada utilizados
forks22
stars1702
watchers7
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Cómo se puntúa
22.5/22.5README
22.5/22.5Licencia — licencia reconocida (MIT)
18/18Guía CONTRIBUTING
13.5/13.5Código de conducta
0/7.2Plantilla de issues
0/6.3Plantilla de PR
Datos de entrada utilizados
has_readme
has_license
has_contributing
has_issue_templateno
has_code_of_conduct
has_pull_request_templateno
Cómo se puntúa
80/80Descargas mensuales — 4.297.376 descargas/mes en packagist
15.8/20Dependientes en el registro — 235 paquetes dependen de él
Datos de entrada utilizados
packagessymfony/security-http
dependents235
ecosystemspackagist
total_downloads180.222.688
monthly_downloads4.297.376

Sostenibilidad y Gobernanza

¿Sobrevivirá el proyecto a sus personas: factor bus, capacidad de respuesta, quién lo respalda y mantenimiento del paquete?

59Moderado · 24% del índice global
Cómo se puntúa
25.2/54Factor bus — la mitad de los commits recae en 2 contribuyente(s)
13.6/22.5Distribución de commits — el principal contribuyente firma el 40% de los commits
13.5/13.5Amplitud de contribuyentes — 100 contribuyentes
10/10OpenSSF Scorecard: Contributors — project has 103 contributing companies or organizations
Datos de entrada utilizados
bus_factor2
contributors_sampled100
top_contributor_share0,397
Cómo se puntúa
0/46.8Resolución de issues — sin issues o sin datos
0/38.3Aceptación de PR — sin PR decididos o sin datos
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Datos de entrada utilizados
merged_prs0
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Excluidos de la puntuación (sin datos o no aplicable): Resolución de issues, Aceptación de PR. Los pesos restantes se han renormalizado.
Cómo se puntúa
30/30Respaldo de la propiedad — propiedad de una organización
0/20Dominio verificado
24/25Alcance del propietario — 2169 seguidores de symfony
25/25Trayectoria — 414 repos públicos, cuenta de ~16 años
Datos de entrada utilizados
followers2169
owner_typeOrganization
is_verified
owner_loginsymfony
public_repos414
account_age_days6115
Cómo se puntúa
25/25Publicado y resoluble — 1 paquete(s) en packagist
35/35Recencia de publicación — última publicación hace 25 días
20/20Historial de versiones — 646 versiones en el registro
20/20No obsoleto — activo, ni obsoleto ni retirado
Datos de entrada utilizados
packagessymfony/security-http
ecosystemspackagist
any_deprecatedno
min_days_since_publish25

Calidad de Ingeniería

¿Existen unas prácticas mínimas de ingeniería y documentación?

44En riesgo · 20% del índice global
Cómo se puntúa
0/24Flujos de trabajo de CI
24/24Pruebas presentes
0/16Configuración de linter
0/9.6Hooks de pre-commit
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — sin datos
Datos de entrada utilizados
has_cino
has_tests
has_editorconfigno
has_linter_configno
has_precommit_configno
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: CI-Tests. Los pesos restantes se han renormalizado.

Documentación

65Moderado
Cómo se puntúa
30/30README
0/25Directorio de documentación
15/15Sitio de documentación / página del proyecto — https://symfony.com/security
10/10Descripción del repositorio
10/10Topics — 4 topics
0/10Wiki
Datos de entrada utilizados
topicsphp, symfony, component, symfony-component
has_wikino
homepagehttps://symfony.com/security
has_readme
has_docs_dirno
has_description

Seguridad

¿Son sólidas las prácticas visibles de seguridad y de cadena de suministro, sin exposición jurisdiccional de alto riesgo sin resolver?

48En riesgo · 16% del índice global
Cómo se puntúa
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — sin datos
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 103 contributing companies or organizations
0/10Dangerous-Workflow — sin datos
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Licencia — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — sin datos
0/5Pinned-Dependencies — sin datos
0/5SAST — no SAST tool detected
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — sin datos
0/7.5Token-Permissions — sin datos
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Datos de entrada utilizados
sourceopenssf_scorecard
checks_evaluated12
scorecard_versionv5.5.0
checks_inconclusive6
scorecard_aggregate4,8
Excluidos de la puntuación (sin datos o no aplicable): ci_tests, dangerous_workflow, packaging, pinned_dependencies, signed_releases, token_permissions. Los pesos restantes se han renormalizado.

Preparación para IA

¿Hasta qué punto está el repositorio preparado para desarrollarse y mantenerse con agentes de codificación de IA? Es una insignia independiente y experimental — peso 0,0, de modo que se presenta por separado y no afecta a la puntuación de salud global.

32En riesgo · 0% del índice global
Cómo se puntúa
0/45Instrucciones para agentes — sin CLAUDE.md / AGENTS.md / reglas de editor
0/15Documentación legible por máquinas (llms.txt)
32/40Historial de commits legible — 60 de 100 commits humanos declaran su intención (asunto estructurado o cuerpo explicativo)
Datos de entrada utilizados
has_llms_txtno
legible_history_share0,6
agent_instruction_files
agent_instruction_max_bytes
Cómo se puntúa
0/18Arranque con un solo comando
22/22Pruebas automatizadas
0/11Configuración de lint / formato
0/11Verificación estática de tipos
0/10Entorno reproducible
0/10Práctica demostrada con agentes — ningún commit con autoría de agente entre los últimos 100
0/8Mantenimiento automatizado — no se observan actualizaciones automáticas de dependencias
0/10OpenSSF Scorecard: Pinned-Dependencies — sin datos
Datos de entrada utilizados
has_nixno
has_tests
lockfiles
has_dockerfileno
typed_languageno
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
Excluidos de la puntuación (sin datos o no aplicable): OpenSSF Scorecard: Pinned-Dependencies. Los pesos restantes se han renormalizado.
Cómo se puntúa
0/45Código verificable por tipos — PHP sin configuración de verificación de tipos
55/55Tamaños de archivo manejables — 0/201 archivos fuente de más de 60 KB
Datos de entrada utilizados
primary_languagePHP
largest_source_bytes27.253
source_files_sampled201
oversized_source_files0

Datos clave

1702estrellas de GitHub
100contribuidores
224commits en los últimos 12 meses
13días desde el último push
100versiones publicadas
2factor bus
0issues abiertas
Packagistecosistemas de paquetes

Advertencias de recopilación de datos

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • No resolved dependencies carried a version and a supported ecosystem

Más detalle

Historial de estrellas y forks 0 ★ / 22 ⇿
0Estrellas
22Forks
96Versiones

Cuándo se añadió cada estrella y fork, recopilado de GitHub y agrupado por día. El crecimiento acumulado se sitúa justo encima de las adiciones diarias que lo componen, de modo que ambos se leen en conjunto: la acumulación orgánica sostenida no se parece en nada a un pico abrupto y efímero. Cuando esa diferencia es medible, se informa como autenticidad del crecimiento.

048121620242112015-062020-122026-06
Mayor 0Menor 5Parche 75

Cada punto abarca 11 días.

OpenSSF Scorecard 4.8 / 10
4.8agregado

Evaluación de seguridad independiente y agnóstica en cuanto a herramientas, procedente del proyecto de código abierto OpenSSF Scorecard. Cada comprobación premia una práctica de seguridad, no la herramienta de un proveedor concreto. Las comprobaciones que Scorecard no pudo determinar se marcan como n/d y se excluyen de la puntuación de seguridad (nunca se cuentan como cero).Scorecard v5.5.0 · 2026-07-22 17:56 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
n/dCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
10Contributorsproject has 103 contributing companies or organizations
n/dDangerous-Workflowno workflows found
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
n/dPackagingpackaging workflow not detected
n/dPinned-Dependenciesno dependencies found
0SASTno SAST tool detected
10Security-Policysecurity policy file detected
n/dSigned-Releasesno releases found
n/dToken-PermissionsNo tokens found
10Vulnerabilities0 existing vulnerabilities detected
Dependencias directas 7
RegistroPaqueteRestricción de versiónManifiesto
Packagistsymfony/deprecation-contracts^2.5|^3composer.json
Packagistsymfony/http-foundation^7.4|^8.0composer.json
Packagistsymfony/http-kernel^8.1composer.json
Packagistsymfony/polyfill-mbstring^1.0composer.json
Packagistsymfony/property-access^7.4|^8.0composer.json
Packagistsymfony/security-core^7.4|^8.0composer.json
Packagistsymfony/service-contracts^2.5|^3composer.json
Todas las dependencias 19

Conjunto completo de dependencias resueltas según el grafo de dependencias de GitHub: 7 paquetes directos y 12 indirectos (transitivos). El cierre transitivo es completo cuando el repositorio incluye un lockfile.

RegistroPaqueteVersiónRelación
Packagistsymfony/deprecation-contractsdirecta
Packagistsymfony/http-foundationdirecta
Packagistsymfony/http-kerneldirecta
Packagistsymfony/polyfill-mbstringdirecta
Packagistsymfony/property-accessdirecta
Packagistsymfony/security-coredirecta
Packagistsymfony/service-contractsdirecta
Packagistphpindirecta
Packagistpsr/logindirecta
Packagistsymfony/cacheindirecta
Packagistsymfony/clockindirecta
Packagistsymfony/expression-languageindirecta
Packagistsymfony/http-clientindirecta
Packagistsymfony/http-client-contractsindirecta
Packagistsymfony/rate-limiterindirecta
Packagistsymfony/routingindirecta
Packagistsymfony/security-csrfindirecta
Packagistsymfony/translationindirecta
Packagistweb-token/jwt-libraryindirecta
Avisos de dependencias sin evaluar

El cotejo de avisos no pudo ejecutarse para este informe: No resolved dependencies carried a version and a supported ecosystem

Informe JSON sin procesar legible por máquina
{
  "data": {
    "repo": {
      "topics": [
        "php",
        "symfony",
        "component",
        "symfony-component"
      ],
      "is_fork": false,
      "size_kb": 3603,
      "has_wiki": false,
      "homepage": "https://symfony.com/security",
      "languages": {
        "PHP": 792752
      },
      "pushed_at": "2026-07-09T15:18:56Z",
      "created_at": "2013-09-18T14:06:45Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-17T10:04:53Z",
      "description": "Symfony Security Component - HTTP Integration",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "8.2",
      "license_spdx_raw": "MIT",
      "primary_language": "PHP",
      "significant_languages": [
        "PHP"
      ]
    },
    "owner": {
      "blog": "https://symfony.com/",
      "name": "Symfony",
      "type": "Organization",
      "login": "symfony",
      "company": null,
      "location": "The Internet",
      "followers": 2169,
      "avatar_url": "https://avatars.githubusercontent.com/u/143937?v=4",
      "created_at": "2009-10-24T04:05:23Z",
      "is_verified": null,
      "public_repos": 414,
      "account_age_days": 6115
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v8.1.1",
          "kind": "patch",
          "published_at": "2026-06-27T09:30:56Z"
        },
        {
          "tag": "v8.0.14",
          "kind": "patch",
          "published_at": "2026-06-27T09:27:57Z"
        },
        {
          "tag": "v7.4.14",
          "kind": "patch",
          "published_at": "2026-06-27T09:17:03Z"
        },
        {
          "tag": "v6.4.42",
          "kind": "patch",
          "published_at": "2026-06-27T09:14:18Z"
        },
        {
          "tag": "v8.1.0",
          "kind": "minor",
          "published_at": "2026-05-29T08:53:40Z"
        },
        {
          "tag": "v8.1.0-RC1",
          "kind": "prerelease",
          "published_at": "2026-05-27T11:34:48Z"
        },
        {
          "tag": "v8.0.13",
          "kind": "patch",
          "published_at": "2026-05-27T10:31:37Z"
        },
        {
          "tag": "v7.4.13",
          "kind": "patch",
          "published_at": "2026-05-27T08:45:34Z"
        },
        {
          "tag": "v6.4.41",
          "kind": "patch",
          "published_at": "2026-05-27T08:30:01Z"
        },
        {
          "tag": "v5.4.53",
          "kind": "patch",
          "published_at": "2026-05-27T08:20:38Z"
        },
        {
          "tag": "v8.1.0-BETA3",
          "kind": "prerelease",
          "published_at": "2026-05-20T12:11:23Z"
        },
        {
          "tag": "v8.0.12",
          "kind": "patch",
          "published_at": "2026-05-20T10:07:31Z"
        },
        {
          "tag": "v7.4.12",
          "kind": "patch",
          "published_at": "2026-05-20T09:43:44Z"
        },
        {
          "tag": "v6.4.40",
          "kind": "patch",
          "published_at": "2026-05-20T09:02:40Z"
        },
        {
          "tag": "v5.4.52",
          "kind": "patch",
          "published_at": "2026-05-20T08:27:36Z"
        },
        {
          "tag": "v8.1.0-BETA2",
          "kind": "prerelease",
          "published_at": "2026-05-13T18:41:24Z"
        },
        {
          "tag": "v8.0.11",
          "kind": "patch",
          "published_at": "2026-05-13T18:23:18Z"
        },
        {
          "tag": "v7.4.11",
          "kind": "patch",
          "published_at": "2026-05-13T18:05:45Z"
        },
        {
          "tag": "v6.4.39",
          "kind": "patch",
          "published_at": "2026-05-13T17:54:02Z"
        },
        {
          "tag": "v8.1.0-BETA1",
          "kind": "prerelease",
          "published_at": "2026-05-06T14:29:00Z"
        },
        {
          "tag": "v8.0.9",
          "kind": "patch",
          "published_at": "2026-05-01T08:14:52Z"
        },
        {
          "tag": "v7.4.9",
          "kind": "patch",
          "published_at": "2026-05-01T08:00:41Z"
        },
        {
          "tag": "v8.0.8",
          "kind": "patch",
          "published_at": "2026-03-31T21:31:46Z"
        },
        {
          "tag": "v7.4.8",
          "kind": "patch",
          "published_at": "2026-03-31T21:11:23Z"
        },
        {
          "tag": "v8.0.6",
          "kind": "patch",
          "published_at": "2026-02-26T09:14:10Z"
        },
        {
          "tag": "v7.4.6",
          "kind": "patch",
          "published_at": "2026-02-26T08:42:02Z"
        },
        {
          "tag": "v6.4.34",
          "kind": "patch",
          "published_at": "2026-02-26T08:29:03Z"
        },
        {
          "tag": "v8.0.4",
          "kind": "patch",
          "published_at": "2026-01-25T08:31:06Z"
        },
        {
          "tag": "v7.4.4",
          "kind": "patch",
          "published_at": "2026-01-24T22:31:55Z"
        },
        {
          "tag": "v7.3.10",
          "kind": "patch",
          "published_at": "2026-01-24T22:04:14Z"
        },
        {
          "tag": "v8.0.3",
          "kind": "patch",
          "published_at": "2025-12-31T09:44:59Z"
        },
        {
          "tag": "v7.4.3",
          "kind": "patch",
          "published_at": "2025-12-31T09:13:53Z"
        },
        {
          "tag": "v7.3.9",
          "kind": "patch",
          "published_at": "2025-12-31T08:44:49Z"
        },
        {
          "tag": "v6.4.31",
          "kind": "patch",
          "published_at": "2025-12-31T08:35:33Z"
        },
        {
          "tag": "v8.0.1",
          "kind": "patch",
          "published_at": "2025-12-07T17:03:29Z"
        },
        {
          "tag": "v7.4.1",
          "kind": "patch",
          "published_at": "2025-12-07T16:51:24Z"
        },
        {
          "tag": "v7.3.8",
          "kind": "patch",
          "published_at": "2025-12-07T16:19:12Z"
        },
        {
          "tag": "v6.4.30",
          "kind": "patch",
          "published_at": "2025-12-07T16:03:29Z"
        },
        {
          "tag": "v7.4.0",
          "kind": "minor",
          "published_at": "2025-11-27T14:00:10Z"
        },
        {
          "tag": "v8.0.0-RC2",
          "kind": "prerelease",
          "published_at": "2025-11-16T17:46:51Z"
        },
        {
          "tag": "v7.4.0-RC2",
          "kind": "prerelease",
          "published_at": "2025-11-16T17:40:08Z"
        },
        {
          "tag": "v7.4.0-RC1",
          "kind": "prerelease",
          "published_at": "2025-11-13T12:54:10Z"
        },
        {
          "tag": "v7.3.5",
          "kind": "patch",
          "published_at": "2025-10-28T10:34:49Z"
        },
        {
          "tag": "v8.0.0-BETA1",
          "kind": "prerelease",
          "published_at": "2025-10-28T10:10:03Z"
        },
        {
          "tag": "v7.4.0-BETA1",
          "kind": "prerelease",
          "published_at": "2025-10-27T10:53:45Z"
        },
        {
          "tag": "v7.3.4",
          "kind": "patch",
          "published_at": "2025-09-27T12:38:53Z"
        },
        {
          "tag": "v6.4.26",
          "kind": "patch",
          "published_at": "2025-09-27T12:32:38Z"
        },
        {
          "tag": "v7.3.3",
          "kind": "patch",
          "published_at": "2025-08-29T08:29:38Z"
        },
        {
          "tag": "v6.4.25",
          "kind": "patch",
          "published_at": "2025-08-29T08:20:36Z"
        },
        {
          "tag": "v7.3.2",
          "kind": "patch",
          "published_at": "2025-07-31T10:56:58Z"
        },
        {
          "tag": "v7.2.9",
          "kind": "patch",
          "published_at": "2025-07-31T10:46:55Z"
        },
        {
          "tag": "v6.4.24",
          "kind": "patch",
          "published_at": "2025-07-31T09:38:59Z"
        },
        {
          "tag": "v7.3.1",
          "kind": "patch",
          "published_at": "2025-06-28T08:31:18Z"
        },
        {
          "tag": "v7.2.8",
          "kind": "patch",
          "published_at": "2025-06-28T08:25:17Z"
        },
        {
          "tag": "v6.4.23",
          "kind": "patch",
          "published_at": "2025-06-28T08:20:57Z"
        },
        {
          "tag": "v7.3.0",
          "kind": "minor",
          "published_at": "2025-05-29T07:54:25Z"
        },
        {
          "tag": "v7.2.7",
          "kind": "patch",
          "published_at": "2025-05-29T07:39:21Z"
        },
        {
          "tag": "v6.4.22",
          "kind": "patch",
          "published_at": "2025-05-29T07:35:17Z"
        },
        {
          "tag": "v7.3.0-RC1",
          "kind": "prerelease",
          "published_at": "2025-05-25T21:10:26Z"
        },
        {
          "tag": "v7.3.0-BETA2",
          "kind": "prerelease",
          "published_at": "2025-05-10T12:16:37Z"
        },
        {
          "tag": "v7.3.0-BETA1",
          "kind": "prerelease",
          "published_at": "2025-05-02T09:31:17Z"
        },
        {
          "tag": "v7.2.6",
          "kind": "patch",
          "published_at": "2025-05-02T09:14:53Z"
        },
        {
          "tag": "v6.4.21",
          "kind": "patch",
          "published_at": "2025-05-02T09:09:28Z"
        },
        {
          "tag": "v7.2.4",
          "kind": "patch",
          "published_at": "2025-02-26T11:07:14Z"
        },
        {
          "tag": "v6.4.19",
          "kind": "patch",
          "published_at": "2025-02-26T11:02:00Z"
        },
        {
          "tag": "v7.2.3",
          "kind": "patch",
          "published_at": "2025-01-29T07:47:36Z"
        },
        {
          "tag": "v7.1.11",
          "kind": "patch",
          "published_at": "2025-01-29T07:39:09Z"
        },
        {
          "tag": "v6.4.18",
          "kind": "patch",
          "published_at": "2025-01-29T07:34:04Z"
        },
        {
          "tag": "v7.1.10",
          "kind": "patch",
          "published_at": "2024-12-31T15:00:24Z"
        },
        {
          "tag": "v7.2.1",
          "kind": "patch",
          "published_at": "2024-12-11T12:16:26Z"
        },
        {
          "tag": "v7.2.0",
          "kind": "minor",
          "published_at": "2024-11-29T08:49:21Z"
        },
        {
          "tag": "v7.1.8",
          "kind": "patch",
          "published_at": "2024-11-13T14:53:12Z"
        },
        {
          "tag": "v6.4.15",
          "kind": "patch",
          "published_at": "2024-11-13T14:23:32Z"
        },
        {
          "tag": "v5.4.47",
          "kind": "patch",
          "published_at": "2024-11-13T13:55:19Z"
        },
        {
          "tag": "v7.2.0-BETA2",
          "kind": "prerelease",
          "published_at": "2024-11-06T10:06:03Z"
        },
        {
          "tag": "v7.1.7",
          "kind": "patch",
          "published_at": "2024-11-06T10:01:01Z"
        },
        {
          "tag": "v6.4.14",
          "kind": "patch",
          "published_at": "2024-11-06T09:55:16Z"
        },
        {
          "tag": "v5.4.46",
          "kind": "patch",
          "published_at": "2024-11-06T09:38:08Z"
        },
        {
          "tag": "v7.2.0-BETA1",
          "kind": "prerelease",
          "published_at": "2024-10-27T16:16:17Z"
        },
        {
          "tag": "v7.1.6",
          "kind": "patch",
          "published_at": "2024-10-27T15:21:52Z"
        },
        {
          "tag": "v6.4.13",
          "kind": "patch",
          "published_at": "2024-10-27T13:57:08Z"
        },
        {
          "tag": "v5.4.45",
          "kind": "patch",
          "published_at": "2024-10-27T13:02:11Z"
        },
        {
          "tag": "v7.1.5",
          "kind": "patch",
          "published_at": "2024-09-21T06:15:47Z"
        },
        {
          "tag": "v6.4.12",
          "kind": "patch",
          "published_at": "2024-09-21T06:09:25Z"
        },
        {
          "tag": "v5.4.44",
          "kind": "patch",
          "published_at": "2024-09-21T06:03:20Z"
        },
        {
          "tag": "v7.1.4",
          "kind": "patch",
          "published_at": "2024-08-30T17:07:41Z"
        },
        {
          "tag": "v6.4.11",
          "kind": "patch",
          "published_at": "2024-08-30T17:02:42Z"
        },
        {
          "tag": "v5.4.43",
          "kind": "patch",
          "published_at": "2024-08-30T16:57:53Z"
        },
        {
          "tag": "v7.1.3",
          "kind": "patch",
          "published_at": "2024-07-26T15:04:38Z"
        },
        {
          "tag": "v7.1.2",
          "kind": "patch",
          "published_at": "2024-06-28T13:22:48Z"
        },
        {
          "tag": "v7.0.9",
          "kind": "patch",
          "published_at": "2024-06-28T13:14:29Z"
        },
        {
          "tag": "v6.4.9",
          "kind": "patch",
          "published_at": "2024-06-28T11:54:03Z"
        },
        {
          "tag": "v5.4.41",
          "kind": "patch",
          "published_at": "2024-06-28T11:48:38Z"
        },
        {
          "tag": "v7.1.1",
          "kind": "patch",
          "published_at": "2024-06-04T07:37:22Z"
        },
        {
          "tag": "v7.0.8",
          "kind": "patch",
          "published_at": "2024-06-02T18:03:47Z"
        },
        {
          "tag": "v6.4.8",
          "kind": "patch",
          "published_at": "2024-06-02T17:04:03Z"
        },
        {
          "tag": "v5.4.40",
          "kind": "patch",
          "published_at": "2024-06-02T16:04:05Z"
        },
        {
          "tag": "v7.1.0",
          "kind": "minor",
          "published_at": "2024-05-31T08:22:38Z"
        },
        {
          "tag": "v7.1.0-RC1",
          "kind": "prerelease",
          "published_at": "2024-05-17T15:51:04Z"
        },
        {
          "tag": "v7.1.0-BETA1",
          "kind": "prerelease",
          "published_at": "2024-05-02T13:12:52Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "8a899d1a0ee80466911afbae5707a04e0ea65d12",
          "body": null,
          "is_bot": false,
          "headline": "Allow disabling redirect on logout",
          "author_name": "Jérôme Vasseur",
          "author_login": "jvasseur",
          "committed_at": "2026-07-09T13:09:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "096ea90476de2b8852392c3d7b185a7fc5126e85",
          "body": "* 8.1:\n  Bump the github-actions group across 1 directory with 2 updates\n  [Validator] Ukrainian translation update\n  [Validator] reviewed Polish translation unit 146\n  [FrameworkBundle] Fix false positives for _instanceof\n  [Validator] Remove needs-review-translation state from Spanish cron express\n[…]\nill\n  [Validator] Add translated messages for the Cron constraint\n  [Security] Fix PHPDoc of OidcTokenGenerateCommand::addGenerator\n  [Serializer] honor `csv_headers` context when `no_headers` is true",
          "is_bot": false,
          "headline": "Merge branch '8.1' into 8.2",
          "author_name": "Fabien Potencier",
          "author_login": "fabpot",
          "committed_at": "2026-06-27T06:18:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "93f5e8bd49489256e469384e5e408257e8dc3e25",
          "body": "* 8.0:\n  Bump the github-actions group across 1 directory with 2 updates\n  [Validator] Ukrainian translation update\n  [Validator] reviewed Polish translation unit 146\n  [FrameworkBundle] Fix false positives for _instanceof\n  [Validator] Remove needs-review-translation state from Spanish cron express\n[…]\nill\n  [Validator] Add translated messages for the Cron constraint\n  [Security] Fix PHPDoc of OidcTokenGenerateCommand::addGenerator\n  [Serializer] honor `csv_headers` context when `no_headers` is true",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Fabien Potencier",
          "author_login": "fabpot",
          "committed_at": "2026-06-27T06:18:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "982838736e0c0c25059d0dc90d21ca148337a060",
          "body": "* 7.4:\n  Bump the github-actions group across 1 directory with 2 updates\n  [Validator] Ukrainian translation update\n  [Validator] reviewed Polish translation unit 146\n  [FrameworkBundle] Fix false positives for _instanceof\n  [Validator] Remove needs-review-translation state from Spanish cron express\n[…]\nill\n  [Validator] Add translated messages for the Cron constraint\n  [Security] Fix PHPDoc of OidcTokenGenerateCommand::addGenerator\n  [Serializer] honor `csv_headers` context when `no_headers` is true",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Fabien Potencier",
          "author_login": "fabpot",
          "committed_at": "2026-06-27T06:17:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "148e038b91c8cc3e42aee177f8b0117437077c9b",
          "body": null,
          "is_bot": false,
          "headline": "[Security] Fix PHPDoc of OidcTokenGenerateCommand::addGenerator",
          "author_name": "Denys Finchenko",
          "author_login": "dfinchenko",
          "committed_at": "2026-06-19T08:40:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0063980871446676583b07250ddf00dd784cd724",
          "body": "* 8.1:\n  [ObjectMapper] Fix mapping of private properties from parent classes\n  CS fix\n  [ObjectMapper] Fix self-referencing property breaking mapping to readonly targets\n  update from Postgres 10 to 16\n  [ObjectMapper] Handle N targets per source in reverse class map\n  [SecurityBundle] Fix state le\n[…]\nvironments\n  [Form][Validator] Review Hungarian translations\n  Bump the github-actions group across 1 directory with 2 updates\n  [Serializer] Fix denormalization of already-instantiated nested objects",
          "is_bot": false,
          "headline": "Merge branch '8.1' into 8.2",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-16T16:09:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "363cbcec0b60dbb4ac186162d20dff3b2bbbe92e",
          "body": "* 8.0:\n  [ObjectMapper] Fix mapping of private properties from parent classes\n  update from Postgres 10 to 16\n  [SecurityBundle] Fix state leak in LogoutUrlGenerator in async environments\n  [Form][Validator] Review Hungarian translations\n  Bump the github-actions group across 1 directory with 2 upda\n[…]\nrializer] Fix denormalization of already-instantiated nested objects\n\n# Conflicts:\n#\tsrc/Symfony/Component/ObjectMapper/ObjectMapper.php\n#\tsrc/Symfony/Component/ObjectMapper/Tests/ObjectMapperTest.php",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-16T16:07:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "52293be0a1fcf488ef0857fc3bb4ee7e9f4f6220",
          "body": "* 7.4:\n  [ObjectMapper] Fix mapping of private properties from parent classes\n  update from Postgres 10 to 16\n  [SecurityBundle] Fix state leak in LogoutUrlGenerator in async environments\n  [Form][Validator] Review Hungarian translations\n  Bump the github-actions group across 1 directory with 2 updates\n  [Serializer] Fix denormalization of already-instantiated nested objects\n\n# Conflicts:\n#\tsrc/Symfony/Component/Serializer/Normalizer/AbstractObjectNormalizer.php",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-16T16:02:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "60187277833743cb258dcea876d1e19e5244c554",
          "body": "* 6.4:\n  update from Postgres 10 to 16\n  [SecurityBundle] Fix state leak in LogoutUrlGenerator in async environments\n  [Form][Validator] Review Hungarian translations\n  [Serializer] Fix denormalization of already-instantiated nested objects",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-16T15:54:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e107436c107892b1255c3364ec8ff46c141230d1",
          "body": null,
          "is_bot": false,
          "headline": "[SecurityHttp] Make OidcTokenHandler `allowedTimeDrift` configurable",
          "author_name": "jprivet-dev",
          "author_login": "jprivet-dev",
          "committed_at": "2026-06-16T12:43:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c6a3836e6c331503a841f439912939c4e1be480f",
          "body": "…nments",
          "is_bot": false,
          "headline": "[SecurityBundle] Fix state leak in LogoutUrlGenerator in async enviro…",
          "author_name": "Kevin MARTINS",
          "author_login": "KevinMartinsDev",
          "committed_at": "2026-06-16T12:40:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "312c2572476dfb415654dab63ac980a8f6d8e24a",
          "body": "* 8.0:\n  [Mime] Reject \\Stringable in DataPart::__unserialize()\n  [Lock][Form][FrameworkBundle][Mailer][HttpKernel] Harden remaining unserialize trampolines and webhook reject paths\n  Remove review state from Serbian translations\n  Harden __toString trampolines via __unserialize()\n  Remove needs-rev\n[…]\ntion/Bridge/Crowdin/Tests/CrowdinProviderTest.php\n#\tsrc/Symfony/Component/VarExporter/Instantiator.php\n#\tsrc/Symfony/Component/VarExporter/Internal/Exporter.php\n#\tsrc/Symfony/Component/Yaml/Inline.php",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-09T10:54:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6545a813eb53bc29317addfc27f9b83c95c681f1",
          "body": "* 7.4:\n  [Lock][Form][FrameworkBundle][Mailer][HttpKernel] Harden remaining unserialize trampolines and webhook reject paths\n  Remove review state from Serbian translations\n  Harden __toString trampolines via __unserialize()\n  Remove needs-review-translation flag for Russian validators\n  [VarExporte\n[…]\nileLoader.php\n#\tsrc/Symfony/Component/HttpKernel/Tests/DependencyInjection/RegisterControllerArgumentLocatorsPassTest.php\n#\tsrc/Symfony/Component/Security/Core/Authentication/Token/RememberMeToken.php",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-09T10:20:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ee57683f588a075a7a58eb60c80539557eb104ee",
          "body": "* 6.4:\n  Remove review state from Serbian translations\n  Harden __toString trampolines via __unserialize()\n  Remove needs-review-translation flag for Russian validators",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-09T07:51:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "143ad81ca4ea33fece065fa7ca46791f3cd38d90",
          "body": null,
          "is_bot": false,
          "headline": "Harden __toString trampolines via __unserialize()",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-09T07:36:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eaf9dd0e543862e35f235184bc47134dff99e836",
          "body": "* 6.4:\n  [VarExporter] Fix exporting objects that cannot be instantiated empty\n  [Translation] Create Crowdin files before uploading translations\n  [Form] reviewed Polish translation unit 129\n  [Validator] reviewed Polish translation units 143-145\n  Harden TemplatedEmail unserialize and enforce hard\n[…]\nony/Component/Intl/Transliterator/EmojiTransliterator.php\n#\tsrc/Symfony/Component/Translation/Bridge/Crowdin/Tests/CrowdinProviderTest.php\n#\tsrc/Symfony/Component/VarExporter/Tests/VarExporterTest.php",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-08T20:24:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "53b50d5600fa42da6b26fd32e65d99851814ccb1",
          "body": null,
          "is_bot": false,
          "headline": " Unsafe unserialize phpstan rule",
          "author_name": "Jack Worman",
          "author_login": "jack-worman",
          "committed_at": "2026-06-08T07:06:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5fb2de222df56c86a671cede0cf03d8c1d37892a",
          "body": "* 8.0:\n  Make tests compatible with PHPUnit 13.2 and Twig 3.28\n  Fix test\n  [Serializer] Keep collection value type for iterable constructor parameters\n  [AssetMapper] Render an empty import map as a JSON object\n  [Translation] Fix test failing without the intl extension\n  [Mailer] [Mailchimp] Fix tests on low-deps\n  [HttpFoundation] Add RFC6598 Shared Address Space to IpUtils::PRIVATE_SUBNETS\n  Fix Content-Type key in createRequest method",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-06T11:11:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "29c2c1224ab76252a76cdb81b0f80f846242b199",
          "body": "* 7.4:\n  Make tests compatible with PHPUnit 13.2 and Twig 3.28\n  Fix test\n  [Serializer] Keep collection value type for iterable constructor parameters\n  [AssetMapper] Render an empty import map as a JSON object\n  [Translation] Fix test failing without the intl extension\n  [Mailer] [Mailchimp] Fix tests on low-deps\n  [HttpFoundation] Add RFC6598 Shared Address Space to IpUtils::PRIVATE_SUBNETS\n  Fix Content-Type key in createRequest method",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-06T11:11:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4af76885fb0aceb42ed1d7a22fd105b88334769",
          "body": null,
          "is_bot": false,
          "headline": "Make tests compatible with PHPUnit 13.2 and Twig 3.28",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-06T11:10:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1e754937917ae4d9f46591536737036ac5369d6b",
          "body": "* 8.0:\n  Drop PR warning and auto-closing on subtree splits\n  Fix merge\n  [Validator] Support SVG dimensions with units\n  Remove review state from Serbian translations\n  [Translation] Copy domains metadata when moving messages to intl ones\n  [Form] Add missing translation for invalid UUID\n  fix(tran\n[…]\nlation messages\n  [Security][HttpKernel] Add allowed_classes => false to unserialize() in CacheWarmerAggregate, LoggerDataCollector, and HttpCache Store\n  Fix XMLHttpRequest URL handling in toolbar JS",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-05T06:23:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "414e7b5f0b3103d9ebba6403a149155e139447c4",
          "body": "* 7.4:\n  Drop PR warning and auto-closing on subtree splits\n  Fix merge\n  [Validator] Support SVG dimensions with units\n  Remove review state from Serbian translations\n  [Translation] Copy domains metadata when moving messages to intl ones\n  [Form] Add missing translation for invalid UUID\n  fix(tran\n[…]\nlation messages\n  [Security][HttpKernel] Add allowed_classes => false to unserialize() in CacheWarmerAggregate, LoggerDataCollector, and HttpCache Store\n  Fix XMLHttpRequest URL handling in toolbar JS",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-05T06:22:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "67f4b7feb6c188c607f64f7b0896d5c4e25aefb7",
          "body": "* 6.4:\n  Drop PR warning and auto-closing on subtree splits\n  Fix merge\n  Remove review state from Serbian translations\n  [Translation] Copy domains metadata when moving messages to intl ones\n  [Form] Add missing translation for invalid UUID\n  fix(translations): fix sr-Latn validation messages and v\n[…]\nlation messages\n  [Security][HttpKernel] Add allowed_classes => false to unserialize() in CacheWarmerAggregate, LoggerDataCollector, and HttpCache Store\n  Fix XMLHttpRequest URL handling in toolbar JS",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-05T06:22:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8c8ce8f284d34ed514def458e686e0d389bab4af",
          "body": null,
          "is_bot": false,
          "headline": "Drop PR warning and auto-closing on subtree splits",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-06-05T06:18:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0e6c7b9e80eec37248b92359cbd6938c7086f4b",
          "body": null,
          "is_bot": false,
          "headline": "Add call to backers in README files",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-29T05:06:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7e1ddefc15812654b1897a1676628dd6eb055194",
          "body": "* 8.0:\n  CS fix",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-25T06:14:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ca895c1303cc1d290f190cd7301d48fcef9e73e5",
          "body": "* 7.4:\n  CS fix",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-25T06:08:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "da3c28025a664e6a88e1af104a74457d99301161",
          "body": "* 6.4:\n  CS fix",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-25T06:06:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1a01cd7a6313d5a375480e0d1d4a0ddf834ae12b",
          "body": null,
          "is_bot": false,
          "headline": "CS fix",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-25T06:03:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b0af66c0a540fe5903307d00427e425fae19ff6c",
          "body": "* 8.0:\n  [Security] Don't honor user-supplied _failure_path on failure_forward\n  [Routing] Fix dot-segment encoding for chained \"../\" and \"./\" in generated URLs\n  [HtmlSanitizer] Sanitize URL attributes on <object>, <applet>, <iframe>, <img>, and the URL inside <meta http-equiv=\"refresh\"> content\n  \n[…]\n Pin Mailomat webhook signature algorithm to SHA-256\n  [HttpFoundation] Block IPv6 transition forms in IpUtils::PRIVATE_SUBNETS\n  [HttpClient] Block IPv6 transition forms in NoPrivateNetworkHttpClient",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-24T11:25:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b7e82065c74a23e786ef719c88bde6eaf50f5247",
          "body": "* 7.4:\n  [Security] Don't honor user-supplied _failure_path on failure_forward\n  [Routing] Fix dot-segment encoding for chained \"../\" and \"./\" in generated URLs\n  [HtmlSanitizer] Sanitize URL attributes on <object>, <applet>, <iframe>, <img>, and the URL inside <meta http-equiv=\"refresh\"> content\n  \n[…]\n Pin Mailomat webhook signature algorithm to SHA-256\n  [HttpFoundation] Block IPv6 transition forms in IpUtils::PRIVATE_SUBNETS\n  [HttpClient] Block IPv6 transition forms in NoPrivateNetworkHttpClient",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-24T11:21:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7ea7162bf81996e8e13e3b0621386e1550af2d29",
          "body": "* 6.4:\n  [Security] Don't honor user-supplied _failure_path on failure_forward\n  [Routing] Fix dot-segment encoding for chained \"../\" and \"./\" in generated URLs\n  [HtmlSanitizer] Sanitize URL attributes on <object>, <applet>, <iframe>, <img>, and the URL inside <meta http-equiv=\"refresh\"> content\n  \n[…]\nnt-encoded BiDi marks and Unicode whitespace in URLs\n  [HttpFoundation] Block IPv6 transition forms in IpUtils::PRIVATE_SUBNETS\n  [HttpClient] Block IPv6 transition forms in NoPrivateNetworkHttpClient",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-24T11:20:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b4acd832ca29fc851b14b813187aa6fee2f4c7ab",
          "body": "* 5.4:\n  [Security] Don't honor user-supplied _failure_path on failure_forward\n  [Routing] Fix dot-segment encoding for chained \"../\" and \"./\" in generated URLs\n  [HttpClient] Block IPv6 transition forms in NoPrivateNetworkHttpClient",
          "is_bot": false,
          "headline": "Merge branch '5.4' into 6.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-24T11:18:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "119cc48b2370db276ed5ab81ef0458943645bcf9",
          "body": null,
          "is_bot": false,
          "headline": "[Security] Don't honor user-supplied _failure_path on failure_forward",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-24T10:45:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "692c1ebc88698eccf911e3ddb652186c339e718e",
          "body": "* 8.0:\n  [HttpClient] ntlm regression on authPersistNonNTLM=false connections where reset no longer discards the connection.",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-23T20:26:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "05916f99c11b97bca38a8cf269aa564b3083a387",
          "body": "* 7.4:\n  [HttpClient] ntlm regression on authPersistNonNTLM=false connections where reset no longer discards the connection.",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-23T20:26:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5312b62b04c92c12186505ebdf7fbdcfb4a4da36",
          "body": "* 6.4:\n  [HttpClient] ntlm regression on authPersistNonNTLM=false connections where reset no longer discards the connection.",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-23T20:26:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9f36b71b756102f75e448a47623f3e84360bf59",
          "body": "* 8.0: (49 commits)\n  [Runtime][FrameworkBundle] Trust argv on CLI-like SAPIs in the remaining QUERY_STRING gates\n  Fix tests and merge resolution after merging 6.4 into 7.4\n  [FrameworkBundle] Allow to pass `doctrine_open_transaction_logger`’s entity manager name positionally\n  Remove protectedHead\n[…]\ntion/Loader/YamlFileLoader.php\n#\tsrc/Symfony/Component/HttpClient/CachingHttpClient.php\n#\tsrc/Symfony/Component/HttpClient/Tests/CachingHttpClientTest.php\n#\tsrc/Symfony/Component/HttpKernel/Kernel.php",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-23T18:18:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4b905040548e31e52bae5c39b32b1438b29bb5a3",
          "body": "* 7.4: (46 commits)\n  [Runtime][FrameworkBundle] Trust argv on CLI-like SAPIs in the remaining QUERY_STRING gates\n  Fix tests and merge resolution after merging 6.4 into 7.4\n  [FrameworkBundle] Allow to pass `doctrine_open_transaction_logger`’s entity manager name positionally\n  Remove protectedHead\n[…]\nLOG-8.0.md\n#\tsrc/Symfony/Component/HttpKernel/Kernel.php\n#\tsrc/Symfony/Component/Mime/Part/SMimePart.php\n#\tsrc/Symfony/Component/Mime/Part/TextPart.php\n#\tsrc/Symfony/Component/String/UnicodeString.php",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-23T18:05:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "860286065f54ab4bc6fa4faaddbca4ae8d4ee49e",
          "body": "* [Mime][Routing] Replace @dataProvider annotation with #[DataProvider] attribute\n* [FrameworkBundle] Move webhook request parsers cleanup to after mailer_webhook.php is loaded",
          "is_bot": false,
          "headline": "Fix tests and merge resolution after merging 6.4 into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-23T16:22:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1081160e05f58f9a8f9bb8fa67a2c00e26a16491",
          "body": "* 6.4:\n  [FrameworkBundle] Allow to pass `doctrine_open_transaction_logger`’s entity manager name positionally\n  [Scheduler] Recover pending RecurringMessages after consumer stops midway\n  [SecurityBundle] Fix Security::login() across firewalls\n  [Routing][RateLimiter][Mime][Security] Harden __unser\n[…]\nTests/Generator/MessageGeneratorTest.php\n#\tsrc/Symfony/Component/Security/Http/Tests/Firewall/ContextListenerTest.php\n#\tsrc/Symfony/Component/Translation/Bridge/Lokalise/Tests/LokaliseProviderTest.php",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-23T16:05:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4523a53e4cb33809d715d8dfa494ce22a0baaafe",
          "body": "protectedHeaderOnly is only used by HeaderCheckerManager not ClaimCheckerManager",
          "is_bot": false,
          "headline": "Remove protectedHeaderOnly from claim checkers",
          "author_name": "Samuel Weirich",
          "author_login": "samuelwei",
          "committed_at": "2026-05-23T15:30:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "20636d3115342cf3c94720aa3ab4c8517b03169f",
          "body": null,
          "is_bot": false,
          "headline": "[Security] Initialize lazy users before serializing them in the session",
          "author_name": "Mathieu",
          "author_login": "MatTheCat",
          "committed_at": "2026-05-23T14:34:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c60b7512cc5702513f9ab1cf244495843df02d3",
          "body": "* 8.0:\n  [Runtime] Fix CVE-2024-50340 patch bypass by gating argv on $_SERVER['QUERY_STRING']",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-20T09:18:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d776945b2dc41c0e609c56c1ef69863ab56856ed",
          "body": "* 7.4:\n  [Runtime] Fix CVE-2024-50340 patch bypass by gating argv on $_SERVER['QUERY_STRING']",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-20T07:22:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1fc7ca636cbd2cad29b42cc13c9fd0c681c6efee",
          "body": "* 6.4:\n  [Runtime] Fix CVE-2024-50340 patch bypass by gating argv on $_SERVER['QUERY_STRING']",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-20T07:20:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "816860d96c4fb7ffd7708ae0531ea6e5a1190773",
          "body": "* 5.4:\n  [Mailer] Add end-of-options separator before recipients in SendmailTransport; reject addresses starting with a dash\n  [Yaml] Harden the Parser::cleanup() regexes against catastrophic backtracking\n  [Yaml] Bound collection-alias resolution in the parser\n  [Yaml] Bound recursion depth in the \n[…]\negex to RDN boundary in X509Authenticator\n  [DomCrawler] Fix XXE in addXmlContent() by not enabling `validateOnParse`\n  [Routing] Fix regex alternation anchoring in UrlGenerator requirement validation",
          "is_bot": false,
          "headline": "Merge branch '5.4' into 6.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-19T20:33:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "897674df0d6245b05769fb595d5c6115cad2e8b2",
          "body": "…andler` (alexandre-daubois)\n\nThis PR was merged into the 6.4 branch.",
          "is_bot": false,
          "headline": "security #cve-2026-45069 [Security] Add missing claims in `OidcTokenH…",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-19T20:33:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "04e055ba57676852b6e341cb42b866a32817d4ae",
          "body": "* 8.0:\n  [Messenger] Fix PhpSerializer::getMessageType() when getting payload with Serializable instances\n  [MonologBridge] Fix `interactive_only` not preventing propagation\n  [DomCrawler] Fix `ChoiceFormField::addChoice()` clobbering values on multi-selects\n  [HttpKernel] Preserve named-attribute override on Request/Session value resolvers\n  [Security] Fix impersonation being deauthenticated on every request\n  Remove wrong documentation",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-19T20:01:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d70ddce220c72330bf768cd884da0296f77ea527",
          "body": "* 7.4:\n  [Messenger] Fix PhpSerializer::getMessageType() when getting payload with Serializable instances\n  [MonologBridge] Fix `interactive_only` not preventing propagation\n  [DomCrawler] Fix `ChoiceFormField::addChoice()` clobbering values on multi-selects\n  [HttpKernel] Preserve named-attribute override on Request/Session value resolvers\n  [Security] Fix impersonation being deauthenticated on every request\n  Remove wrong documentation",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-19T19:56:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "46a887c21940aed11edcd74f3c7efd2f8f5e1514",
          "body": null,
          "is_bot": false,
          "headline": "[Security] Various fixes and hardenings",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-19T15:48:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "626a6f32cf0497863b72c4a10fba3aa385e2cdfa",
          "body": "… when using CAS authentication (nicolas-grekas)\n\nThis PR was merged into the 7.4 branch.",
          "is_bot": false,
          "headline": "security #cve-2026-45074 [Security] Require configuring trusted hosts…",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-15T07:14:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2322d5aa6adb4c44600988e27555087448758e6a",
          "body": "…assing methods filter in `IsGranted`, `IsCsrfTokenValid` and `IsSignatureValid` attributes (nicolas-grekas)\n\nThis PR was merged into the 7.4 branch.",
          "is_bot": false,
          "headline": "security #cve-2026-45075 [Security][HttpKernel] Fix HEAD requests byp…",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-15T07:14:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e89d245e47016cb0f06d315d10a536f0a55e36db",
          "body": null,
          "is_bot": false,
          "headline": "[Security] Fix impersonation being deauthenticated on every request",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-15T06:48:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "67abea64ce64f2bc932dc522f2327a0c064d2b70",
          "body": "…ation",
          "is_bot": false,
          "headline": "[Security] Require configuring trusted hosts when using CAS authentic…",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-15T06:45:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bf09203388c5f86fd10f8d2bed891400c0d57349",
          "body": "* 8.0:\n  Allow defining security provider factories without config\n  [FrameworkBundle] Bump Request/Session value resolver priority above EntityValueResolver\n  [Messenger] Ensure SigningSerializer won't decode before verifying the signature\n  [Security] Remove the legacy nested unserialize() call fr\n[…]\n] Warn on missing bare CSS and JSON imports\n  When pushing, run GHA only on \"*.*\" branches\n  [Console] Fix signal handler scoping\n  [Security] Preserve webserver base URL in HttpUtils::createRequest()",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-13T12:23:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3c29d0118c6bc5919ce6f2ef4e9ead24503ca819",
          "body": "* 7.4:\n  Allow defining security provider factories without config\n  [FrameworkBundle] Bump Request/Session value resolver priority above EntityValueResolver\n  [Messenger] Ensure SigningSerializer won't decode before verifying the signature\n  [Security] Remove the legacy nested unserialize() call fr\n[…]\nection/XmlCustomProviderTest.php\n#\tsrc/Symfony/Component/Security/Core/Authentication/Token/RememberMeToken.php\n#\tsrc/Symfony/Component/Security/Core/Tests/Authentication/Token/RememberMeTokenTest.php",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-13T12:07:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2405335470a69e06e549fbb2bb78f96720d52fcc",
          "body": "* 6.4:\n  Allow defining security provider factories without config\n  [FrameworkBundle] Bump Request/Session value resolver priority above EntityValueResolver\n  [Security] Remove the legacy nested unserialize() call from token and exception classes\n  [Yaml] Reject non-stringables when using \"!!binary\n[…]\n] Warn on missing bare CSS and JSON imports\n  When pushing, run GHA only on \"*.*\" branches\n  [Console] Fix signal handler scoping\n  [Security] Preserve webserver base URL in HttpUtils::createRequest()",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-13T12:04:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fc64f2f7cf591db8821bf097e886255da6098a5a",
          "body": null,
          "is_bot": false,
          "headline": "[Security] Preserve webserver base URL in HttpUtils::createRequest()",
          "author_name": "Ousama Ben Younes",
          "author_login": "ousamabenyounes",
          "committed_at": "2026-05-12T06:36:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "57598d9bfbf5033febda6dc41f4e1ac4c07b4361",
          "body": "* 8.0:\n  [DependencyInjection] Relax tests\n  [Scheduler] Make debug:scheduler test independent of terminal width\n  [Messenger] Fix ErrorDetailsStampTest after dropping trace args from normalization\n  [Scheduler] Use stored checkpoint as base date for debug:scheduler\n  [Messenger] Drop trace args fro\n[…]\nG for 7.4.10\n\n# Conflicts:\n#\tsrc/Symfony/Component/HttpKernel/Kernel.php\n#\tsrc/Symfony/Component/Scheduler/Command/DebugCommand.php\n#\tsrc/Symfony/Component/Scheduler/Tests/Command/DebugCommandTest.php",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-11T13:20:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2125459087fd42e3878df3041a01334fc67a3ee1",
          "body": "* 7.4:\n  [DependencyInjection] Relax tests\n  [Scheduler] Make debug:scheduler test independent of terminal width\n  [Messenger] Fix ErrorDetailsStampTest after dropping trace args from normalization\n  [Scheduler] Use stored checkpoint as base date for debug:scheduler\n  [Messenger] Drop trace args fro\n[…]\nrs`\n  [Security] Clarify AbstractToken's role-name decoupling and simplify ContextListener\n  [Notifier] update Slack readme\n  [Dotenv] Don't truncate OS env vars containing $ when $_ENV is unpopulated",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-11T13:06:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "78a03cf62f41f5e5eacbad29425614696998c433",
          "body": "* 6.4:\n  [Scheduler] Make debug:scheduler test independent of terminal width\n  [Messenger] Fix ErrorDetailsStampTest after dropping trace args from normalization\n  [Scheduler] Use stored checkpoint as base date for debug:scheduler\n  [Messenger] Drop trace args from FlattenException normalization\n  [\n[…]\ntry to access `RawMessage::$headers`\n  [Security] Clarify AbstractToken's role-name decoupling and simplify ContextListener\n  [Dotenv] Don't truncate OS env vars containing $ when $_ENV is unpopulated",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-11T13:02:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ceb27a7151ea3b2c25c7f416940778d888b623f7",
          "body": "…ContextListener",
          "is_bot": false,
          "headline": "[Security] Clarify AbstractToken's role-name decoupling and simplify …",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-10T09:44:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f42cdeb2c9dac7f6a59011da943a84ad9a2897c0",
          "body": "…`IsGranted`, `IsCsrfTokenValid` and `IsSignatureValid` attributes",
          "is_bot": false,
          "headline": "[Security][HttpKernel] Fix HEAD requests bypassing methods filter in …",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-08T09:53:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4889312fd4c855735c3476d3998fb23221548cd5",
          "body": "* 8.0:\n  Fix low-deps\n  Fix up\n  [Cache] Ensure compatibility with Relay extension 0.22.0\n  [Yaml] fix flow collection drops `&anchor` and `!!str &anchor` items\n  Fix excludePaths in PHPStan config\n  [Security] Fix typos in method documentations\n  [Messenger] Move --time-limit handling to Worker for proper capping with --sleep\n  [Cache] Remove conflict with dbal<4.3\n  Fix inline attachment contentId for Azure Communication Services mailer",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-05T08:10:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "df93cd314e7ffe827645dbea93a3dfe58ae3ab77",
          "body": "* 7.4:\n  Fix low-deps\n  Fix up\n  [Cache] Ensure compatibility with Relay extension 0.22.0\n  [Yaml] fix flow collection drops `&anchor` and `!!str &anchor` items\n  Fix excludePaths in PHPStan config\n  [Security] Fix typos in method documentations\n  [Messenger] Move --time-limit handling to Worker for proper capping with --sleep\n  Fix inline attachment contentId for Azure Communication Services mailer",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-05T08:10:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fed59f72784e1fce5df0961ce7ed23f6e50f826c",
          "body": "* 6.4:\n  Fix up\n  [Cache] Ensure compatibility with Relay extension 0.22.0\n  [Yaml] fix flow collection drops `&anchor` and `!!str &anchor` items\n  Fix excludePaths in PHPStan config\n  [Security] Fix typos in method documentations\n  [Messenger] Move --time-limit handling to Worker for proper capping with --sleep",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-05T08:01:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9902fac434617310dd5feb6f90d1765e3864d249",
          "body": "…o prevent brute-force attacks (ayyoub-afwallah)\"\n\nThis reverts commit 692ecef8f554f464c1b4c23c842c9e5e11c47621, reversing\nchanges made to 965b0fcc19537fde044ba03b9ce4d36aec910fd0.",
          "is_bot": false,
          "headline": "Revert \"feature #64104 [Security] Add per-username login rate-limit t…",
          "author_name": "Wouter de Jong",
          "author_login": "wouterj",
          "committed_at": "2026-05-04T20:16:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d08c803184bc0696f3ed998c3c95d3145150802",
          "body": null,
          "is_bot": false,
          "headline": "[Security] Fix typos in method documentations",
          "author_name": "Matthias Schmidt",
          "author_login": "mttsch",
          "committed_at": "2026-05-04T18:23:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b1de103a0d84e4966c1f3d0648aa97ae843a615",
          "body": "…t brute-force attacks (ayyoub-afwallah)\n\nThis PR was merged into the 8.1 branch.\n\nDiscussion\n----------\n\n[Security] Add per-username login rate-limit to prevent brute-force attacks\n\n| Q             | A\n| ------------- | ---\n| Branch?       | 8.1\n| Bug fix?      | no\n| New feature?  | yes\n| Deprecat\n[…]\neLimiter as suggested in https://github.com/symfony/symfony/pull/63997#issuecomment-4341549421\n\nCommits\n-------\n\na84ec30c21a [Security] Add per-username login rate-limit to prevent brute-force attacks",
          "is_bot": false,
          "headline": "feature #64104 [Security] Add per-username login rate-limit to preven…",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-04T15:40:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bd42ec6578b84078f9af6118435e604a0665061f",
          "body": "…ttacks",
          "is_bot": false,
          "headline": "[Security] Add per-username login rate-limit to prevent brute-force a…",
          "author_name": "Ayyoub AFW-ALLAH",
          "author_login": "ayyoub-afwallah",
          "committed_at": "2026-05-04T15:40:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "650815fc5c2a9c8a16c96de97ba48c307251e44f",
          "body": "* 8.0:\n  [AssetMapper] Stop baking CSP nonce into the importmap polyfill body\n  [Translation] URL-encode tmp path in XliffUtils::shouldEnableEntityLoader\n  [RateLimiter] Carry over reserved tokens past fixed window resets\n  [Security] Document that AbstractLoginFormAuthenticator::getLoginUrl() must \n[…]\nny version to 7.4.10\n  Update VERSION for 7.4.9\n  Update CHANGELOG for 7.4.9\n  Bump Symfony version to 6.4.38\n  Update VERSION for 6.4.37\n  Update CONTRIBUTORS for 6.4.37\n  Update CHANGELOG for 6.4.37",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-04T13:43:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ef95e76da50c6af01894c15268864e65dcd540e3",
          "body": "* 7.4:\n  [AssetMapper] Stop baking CSP nonce into the importmap polyfill body\n  [Translation] URL-encode tmp path in XliffUtils::shouldEnableEntityLoader\n  [RateLimiter] Carry over reserved tokens past fixed window resets\n  [Security] Document that AbstractLoginFormAuthenticator::getLoginUrl() must \n[…]\nny version to 7.4.10\n  Update VERSION for 7.4.9\n  Update CHANGELOG for 7.4.9\n  Bump Symfony version to 6.4.38\n  Update VERSION for 6.4.37\n  Update CONTRIBUTORS for 6.4.37\n  Update CHANGELOG for 6.4.37",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-04T13:41:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "10ca6afdc347ae771b5f7baea68f655666fe9b0e",
          "body": "* 6.4:\n  [Translation] URL-encode tmp path in XliffUtils::shouldEnableEntityLoader\n  [RateLimiter] Carry over reserved tokens past fixed window resets\n  [Security] Document that AbstractLoginFormAuthenticator::getLoginUrl() must return a path\n  [Ldap] Cast default network_timeout to int\n  Bump Symfony version to 6.4.38\n  Update VERSION for 6.4.37\n  Update CONTRIBUTORS for 6.4.37\n  Update CHANGELOG for 6.4.37",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-05-04T13:25:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a87eafe04970a043988bb7a37b3463d643bc9569",
          "body": "…) must return a path",
          "is_bot": false,
          "headline": "[Security] Document that AbstractLoginFormAuthenticator::getLoginUrl(…",
          "author_name": "Ousama Ben Younes",
          "author_login": "ousamabenyounes",
          "committed_at": "2026-05-04T12:02:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "de300e6942fe0a23e822338e9e6dfd23f28f8380",
          "body": null,
          "is_bot": false,
          "headline": "[HttpKernel][Security] Type-check evaluated attribute keys",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-30T06:57:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f139d56a79a23169247210bb073ef7cef527fda",
          "body": "* 8.0: (24 commits)\n  [Validator] Drop PHP < 8.4 compat in PropertyMetadata\n  [Form] Preserve collection children added by PRE_SET_DATA listeners\n  [Messenger] Keep deduplication lock when handler throws\n  [Mailer][Postmark] Handle alternate error payload shapes for Payload Too Large\n  CS fix\n  [Ser\n[…]\nests/ObjectMapperTest.php\n#\tsrc/Symfony/Component/Security/Http/Tests/EventListener/IsCsrfTokenValidAttributeListenerTest.php\n#\tsrc/Symfony/Component/Serializer/Normalizer/AbstractObjectNormalizer.php",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-29T15:16:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "51fff88fc8436e42b4d92cae005f86b9233e0f88",
          "body": "* 7.4: (23 commits)\n  [Form] Preserve collection children added by PRE_SET_DATA listeners\n  [Messenger] Keep deduplication lock when handler throws\n  [Mailer][Postmark] Handle alternate error payload shapes for Payload Too Large\n  CS fix\n  [Serializer] Catch TypeError when setting an attribute to co\n[…]\nt/Serializer/Tests/Normalizer/AbstractObjectNormalizerTest.php\n#\tsrc/Symfony/Component/Serializer/Tests/Normalizer/PropertyNormalizerTest.php\n#\tsrc/Symfony/Component/TypeInfo/Tests/TypeFactoryTest.php",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-29T15:02:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a34991b13899de1f953df245395aa2196f9bc113",
          "body": null,
          "is_bot": false,
          "headline": "[7.4] Remove usages of named arguments in tests",
          "author_name": "Robin Chalas",
          "author_login": "chalasr",
          "committed_at": "2026-04-22T15:21:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a185c705f887be995bb11425311e8889c86b9c0",
          "body": null,
          "is_bot": false,
          "headline": "[6.4] Remove usages of named arguments in tests",
          "author_name": "Robin Chalas",
          "author_login": "chalasr",
          "committed_at": "2026-04-20T13:36:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "61b2cdae84864e56bc126e39d45299f3b00c061d",
          "body": "* 8.0:\n  [Security] Throw BadCredentialsException on empty JSON login username/password\n  [Routing] Honor the Request's method in UrlMatcher::matchRequest()\n  [DependencyInjection] Log every build parameter removed during compilation\n  [Serializer] Remove @internal from ClassMetadataInterface and At\n[…]\nake `BackedEnumNormalizer` unconditionally return `null` on invalid value if `allow_invalid_values` is set\n  [Cache] Ensure internal state is cleared in TagAwareAdapter::reset() even on commit failure",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-18T13:52:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ffdf31650eb2b41482d66aca91a31f5f647e1cd3",
          "body": "* 7.4:\n  [Security] Throw BadCredentialsException on empty JSON login username/password\n  [Routing] Honor the Request's method in UrlMatcher::matchRequest()\n  [DependencyInjection] Log every build parameter removed during compilation\n  [Serializer] Remove @internal from ClassMetadataInterface and At\n[…]\nake `BackedEnumNormalizer` unconditionally return `null` on invalid value if `allow_invalid_values` is set\n  [Cache] Ensure internal state is cleared in TagAwareAdapter::reset() even on commit failure",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-18T13:51:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5b1110405842622429e92d2c290fe6f9fc6e728f",
          "body": "…in username/password (ousamabenyounes)\n\nThis PR was merged into the 7.4 branch.\n\nDiscussion\n----------\n\n[Security] Throw BadCredentialsException on empty JSON login username/password\n\n| Q             | A\n| ------------- | ---\n| Branch?       | 7.4\n| Bug fix?      | yes\n| New feature?  | no\n| Deprec\n[…]\nt 11) that all 4 empty/non-string data rows fail on `7.4` before the fix and pass after it.\n\nCommits\n-------\n\ndce79918841 [Security] Throw BadCredentialsException on empty JSON login username/password",
          "is_bot": false,
          "headline": "bug #63983 [Security] Throw BadCredentialsException on empty JSON log…",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-18T13:50:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a43db022814bd5bd6ecf52e3336ab4118ad894f3",
          "body": "…/password",
          "is_bot": false,
          "headline": "[Security] Throw BadCredentialsException on empty JSON login username…",
          "author_name": "Ousama Ben Younes",
          "author_login": "ousamabenyounes",
          "committed_at": "2026-04-18T13:49:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "63e0e4bb91ef4d1a95eb63b31c1bb0cead53bdd9",
          "body": null,
          "is_bot": false,
          "headline": "Update XSD references in phpunit.xml.dist files",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-18T13:18:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "355f32f4318c962842f016eabd0966fde739f6fc",
          "body": "…ator",
          "is_bot": false,
          "headline": "[Security] Anchor emailAddress regex to RDN boundary in X509Authentic…",
          "author_name": "Alexandre Daubois",
          "author_login": "alexandre-daubois",
          "committed_at": "2026-04-17T13:15:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ded4747bc69d692364c0e561530c7d40654ccd9",
          "body": null,
          "is_bot": false,
          "headline": "[Security] Add missing claims in `OidcTokenHandler`",
          "author_name": "Alexandre Daubois",
          "author_login": "alexandre-daubois",
          "committed_at": "2026-04-17T13:11:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8121e9d7817bac8bccbdf34d4d7f838c6c995ad1",
          "body": "* 8.0:\n  [Tests] Fix \"Incomplete version\" PHPUnit warnings\n  chore: Component/String/Resources/data - cleanup header",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-17T05:56:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2749f880dbfbc7c6c7b0b7f3da8c7f2dfc610710",
          "body": "* 7.4:\n  [Tests] Fix \"Incomplete version\" PHPUnit warnings\n  chore: Component/String/Resources/data - cleanup header",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-17T05:56:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5835d0d3f023bce509f56a8a2c5d3a2157cd3eb2",
          "body": null,
          "is_bot": false,
          "headline": "[Tests] Fix \"Incomplete version\" PHPUnit warnings",
          "author_name": "hubert.lenoir",
          "author_login": "Jean-Beru",
          "committed_at": "2026-04-17T05:48:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e8fa5faf8cc28e417fe0ed93ab76daf4534047cc",
          "body": "* 7.4:\n  CS fixes\n  Fix merge\n  More CS fixes",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-13T15:47:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2e151652e4b18e744f6bb0fa54624e003bfc3e82",
          "body": null,
          "is_bot": false,
          "headline": "CS fixes",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-13T15:40:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3913e78fb442d7106dfb68688fa4e9bf753012ab",
          "body": "* 6.4:\n  More CS fixes",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-13T15:32:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0ae423be0cb800fe41214ee5a1e054e5766e0138",
          "body": null,
          "is_bot": false,
          "headline": "More CS fixes",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-13T15:27:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "72b620c2e4799505fa72e4fad8ec70894325bf61",
          "body": "* 7.4:\n  Fix merge",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-13T14:49:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6ced1f456f94688aa586b65ba40c3f4376fbda8",
          "body": "* 7.4:\n  CS fixes - native_function_invocation & static_lambda\n  Backport some CS fixes from 7.4\n  [CS] Back config from 8.1 and apply heredoc_indentation rule\n  [Workflow] Fix HTML escaping in GraphvizDumper labels",
          "is_bot": false,
          "headline": "Merge branch '7.4' into 8.0",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-13T14:34:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "128043f0cd7260c77bbdc34196b9866874f121bb",
          "body": "* 6.4:\n  CS fixes - native_function_invocation & static_lambda\n  Backport some CS fixes from 7.4",
          "is_bot": false,
          "headline": "Merge branch '6.4' into 7.4",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-13T14:28:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f31612626f8e3eb779a0182e2aab141d8b25a146",
          "body": null,
          "is_bot": false,
          "headline": "CS fixes - native_function_invocation & static_lambda",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-13T14:11:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6ce45ef6ebbd7be845edf57e78b1fcdf900718fb",
          "body": null,
          "is_bot": false,
          "headline": "Bump to php >= 8.4.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-07T06:26:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b693cfa2657b7e2881699d27591db72108791627",
          "body": "* 8.0:\n  Add deprecationTrigger ignoreUndefinedTriggers=\"true\" in phpunit.xml.dist files",
          "is_bot": false,
          "headline": "Merge branch '8.0' into 8.1",
          "author_name": "Nicolas Grekas",
          "author_login": "nicolas-grekas",
          "committed_at": "2026-04-06T11:11:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 100,
      "commits_last_year": 224,
      "latest_release_at": "2026-06-27T09:30:56Z",
      "latest_release_tag": "v8.1.1",
      "releases_from_tags": false,
      "days_since_last_push": 13,
      "active_weeks_last_year": 44,
      "days_since_latest_release": 25,
      "mean_days_between_releases": 3.4
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 75,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "symfony/security-http",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "packagist",
          "matches_repo": true,
          "registry_url": "https://packagist.org/packages/symfony/security-http",
          "is_deprecated": false,
          "latest_version": "v8.1.1",
          "repository_url": "https://github.com/symfony/security-http",
          "versions_count": 646,
          "total_downloads": 180222688,
          "dependents_count": 235,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 4297376,
          "first_published_at": null,
          "latest_published_at": "2026-06-27T06:18:14Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 25
        }
      ]
    },
    "popularity": {
      "forks": 22,
      "stars": 1702,
      "watchers": 7,
      "fork_history": {
        "days": [
          {
            "date": "2015-06-07",
            "count": 1
          },
          {
            "date": "2015-10-07",
            "count": 1
          },
          {
            "date": "2018-08-03",
            "count": 1
          },
          {
            "date": "2019-03-15",
            "count": 1
          },
          {
            "date": "2019-05-07",
            "count": 1
          },
          {
            "date": "2019-06-21",
            "count": 1
          },
          {
            "date": "2020-03-12",
            "count": 1
          },
          {
            "date": "2021-06-24",
            "count": 1
          },
          {
            "date": "2021-09-04",
            "count": 1
          },
          {
            "date": "2022-03-25",
            "count": 1
          },
          {
            "date": "2022-05-12",
            "count": 1
          },
          {
            "date": "2022-12-25",
            "count": 1
          },
          {
            "date": "2023-02-02",
            "count": 1
          },
          {
            "date": "2023-10-24",
            "count": 1
          },
          {
            "date": "2024-02-10",
            "count": 1
          },
          {
            "date": "2024-04-11",
            "count": 1
          },
          {
            "date": "2024-07-29",
            "count": 1
          },
          {
            "date": "2025-06-01",
            "count": 1
          },
          {
            "date": "2025-08-20",
            "count": 1
          },
          {
            "date": "2026-02-13",
            "count": 1
          },
          {
            "date": "2026-06-22",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 21,
        "total_forks": 22
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": 27253,
      "source_files_sampled": 201,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "composer.json"
      ],
      "advisories": {
        "error": "No resolved dependencies carried a version and a supported ecosystem",
        "scope": "repository_graph",
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 19,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "packagist"
      ],
      "dependencies": [
        {
          "name": "symfony/deprecation-contracts",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^2.5|^3"
        },
        {
          "name": "symfony/http-foundation",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^7.4|^8.0"
        },
        {
          "name": "symfony/http-kernel",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^8.1"
        },
        {
          "name": "symfony/polyfill-mbstring",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^1.0"
        },
        {
          "name": "symfony/property-access",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^7.4|^8.0"
        },
        {
          "name": "symfony/security-core",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^7.4|^8.0"
        },
        {
          "name": "symfony/service-contracts",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^2.5|^3"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "symfony/deprecation-contracts",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/http-foundation",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/http-kernel",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/polyfill-mbstring",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/property-access",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/security-core",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/service-contracts",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "php",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "psr/log",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/cache",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/clock",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/expression-language",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/http-client",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/http-client-contracts",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/rate-limiter",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/routing",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/security-csrf",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/translation",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "web-token/jwt-library",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 19,
        "direct_count": 7,
        "indirect_count": 12
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 2,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "nicolas-grekas",
          "commits": 970,
          "avatar_url": "https://avatars.githubusercontent.com/u/243674?v=4"
        },
        {
          "type": "User",
          "login": "fabpot",
          "commits": 578,
          "avatar_url": "https://avatars.githubusercontent.com/u/47313?v=4"
        },
        {
          "type": "User",
          "login": "xabbuh",
          "commits": 201,
          "avatar_url": "https://avatars.githubusercontent.com/u/1957048?v=4"
        },
        {
          "type": "User",
          "login": "chalasr",
          "commits": 110,
          "avatar_url": "https://avatars.githubusercontent.com/u/7502063?v=4"
        },
        {
          "type": "User",
          "login": "derrabus",
          "commits": 105,
          "avatar_url": "https://avatars.githubusercontent.com/u/1506493?v=4"
        },
        {
          "type": "User",
          "login": "wouterj",
          "commits": 104,
          "avatar_url": "https://avatars.githubusercontent.com/u/749025?v=4"
        },
        {
          "type": "User",
          "login": "Tobion",
          "commits": 26,
          "avatar_url": "https://avatars.githubusercontent.com/u/610090?v=4"
        },
        {
          "type": "User",
          "login": "alexandre-daubois",
          "commits": 23,
          "avatar_url": "https://avatars.githubusercontent.com/u/2144837?v=4"
        },
        {
          "type": "User",
          "login": "jderusse",
          "commits": 23,
          "avatar_url": "https://avatars.githubusercontent.com/u/578547?v=4"
        },
        {
          "type": "User",
          "login": "keradus",
          "commits": 16,
          "avatar_url": "https://avatars.githubusercontent.com/u/2716794?v=4"
        }
      ],
      "contributors_sampled": 100,
      "top_contributor_share": 0.397
    },
    "quality_signals": {
      "has_ci": false,
      "has_tests": true,
      "ci_workflows": [],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 103 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": null,
            "reason": "no workflows found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": null,
            "reason": "no dependencies found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": null,
            "reason": "No tokens found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "8a899d1a0ee80466911afbae5707a04e0ea65d12",
        "ran_at": "2026-07-22T17:56:47Z",
        "aggregate_score": 4.8,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": null,
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": null,
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/symfony/security-http",
    "host": "github.com",
    "name": "security-http",
    "owner": "symfony"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 65,
      "inputs": {
        "security": 48,
        "vitality": 92,
        "community": 81,
        "governance": 59,
        "engineering": 44
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 92,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 87,
            "inputs": {
              "commits_last_year": 224,
              "human_commit_share": 1,
              "days_since_last_push": 13,
              "active_weeks_last_year": 44
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 13 days ago",
                "points": 28.8,
                "status": "partial",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 13
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "44/52 weeks with commits",
                "points": 30.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 44
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "224 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 224
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 100,
              "latest_release_tag": "v8.1.1",
              "releases_from_tags": false,
              "days_since_latest_release": 25,
              "mean_days_between_releases": 3.4
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "100 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 100
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 25 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 25
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~3.4 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 3.4
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 13,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 13 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 13
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "good",
        "name": "Community & Adoption",
        "value": 81,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "forks": 22,
              "stars": 1702,
              "watchers": 7,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1,702 stars",
                "points": 52.4,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1702
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "22 forks",
                "points": 11,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 22
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "7 watchers",
                "points": 4.3,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "excellent",
            "name": "Ecosystem adoption (downloads)",
            "note": null,
            "notes": [],
            "value": 96,
            "inputs": {
              "packages": [
                "symfony/security-http"
              ],
              "dependents": 235,
              "ecosystems": "packagist",
              "total_downloads": 180222688,
              "monthly_downloads": 4297376
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "4,297,376 downloads/month across packagist",
                "points": 80,
                "status": "met",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 4297376,
                      "ecosystems": "packagist"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "235 packages depend on it",
                "points": 15.8,
                "status": "partial",
                "details": [
                  {
                    "code": "registry_dependents",
                    "params": {
                      "count": 235
                    }
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 59,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "moderate",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 62,
            "inputs": {
              "bus_factor": 2,
              "contributors_sampled": 100,
              "top_contributor_share": 0.397
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "2 contributor(s) cover half of all commits",
                "points": 25.2,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 40% of commits",
                "points": 13.6,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 40
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "100 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 100
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 103 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution",
                    "pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 79,
            "inputs": {
              "followers": 2169,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "symfony",
              "public_repos": 414,
              "account_age_days": 6115
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "2,169 followers of symfony",
                "points": 24,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 2169,
                      "login": "symfony"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "414 public repos, account ~16 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 414
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 16
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "symfony/security-http"
              ],
              "ecosystems": "packagist",
              "any_deprecated": false,
              "min_days_since_publish": 25
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on packagist",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "packagist"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 25 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 25
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "646 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 646
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "at_risk",
        "name": "Engineering Quality",
        "value": 44,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 30,
            "inputs": {
              "has_ci": false,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [
                "php",
                "symfony",
                "component",
                "symfony-component"
              ],
              "has_wiki": false,
              "homepage": "https://symfony.com/security",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://symfony.com/security",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "4 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 48,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Dangerous-Workflow, Packaging, Pinned-Dependencies, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "dangerous_workflow",
                    "packaging",
                    "pinned_dependencies",
                    "signed_releases",
                    "token_permissions"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 48,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 12,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 6,
              "scorecard_aggregate": 4.8
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 103 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no workflows found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "No tokens found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 31
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "at_risk",
        "name": "AI Readiness",
        "value": 32,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 32,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.6,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "60 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 32,
                "status": "partial",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 60,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "critical",
            "name": "Verify loop (build / test / typecheck)",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Pinned-Dependencies. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_pinned_dependencies"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 24,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "primary_language": "PHP",
              "largest_source_bytes": 27253,
              "source_files_sampled": 201,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "PHP without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "PHP"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/201 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 201,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "No resolved dependencies carried a version and a supported ecosystem"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-22T17:57:04.422694Z",
  "schema_version": "0.26.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/s/symfony/security-http.svg",
  "full_name": "symfony/security-http",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Las puntuaciones son señales, no garantías. Reflejan prácticas públicamente visibles en GitHub; no son una auditoría de código ni una garantía de seguridad.

Los datos ausentes se excluyen y los pesos se renormalizan; nunca se puntúan como cero. La metodología es versionada y abierta: métricas v1.13.0, esquema v0.26.0 — metodología completa · wiki de métricas.

Cómo se sitúa un resultado dentro del registro general: estadísticas agregadasPackagist.