Skip to content

Bump symfony/security-bundle from 7.2.9 to 7.3.3#200

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/composer/symfony/security-bundle-7.3.3
Closed

Bump symfony/security-bundle from 7.2.9 to 7.3.3#200
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/composer/symfony/security-bundle-7.3.3

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Sep 15, 2025

Bumps symfony/security-bundle from 7.2.9 to 7.3.3.

Release notes

Sourced from symfony/security-bundle's releases.

v7.3.3

Changelog (symfony/security-bundle@v7.3.2...v7.3.3)

  • no significant changes

v7.3.2

Changelog (symfony/security-bundle@v7.3.1...v7.3.2)

v7.3.1

Changelog (symfony/security-bundle@v7.3.0...v7.3.1)

  • no significant changes

v7.3.0

Changelog (symfony/security-bundle@v7.3.0-RC1...v7.3.0)

  • no significant changes

v7.3.0-RC1

Changelog (symfony/security-bundle@v7.3.0-BETA2...v7.3.0-RC1)

v7.3.0-BETA2

Changelog (symfony/security-bundle@v7.3.0-BETA1...v7.3.0-BETA2)

v7.3.0-BETA1

Changelog (symfony/security-bundle@v7.2.6...v7.3.0-BETA1)

Changelog

Sourced from symfony/security-bundle's changelog.

CHANGELOG

7.3

  • Add Security::isGrantedForUser() to test user authorization without relying on the session. For example, users not currently logged in, or while processing a message from a message queue
  • Add encryption support to OidcTokenHandler (JWE)
  • Add expose_security_errors config option to display AccountStatusException
  • Deprecate the security.hide_user_not_found config option in favor of security.expose_security_errors
  • Add ability to fetch LDAP roles
  • Add OAuth2TokenHandlerFactory for AccessTokenFactory
  • Add discovery support to OidcTokenHandler and OidcUserInfoTokenHandler

7.2

  • Allow configuring the secret used to sign login links
  • Allow passing optional passport attributes to Security::login()

7.1

  • Mark class ExpressionCacheWarmer as final
  • Support multiple signature algorithms for OIDC Token
  • Support JWK or JWKSet for OIDC Token

7.0

  • Enabling SecurityBundle and not configuring it is not allowed
  • Remove the enable_authenticator_manager config option
  • Remove the security.firewalls.logout.csrf_token_generator config option, use security.firewalls.logout.csrf_token_manager instead
  • Remove the require_previous_session config option from authenticators

6.4

  • Deprecate Security::ACCESS_DENIED_ERROR, AUTHENTICATION_ERROR and LAST_USERNAME constants, use the ones on SecurityRequestAttributes instead
  • Allow an array of pattern in firewall configuration
  • Add $badges argument to Security::login
  • Deprecate the require_previous_session config option. Setting it has no effect anymore
  • Add LogoutRouteLoader

6.3

  • Deprecate enabling bundle and not configuring it
  • Add _stateless attribute to the request when firewall is stateless and the attribute is not already set
  • Add StatelessAuthenticatorFactoryInterface for authenticators targeting stateless firewalls only and that don't require a user provider

... (truncated)

Commits
  • fbecca9 Merge branch '6.4' into 7.3
  • 9780abd [SecurityBundle] Add tests for debug:firewall command
  • d8278a9 Merge branch '7.2' into 7.3
  • 034665e Merge branch '7.2' into 7.3
  • 428a281 Merge branch '7.2' into 7.3
  • 9a208c6 Merge branch '7.2' into 7.3
  • 61e7433 minor #60425 [SecurityBundle] forbid to use hide_user_not_found and `expose...
  • 5630fb2 Merge branch '7.2' into 7.3
  • 6f53315 forbid to use "hide_user_not_found" and "expose_security_errors" at the same ...
  • 7fff19a normalize string values to a single ExposeSecurityLevel instance
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [symfony/security-bundle](https://github.com/symfony/security-bundle) from 7.2.9 to 7.3.3.
- [Release notes](https://github.com/symfony/security-bundle/releases)
- [Changelog](https://github.com/symfony/security-bundle/blob/7.3/CHANGELOG.md)
- [Commits](symfony/security-bundle@v7.2.9...v7.3.3)

---
updated-dependencies:
- dependency-name: symfony/security-bundle
  dependency-version: 7.3.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update php code labels Sep 15, 2025
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Sep 29, 2025

Superseded by #204.

@dependabot dependabot Bot closed this Sep 29, 2025
@dependabot dependabot Bot deleted the dependabot/composer/symfony/security-bundle-7.3.3 branch September 29, 2025 02:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants