Skip to content
CAI
Software that uses CAICheck a score

laravel/framework

58.3

Adequate · 22 September 2026

239.7k

lines of production code

PHP

primary language

3

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the core framework of the Laravel PHP ecosystem, providing a comprehensive suite of components for building web applications. It manages application structure through a service container, handles HTTP requests via routing and middleware, and facilitates data persistence with a robust database abstraction and Eloquent ORM. The framework also includes built-in tools for authentication, authorization, caching, queuing, and background job processing to streamline common development tasks.

How it got here

2013 — Laravel 13 modernization and refactoring

64 changes.

This period focused on a comprehensive overhaul of the Laravel framework to target PHP 8.3 and Symfony 7/8, replacing legacy components like SwiftMailer and Bootstrap views with modern equivalents such as Symfony Mailer and Tailwind CSS. It involved significant architectural shifts, including the introduction of attribute-driven service bindings, a compiled route collection for performance, and a complete rewrite of the database, queue, and session systems to support advanced concurrency, locking, and transactional integrity. The work also standardized codebases across all components, removed deprecated legacy classes, and expanded testing coverage to ensure stability for the new version.

2014–2015 — Contract layer standardization and scaffolding expansion

65 changes.

This period focused on establishing a comprehensive contract layer across the framework, introducing formal interfaces for core components like the container, queue, mail, and routing to improve decoupling and testability. It also significantly expanded the scaffolding ecosystem by adding modern PHP stubs for commands, controllers, and middleware, alongside new testing traits and middleware for authentication and request handling.

2016–2021 — Component extraction and API modernization

67 changes.

This period focused on decoupling the framework into standalone packages, notably extracting Collections, Conditionable, and Testing into independent components. It simultaneously modernized the API surface by introducing PHP attributes, fluent builders, and dedicated traits for Eloquent, Notifications, and HTTP clients to improve type safety and developer experience.

2022–2026 — Laravel 11 modernization and new components

50 changes.

This period focused on modernizing the framework through extensive adoption of PHP 8 attributes for configuration and dependency injection, alongside a comprehensive overhaul of the application bootstrapping and exception rendering systems. It also introduced several new first-party components, including dedicated Process, Concurrency, Image, and JSON Schema handling, while expanding support for modern standards like JSON:API and Mercure.

Features

Add GateEvaluated event to expose authorization check results

A new \GateEvaluated\ event class has been added to the \Illuminate\\Auth\\Access\\Events\ namespace. This event is dispatched after a gate authorization check, allowing applications to listen for and react to the outcome of ability evaluations. The event instance exposes the authenticated user, the ability name, the boolean result of the check, and any arguments passed during the evaluation, enabling features like audit logging or custom access-control logic based on specific authorization outcomes.

src/Illuminate/Auth/Access/Events · high confidence

Add MariaDB query grammar and refactor database grammars to PSR-12

This change introduces a new MariaDbGrammar class that extends MySqlGrammar, adding support for MariaDB-specific features such as lateral join rejection, JSON value casting via json\_query, thread count inspection, and vector distance calculations using vec\_distance\_cosine. Additionally, the database query grammars (Grammar, MySqlGrammar, PostgresGrammar, SQLiteGrammar, SqlServerGrammar) have been refactored to follow PSR-12 coding standards, including namespace declarations, strict typing, and modern PHP syntax, while preserving existing functionality for MySQL timeouts, full-text search, JSON handling, and date/time comparisons.

src/Illuminate/Database/Query/Grammars · high confidence

Add MathException class

A new MathException class has been added to the Illuminate Support Exceptions namespace, extending RuntimeException to serve as a base exception for mathematical errors.

src/Illuminate/Support/Exceptions · high confidence

Add Mercure broadcast driver with end-to-end encryption support

Introduces a new Mercure broadcast driver for Laravel, allowing applications to publish events to a Mercure hub. This implementation includes a CachingTokenProvider to optimize JWT generation and a ChannelEncrypter that enables optional end-to-end encryption of channel updates using AES-256-GCM, ensuring the hub cannot read message content. The driver supports configuration for both external hubs and FrankenPHP's built-in Mercure hub, with options for custom expiration times, algorithms, and cookie names.

src/Illuminate/Broadcasting/Mercure · high confidence

Add Redis-based concurrency and duration limiters

Introduces new Redis-based rate limiting capabilities via the \ConcurrencyLimiter\ and \DurationLimiter\ classes, along with their respective builders (\ConcurrencyLimiterBuilder\ and \DurationLimiterBuilder\). The concurrency limiter allows controlling the maximum number of simultaneous tasks by acquiring distributed locks, while the duration limiter restricts the number of tasks allowed within a specific time window using a sliding window algorithm. Both implementations use Lua scripts for atomic operations and provide builder APIs to configure parameters such as lock limits, time windows, timeouts, and retry sleep intervals.

src/Illuminate/Redis/Limiters · high confidence

Add ShareErrorsFromSession middleware

A new ShareErrorsFromSession middleware has been introduced to the View middleware layer. This middleware automatically shares the 'errors' variable from the current session with all view instances, ensuring that error bags are always available in views without requiring explicit binding or checks by the developer.

src/Illuminate/View/Middleware · high confidence

Add default application configuration stub

A new \config-stubs/app.php\ file has been added to provide a default template for the application configuration. This stub includes standard settings for the application name, environment, debug mode, URL, timezone, and locale. It also defines the encryption cipher as AES-256-CBC, handles the application key via environment variables, and supports previous keys for key rotation. Additionally, it configures the maintenance mode driver to default to 'file' with a 'database' store, ensuring consistent initial configuration for new installations.

config-stubs · high confidence

Add make:session-table command for session migration generation

A new Artisan command, make:session-table (aliased as session:table), has been introduced to generate database migrations for the session storage table. This command extends the base MigrationGeneratorCommand and allows users to create the necessary schema file for session persistence, with built-in checks to prevent duplicate migration files.

src/Illuminate/Session/Console · high confidence

Added AuthenticatesSessions contract

Introduced the AuthenticatesSessions interface within the Illuminate Contracts package to define the contract for session authentication middleware, providing a standardized marker for components that handle session authentication logic.

src/Illuminate/Contracts/Session/Middleware · high confidence

Comprehensive set of new Artisan command stubs for Laravel scaffolding

The \src/Illuminate/Foundation/Console/stubs\ directory has been populated with a complete suite of new stub files that serve as the templates for Laravel's code-generation commands. This change introduces scaffolding for a wide range of framework components, including API and broadcasting routes, model casts (standard and inbound), event listeners (sync, queued, and typed), jobs (sync, queued, and batched), and mailables (using the new envelope/content syntax). It also adds stubs for validation rules (implicit and explicit), notifications (including Markdown variants), policies, observers, exceptions, service providers, and view components. Additionally, it provides templates for testing, including PHPUnit feature/unit tests and Pest tests, as well as JavaScript configuration stubs for real-time broadcasting via Pusher, Ably, Reverb, and Mercure. These files define the default structure and imports for newly generated classes, ensuring consistency across new projects.

src/Illuminate/Foundation/Console/stubs · high confidence

Conditionable trait now supports HigherOrderWhenProxy chaining

The Conditionable trait in src/Illuminate/Conditionable/Traits now allows method chaining via HigherOrderWhenProxy when the when() or unless() methods are called with no arguments or a single argument. This enables fluent conditional logic, such as $object-\>when()-\>doSomething(), by returning a proxy object that can further refine the condition before applying the callback.

src/Illuminate/Conditionable/Traits · high confidence

Email verification notification listener added

A new listener class, SendEmailVerificationNotification, has been introduced to handle the Registered event. This listener ensures that an email verification notification is sent only to users who implement the MustVerifyEmail interface and have not already verified their email address, preventing redundant verification emails for existing verified accounts.

src/Illuminate/Auth/Listeners · high confidence

Failed job providers now support counting and pruning

The failed job storage providers (Database, Database UUID, File, and Null) now implement the CountableFailedJobProvider and PrunableFailedJobProvider interfaces. This allows users to count failed jobs by connection and queue, and to prune old failed job records based on a date threshold, providing better control over storage growth and monitoring capabilities.

src/Illuminate/Queue/Failed · high confidence

First-party image processing with Intervention Image integration

The Image component now provides first-party support for image processing by introducing GdDriver and ImagickDriver implementations that wrap the Intervention Image library. This change enables users to perform various image transformations such as resizing, cropping, rotating, and applying effects like blur or grayscale. Additionally, the system now supports a wider range of output formats including PNG, GIF, AVIF, BMP, and HEIC, allowing for more flexible image handling and optimization in applications.

src/Illuminate/Image/Drivers · high confidence

First-party image transformation classes added

This location introduces a new set of first-party image transformation classes (Blur, Contain, Cover, Crop, FlipHorizontally, FlipVertically, Grayscale, Orient, Resize, Rotate, Scale, Sharpen) that implement the Transformation contract, providing a structured API for applying visual modifications to images.

src/Illuminate/Image/Transformations · high confidence

Include default English language files in the framework

The framework now ships with default English translation files for authentication, pagination, password reset, and validation. This means applications no longer need to manually publish these language files to see default error messages for features like login failures, pagination links, password reset outcomes, and the full suite of validation rules (including new rules like \anyOf\, \base64\, \encoding\, and \prohibited\_if\_declined\).

src/Illuminate/Translation/lang · high confidence

Initial broadcasting contract interfaces

This change introduces the foundational contract interfaces for the broadcasting system, including Broadcaster, Factory, and event markers like ShouldBroadcast, ShouldBroadcastNow, ShouldBeUnique, and ShouldRescue. These interfaces define the core abstractions for authenticating users, retrieving connections, and marking events for asynchronous or immediate broadcast, establishing the structural basis for the broadcasting feature.

src/Illuminate/Contracts/Broadcasting · high confidence

Initial definition of Gate and Authorizable contracts

This change introduces the foundational interface contracts for Laravel's authorization system. The new \Gate\ interface defines the contract for the authorization service, specifying methods for defining abilities (\define\, \resource\), checking permissions (\allows\, \denies\, \check\, \any\, \authorize\), and managing policies (\policy\, \getPolicyFor\). It also exposes hooks for pre- and post-check callbacks (\before\, \after\) and utility methods like \has\, \inspect\, \raw\, and \abilities\. The \Authorizable\ interface provides the contract for entities that can be authorized, specifically requiring a \can\ method that accepts string, iterable, or \UnitEnum\ ability identifiers. These interfaces establish the API surface for dependency injection and testing within the auth/access component.

src/Illuminate/Contracts/Auth/Access · high confidence

Introduce AggregateServiceProvider for bundled service providers

The \src/Illuminate/Support\ component now includes a new \AggregateServiceProvider\ class. This class allows developers to register multiple service providers as a single unit by defining them in a \$providers\ array, automatically instantiating and registering each one while aggregating their \provides\ lists. This simplifies the registration of related services in applications or packages.

src/Illuminate/Support · high confidence

Introduce Container component with attribute-driven bindings and scoped instances

The new \Illuminate\\Container\ component provides the service container implementation, featuring support for \\#\[Bind\]\, \\#\[BindWhen\]\, \\#\[Singleton\]\, and \\#\[Scoped\]\ attributes to declaratively define service lifecycles and conditional bindings. It introduces scoped instance management, allowing services to be resolved once per request scope, and enhances contextual binding with infinite method chaining via \ContextualBindingBuilder\. The container also includes a \BoundMethod\ helper for dependency injection into callables, a \RewindableGenerator\ for efficient tagged service iteration, and utility classes for reflection and array handling, all while removing the dependency on \Illuminate\\Support\ to keep the container lightweight.

src/Illuminate/Container · high confidence

Introduce ContextLogProcessor interface for log context processing

A new \ContextLogProcessor\ interface has been added to the \Illuminate\\Contracts\\Log\ namespace. This interface extends Monolog's \ProcessorInterface\, providing a standardized contract for components that need to process and attach contextual data to log entries within the Laravel logging system.

src/Illuminate/Contracts/Log · high confidence

Introduce Contextual Logging with Queue Propagation

Laravel now includes a Context system that allows developers to attach key-value metadata to the current request lifecycle, which is automatically merged into log entries via the new ContextLogProcessor. This context is also automatically serialized and passed through to queued jobs via the ContextServiceProvider, ensuring that logging remains consistent and contextual even when code executes asynchronously in the queue.

src/Illuminate/Log/Context · high confidence

Added the \Illuminate\\Contracts\\Cookie\\Factory\ and \Illuminate\\Contracts\\Cookie\\QueueingFactory\ interfaces to define the contract for cookie creation, expiration, and queuing. These interfaces standardize the method signatures for creating cookies (\make\, \forever\), forgetting them (\forget\), and managing queued cookies (\queue\, \unqueue\, \getQueuedCookies\), providing a clear API contract for cookie handling within the framework.

src/Illuminate/Contracts/Cookie · high confidence

Introduce HTTP Client Batch API with concurrency control and fluent promise support

The HTTP client now includes a new \Batch\ class and \Http::batch()\ method, allowing users to group multiple HTTP requests into a single batch that executes concurrently. This feature introduces concurrency limits to control the number of simultaneous requests, callback hooks for tracking progress, handling failures, and managing completion states, and support for fluent promise chaining via the new \FluentPromise\ class. The implementation also adds \LazyPromise\ for deferred promise building, new exception classes (\BatchInProgressException\, \StrayRequestException\, \ConnectionException\, \HttpClientException\), and enhances the \Pool\ class to support concurrent request execution with proper ordering and error handling.

src/Illuminate/Http/Client · high confidence

Introduce JSON Schema parsing and serialization capabilities

The \src/Illuminate/JsonSchema\ directory now contains the core implementation for handling JSON Schema definitions. This includes a \Deserializer\ that converts raw schema arrays into a typed object model (supporting \anyOf\, unions, and various primitive types) with safeguards against unbounded \$ref\ expansion, a \Serializer\ that converts the typed model back into JSON-compatible arrays, and factory classes (\JsonSchema\, \JsonSchemaTypeFactory\) to programmatically construct schemas. This change adds the foundational infrastructure for validating and generating JSON Schema structures within the framework.

src/Illuminate/JsonSchema · high confidence

Introduce JSON:API resource classes and request handling

This change adds a new \JsonApi\ namespace under \Illuminate\\Http\\Resources\ to support the JSON:API specification. It introduces \JsonApiResource\ and \AnonymousResourceCollection\ classes that format responses with \application/vnd.api+json\ content types, handle sparse fieldsets and included relationships via \JsonApiRequest\, and manage resource identification, links, and meta information. A \RelationResolver\ is also added to resolve relationship data, and specific exceptions are defined for resource identification errors.

src/Illuminate/Http/Resources/JsonApi · high confidence

Introduce JSON:API resource concerns for element resolution and request handling

Added two new traits to the JSON:API resource system: ResolvesJsonApiElements and ResolvesJsonApiRequest. ResolvesJsonApiElements provides the core logic for resolving JSON:API resource objects, including handling resource identifiers, types, attributes (with sparse fieldset support), and relationship identifiers, while also managing relationship depth limits and circular reference deduplication. ResolvesJsonApiRequest simplifies the conversion of standard HTTP requests into JSON:API-specific request instances, ensuring consistent request context for resource resolution.

src/Illuminate/Http/Resources/JsonApi/Concerns · high confidence

Introduce JsonSchema contract with union and anyOf support

A new \JsonSchema\ interface has been added to the \Illuminate\\Contracts\\JsonSchema\ namespace, defining the contract for JSON schema generation. This interface provides methods for creating standard property types (object, array, string, integer, number, boolean) and introduces support for complex type structures via \union()\ for multi-type unions and \anyOf()\ for schema composition.

src/Illuminate/Contracts/JsonSchema · high confidence

Introduce Laravel Notifications component with database-backed read/unread tracking

The new \Illuminate/Notifications\ package provides the core infrastructure for sending notifications via mail, database, and broadcast channels. It introduces the \DatabaseNotification\ model and \HasDatabaseNotifications\ trait, enabling entities to store and query notifications with explicit \read\ and \unread\ scopes and methods. The \ChannelManager\ and \NotificationSender\ handle delivery logic, while \SendQueuedNotifications\ supports job attributes like \Backoff\, \Timeout\, and \DeleteWhenMissingModels\ for robust queue management. Additionally, \AnonymousNotifiable\ allows sending on-demand notifications to non-model targets, and the \Notification\ base class supports locale selection and an \afterSending\ hook.

src/Illuminate/Notifications · high confidence

Introduce Laravel Precognition support with success headers

This change introduces Laravel Precognition by adding two new routing dispatchers: PrecognitionCallableDispatcher and PrecognitionControllerDispatcher. These classes handle the execution of route callbacks and controller methods respectively, intercepting the response to return a 204 No Content status with a 'Precognition-Success: true' header instead of the actual response body. This enables clients to validate route logic and parameter resolution without triggering side effects or receiving full payloads.

src/Illuminate/Foundation/Routing · high confidence

Introduce MariaDB schema grammar with vector index and version-specific type support

Adds a new MariaDbGrammar class that extends MySqlGrammar to provide MariaDB-specific schema compilation. This includes support for vector indexes (compileVectorIndex and compileDropVectorIndex), version-aware UUID column definitions (using native uuid on MariaDB 10.7.0+ and char(36) on older versions), and specific handling for column renaming on legacy MariaDB versions (pre-10.5.2). It also implements proper JSON selector wrapping using json\_value for compatibility.

src/Illuminate/Database/Schema/Grammars · high confidence

Introduce Pipeline and Hub components for middleware-style processing

The \src/Illuminate/Pipeline\ directory now contains the core Pipeline and Hub classes, along with a \PipelineServiceProvider\ that registers them in the container. The \Pipeline\ class allows objects to be passed through a chain of pipes (middleware) with support for transactions, final callbacks, and macroability. The \Hub\ class provides a way to define and manage named pipelines, enabling users to send objects through pre-configured pipeline definitions. This change introduces a new architectural component for handling sequential processing logic within the application.

src/Illuminate/Pipeline · high confidence

Introduce class-based Blade components and rename View Environment to Factory

This change introduces a new class-based component system for Blade templates, adding \Component\, \AnonymousComponent\, \DynamicComponent\, \ComponentAttributeBag\, and \ComponentSlot\ classes to allow developers to define components as PHP classes with explicit data binding and attribute handling. Additionally, the legacy \Environment\ class is renamed to \Factory\ (with corresponding updates to \ViewServiceProvider\ and \ViewFinderInterface\), and the \ViewFinderInterface\ is expanded with methods like \prependNamespace\ and \replaceNamespace\ to improve view location management.

src/Illuminate/View · high confidence

Adds the EncryptCookies middleware to automatically encrypt outgoing cookies and decrypt incoming ones, with support for excluding specific cookies from encryption and handling nested array structures. Also introduces the AddQueuedCookiesToResponse middleware to attach cookies that were queued during request handling to the final HTTP response.

src/Illuminate/Cookie/Middleware · high confidence

Introduce core authentication and authorization middleware

This change introduces a new set of middleware classes in the \src/Illuminate/Auth/Middleware\ directory to handle common authentication and authorization flows. The \Authenticate\ middleware enforces user login across specified guards and allows customizing the unauthenticated redirect path. \AuthenticateWithBasicAuth\ enables HTTP Basic authentication with configurable fields. \Authorize\ integrates with the Gate policy system, supporting string or enum abilities and resolving model instances from route parameters. \EnsureEmailIsVerified\ restricts access to users with verified email addresses, while \RedirectIfAuthenticated\ redirects logged-in users away from login pages, defaulting to 'dashboard' or 'home' routes. \RequirePassword\ ensures recent password confirmation, supporting JSON responses and configurable timeouts.

src/Illuminate/Auth/Middleware · high confidence

Introduce customizable Auth notification classes for password reset and email verification

The \src/Illuminate/Auth/Notifications\ directory now contains \ResetPassword\ and \VerifyEmail\ notification classes, providing a structured way to handle authentication emails. These classes allow developers to customize the generated mail content and URLs via static \toMailUsing\ and \createUrlUsing\ callbacks, ensuring consistent interface patterns across both notification types while maintaining default behaviors for standard password reset and email verification flows.

src/Illuminate/Auth/Notifications · high confidence

Introduce dedicated Broadcast and Database notification channels

This change adds new \BroadcastChannel\ and \DatabaseChannel\ classes to the notification system. The \BroadcastChannel\ dispatches a \BroadcastNotificationCreated\ event, supporting connection and queue configuration via \BroadcastMessage\, and resolves notification data through \toBroadcast\ or \toArray\ methods. The \DatabaseChannel\ creates database notification records, storing custom types via a \databaseType\ method (falling back to the class name) and supporting initial read timestamps via \initialDatabaseReadAtValue\. These channels provide structured, dedicated pathways for real-time broadcast and persistent database notifications, complementing the existing \MailChannel\.

src/Illuminate/Notifications/Channels · high confidence

Introduce dedicated Laravel Cloud managed queues

This change adds a new \Illuminate\\Foundation\\Cloud\ namespace containing a dedicated queue system for Laravel Cloud. It introduces a \CloudManager\ to detect and manage cloud-hosted queues, a \CloudJob\ class that reports job outcomes (processed, released, failed) to a local cloud-agent via a Unix socket instead of direct SQS deletion, and a \Queue\ implementation that aggregates metrics across managed queues. The \QueueConnector\ wires this up by configuring the worker to use the agent for job polling and result reporting, and introduces an \AgentAwareLostConnectionDetector\ to restart pods if the agent socket becomes unreachable. A \FailedJobProvider\ logs failures to the agent, and a \JsonFormatter\ injects cloud request IDs into logs.

src/Illuminate/Foundation/Cloud · high confidence

Introduce dedicated Process component with execution, pooling, and testing capabilities

This change extracts the Process functionality into a new, standalone \src/Illuminate/Process\ component. It provides a fluent API for running external commands via \PendingProcess\, supports chaining commands with \Pipe\, and allows concurrent execution with \Pool\. The component includes robust testing utilities, such as \Factory::fake()\ for mocking process outcomes, \FakeProcessDescription\ for defining expected outputs, and assertion helpers like \assertRan\. It also introduces \InvokedProcess\ and \InvokedProcessPool\ for managing running processes, including methods to stop, signal, and wait for completion, along with dedicated exceptions for timeouts and failures.

src/Illuminate/Process · high confidence

Introduce deferred callback execution in Support component

Adds the \Illuminate\\Support\\Defer\ namespace containing \DeferredCallback\ and \DeferredCallbackCollection\ classes, enabling developers to register callbacks that are executed at the end of a request or job lifecycle. The \DeferredCallback\ class allows naming callbacks for later cancellation and configuring them to run even on unsuccessful requests, while the collection manages these callbacks, deduplicates them by name, and invokes them recursively when the request completes.

src/Illuminate/Support/Defer · high confidence

Introduce first-party Image processing component

Adds a new \Illuminate/Image\ package that provides a fluent API for image manipulation, including resizing, cropping, rotating, and applying effects like blur or grayscale. The component supports multiple output formats (PNG, GIF, AVIF, BMP, HEIC, WebP) and allows creating images from various sources such as bytes, streams, base64, file paths, storage disks, uploaded files, and URLs. It includes a driver-based architecture (GD and Imagick) and registers an \ImageManager\ via \ImageServiceProvider\ for easy integration.

src/Illuminate/Image · high confidence

Introduce fluent JSON Schema type definitions with validation constraints

The \src/Illuminate/JsonSchema/Types\ directory now provides a new fluent API for defining JSON Schema types, allowing users to programmatically construct schemas with validation rules. This includes specific type classes for strings (with length, pattern, and format constraints), integers and numbers (with min/max and multipleOf constraints), arrays (with item count and uniqueness rules), objects (with additional property controls), and booleans. The system also supports multi-type unions via \UnionType\ and \AnyOfType\, enabling schemas that accept multiple data types, and includes a base \Type\ class with support for required/nullable flags, titles, descriptions, and enumerations.

src/Illuminate/JsonSchema/Types · high confidence

Introduce granular cache operation events

The cache subsystem now fires a comprehensive set of object-based events for cache interactions, allowing applications to monitor and react to specific operations. New events include CacheHit, CacheMissed, KeyWritten, KeyWriteFailed, ForgettingKey, KeyForgotten, KeyForgetFailed, RetrievingKey, RetrievingManyKeys, WritingKey, and WritingManyKeys, which expose details such as the store name, key, value, tags, and TTL. Additionally, flush operations are now observable via CacheFlushing, CacheFlushed, and CacheFlushFailed, while lock management is covered by CacheLocksFlushing, CacheLocksFlushed, and CacheLocksFlushFailed. A new CacheFailedOver event is also available to handle failover scenarios. All events share a common base (CacheEvent) providing store, key, and tag context, and include a setTags method for dynamic tag assignment.

src/Illuminate/Cache/Events · high confidence

Introduce job batching, debouncing, and unique locking infrastructure

The \Illuminate\\Bus\ package now provides a complete job batching system, allowing multiple queueable jobs to be dispatched and tracked as a single unit with progress, success, and failure callbacks. This includes the \Batch\, \PendingBatch\, and \ChainedBatch\ classes, along with \DatabaseBatchRepository\ and \DynamoBatchRepository\ implementations for persisting batch state. Additionally, the package introduces debouncing for queued jobs via the \DebounceLock\ class and unique job locking via \UniqueLock\, supported by the new \Batchable\ trait for jobs and enhancements to the \Queueable\ trait.

src/Illuminate/Bus · high confidence

Introduce make:factory Artisan command for generating model factories

Users can now generate Eloquent factory classes using the new \make:factory\ command. The command accepts a factory name and an optional \--model\ flag to specify the associated model; if the model is not provided, the command attempts to guess it from the factory name or defaults to the application's root model. Generated factories are placed in the \database/factories\ directory and use a customizable stub, supporting both modern \Stringable\ helpers and legacy string functions for compatibility.

src/Illuminate/Database/Console/Factories · high confidence

Introduce new Artisan console view components

The \src/Illuminate/Console/View\ location now provides a new set of decoupled console components (Alert, Ask, BulletList, Choice, Confirm, Error, Info, Line, Secret, Success, Task, TwoColumnDetail, Warn) and their corresponding Termwind view templates. These components enable developers to render structured, styled CLI output—such as success/error lines, task progress with human-readable runtimes, and interactive prompts—using a consistent factory-based API.

src/Illuminate/Console/View · high confidence

Introduce new Concurrency component with process, fork, and sync drivers

Laravel now includes a dedicated Concurrency component that allows applications to run multiple tasks in parallel. The component provides a \ConcurrencyManager\ and three drivers: \ProcessDriver\ (spawns child processes via the Process component, propagating context and supporting timeouts), \ForkDriver\ (uses the \spatie/fork\ package for native forking, restricted to console commands), and \SyncDriver\ (executes tasks sequentially as a fallback). A new \ConcurrencyServiceProvider\ registers the manager, replacing the previous \ServerServiceProvider\.

src/Illuminate/Concurrency · high confidence

Introduce new mail events with serialization support

Added \MessageSending\ and \MessageSent\ event classes to the mail system. The \MessageSent\ event now supports serialization via \\_\serialize\ and \\\_unserialize\ methods, enabling it to be safely queued or stored, particularly handling attachment data by base64-encoding the message data when attachments are present. The \MessageSending\ event provides a simple structure holding the Symfony Email instance and associated data.

src/Illuminate/Mail/Events · high confidence

Introduce the isolated Illuminate Testing component

The \src/Illuminate/Testing\ directory is now a standalone, isolated component. This change introduces the core testing infrastructure classes—including \TestResponse\, \TestView\, \TestComponent\, \PendingCommand\, and \AssertableJsonString\—alongside the \ParallelTesting\ service provider and runner support. By extracting these classes into their own namespace and package structure, the framework ensures that testing capabilities are decoupled from the main application bootstrap, allowing for independent versioning and cleaner dependency boundaries.

src/Illuminate/Testing · high confidence

Introduce unified cache locking and concurrency limiting

The Cache component now includes a comprehensive locking system and concurrency limiter. New classes such as \Lock\, \CacheLock\, \ArrayLock\, \FileLock\, \DatabaseLock\, and \DynamoDbLock\ provide driver-specific implementations for distributed locking, while the \ConcurrencyLimiter\ and \ConcurrencyLimiterBuilder\ classes offer a fluent API to limit concurrent execution of code blocks. Additionally, a \FailoverStore\ has been added to allow caching operations to automatically fall back to secondary stores if the primary one fails, and the \HasCacheLock\ trait simplifies adding lock support to custom cache stores.

src/Illuminate/Cache · high confidence

Introduces Fluent JSON testing concerns

Adds new traits to the \Illuminate\\Testing\\Fluent\\Concerns\ namespace to support fluent assertions on JSON data structures. The \Debugging\ trait provides a \dump\ method for inspecting properties, \Has\ adds assertions for property existence and size (\has\, \hasAll\, \hasAny\, \missingAll\, \count\), \Interaction\ enables strict checking of accessed properties via \interacted\ and \etc\, and \Matching\ introduces value comparison methods (\where\, \whereNot\, \whereNull\, \whereNotNull\, \whereAll\, \whereType\) that support closures, \Arrayable\ objects, and PHP enums.

src/Illuminate/Testing/Fluent/Concerns · high confidence

Introduces MigrationEvent contract for database migrations

A new \MigrationEvent\ interface has been added to the \Illuminate\\Contracts\\Database\\Events\ namespace. This empty marker interface allows developers to type-hint against any event class that represents a database migration, enabling more specific event handling and filtering within the application's event system.

src/Illuminate/Contracts/Database/Events · high confidence

Introduces PHP attributes and traits for API resource collection and conditional loading

This change adds the \Collects\ and \PreserveKeys\ PHP attributes to the \src/Illuminate/Http/Resources/Attributes\ namespace, allowing developers to declaratively specify the resource class a collection wraps and whether array keys should be preserved during serialization. It introduces the \CollectsResources\ trait, which implements the logic to resolve the target resource class (via the new attribute, a property, or convention) and handles JSON options and iteration for resource collections. Additionally, it adds the \ConditionallyLoadsAttributes\ trait, which provides the core conditional loading methods (\when\, \unless\, \merge\, \mergeWhen\, \mergeUnless\, \attributes\) and the \removeMissingValues\ filtering logic that respects the \PreserveKeys\ attribute. The \MergeValue\ class is updated to support \JsonSerializable\ objects, and the \DelegatesToResource\ trait is introduced to handle method delegation and route binding exceptions for resource wrappers.

src/Illuminate/Http/Resources · high confidence

Introduces PHP attributes for Eloquent model configuration

Adds a comprehensive suite of PHP 8 attributes to the \Illuminate\\Database\\Eloquent\\Attributes\ namespace, allowing developers to configure model behavior directly on the class definition. This includes attributes for defining fillable and guarded columns (\Fillable\, \Guarded\), hidden and visible attributes (\Hidden\, \Visible\), and appended attributes (\Appends\). It also introduces attributes for model lifecycle and relationships such as \Boot\, \Initialize\, \Refreshes\, and \Touches\. Additional attributes allow specifying the database connection (\Connection\), table details (\Table\), and disabling timestamps or auto-increment (\WithoutTimestamps\, \WithoutIncrementing\). The set also covers custom builders (\UseEloquentBuilder\), factories (\UseFactory\), policies (\UsePolicy\), resources (\UseResource\, \UseResourceCollection\), scopes (\Scope\, \ScopedBy\), observers (\ObservedBy\), collection types (\CollectedBy\), and route keys (\RouteKey\).

src/Illuminate/Database/Eloquent/Attributes · high confidence

Introduces Pipeline and Hub contracts

Adds the \Illuminate\\Contracts\\Pipeline\\Pipeline\ and \Illuminate\\Contracts\\Pipeline\\Hub\ interfaces to define the contract for the pipeline system. The \Pipeline\ interface specifies methods to send a passable object, configure the array of pipes, set the invocation method, and execute the pipeline with a final destination callback. The \Hub\ interface provides a method to send an object through a named pipeline, establishing the foundational API for pipeline-based processing.

src/Illuminate/Contracts/Pipeline · high confidence

Introduces ValidatesRequests trait with Precognition support

The ValidatesRequests trait is added to provide controller validation shortcuts. It includes validate(), validateWith(), and validateWithBag() methods. A key behavioral change is the integration of Laravel Precognition: when a request is identified as precognitive, the validation rules are filtered to remove placeholders and an after-validation hook is attached, enabling real-time validation feedback without throwing standard validation errors for precognitive requests.

src/Illuminate/Foundation/Validation · high confidence

Introduces anonymous broadcasting and dedicated broadcast event handling

Developers can now broadcast events without defining a dedicated class by using the new AnonymousEvent and the BroadcastManager's on(), private(), and presence() methods, which allow specifying channels, payload, and connection directly. The broadcasting system now uses a dedicated BroadcastEvent job class to handle queued broadcasts, supporting queue attributes like tries, timeout, backoff, and max exceptions via PHP attributes on the underlying event. Additionally, the BroadcastServiceProvider has been moved to the Broadcasting namespace and now registers the BroadcastManager as a singleton, replacing the previous TinkerServiceProvider registration.

src/Illuminate/Broadcasting · high confidence

Introduces dedicated concurrency and lost-connection detection with a new transaction manager

The database layer now includes a new \DatabaseTransactionsManager\ to handle transaction lifecycle and callbacks, alongside dedicated \ConcurrencyErrorDetector\ and \LostConnectionDetector\ classes to reliably identify deadlocks and connection drops. This is supported by new exception types such as \DeadlockException\, \LostConnectionException\, and \UniqueConstraintViolationException\ (which now exposes index and column details), as well as a \MariaDbConnection\ class for MariaDB-specific handling.

src/Illuminate/Database · high confidence

Introduces first-party image processing contracts

Adds the \Illuminate\\Contracts\\Image\\Driver\ and \Transformation\ interfaces, establishing a standardized contract for image processing. The \Driver\ interface defines methods for processing image contents via a pipeline, retrieving dimensions, extracting the dominant color, and registering custom transformation handlers, enabling consistent image manipulation across different implementations.

src/Illuminate/Contracts/Image · high confidence

Introduces structured Mailables classes for envelope, content, and address handling

The \src/Illuminate/Mail/Mailables\ directory now contains new classes (\Envelope\, \Content\, \Address\, \Headers\, \Attachment\) that provide a structured, object-oriented API for defining email messages. Users can now explicitly define message metadata (recipients, subject, tags, headers) via the \Envelope\ class and content details (views, HTML, text, markdown) via the \Content\ class, replacing or supplementing previous implicit or less structured approaches. The \Address\ class includes validation to prevent line-break injection in email addresses, enhancing security for message routing.

src/Illuminate/Mail/Mailables · high confidence

Introduction of dedicated message classes for notifications

The notification system now uses specific message classes for each channel type: \BroadcastMessage\ for broadcast notifications, \DatabaseMessage\ for database notifications, and \MailMessage\ (extending \SimpleMessage\) for email notifications. \MailMessage\ provides a fluent API to configure recipients (from, replyTo, cc, bcc), attachments, markdown templates, themes, and metadata, while \SimpleMessage\ offers common methods for setting subjects, greetings, and action buttons. This structure allows users to build channel-specific notification content with type-safe, dedicated objects rather than generic arrays or mixed objects.

src/Illuminate/Notifications/Messages · high confidence

Introduction of new Queue contracts and interfaces

This change introduces a comprehensive set of new interfaces and classes within the \Illuminate\\Contracts\\Queue\ namespace to define the queueing system's architecture. Key additions include the \Job\ interface, which standardizes job lifecycle methods such as \uuid\, \release\, \fail\, \hasFailed\, and \retryUntil\, alongside the \Queue\ interface for core operations like \push\, \pop\, and \bulk\. The update also adds specialized contracts for queue management (\Factory\, \ClearableQueue\, \Monitor\), entity handling (\EntityResolver\, \EntityNotFoundException\, \QueueableEntity\, \QueueableCollection\), and job behaviors (\ShouldQueue\, \ShouldBeUnique\, \ShouldBeEncrypted\, \Interruptible\, \PreparesForDispatch\). These interfaces provide a standardized contract for queue implementations, enabling features like daemon monitoring, job interruption via signals, and detailed queue metrics.

src/Illuminate/Contracts/Queue · high confidence

Introduction of new validation contract interfaces

The validation contract layer has been expanded with several new interfaces to support advanced validation patterns. Users can now implement \ValidationRule\ for modern invokable validation classes, \CompilableRules\ to compile rule objects into usable formats, and \DataAwareRule\ to access the full validation dataset within a rule. Additionally, \ValidatorAwareRule\ allows rules to access the validator instance, while \ValidatesWhenResolved\ enables automatic validation during service resolution. The \Factory\ contract now explicitly exposes methods for extending validation logic, and the \Validator\ contract standardizes error handling and data retrieval methods.

src/Illuminate/Contracts/Auth, src/Illuminate/Contracts/Validation · high confidence

Introduction of the Config Repository contract

A new \Illuminate\\Contracts\\Config\\Repository\ interface has been added, defining the standard contract for configuration management. This interface specifies methods for retrieving configuration values (\get\, \has\, \all\), setting values (\set\), and manipulating array-based configuration entries (\push\, \prepend\), providing a standardized API for interacting with application configuration.

src/Illuminate/Contracts/Config · high confidence

Introduction of the Macroable trait for dynamic method extension

The Macroable trait has been added to the codebase, enabling classes to register and execute custom macros via dynamic method calls. This feature allows developers to extend existing classes with new static or instance methods at runtime by defining closures, which are bound to the appropriate context (static or instance) when invoked. The trait provides methods to register macros, check for their existence, mix in methods from other objects, and flush all registered macros.

src/Illuminate/Macroable/Traits · high confidence

Introduction of the Session contract interface

A new \Illuminate\\Contracts\\Session\\Session\ interface has been added, defining the standard contract for session management. This interface exposes methods for managing session lifecycle (start, save, invalidate, regenerate), data manipulation (get, put, pull, forget, flush), and session metadata (getName, getId, previousUrl). This change establishes a decoupled abstraction for session handling, allowing implementations to vary without affecting code that depends on the contract.

src/Illuminate/Contracts/Session · high confidence

Logging subsystem refactored with new context events and LogManager

The logging component has been restructured to support a new context system and improved channel management. The old Writer class has been replaced by a new LogManager and Logger implementation, introducing ContextDehydrating and ContextHydrated events to manage logging context lifecycle. The LogServiceProvider now registers the LogManager as a singleton, and the system now supports shared context across channels and stacks via the new ContextLogProcessor.

src/Illuminate/Log · high confidence

New Artisan command to clear expired password reset tokens

A new console command, \auth:clear-resets\, has been added to the authentication package. This command allows users to manually flush expired password reset tokens from the repository, helping to keep the database clean and secure. It accepts an optional argument to specify the password broker name, defaulting to the application's primary broker if not provided.

src/Illuminate/Auth/Console · high confidence

New Artisan command to generate the notifications table migration

Developers can now run the \make:notifications-table\ (or its alias \notifications:table\) Artisan command to automatically generate a database migration for the notifications table. This new console command extends the shared \MigrationGeneratorCommand\ base class, ensuring consistent behavior with other migration generation commands while specifically targeting the \notifications\ table schema using a dedicated stub file.

src/Illuminate/Notifications/Console · high confidence

New Artisan commands for application scaffolding and diagnostics

This release introduces several new console commands to streamline application setup and inspection. The \about\ command displays key application information (environment, cache status, drivers) in a formatted table or JSON output. The \install:api\ command scaffolds API routes and installs either Laravel Sanctum or Passport. The \install:broadcasting\ command sets up broadcasting routes, publishes configuration, and installs driver-specific packages (Reverb, Pusher, Ably, Mercure). Additionally, the \channel:list\ command displays registered private broadcast channels, and the \make:cast\ command generates custom Eloquent cast classes with support for inbound casts.

src/Illuminate/Foundation/Console · high confidence

New Artisan commands for cache management

This update introduces four new Artisan commands to the \Illuminate\\Cache\\Console\ namespace: \cache:clear\ (with support for specific stores, tags, and a new \--locks\ flag to clear only cache locks), \cache:forget\ (to remove specific cache keys), \cache:prune-stale-tags\ (to clean up stale tags in Redis stores), and \make:cache-table\ (to generate migrations for the database cache driver). These commands provide more granular control over cache operations and improve the developer experience by offering dedicated tools for common cache maintenance tasks.

src/Illuminate/Cache/Console · high confidence

New AssertableJson class for fluent JSON assertions

A new \AssertableJson\ class has been introduced in the \Illuminate\\Testing\\Fluent\ namespace to provide a fluent interface for asserting JSON response structures. This class supports chaining assertions via methods like \first()\ and \each()\ to navigate and validate nested JSON data, and can be instantiated from arrays or existing \AssertableJsonString\ instances.

src/Illuminate/Testing/Fluent · high confidence

New BladeMapper for improved exception stack traces

A new BladeMapper class has been added to the exception renderer to improve the clarity of error reports for Blade view exceptions. This component maps compiled view file paths back to their original source files and detects the correct line numbers in the original Blade templates, allowing developers to see exactly where an error occurred in their view code rather than in the compiled PHP output.

src/Illuminate/Foundation/Exceptions/Renderer/Mappers · high confidence

New Broadcasting Driver Architecture with Ably, Mercure, and Redis Cluster Support

The broadcasting subsystem has been restructured around a new abstract \Broadcaster\ base class, introducing dedicated driver implementations for Ably, Mercure, Log, Null, Pusher, and Redis. This change adds native support for the Ably and Mercure broadcast drivers, while significantly enhancing the Redis driver to support cluster environments via Lua scripts for atomic multi-channel publishing. The core \Broadcaster\ class now provides a unified channel authentication system that allows registering channel handlers as classes (via the \HasBroadcastChannel\ interface) or callables, with automatic parameter extraction and model binding resolution. Additionally, the Pusher driver now supports JSONP authentication callbacks and user authentication payloads, while the Mercure driver introduces end-to-end encrypted channel support and client-side whisper topics.

src/Illuminate/Broadcasting/Broadcasters · high confidence

New Capsule Manager for standalone database usage

Introduced a new \Illuminate\\Database\\Capsule\\Manager\ class that provides a lightweight, standalone database connection manager for applications not using the full Laravel framework. This manager initializes a default configuration with \PDO::FETCH\_OBJ\ as the fetch mode, sets up the \DatabaseManager\ and \ConnectionFactory\, and exposes static convenience methods like \connection()\, \table()\, and \schema()\ to interact with the database. It also supports bootstrapping Eloquent ORM, registering custom event dispatchers, and dynamically passing method calls to the default connection, enabling easy integration of Laravel's database components into other PHP projects.

src/Illuminate/Database/Capsule · high confidence

New Dispatcher and QueueingDispatcher contracts introduced

The Bus component now exposes two new interfaces: \Dispatcher\ and \QueueingDispatcher\. The \Dispatcher\ contract defines the core command bus capabilities, including synchronous dispatching (\dispatchSync\, \dispatchNow\), deferred execution (\dispatchAfterResponse\), job chaining (\chain\), and handler mapping (\map\, \pipeThrough\). The \QueueingDispatcher\ extends this to support queue-specific operations like creating job batches (\batch\), finding batch status (\findBatch\), and dispatching directly to the queue (\dispatchToQueue\). These interfaces standardize the contract for command dispatching and batch management within the application.

src/Illuminate/Contracts/Bus · high confidence

New Eloquent casting and relationship contract interfaces

This location introduces a suite of new PHP interfaces to define and extend Eloquent model behavior. The \CastsAttributes\ and \CastsInboundAttributes\ interfaces formalize custom attribute casting, while \SerializesCastableAttributes\, \DeviatesCastableAttributes\, and \ComparesCastableAttributes\ add support for serialization, increment/decrement operations, and granular dirty-state comparison. The \Castable\ interface allows classes to specify their caster, and \SupportsPartialRelations\ defines the contract for one-of-many relationship queries. Additionally, the \Builder\ interface is established here to improve IDE support by extending the base query builder contract.

src/Illuminate/Contracts/Database/Eloquent · high confidence

New Eloquent model casts and JSON encoding customization

This update introduces several new Eloquent model casts to simplify handling specific data types: AsBinary for encoding/decoding binary UUIDs and ULIDs, AsVector for MariaDB and PostgreSQL vector columns, AsHtmlString for HTML strings, AsStringable for Stringable objects, AsUri for URI objects, AsFluent for fluent data structures, and AsEnumCollection/AsEnumArrayObject for storing collections or arrays of PHP enums. It also adds AsArrayObject and AsEncryptedArrayObject for ArrayObject instances, with the encrypted variants supporting nullable columns. Additionally, the JSON cast behavior is now customizable via the new Json::encodeUsing() and Json::decodeUsing() methods, allowing developers to pass custom flags or handlers to the underlying JSON encoder and decoder.

src/Illuminate/Database/Eloquent/Casts · high confidence

New Eloquent relationship concern traits for pivot handling, one-of-many logic, and inverse relations

This change introduces several new traits in the \src/Illuminate/Database/Eloquent/Relations/Concerns\ directory to refactor and extend Eloquent relationship capabilities. The \AsPivot\ trait provides a reusable base for custom pivot models, handling attribute filling, timestamp management, and deletion logic. The \CanBeOneOfMany\ trait implements the inner-join subquery logic required for 'one-of-many' relationships (e.g., \latestOfMany\), allowing developers to retrieve a single related model per group. The \SupportsInverseRelations\ and \SupportsPivotInverseRelations\ traits add 'chaperone' functionality, which automatically links related models back to their parents (and pivot models back to declaring/related models) after a query executes. Additionally, \InteractsWithDictionary\ standardizes key casting for enums and objects, while \ComparesRelatedModels\ refines model identity checks, and \SupportsDefaultModels\ handles default model instantiation for optional relationships.

src/Illuminate/Database/Eloquent/Relations/Concerns · high confidence

New Eloquent relationship types and polymorphic pivot support

This release introduces the HasManyThrough, HasOneThrough, and MorphTo relationship classes, enabling many-to-many-through and polymorphic one-to-many associations, alongside a new MorphPivot class that ensures correct scoping for polymorphic pivot records during save, select, and delete operations.

src/Illuminate/Database/Eloquent/Relations · high confidence

New Facades for Cloud, Concurrency, Context, Date, Exceptions, and Bus

The framework introduces several new static Facades to provide convenient access to underlying services. The new Cloud Facade offers methods to check if the application is hosted and manage managed queues. The Concurrency Facade allows creating and managing process, fork, and sync drivers for concurrent task execution. The Context Facade provides a global repository for storing and retrieving contextual data, including hidden values and scoped data. The Date Facade acts as a static interface to the Carbon date factory, enabling date manipulation and testing. The Exceptions Facade simplifies registering custom handlers for reporting and rendering exceptions. Finally, the Bus Facade is enhanced with a static fake() method for testing job dispatching and a dispatchChain() helper for chaining jobs.

src/Illuminate/Support/Facades · high confidence

New Filesystem contract interfaces and exception classes

The \src/Illuminate/Contracts/Filesystem\ directory now includes the \Cloud\, \Factory\, \Filesystem\, and \FileNotFoundException\ interfaces, along with \LockTimeoutException\. This introduces a standardized contract for cloud storage access (via \Cloud::url\), a factory for retrieving disk instances (\Factory::disk\), and a comprehensive set of file operations (read, write, stream, metadata) defined in the \Filesystem\ interface, alongside specific exception types for file-not-found and lock-timeout scenarios.

src/Illuminate/Contracts/Filesystem · high confidence

New Form Request attributes for error bag, validation strictness, and redirection

This change introduces five new PHP attributes in the \Illuminate\\Foundation\\Http\\Attributes\ namespace to enhance Form Request behavior. Users can now use \\#\[ErrorBag\]\ to specify a custom error bag name, \\#\[FailOnUnknownFields\]\ to enforce strict validation against unknown input fields, \\#\[RedirectTo\]\ and \\#\[RedirectToRoute\]\ to declaratively define post-validation redirection targets, and \\#\[StopOnFirstFailure\]\ to halt validation on the first error.

src/Illuminate/Foundation/Http/Attributes · high confidence

New Foundation Queue traits for unique job handling

Added two new traits in the \Illuminate\\Foundation\\Queue\ namespace: \InteractsWithUniqueJobs\ and \Queueable\. The \InteractsWithUniqueJobs\ trait provides methods to store and remove unique job information (cache store, key, and lock owner) in the application context, facilitating better management of unique job locks. The \Queueable\ trait consolidates common queue-related functionality by composing \Dispatchable\, \InteractsWithQueue\, \QueueableByBus\, and \SerializesModels\.

src/Illuminate/Foundation/Queue · high confidence

New HTTP Client lifecycle events for request and response tracking

The HTTP Client now exposes three new event classes—RequestSending, ResponseReceived, and ConnectionFailed—to allow users to hook into the request lifecycle. RequestSending provides the outgoing Request instance before dispatch, ResponseReceived provides both the Request and the resulting Response instance after a successful call, and ConnectionFailed provides the Request and the specific ConnectionException when a network error occurs, enabling detailed monitoring and error handling.

src/Illuminate/Http/Client/Events · high confidence

New HTTP event, enhanced debugging, and stricter maintenance mode cookies

This update introduces the RequestHandled event, allowing applications to listen for when an HTTP request is fully processed. It also improves developer experience by updating the HTML dumper to display clickable source file and line information in dump output. Additionally, the maintenance mode bypass cookie now enforces stricter validation, rejecting non-string MAC values to prevent potential issues.

src/Illuminate/Foundation/Http · high confidence

New HTTP middleware components for caching, CORS, and request validation

This update introduces several new middleware classes to the framework. The \SetCacheHeaders\ middleware now supports configurable caching options, including boolean ETag generation using the faster xxhash algorithm and timestamp-based last-modified handling. The \HandleCors\ middleware integrates the Fruitcake CORS library and adds a \skipWhen\ feature to conditionally bypass CORS checks. New \TrustProxies\ and \TrustHosts\ middlewares provide static configuration methods (\at\, \withHeaders\, \at\ with subdomains) to manage trusted proxy IPs and host patterns, with automatic detection for cloud environments like Forge and Vapor. Additionally, \ValidatePathEncoding\ ensures request paths are valid UTF-8, \ValidatePostSize\ throws a specific exception when POST data exceeds \post\_max\_size\, \PrefersJsonResponses\ automatically sets the Accept header to JSON for broad requests, \FrameGuard\ sets the X-Frame-Options header, \CheckResponseForModifications\ handles 304 Not Modified responses, and \AddLinkHeadersForPreloadedAssets\ injects Link headers for Vite preloaded assets with a configurable limit.

src/Illuminate/Http/Middleware · high confidence

New JsonFormatter extracts exception context via ExceptionHandler

A new \JsonFormatter\ class has been introduced in the logging component to enhance JSON log output. It extends Monolog's \JsonFormatter\ to automatically extract and merge exception context into log entries. The formatter attempts to use the application's bound \ExceptionHandler\ to build context for exceptions (if the handler supports \buildContextForException\ and is reporting the error); if the handler is not bound or does not support this method, it falls back to extracting context directly from the exception's \context()\ method. This ensures that structured logging includes richer diagnostic information when exceptions occur.

src/Illuminate/Log/Formatters · high confidence

New MessageLogged event class for log messages

A new \MessageLogged\ event class has been introduced in the \Illuminate\\Log\\Events\ namespace. This class serves as a data carrier for log events, exposing the log level (restricted to standard levels like emergency, alert, critical, error, warning, notice, info, and debug), the log message string, and an optional context array via public constructor properties. This allows consumers to access structured log data when listening to log events.

src/Illuminate/Log/Events · high confidence

New PHP 8 attributes for container binding and contextual resolution

This location introduces a suite of new PHP 8 attributes in the \Illuminate\\Container\\Attributes\ namespace to simplify dependency injection and service resolution. Classes like \Bind\ and \BindWhen\ allow developers to specify concrete implementations and conditional binding rules directly on classes, while \Singleton\ and \Scoped\ mark classes for specific lifetime management. Contextual attributes such as \Auth\, \Authenticated\, \CurrentUser\, \Database\, \DB\, \Cache\, \Config\, \Context\, \Log\, \RequestAttribute\, \RouteParameter\, \Storage\, and \Tag\ enable automatic resolution of framework services (like authentication guards, database connections, cache stores, and route parameters) by annotating constructor parameters. Additionally, \Give\ allows providing specific class implementations for injection, and aliases like \CurrentUser\ and \DB\ provide convenient shorthand for \Authenticated\ and \Database\ respectively.

src/Illuminate/Container/Attributes · high confidence

New PHP attributes and isolated command execution support

Console commands can now be configured using PHP 8 attributes such as \#\[Signature\], \#\[Aliases\], \#\[Description\], \#\[Help\], \#\[Usage\], and \#\[Hidden\], providing a more expressive way to define command metadata. Additionally, the console component introduces a new isolation mechanism via the Prohibitable trait and CacheCommandMutex, allowing commands to prevent concurrent execution and block destructive operations in specific environments.

src/Illuminate/Console · high confidence

New Process contract interfaces for InvokedProcess and ProcessResult

The Process component now exposes dedicated interfaces for interacting with running processes and their outcomes. The new InvokedProcess interface allows users to monitor active processes by retrieving their ID, command, and output streams, as well as sending signals, checking status, and waiting for completion or specific conditions. The ProcessResult interface provides methods to inspect the outcome of a finished process, including checking success/failure status, retrieving exit codes and output, searching within output streams, and conditionally throwing exceptions based on the result.

src/Illuminate/Contracts/Process · high confidence

New Queue Capsule Manager for simplified queue configuration

A new \Illuminate\\Queue\\Capsule\\Manager\ class has been introduced to provide a streamlined, static-interface for configuring and accessing the queue system. This component allows users to set up default queue connections and configurations via a capsule pattern, exposing static methods like \connection()\, \push()\, \bulk()\, and \later()\ to interact with the queue without needing to manually resolve the manager from the container. It acts as a facade-like wrapper that delegates calls to the underlying \QueueManager\, simplifying the setup process for applications that prefer a global capsule approach over direct service container usage.

src/Illuminate/Queue/Capsule · high confidence

New ReflectsClosures trait for introspecting Closure parameters and return types

The new ReflectsClosures trait provides methods to inspect the type hints of Closure parameters and return values. It includes firstClosureParameterType and firstClosureParameterTypes to retrieve the class name(s) of the first parameter, handling union types, and closureParameterTypes to get types for all parameters. Additionally, closureReturnTypes extracts non-builtin class names from the return type, supporting union types while excluding built-ins and 'static'/'self'. This trait is part of the new illuminate/reflections component.

src/Illuminate/Reflection/Traits · high confidence

New Whoops exception renderer for debug error pages

Added WhoopsExceptionRenderer and WhoopsHandler classes to integrate the Whoops library for rendering detailed, pretty-printed debug error pages. The renderer implements the ExceptionRenderer interface to output HTML error details, while the handler configures the Whoops PrettyPageHandler with application-specific paths, blacklists for sensitive data (from app.debug\_blacklist or app.debug\_hide), and editor links (from app.editor).

src/Illuminate/Foundation/Exceptions/Whoops · high confidence

New and updated controller and middleware stubs with modern PHP features

The \src/Illuminate/Routing/Console/stubs\ directory now includes a comprehensive set of new stub files for generating controllers and middleware, introducing support for invokable controllers, singleton resources (both standard and nested), and model-based resource controllers. These stubs utilize native PHP type declarations (such as \string\ and \never\) and return types, and they automatically import the \Illuminate\\Http\\Request\ class. The new middleware stub also adopts modern type hints for the request and response handling, providing a more robust starting point for developers using the \make:controller\ and \make:middleware\ commands.

src/Illuminate/Routing/Console/stubs · high confidence

New application configuration API via ApplicationBuilder

Laravel introduces a new \ApplicationBuilder\ class in \src/Illuminate/Foundation/Configuration\ to streamline application bootstrapping. This change adds dedicated configuration classes for \Exceptions\ (allowing fine-grained control over reporting, retrying, and mapping exceptions) and \Middleware\ (providing fluent methods to prepend, append, remove, or replace global and group middleware, as well as configure trust hosts, proxies, and session authentication). The \ApplicationBuilder\ itself exposes methods like \withRouting\, \withKernels\, \withProviders\, \withEvents\, and \withBroadcasting\ to replace the traditional \bootstrap/app.php\ setup, offering a more structured and type-safe way to configure the application's core services and middleware stack.

src/Illuminate/Foundation/Configuration · high confidence

New attribute-based controller middleware configuration

Developers can now apply middleware to controllers using PHP 8 attributes instead of relying solely on the $middleware property or route definitions. This change introduces three new attributes in the Illuminate\\Routing\\Attributes\\Controllers namespace: Middleware, which allows specifying a custom middleware class or closure along with optional only/except filters; Authorize, a convenience wrapper that configures the authorization middleware for specific abilities and models; and WithoutMiddleware, which explicitly excludes specific middleware from being applied to a controller or method. These attributes support targeting both classes and methods and can be repeated.

src/Illuminate/Routing/Attributes · high confidence

New batch lifecycle events for job dispatching

The Bus component now exposes four new event classes—BatchStarted, BatchDispatched, BatchFinished, and BatchCanceled—to allow applications to react to specific stages of a batch's execution. These events carry the Batch instance, and the BatchCanceled event additionally includes an optional exception to indicate why the batch was cancelled, enabling more granular monitoring and error handling for batched jobs.

src/Illuminate/Bus/Events · high confidence

New collection traits for resource transformation and enhanced proxy support

This change introduces two new traits to the Collections component. The \TransformsToResourceCollection\ trait adds a \toResourceCollection()\ method to collections, enabling automatic conversion of model collections into API resource collections by inspecting \\#\[UseResource\]\ and \\#\[UseResourceCollection\]\ attributes on the underlying models. Additionally, the \EnumeratesValues\ trait has been updated to include \hasMany\ and \hasSole\ in its list of proxied methods, allowing these operations to be used via higher-order proxies (e.g., \$collection-\>hasMany-\>count()\).

src/Illuminate/Collections/Traits · high confidence

New console and scheduling event classes

The \src/Illuminate/Console/Events\ directory now contains a set of new event classes that signal specific moments in the command-line application lifecycle. These include \ArtisanStarting\ for when the application initializes, \CommandStarting\ and \CommandFinished\ for individual command execution (carrying input, output, and exit code data), and a suite of events for the task scheduler: \ScheduledTaskStarting\, \ScheduledTaskFinished\ (including runtime), \ScheduledTaskFailed\ (including the exception), \ScheduledTaskSkipped\, \ScheduledBackgroundTaskFinished\, \SchedulePaused\, and \ScheduleResumed\. Users can now listen to these events to monitor or react to console and scheduled task activity.

src/Illuminate/Console/Events · high confidence

New console application contracts and interfaces

This change introduces several new interfaces in the \Illuminate\\Contracts\\Console\ namespace to define the contract for the console kernel and application behavior. The new \Kernel\ interface specifies methods for bootstrapping, handling input, calling and queuing commands, retrieving command output, listing all registered commands, and terminating the application. Additionally, the \Application\ interface defines how to call commands and retrieve their output, while \Isolatable\ and \PromptsForMissingInput\ serve as marker interfaces to support isolated command execution and CLI prompting capabilities respectively.

src/Illuminate/Contracts/Console · high confidence

New console command to invoke serialized closures

A new Artisan command, \invoke-serialized-closure\, has been added to the Concurrency package. This command allows users to execute a serialized closure passed either as a command argument or via the \LARAVEL\_INVOKABLE\_CLOSURE\ environment variable (which is expected to be base64-encoded). The command outputs a JSON response indicating success or failure, including the serialized result or detailed exception information if an error occurs.

src/Illuminate/Concurrency/Console · high confidence

New console command traits for prompts, signals, and command invocation

This change introduces several new traits in the console concerns namespace to enhance command capabilities. The ConfiguresPrompts trait provides a global validation layer and fallback mechanisms for Laravel Prompts, ensuring prompts degrade gracefully on Windows or during unit tests. The InteractsWithSignals trait adds the ability to trap and handle OS signals (like SIGINT) within commands. The CallsCommands trait allows commands to invoke other Artisan commands, automatically restoring prompt state after the sub-command runs. Additionally, PromptsForMissingInput enables interactive prompting for required arguments, CreatesMatchingTest adds --test/--pest/--phpunit options to generator commands, and HasParameters refines how arguments and options are specified with improved type definitions.

src/Illuminate/Console/Concerns · high confidence

New container contracts and exception classes

The \src/Illuminate/Contracts/Container\ area now includes a comprehensive set of new interfaces and exception classes to define the service container's contract. This adds \Container.php\ (extending PSR-11 with Laravel-specific methods like \scoped\, \instance\, and \factory\), \ContextualBindingBuilder.php\ (for contextual bindings), \ContextualAttribute.php\, and \SelfBuilding.php\. It also introduces specific exception classes \BindingResolutionException\ and \CircularDependencyException\ that implement \ContainerExceptionInterface\, providing a stricter and more structured contract for container operations and error handling.

src/Illuminate/Contracts/Container · high confidence

New contracts for concurrency detection and model serialization identifiers

Added the ConcurrencyErrorDetector and LostConnectionDetector interfaces to allow applications to define custom logic for identifying database concurrency errors (such as deadlocks) and lost connections. Additionally, introduced the ModelIdentifier class to standardize how Eloquent models are serialized for queue jobs, supporting features like morph map usage for class names, storing loaded relationships, specifying the database connection, and preserving custom collection classes during serialization.

src/Illuminate/Contracts/Database · high confidence

New database inspection and management console commands

This release introduces a suite of new Artisan commands for database inspection and management, replacing older legacy implementations. The \db\ command now opens an interactive CLI session for the configured database driver, supporting read/write connection splitting and PostgreSQL pooling. The \db:show\ command displays database platform details, table counts, and optional row counts or views, while \db:table\ provides detailed schema information for specific tables, including columns, indexes, and foreign keys, with a searchable prompt for table selection. The \db:monitor\ command tracks open connections and dispatches events when thresholds are exceeded. Additionally, \schema:dump\ allows dumping the database schema to files with an optional \--prune\ flag to delete existing migrations, and \db:wipe\ safely drops all tables, views, and types. The legacy \SeedCommand\ has been removed in favor of the updated seeding infrastructure.

src/Illuminate/Database/Console · high confidence

New database query builder and connection management traits

This change introduces a suite of new traits in the \src/Illuminate/Database/Concerns\ directory to modularize database operations. The \BuildsQueries\ trait provides methods for chunking results (\chunk\, \chunkById\, \chunkByIdDesc\), mapping over chunks (\chunkMap\), and iterating (\each\). The \BuildsWhereDateClauses\ trait adds convenience methods for filtering by date relative to the current time, such as \wherePast\, \whereFuture\, \whereToday\, and their \or\ variants. The \CompilesJsonPaths\ trait handles the parsing and wrapping of JSON column paths for queries. The \ExplainsQueries\ trait adds an \explain()\ method to retrieve query execution plans. The \ManagesTransactions\ trait centralizes transaction logic, including retry handling for concurrency errors and savepoint support. Finally, the \ParsesSearchPath\ trait assists in parsing Postgres search path configurations.

src/Illuminate/Database/Concerns · high confidence

New database seeding commands and traits

This change introduces the \db:seed\ command, which seeds the database with records, supports specifying a root seeder class or database connection, reports progress for non-default seeders, and restores the previous database connection upon failure. It also adds the \make:seeder\ command to generate new seeder classes, placing them in the \database/seeders\ directory (or \database/seeds\ if that directory exists), and includes the \WithoutModelEvents\ trait to allow running seeders without dispatching Eloquent model events.

src/Illuminate/Database/Console/Seeds · high confidence

New dedicated exception classes for process failures and timeouts

The Process component now includes specific exception classes to handle process execution issues more precisely. \ProcessFailedException\ is introduced to wrap failed process results, ensuring that command output and error output are included in the exception message for easier debugging. Additionally, \ProcessTimedOutException\ and its subclass \ProcessIdleTimedOutException\ provide structured handling for process timeouts, allowing developers to distinguish between idle timeouts and general execution timeouts while retaining access to the original Symfony exception and the process result.

src/Illuminate/Process/Exceptions · high confidence

New default HTTP error page views for Laravel

The framework now ships with a set of default Blade templates for common HTTP error codes (401, 402, 403, 404, 419, 429, 500, and 503) located in \src/Illuminate/Foundation/Exceptions/views\. These views utilize a new \minimal.blade.php\ layout that provides a clean, responsive design with dark mode support, replacing the previous default error page implementations. The 403 view specifically includes logic to display the exception message when available, improving clarity for users encountering authorization failures.

src/Illuminate/Foundation/Exceptions/views · high confidence

New email verification request handler and default user model

The framework now includes a dedicated \EmailVerificationRequest\ class in \src/Illuminate/Foundation/Auth\ to handle email verification logic, providing methods to authorize the request by validating user ID and hash, and to fulfill the verification by marking the email as verified and firing the \Verified\ event. Additionally, a default \User\ model is introduced in the same directory, implementing standard authentication, authorization, and password reset contracts while including the \MustVerifyEmail\ trait to enforce email verification requirements.

src/Illuminate/Foundation/Auth · high confidence

New event classes and event discovery infrastructure

This change introduces several new event classes to the framework's foundation, including DiagnosingHealth, Terminating, MaintenanceModeEnabled, MaintenanceModeDisabled, VendorTagPublished, and PublishingStubs, alongside an updated LocaleUpdated event that now tracks the previous locale. It also adds the Dispatchable trait, providing static dispatchIf, dispatchUnless, and broadcast methods for event classes, and introduces the DiscoverEvents class to handle automatic event listener discovery from directories, supporting custom class name guessing and filtering non-instantiable classes.

src/Illuminate/Foundation/Events · high confidence

New event dispatcher contracts and discovery markers introduced

The framework now exposes formal contracts for the event system, adding the \Illuminate\\Contracts\\Events\\Dispatcher\ interface which defines the standard methods for listening, subscribing, dispatching, and managing queued events. Additionally, new marker interfaces \ShouldBeDiscovered\, \ShouldDispatchAfterCommit\, and \ShouldHandleEventsAfterCommit\ are provided to allow event listeners to opt into auto-discovery and control whether they should be dispatched or handled after a database transaction commits.

src/Illuminate/Contracts/Events · high confidence

New fluent validation rule builders and conditional rules

The validation rules in this namespace have been modernized with new object-oriented builders that replace string-based syntax with a fluent interface. New rules include \AnyOf\ (validating against multiple rule sets), \ArrayKeys\ (validating array keys), \Contains\ and \DoesntContain\ (checking for value presence), \Can\ (authorization checks), and \Date\ (with methods like \beforeToday\ and \past\). Existing rules like \Email\, \File\, \Numeric\, and \Password\ now offer fluent methods for configuration (e.g., \File::image()\, \Numeric::integer()\). Additionally, conditional rules \ExcludeIf\, \ProhibitedIf\, and \RequiredIf\ allow dynamic validation based on boolean conditions or closures.

src/Illuminate/Validation/Rules · high confidence

New health check UI and built-in PHP server script

The framework now includes a styled health check view (\health-up.blade.php\) that displays the application status, name, and response time using Tailwind CSS, replacing the previous plain text output. Additionally, a new \server.php\ file is provided to emulate Apache's mod\_rewrite functionality, allowing developers to easily test Laravel applications using the built-in PHP web server without external web server software.

src/Illuminate/Foundation/resources · high confidence

New illuminate/reflections component with lazy object helpers

A new \illuminate/reflections\ package has been introduced, extracted from \illuminate/support\. This component provides a \Reflector\ utility class for advanced reflection tasks, including a PHP 7.4-compatible \isCallable\ check, retrieving class attributes with inheritance support, and analyzing parameter types (including union types and backed enums). Additionally, it introduces two global helper functions: \lazy()\, which creates lazy-initialized object instances using PHP's lazy ghost objects, and \proxy()\, which creates lazy proxy instances. The package also includes standard distribution files like \.gitattributes\ and \LICENSE.md\.

src/Illuminate/Reflection · high confidence

New in-memory maintenance mode driver for parallel testing

The framework now includes an \ArrayMaintenanceMode\ implementation that stores maintenance state in memory rather than on disk. This allows applications to run parallel tests without file-locking conflicts or the need for a shared filesystem, providing a faster and more reliable maintenance mode state for isolated test environments.

src/Illuminate/Foundation · high confidence

New job dispatching traits and pending dispatch classes

This change introduces the \Dispatchable\ trait and \DispatchesJobs\ trait to the \src/Illuminate/Foundation/Bus\ directory, providing static and instance methods for dispatching jobs (including \dispatch\, \dispatchSync\, \dispatchIf\, \dispatchUnless\, and \withChain\). It also adds \PendingDispatch\, \PendingChain\, and \PendingClosureDispatch\ classes to handle the configuration and execution of queued jobs, supporting features like chaining, conditional dispatching, connection/queue selection, and post-response dispatching.

src/Illuminate/Foundation/Bus · high confidence

New mail transport implementations for Resend, Cloudflare, SES, and debugging

This change introduces several new mail transport classes to the \src/Illuminate/Mail/Transport\ directory, expanding the available email delivery options. It adds \ResendTransport\ for sending emails via the Resend API, \CloudflareTransport\ for Cloudflare Email Service, and dedicated transports for Amazon SES (\SesTransport\ for the V1 API and \SesV2Transport\ for the V2 API), including support for SES list management options and tenant names. Additionally, it provides \ArrayTransport\ for storing sent messages in memory (useful for testing) and \LogTransport\ for logging raw email content to the application logger.

src/Illuminate/Mail/Transport · high confidence

New marker interface for authentication middleware

A new \AuthenticatesRequests\ marker interface has been added to the \Illuminate\\Contracts\\Auth\\Middleware\ namespace. This interface serves as a type hint for middleware classes that handle request authentication, allowing for more specific type checking and dependency injection within the framework's authentication system.

src/Illuminate/Contracts/Auth/Middleware · high confidence

New notification lifecycle events for broadcasting and delivery tracking

The notification system now exposes specific events for key moments in the notification lifecycle, allowing applications to react to broadcasting, sending, success, failure, and skipping. BroadcastNotificationCreated handles channel resolution and data preparation for WebSocket/Pusher broadcasts, supporting custom channel names and broadcast types. NotificationSent fires after a notification is successfully delivered and includes the channel's response data. NotificationFailed captures delivery errors with context about the channel and failure data. NotificationSkipped indicates when a notification was not sent to a recipient. NotificationSending fires before delivery attempts. All events implement Queueable and SerializesModels traits for safe queueing.

src/Illuminate/Notifications/Events · high confidence

New pagination view templates for Bootstrap 3/4/5, Tailwind, and Semantic UI

The pagination resources now include dedicated Blade view templates for Bootstrap 3, Bootstrap 4, Bootstrap 5, Tailwind CSS, and Semantic UI, alongside their respective 'simple' variants. These views provide framework-specific styling and structure for pagination controls, including responsive layouts, dark mode support (Tailwind), and accessibility improvements like ARIA labels and semantic navigation elements.

src/Illuminate/Pagination/resources · high confidence

New queue driver implementations and AWS credential caching

The queue component introduces several new queue driver classes: BackgroundQueue (defers jobs to a process-based concurrency driver), DeferredQueue (defers jobs to the global defer mechanism), and FailoverQueue (routes jobs to a primary connection with fallback logic). Additionally, a new AwsCredentialCache class is added to share and cache AWS credentials across worker processes using a distributed lock, and the existing DatabaseQueue driver is updated to support enum-based queue names and provides detailed job inspection metrics (pending, delayed, reserved, and total sizes).

src/Illuminate/Queue · high confidence

New queue job attributes for configuration

This location introduces a suite of new PHP attributes to configure queued jobs declaratively. The \Backoff\ attribute allows specifying retry delays, while \Connection\ and \Queue\ attributes now support both string values and PHP enums for type-safe configuration. Additional attributes include \DebounceFor\ for debouncing, \Delay\ for initial job delays, \DeleteWhenMissingModels\ to auto-delete jobs when referenced models are gone, \FailOnTimeout\ and \Timeout\ for execution limits, \MaxExceptions\ for failure thresholds, \Tries\ for retry counts, \UniqueFor\ for job uniqueness, and \WithoutRelations\ to control model serialization. A \ReadsQueueAttributes\ trait is also provided to help classes read these attribute values.

src/Illuminate/Queue/Attributes · high confidence

New queue middleware for conditional skipping, releasing, and exception handling

This update introduces several new job middleware classes to \src/Illuminate/Queue/Middleware\ that give developers finer control over job execution flow. The \Skip\ and \SkipIfBatchCancelled\ middleware allow jobs to be conditionally bypassed or skipped entirely if a batch has been cancelled. The \Release\ middleware enables jobs to be released back onto the queue based on a boolean condition or closure. Additionally, \FailOnException\ allows jobs to be explicitly marked as failed if a specific exception type is thrown, while \ThrottlesExceptions\ and \ThrottlesExceptionsWithRedis\ provide advanced rate-limiting for jobs that throw exceptions, supporting custom callbacks for reporting, deleting, or failing jobs based on the exception. The \RateLimited\ and \RateLimitedWithRedis\ middleware are also present, offering configurable rate limiting with options to release jobs after a delay or prevent release entirely.

src/Illuminate/Queue/Middleware · high confidence

New rate-limiting classes and fluent builder methods

The rate-limiting component now includes dedicated classes for global limits (GlobalLimit) and unlimited access (Unlimited), alongside a refactored Limit class. This introduces a fluent API allowing developers to define limits with per-second, per-minute, per-hour, and per-day decay windows, set custom keys, attach an 'after' callback for side effects, and provide a custom response generator when limits are exceeded.

src/Illuminate/Cache/RateLimiting · high confidence

New release, split, and test scripts for Laravel 13.x

The repository now includes three new executable scripts in the bin directory to support the Laravel 13.x release cycle. The release.sh script automates tagging the main framework and all illuminate components, enforcing that version tags are prefixed with 'v' and ensuring the working directory is clean and up-to-date. The split.sh script manages the synchronization of code changes from the main repository into individual component repositories (such as auth, cache, and database) using splitsh-lite. Additionally, test.sh provides a local testing environment by spinning up Docker containers for MySQL, Redis, and DynamoDB, running PHPUnit tests against PHP 8.3 by default.

bin · high confidence

New routing and response factory contracts introduced

The framework now exposes formal interfaces for core routing and response capabilities, allowing for better decoupling and testing. New contracts include \BindingRegistrar\ and \Registrar\ to define route registration and model binding logic, \ResponseFactory\ to standardize the creation of various HTTP responses (including JSON, views, streams, and downloads), \UrlGenerator\ to abstract URL generation and route resolution, and \UrlRoutable\ to standardize how models participate in route binding.

src/Illuminate/Contracts/Routing · high confidence

New routing middleware for bindings, throttling, and signature validation

This change introduces the core routing middleware classes for the application. The SubstituteBindings middleware now handles route model binding, including implicit bindings and custom missing-model callbacks. The ThrottleRequests middleware provides rate limiting capabilities, supporting named limiters, enum-based configurations, and customizable response callbacks, while the ThrottleRequestsWithRedis variant offers distributed rate limiting via Redis. Additionally, the ValidateSignature middleware has been added to verify signed URLs, supporting both absolute and relative URL signatures with configurable ignored parameters.

src/Illuminate/Routing/Middleware · high confidence

New schema state and definition classes for dump/load operations

The schema builder now includes new classes to manage database schema dumps and loads. \SchemaState\ serves as the abstract base for database-specific implementations, with new concrete classes for MySQL (\MySqlSchemaState\), MariaDB (\MariaDbSchemaState\), PostgreSQL (\PostgresSchemaState\), and SQLite (\SqliteSchemaState\). These classes handle the underlying command-line tools (like \mysqldump\, \pg\_dump\, \sqlite3\) to export and import schema definitions. Additionally, new meta classes \ColumnDefinition\, \ForeignKeyDefinition\, and \IndexDefinition\ provide structured representations of schema elements, and \BlueprintState\ captures the current state of a blueprint for synchronization.

src/Illuminate/Database/Schema · high confidence

New session concurrency limiting and session authentication middleware

This change introduces two new session middleware components. The \AuthenticateSession\ middleware enhances security by validating the user's password hash stored in the session against the current password hash, logging out the user if they mismatch (e.g., after a password change) or if the remember-me cookie is invalid. The \StartSession\ middleware now supports route-level concurrency limiting via a new \locksFor()\ method on routes, allowing developers to configure locks that prevent concurrent requests from the same session from executing simultaneously, thereby reducing race conditions and resource contention.

src/Illuminate/Session/Middleware · high confidence

New support traits introduced for capsule management, data interaction, and object handling

This change introduces several new traits in the \Illuminate\\Support\\Traits\ namespace to enhance framework capabilities. \CapsuleManagerTrait\ provides a reusable mechanism for managing global IoC container instances. \InteractsWithData\ adds a comprehensive suite of methods for data access, validation, and conditional callbacks, including new support for PHP enums (\whenEnum\, \whenFilledEnum\) and SQL Server DSN parsing via \ParsesSqlServerConfigurationUrls\. \ForwardsCalls\ standardizes method forwarding with improved error handling for undefined methods, while \Dumpable\ and \Tappable\ offer convenient debugging and chaining helpers (\dd\, \dump\, \tap\). Additionally, \Localizable\ enables temporary locale switching for callbacks, and \ReadsClassAttributes\ allows reading configuration from class attributes with property override support.

src/Illuminate/Support/Traits · high confidence

New testing concern traits for authentication, console, database, and HTTP requests

This change introduces a suite of new testing concern traits in \src/Illuminate/Foundation/Testing/Concerns\ to streamline application testing. The \InteractsWithAuthentication\ trait provides methods like \actingAs\ and \assertAuthenticated\ for managing user sessions. \InteractsWithConsole\ adds the \artisan\ helper for invoking and mocking Artisan commands. \InteractsWithDatabase\ introduces assertions such as \assertDatabaseHas\, \assertDatabaseMissing\, \assertDatabaseCount\, and \assertSoftDeleted\ for verifying database state. \MakesHttpRequests\ offers a comprehensive API for simulating HTTP requests, including setting headers, cookies, and following redirects. Additional traits like \InteractsWithContainer\ (for mocking and spying), \InteractsWithTime\ (for freezing and traveling through time), \InteractsWithViews\ (for rendering Blade templates and components), \InteractsWithSession\ (for managing session data), \InteractsWithRedis\ (for Redis integration tests), \InteractsWithExceptionHandling\ (for controlling exception handling behavior), \InteractsWithDeprecationHandling\ (for managing deprecation warnings), and \InteractsWithTestCaseLifecycle\ (for managing setup and teardown hooks) are also added, providing a robust foundation for writing unit and feature tests.

src/Illuminate/Foundation/Testing/Concerns · high confidence

New testing concerns for HTTP status assertions and parallel test isolation

This change introduces several new traits in the \src/Illuminate/Testing/Concerns\ directory to enhance testing capabilities. The \AssertsStatusCodes\ trait provides a comprehensive set of shorthand methods for asserting HTTP response status codes (such as \assertOk\, \assertNotFound\, \assertMethodNotAllowed\, etc.), allowing developers to write more readable and concise tests. Additionally, new traits \RunsInParallel\, \TestCaches\, \TestDatabases\, and \TestViews\ are added to support parallel testing execution. These traits handle process isolation by managing unique cache prefixes, database names, and compiled view paths per test process, ensuring that parallel test runs do not interfere with each other's state.

src/Illuminate/Testing/Concerns · high confidence

New validation rule abstractions and precognition support

The validation component introduces several new classes to support more expressive and structured validation logic. ClosureValidationRule and InvokableValidationRule provide wrappers for closure-based and invokable rule objects, enabling custom validation logic with better integration into the validator lifecycle. ConditionalRules and the Rule::when()/unless() methods allow rules to be applied conditionally based on other data. NestedRules (accessed via Rule::forEach()) enables defining validation rules for nested array structures. Additionally, ValidatesWhenResolvedTrait adds support for precognition by integrating authorization checks and validation hooks during class resolution, while FakeDnsGetRecordWrapper allows faking DNS lookups for email validation in tests.

src/Illuminate/Validation · high confidence

New validation rules and email validation improvements

This update introduces several new validation rules including \uppercase\, \base64\, \encoding\, \in\_array\_keys\, \doesnt\_contain\, \list\, \has\, \HEIC/AVIF\ image support, and \decimal\ shape validation. It also adds conditional rules like \accepted\_if\, \declined\_if\, \prohibited\_if\, and \prohibited\_unless\. Email validation now supports unicode characters via the \email:filter\_unicode\ option and uses the Egulias/EmailValidator library for stricter RFC compliance. Additionally, the \distinct\ rule can now ignore case, and the \url\ rule accepts underscores and additional protocols.

src/Illuminate/Validation/Concerns · high confidence

Queued event listeners now support debouncing, uniqueness, and after-commit execution

The event dispatcher in src/Illuminate/Events has been significantly refactored to support advanced queueing behaviors. Listeners can now be marked as debounced or unique (including unique until processing) via new properties and attributes on the CallQueuedListener job. A new QueuedClosure class and queueable() helper allow closures to be queued with custom connection, queue, delay, and deduplication settings. Additionally, the Dispatcher now supports dispatching listeners after database transactions commit, and the EventServiceProvider registers the queue and transaction resolvers to enable these features.

src/Illuminate/Events · high confidence

Refactored testing infrastructure with new traits and caching support

The testing foundation has been restructured to improve performance and modularity. New traits \WithCachedRoutes\ and \WithCachedConfig\ allow tests to cache compiled routes and configuration, significantly speeding up test suites. Database management is now handled by distinct traits (\RefreshDatabase\, \DatabaseMigrations\, \DatabaseTruncation\, \LazilyRefreshDatabase\), offering more granular control over database state. The \TestCase\ class has been modernized to use PHPUnit's native \TestCase\ and delegates functionality to focused concern traits (e.g., \InteractsWithDatabase\, \MakesHttpRequests\). Additionally, the \Wormhole\ class now supports time travel with microsecond precision, and the legacy \Client\ class has been removed.

src/Illuminate/Foundation/Testing · high confidence

Repository initialization with standardized configuration files

The repository is initialized with a set of configuration files that standardize development and distribution. An \.editorconfig\ enforces consistent coding styles (UTF-8, LF line endings, 4-space indentation for PHP, 2-space for YAML). A \.gitattributes\ file defines diff drivers for code files and excludes development-only directories (\.github\, \/bin\, \/tests\, \/types\) and configuration files (\.editorconfig\, \CHANGELOG.md\, \pint.json\, etc.) from source distributions via \export-ignore\. A \.styleci.yml\ file configures code style checks for PHP 8.2 using the Laravel preset. A \pint.json\ file configures the Laravel Pint code style fixer with specific rules. A \rector.php\ file configures static analysis and refactoring rules using Rector. A \phpunit.xml.dist\ file sets up the PHPUnit test suite with specific extensions and environment variables. A \docker-compose.yml\ file provides local development services for DynamoDB, Memcached, MySQL, and Redis. A \phpstan.src.neon.dist\ and \phpstan.types.neon.dist\ configure PHPStan static analysis at different levels for source and type files. A \LICENSE.md\ file contains the MIT license text. A \README.md\ file provides project information and links. A \RELEASE.md\ file documents the release process. The old \phpunit.xml\ file is removed.

(repo-wide) · high confidence

View rendering logic extracted into dedicated concern traits

The view rendering logic previously contained in the View factory has been refactored into a set of dedicated concern traits (ManagesComponents, ManagesEvents, ManagesFragments, ManagesLayouts, ManagesLoops, ManagesStacks, ManagesTranslations). This change introduces new capabilities for Blade templates, including support for view components with slot attributes, template fragments, and enhanced loop variables (even/odd flags), while also improving the handling of view composers and section management.

src/Illuminate/View/Concerns · high confidence

Removals

Removal of legacy ControllerGenerator class

The \ControllerGenerator\ class, previously responsible for generating resourceful controller files by combining a base stub with method stubs (such as index, create, store, etc.) based on options like 'only' or 'except', has been deleted. This change removes the specific code path that handled the creation of these controller files via this generator, likely as part of a broader routing or code-generation refactoring.

src/Illuminate/Routing/Generators · high confidence

Removal of legacy Illuminate and Pheanstalk components

The \src/Illuminate\ and \src/Pheanstalk\ directories have been completely removed from the codebase. This deletes the legacy \Illuminate\ container, cookie jar, encrypter, and filesystem classes, as well as the entire \Pheanstalk\ beanstalkd client library (including its connection, command, and response handling logic). Applications relying on these specific legacy implementations for dependency injection, encryption, file operations, or beanstalkd queue interactions will lose this functionality.

src/Illuminate, src/Pheanstalk · high confidence

Removal of legacy Workbench package scaffolding classes

The \Package\, \PackageCreator\, and \Starter\ classes within the \src/Illuminate/Workbench\ directory have been removed. This eliminates the legacy functionality for automatically generating package directory structures (including support files, tests, and service providers) and the manual autoload mechanism for workbench packages, effectively stripping out the old package scaffolding and starter tools from the framework.

src/Illuminate/Workbench · high confidence

Removal of legacy controller and update method stubs

The legacy controller stubs located in the routing generators have been removed. Specifically, the generic \controller.php\ stub (which previously extended \BaseController\) and the \update.php\ stub (containing the standard update method signature) are no longer present. This change eliminates these specific template files from the codebase, likely reflecting a shift in how resource controllers or specific HTTP methods are generated or managed in newer versions of the framework.

src/Illuminate/Routing/Generators/stubs · high confidence

Removal of legacy exception handling service provider and handler

The \ExceptionServiceProvider\ and \Handler\ classes in \src/Illuminate/Exception\ have been removed. This eliminates the previous mechanism for registering custom exception handlers via closures and the service container, as well as the automatic conversion of PHP errors to \ErrorException\s via the Symfony \ErrorHandler\. Users relying on the old \App::error()\ or \$app\['exception'\]\ patterns must migrate to the current framework exception handling implementation.

src/Illuminate/Exception · high confidence

Removal of legacy helper functions from src/helpers.php

The file src/helpers.php has been deleted, removing a set of legacy PHP helper functions including array manipulation utilities (such as array\_dot, array\_except, array\_get, array\_only, array\_pluck) and application helpers (such as app, action, app\_path). Users relying on these global functions for array processing or application instance access will need to update their code to use alternative methods or frameworks.

src · high confidence

Removal of the 'workbench' console command

The 'workbench' Artisan command, previously used to scaffold new package workbenches with interactive prompts for vendor and package names, has been removed from the framework. Users can no longer generate workbench structures via this specific CLI tool.

src/Illuminate/Workbench/Console · high confidence

Removed legacy Bootstrap pagination view templates

The legacy Bootstrap-based pagination view templates (\simple.php\ and \slider.php\) have been removed from the pagination component. These files previously rendered pagination controls using the \BootstrapPresenter\ and specific CSS classes (\pagination\, \pager\). Users relying on these specific view files for custom pagination styling will need to update their configuration or provide alternative view implementations.

src/Illuminate/Pagination/views · high confidence

Architecture

Blade compiler concerns are reorganized into dedicated traits

The Blade compiler implementation has been refactored by splitting the monolithic compiler class into a set of focused concern traits (e.g., CompilesComponents, CompilesConditionals, CompilesStacks, CompilesEchos). This structural change improves code maintainability and modularity without altering the user-facing Blade syntax or compilation behavior.

src/Illuminate/View/Compilers/Concerns · high confidence

Collections extracted to a standalone package

The \Illuminate\\Support\\Collection\, \LazyCollection\, \Arr\ helper, and related utilities have been moved into a dedicated \illuminate/collections\ package. This structural change allows developers to use the collection functionality independently of the full Laravel framework, and includes the \Enumerable\ interface, \HigherOrderCollectionProxy\, and helper functions like \collect()\, \data\_get()\, and \data\_set()\ as part of this new standalone component.

src/Illuminate/Collections · high confidence

Extract Conditionable traits into a standalone package

The Conditionable functionality has been split out from the main framework into a dedicated, standalone package. This change introduces the \HigherOrderWhenProxy\ class, which enables conditional method and property chaining on target objects, and includes standard package files such as the MIT license and git attributes to support its independent distribution.

src/Illuminate/Conditionable · high confidence

Mail component rewritten to use Symfony Mailer

The \src/Illuminate/Mail\ component has been completely rewritten to replace the deprecated SwiftMailer with Symfony Mailer. This architectural shift introduces new core classes such as \MailManager\, \Mailable\, and \Attachment\, and updates the \MailServiceProvider\ to register the new Symfony-based transport factory. Existing code relying on SwiftMailer-specific APIs will need to be updated to use the new Symfony Mailer interfaces and the new \Attachment\ abstraction for handling file attachments.

src/Illuminate/Mail · high confidence

Query builder refactored to use traits and modern PHP syntax

The query builder in src/Illuminate/Database/Query has been significantly refactored to improve code structure and type safety. The Builder class now implements the BuilderContract and uses traits like BuildsQueries and BuildsWhereDateClauses to organize functionality, replacing the previous monolithic structure. The Expression class now implements ExpressionContract and uses constructor property promotion, while JoinClause extends Builder to inherit query-building capabilities, allowing for more complex join conditions. New classes IndexHint and JoinLateralClause have been added to support advanced database features.

src/Illuminate/Database/Query · high confidence

Refactor HTTP request handling into modular concerns

The HTTP request handling logic in the \Illuminate\\Http\\Concerns\ directory has been reorganized into distinct, reusable traits: \CanBePrecognitive\ for precognition support, \InteractsWithContentTypes\ for content negotiation (JSON, Markdown, HTML), \InteractsWithFlashData\ for session flash data, and \InteractsWithInput\ for input retrieval. This change extracts specific capabilities from the main Request class into focused components, improving code modularity and maintainability without altering the external API surface for existing users.

src/Illuminate/Http/Concerns · high confidence

View contract interfaces moved to the Contracts namespace

The core view interfaces (Factory, View, Engine) and the ViewCompilationException have been relocated from the implementation namespace (Illuminate\\View\\Engines) to the contracts namespace (Illuminate\\Contracts\\View). This change establishes a clear separation between the framework's view rendering logic and its public API contracts, allowing developers to type-hint against these interfaces for better decoupling and testability.

src/Illuminate/Contracts/View · high confidence

Behavioural changes

Add terminate method to HTTP Kernel contract

The HTTP Kernel contract now includes a \terminate\ method, allowing developers to perform final actions after an HTTP request lifecycle is complete. This enables the execution of terminating middleware and other cleanup tasks that occur after the response has been sent to the client.

src/Illuminate/Contracts/Http · high confidence

Authentication events converted to modern PHP classes

The authentication event classes in src/Illuminate/Auth/Events have been refactored to use PHP 8+ promoted properties and the SerializesModels trait where appropriate. This change standardizes the event structure across the authentication system, ensuring consistent serialization behavior for user models and simplifying the constructor signatures for events such as Login, Logout, Authenticated, Failed, and Verified.

src/Illuminate/Auth/Events · high confidence

Authentication system refactored to use modern interfaces and traits

The authentication component has been significantly restructured to align with modern Laravel standards. The legacy \Guard\ class and \UserProviderInterface\ have been removed and replaced with a trait-based architecture (\GuardHelpers\) and the \UserProvider\ interface. New dedicated guard implementations (\SessionGuard\, \RequestGuard\, \TokenGuard\) now handle specific authentication scenarios, while the \AuthManager\ has been updated to support custom driver closures and enum-based guard names. Additionally, the \Authenticatable\ trait and \MustVerifyEmail\ trait provide standardized methods for user identification and email verification, and the \Recaller\ class now securely handles remember-me cookies using password hashing.

src/Illuminate/Auth · high confidence

Backed Enum support and ability name guessing in authorization traits

The Authorizable trait now accepts UnitEnum values in addition to strings for ability checks (can, canAny, cant, cannot), allowing users to pass PHP backed enums directly to authorization methods. In the AuthorizesRequests trait, the authorize and authorizeForUser methods now automatically guess the ability name from the calling method if a non-string ability is provided, normalizing controller actions like 'index' to 'viewAny' and 'destroy' to 'delete' via the resourceAbilityMap. This simplifies authorization in controllers by reducing the need to explicitly specify ability names for standard resource actions.

src/Illuminate/Foundation/Auth/Access · high confidence

Blade view compilation refactored with xxh128 hashing and new ComponentTagCompiler

The Blade view compiler has been significantly updated to improve performance and support modern component syntax. Compiled view file names now use the faster xxh128 hash algorithm instead of md5, and the \Compiler\ base class now supports configurable cache paths, base paths, and view cache timestamp checking. A new \ComponentTagCompiler\ class has been introduced to handle the compilation of Blade component tags (e.g., \\<x-\*\>\) and slots, separating this logic from the main \BladeCompiler\. The \BladeCompiler\ itself has been modernized with stricter typing, updated docblocks, and a more robust compilation pipeline that integrates with the new component tag compiler.

src/Illuminate/View/Compilers · high confidence

Cache contracts updated to support enums, PSR-16, and lock management

The cache contract interfaces have been expanded to support modern PHP features and more granular control. The Repository interface now accepts UnitEnum values for cache keys, allows flexible TTL inputs (DateTimeInterface, DateInterval, or int), and includes new methods like touch() for TTL extension, pull(), and sear(). The Store interface adds many() and putMany() for batch operations. Additionally, new contracts (CanFlushLocks, Lock, LockProvider) and a LockTimeoutException have been introduced to provide robust distributed locking capabilities, including the ability to flush all locks and restore locks by owner.

src/Illuminate/Contracts/Cache · high confidence

Concurrency driver interface now supports timeouts and deferred execution

The \Illuminate\\Contracts\\Concurrency\\Driver\ interface has been updated to include a \$timeout\ parameter in the \run\ method, allowing concurrent tasks to be limited by a specified duration, and a new \defer\ method that returns a \DeferredCallback\ for scheduling tasks to run later.

src/Illuminate/Contracts/Concurrency · high confidence

Configuration system refactored with new loader interface and repository changes

The configuration component has undergone significant structural changes. The \FileLoader\ and \LoaderInterface\ classes have been removed, indicating a shift away from the previous file-based loading mechanism. The \Repository\ class has been updated to no longer extend \NamespacedItemResolver\ and now implements \ArrayAccess\ directly, simplifying its inheritance hierarchy. Additionally, a \.gitattributes\ file and \LICENSE.md\ have been added to the component directory to manage exports and licensing.

src/Illuminate/Config · medium confidence

The cookie subsystem has been restructured to improve security and configuration flexibility. A new \CookieValuePrefix\ class introduces HMAC-based value signing for cookies, replacing the previous encryption-based approach. The \CookieJar\ now supports the SameSite attribute (defaulting to 'lax') and allows cookies to be queued by both name and path, enabling distinct cookies with the same name. Additionally, the \CookieServiceProvider\ now registers the cookie jar using the session configuration settings for path, domain, and secure flags, and the service provider class has been renamed from \EncryptionServiceProvider\ to \CookieServiceProvider\.

src/Illuminate/Cookie · high confidence

Database connector refactoring and enhanced configuration support

The database connectors have been refactored to support more granular configuration and improved connection handling. The base Connector class now uses PDO::CASE\_NATURAL by default and includes automatic retry logic for lost connections. MySQL and SQL Server connectors now support configuring transaction isolation levels, while PostgreSQL connectors support isolation levels, timezones, synchronous commit settings, and SSL/keepalive options in the DSN. SQLite connectors now support configuring pragmas (foreign keys, busy timeout, journal mode, synchronous mode) and handle relative paths and in-memory databases more robustly. A new MariaDbConnector class extends MySQL with specific sql\_mode handling. The ConnectionFactory now supports pooled PostgreSQL connections with direct endpoints and read/write separation.

src/Illuminate/Database/Connectors · high confidence

Database events refactored into dedicated classes with expanded capabilities

The database event system has been restructured so that every event (such as connection, migration, transaction, query, and schema events) is now a dedicated class in the \Illuminate\\Database\\Events\ namespace, replacing previous array or simple object patterns. This change introduces new event types including \ConnectionEstablished\, \MigrationSkipped\, \NoPendingMigrations\, \StatementPrepared\, \SchemaDumped\, and \SchemaLoaded\, while enhancing existing ones: \QueryExecuted\ now exposes a \readWriteType\ property and a \toRawSql()\ method, and migration events (\MigrationStarted\, \MigrationEnded\, etc.) now carry the migration name and method details. Users listening to these events will receive richer, strongly-typed objects with additional context about the database operation.

src/Illuminate/Database/Events · high confidence

Default queue connection and name resolution via class type

The queue system now supports resolving the default connection and queue name for a job based on its class type. A new \ResolvesQueueRoutes\ trait has been added to \src/Illuminate/Support/Queue/Concerns/\, providing methods to look up these defaults from a central \QueueRoutes\ manager. This allows jobs to automatically use configured default queues without requiring explicit configuration on every job instance.

src/Illuminate/Support/Queue · high confidence

Eloquent model concerns refactored into traits with attribute-based configuration

The Eloquent model concerns in src/Illuminate/Database/Eloquent/Concerns have been restructured into individual traits (GuardsAttributes, HasAttributes, HasEvents, HasGlobalScopes, HasRelationships, HasTimestamps, HasUlids, HasUniqueIds, HasUniqueStringIds, HasUuids, HasVersion4Uuids, HidesAttributes) that are initialized via the \#\[Initialize\] attribute and support class-level attributes like \#\[Fillable\], \#\[Guarded\], \#\[Hidden\], \#\[Visible\], \#\[ScopedBy\], \#\[ObservedBy\], \#\[Touches\], \#\[WithoutTimestamps\], and \#\[Table\]. This allows developers to configure mass assignment guards, hidden/visible attributes, global scopes, observers, touched relationships, and timestamp behavior directly on model classes using PHP attributes instead of relying solely on protected properties, while preserving the existing public API methods for runtime configuration.

src/Illuminate/Database/Eloquent/Concerns · high confidence

Eloquent models now automatically refresh configured attributes after writes

When saving a model, Eloquent now automatically refreshes the model's attributes to reflect any database-side defaults, computed columns, or triggers that may have modified the data during the insert or update operation. This ensures that the in-memory model state remains consistent with the database without requiring manual calls to \refresh()\ or \fresh()\.

src/Illuminate/Database/Eloquent · high confidence

Encryption component introduces GCM support, key rotation, and strict validation

The \Encrypter\ class now supports AES-GCM ciphers (aes-128-gcm, aes-256-gcm) alongside existing CBC modes, enabling authenticated encryption. It adds support for key rotation via a \previousKeys\ configuration, allowing decryption of values encrypted with older keys. The implementation enforces strict validation of key lengths and cipher names, throws specific exceptions for missing keys (\MissingAppKeyException\) or invalid MACs, and marks sensitive parameters with the \\#\[SensitiveParameter\]\ attribute to prevent secret leakage in logs. The \EncryptionServiceProvider\ registers the encrypter and configures the \SerializableClosure\ security key.

src/Illuminate/Encryption · high confidence

Enhanced IDE integration and source resolution for dump debugging

The ResolvesDumpSource trait now supports a wider range of IDEs for clickable debug links, adding editors such as Windsurf, Neovim, Fleet, Cursor, Kiro, and Google's Antigravity. It also improves source resolution accuracy by handling compiled view files more robustly and allowing the application's base path to be configured as an empty string, ensuring correct file paths are generated in the dump output.

src/Illuminate/Foundation/Concerns · high confidence

Extracted queue argument parsing into a reusable trait

The queue console commands now utilize a new \ParsesQueue\ trait to handle the parsing of queue arguments. This trait standardizes how queue arguments are split into connection and queue name components, ensuring consistent behavior across queue-related console commands by defaulting to the configured default connection and 'default' queue name when specific values are not provided.

src/Illuminate/Queue/Console/Concerns · high confidence

Foundation service providers consolidated and modernized

The framework's service provider structure has been reorganized to improve modularity and performance. A new ConsoleSupportServiceProvider aggregates the Artisan, Migration, and Composer providers, while the PublisherServiceProvider has been removed as its functionality is no longer needed. The ArtisanServiceProvider has been significantly expanded to register a comprehensive list of console commands directly, replacing the previous single-artisan binding. Additionally, the CookieServiceProvider has been renamed and repurposed as FormRequestServiceProvider to handle form request validation and resolution logic, and several providers now implement the DeferrableProvider interface to support deferred loading.

src/Illuminate/Foundation/Providers · high confidence

HTTP client response status helpers extracted to trait

The HTTP client now provides a set of convenience methods for checking response status codes, such as \ok()\, \notFound()\, \unprocessableContent()\, and \notModified()\. These methods are implemented in the new \DeterminesStatusCode\ trait, which allows classes to easily determine if a response matches specific HTTP status codes (e.g., 200, 404, 422) without manually comparing the status integer. The \unprocessableEntity()\ method is also available as an alias for \unprocessableContent()\ for backward compatibility.

src/Illuminate/Http/Client/Concerns · high confidence

Hasher contract adds info method and marks sensitive parameters

The Hasher contract in the Hashing component now includes an info method to retrieve details about a hashed value, alongside the existing make, check, and needsRehash methods. Additionally, the value parameters for make and check are marked with the SensitiveParameter attribute to help prevent accidental logging of sensitive data.

src/Illuminate/Contracts/Hashing · high confidence

Hashing component refactored to use HashManager with Argon2id support and algorithm verification

The hashing subsystem has been restructured to use a driver-based \HashManager\ instead of a direct \BcryptHasher\ binding, enabling the use of Argon2i and the new Argon2id algorithms alongside Bcrypt. The \HashServiceProvider\ now registers the manager as a deferrable singleton, and the \HasherInterface\ has been removed in favor of the \Hasher\ contract. All hashers now extend \AbstractHasher\, which centralizes null/empty checks and uses PHP's \password\_verify\ for consistency. A new \isHashed\ method on the manager allows users to check if a string is already hashed, and \needsRehash\ is available on individual hashers to detect when parameters (like Bcrypt's default rounds increased to 12) require re-hashing. Additionally, an optional \verify\ configuration option allows enforcing that stored hashes match the expected algorithm, throwing a \RuntimeException\ if they do not.

src/Illuminate/Hashing · high confidence

Improved view engine exception handling and compilation reliability

The view engine layer now provides more robust error handling and compilation logic. The \PhpEngine\ catches all \Throwable\ instances (including PHP 7 throwables) and properly manages output buffering levels to prevent partial view leakage. The \CompilerEngine\ now tracks compiled view expiration to avoid unnecessary recompilation and includes a fallback mechanism that re-compiles views if a 'file not found' error occurs during evaluation. Additionally, the \EngineResolver\ now supports forgetting resolved engines, and the \Engine\ interface has been simplified.

src/Illuminate/View/Engines · high confidence

Introduce Flysystem v3 integration and read-through filesystem support

The Filesystem component has been upgraded to use Flysystem v3, introducing new adapter classes like AwsS3V3Adapter and LocalFilesystemAdapter that wrap the updated League adapters. This change brings support for read-through filesystems via ReadThroughFilesystem and ReadThroughFilesystemAdapter, allowing applications to configure a primary disk with a fallback disk for automatic promotion of files. Additionally, the new FilesystemServiceProvider registers routes to serve and receive files from local disks when the 'serve' config option is enabled, and the FilesystemManager now supports UnitEnum disk names.

src/Illuminate/Filesystem · high confidence

Introduce compiled route collection for improved routing performance

The routing layer now utilizes a compiled route collection (CompiledRouteCollection) backed by Symfony's CompiledUrlMatcher to optimize route matching and URL generation. This change replaces the previous linear route matching approach with a compiled regex-based matcher, significantly reducing the time required to resolve routes, especially in applications with a large number of defined routes. The AbstractRouteCollection base class and its compile() method facilitate the generation of this optimized structure, which is then used during request handling to match incoming requests against the pre-compiled route definitions.

src/Illuminate/Routing · high confidence

Introduce new exception handling architecture with dedicated renderer and reportable handlers

The exception handling subsystem has been restructured to support more granular control over reporting and rendering. The core \Handler\ class now utilizes a new \Renderer\ component for displaying exceptions and introduces \ReportableHandler\ objects to wrap reporting callbacks, allowing them to explicitly stop further processing via a \stop()\ method. Additionally, a new \RegisterErrorViewPaths\ class automatically registers framework error views, and the handler now supports custom log levels and throttling for specific exception types.

src/Illuminate/Foundation/Exceptions · high confidence

Introduce structured authorization response and exception handling

The Auth/Access component now uses a dedicated Response object to represent authorization outcomes, allowing developers to attach custom HTTP status codes (including 404) and error codes to denied actions. The AuthorizationException has been updated to carry this response context, enabling middleware and error handlers to inspect the original denial reason and status. Additionally, the Gate class now supports on-demand authorization checks via allowIf and denyIf, and policies can use the HandlesAuthorization trait to return structured responses instead of throwing exceptions directly.

src/Illuminate/Auth/Access · high confidence

Introduces Foundation application and caching contracts

This change establishes a new set of interfaces in the \Illuminate\\Contracts\\Foundation\ namespace to define the core application contract and specific caching capabilities. The \Application\ interface now explicitly declares methods for path resolution (base, bootstrap, config, database, lang, public, resource, storage), environment detection, console and unit test execution checks, debug mode status, maintenance mode management, service provider registration and bootstrapping, and locale retrieval. Additionally, new contracts \CachesConfiguration\, \CachesRoutes\, \ExceptionRenderer\, and \MaintenanceMode\ are introduced to standardize how configuration/route caching, exception rendering, and maintenance mode states are accessed and managed, replacing legacy or implicit behaviors with explicit interface definitions.

src/Illuminate/Contracts/Foundation · high confidence

Introduces new mail contract interfaces for factory, queue, mailable, and attachment handling

This change establishes a set of new interfaces in the \Illuminate\\Contracts\\Mail\ namespace to define the mail system's contract layer. It adds \Factory\ for retrieving mailer instances by name (supporting enum or string keys), \MailQueue\ for defining queue and delayed queue operations, \Mailable\ for specifying how email messages are sent, queued, and configured (including recipients and locale), and \Mailer\ for the core sending methods including synchronous sending via \sendNow\. Additionally, it introduces the \Attachable\ interface (repurposed from a removed Pheanstalk exception class) to allow entities to provide mail attachments. These contracts standardize the interfaces that mail implementations must adhere to, enabling features like multiple mailers and delayed mailing.

src/Illuminate/Contracts/Mail · high confidence

Introduction of Notifications Dispatcher and Factory contracts

New interface contracts have been added to define the notification system's core abstractions. The Dispatcher contract specifies methods for sending notifications to notifiable entities, including a new \sendNow\ method that accepts an optional array of channels to restrict delivery, enhancing testability and control. The Factory contract defines the interface for retrieving channel instances and sending notifications, establishing the foundational API for the notification subsystem.

src/Illuminate/Contracts/Notifications · high confidence

Introduction of dedicated route-matching validators

The routing system now uses a set of dedicated validator classes (HostValidator, MethodValidator, SchemeValidator, UriValidator) implementing ValidatorInterface to determine if a request matches a route. This refactors the matching logic, introducing specific handling for URI path normalization (trailing slashes) and allowing routes to explicitly force HTTP or HTTPS schemes via the SchemeValidator.

src/Illuminate/Routing/Matching · high confidence

Major overhaul of queue management Artisan commands

The queue management console commands in \src/Illuminate/Queue/Console\ have been significantly refactored and modernized. New commands have been introduced to provide granular control over queue operations: \queue:clear\ allows deleting jobs from specific queues, \queue:pause\ and \queue:resume\ enable pausing and resuming job processing (including globally via \--all\), and \queue:prune-batches\ and \queue:prune-failed\ allow pruning stale batch and failed job data based on age. The \queue:retry-batch\ command now supports retrying failed jobs for specific batches. Existing commands like \queue:work\ and \queue:listen\ have been updated with new options such as \--rest\, \--stop-when-empty\, and \--json\ for structured output. Migration generation commands (\make:queue-table\, \make:queue-failed-table\, \make:queue-batches-table\) have been consolidated to extend a new \MigrationGeneratorCommand\ base class, improving consistency and respecting custom table configurations.

src/Illuminate/Queue/Console · high confidence

Major refactor of HTTP component classes and introduction of file handling helpers

The HTTP component has been significantly refactored to modernize its codebase and improve consistency. \Request\, \Response\, \JsonResponse\, and \RedirectResponse\ now utilize a new \ResponseTrait\ for shared functionality (such as header and cookie management) and the \Macroable\ trait, enabling method chaining and custom macros. \JsonResponse\ and \Response\ now feature improved JSON encoding logic, including support for \JsonSerializable\ and \Arrayable\ objects, better error handling for encoding failures, and explicit encoding options. A new \File\ class and \FileHelpers\ trait have been introduced to provide convenient methods for uploaded files, such as \hashName()\, \extension()\, and \dimensions()\. Additionally, \UploadedFile\ now supports storing files directly via \store()\, \storePublicly()\, and \storeAs()\ methods that integrate with the filesystem abstraction. The \RedirectResponse\ has been updated to use the new trait and supports flashing multiple keys at once.

src/Illuminate/Http · high confidence

Major session backend overhaul to use Symfony HttpFoundation

The session component has been completely refactored to use the Symfony HttpFoundation session interface, replacing the legacy internal storage classes (such as CookieStore, FileStore, and CacheDrivenStore) with a new handler-based architecture. This change introduces dedicated handler classes (ArraySessionHandler, CacheBasedSessionHandler, CookieSessionHandler, DatabaseSessionHandler, FileSessionHandler, and NullSessionHandler) that implement PHP's SessionHandlerInterface, allowing for more robust and standard session management. The SessionManager and Store classes have been rewritten to support this new driver system, and the service provider now registers the session manager and driver separately, improving modularity and compatibility with modern PHP versions.

src/Illuminate/Session · high confidence

Migrate mail text components to new view structure

The text-based email view components (button, footer, header, layout, message, panel, subcopy, table) have been reorganized into a dedicated 'text' directory. This change establishes a new structure for plain-text email rendering, ensuring that components like the header and button correctly output their content without relying on markdown processing, which fixes issues where markdown syntax was inadvertently included in plain-text emails.

src/Illuminate/Mail/resources/views/text · high confidence

Migration stubs now use PHP 8 native type declarations

The default migration stubs (create, update, and base) have been updated to use PHP 8 native return type declarations (\void\) for the \up()\ and \down()\ methods. This change modernizes the generated code structure, ensuring that new migrations created via the stubs align with current PHP standards and provide stricter type safety for the migration lifecycle methods.

src/Illuminate/Database/Migrations/stubs · high confidence

Modernized HTML email templates with component-based structure

The HTML email view files in src/Illuminate/Mail/resources/views/html have been completely rewritten to use a modern, component-based architecture. The main layout (layout.blade.php) now includes proper viewport and color-scheme meta tags for better mobile and dark-mode support, while structural elements like headers, footers, buttons, and panels are extracted into dedicated, reusable Blade components. The default message template (message.blade.php) has been updated to compose these new components, ensuring consistent styling and improved rendering across various email clients.

src/Illuminate/Mail/resources/views/html · high confidence

Modernized default email theme styling

The default HTML email theme has been updated with a refreshed visual design, including a new system font stack, adjusted color palette, and refined typography. The layout now features a centered content area with rounded corners and subtle shadows, improved spacing for headers and paragraphs, and specific fixes for email client compatibility such as preventing long URLs from breaking the layout and ensuring proper image rendering in Yahoo Mail.

src/Illuminate/Mail/resources/views/html/themes · high confidence

Modernized migration system with typed results, conditional execution, and structured events

The migration subsystem has been significantly refactored to improve type safety, performance, and developer control. A new \MigrationResult\ enum now standardizes migration outcomes (Success, Failure, Skipped). The base \Migration\ class introduces a \shouldRun()\ method, allowing developers to conditionally skip migrations (e.g., based on environment or feature flags), and a \withinTransaction\ property to control transaction wrapping. The \MigrationRepositoryInterface\ has been updated with stricter return types (e.g., \string\[\]\ for \getRan()\) and new methods like \getMigrations()\ and \getMigrationBatches()\ to support more efficient batch operations. Additionally, the \Migrator\ now leverages structured events (\MigrationStarted\, \MigrationEnded\, \MigrationSkipped\, etc.) for better observability and integrates with modern console output components for clearer status reporting.

src/Illuminate/Database/Migrations · high confidence

New Bootstrap 4-based authentication layout stub

The authentication scaffolding now uses a new \app.stub\ layout file built with Bootstrap 4 classes (e.g., \navbar-expand-md\, \py-4\) instead of previous versions. This change updates the default HTML structure for generated auth views, including the navigation bar, main content area, and logout form submission logic (using a POST request via JavaScript to prevent CSRF issues with GET requests). It also integrates modern Blade directives like \@guest\ and ensures proper CSRF token handling within the layout.

src/Illuminate/Auth/Console/stubs · high confidence

New Redis contract interfaces and limiter exception

The framework introduces new contract interfaces for the Redis component to support a rewritten layer and custom drivers. The \Connection\ interface defines methods for subscribing (\subscribe\, \psubscribe\) and running raw commands (\command\). The \Connector\ interface specifies how to create connections to both standard Redis instances and clusters. A \Factory\ interface allows retrieving connections by name, now supporting \UnitEnum\ types in addition to strings. Additionally, a \LimiterTimeoutException\ class is added to handle timeouts in Redis rate limiters.

src/Illuminate/Contracts/Redis · high confidence

New SVG icon components for the exception renderer

The local exception page now uses a new set of inline SVG icon components (alert, check, chevron-left/right, chevrons-up-down, copy, database, folder, globe, info, and the Laravel ASCII logo) to replace previous icon implementations. This change updates the visual assets used in the exception renderer, ensuring consistent styling and alignment for UI elements like navigation, status indicators, and the brand logo.

src/Illuminate/Foundation/resources/exceptions/renderer/components/icons · high confidence

New base service providers for events, routes, and authentication policies

This change introduces three new base service providers in the Foundation support layer to standardize how applications register core services. The new EventServiceProvider enables automatic event discovery (scanning the Listeners directory) alongside manual $listen mappings, subscribers, and model observers, with caching support. The RouteServiceProvider now centralizes route loading logic, supporting both cached and uncached routes, allowing custom callbacks via loadRoutesUsing/loadCachedRoutesUsing, and forwarding dynamic method calls to the router. The AuthServiceProvider replaces the previous SeedServiceProvider location to provide a base for registering authorization policies via the Gate facade, using a $policies array and a registerPolicies method.

src/Illuminate/Foundation/Support · high confidence

New bootstrap phase for provider registration and booting

The application bootstrap process now includes two new steps: RegisterProviders and BootProviders. RegisterProviders handles merging additional configured providers and loading the application's service providers, while BootProviders explicitly boots the registered providers by calling the application's boot method. This separates provider registration from the booting phase, allowing for more controlled initialization of services that depend on other providers being fully registered first.

src/Illuminate/Foundation/Bootstrap · high confidence

New database expression contracts for grammar-specific formatting

The query builder contracts now include a new \Expression\ interface that accepts a \Grammar\ instance in its \getValue\ method, enabling database expressions to format their output based on the specific grammar being used. A new \ConditionExpression\ interface has been introduced to specifically mark expressions used in query conditions. Additionally, the \Builder\ contract has been redefined as an empty interface with an \@mixin\ annotation to improve IDE support, replacing its previous unrelated origin.

src/Illuminate/Contracts/Database/Query · high confidence

New default email notification template using Mail components

The default email notification view has been replaced with a new Blade template that leverages the \x-mail::message\, \x-mail::button\, and \x-mail::subcopy\ components. This change introduces support for customizable greetings and salutations, dynamic button coloring based on the notification level (success, error, or primary), and improved handling of action URLs with a fallback display for users who cannot click the button.

src/Illuminate/Notifications/resources · high confidence

New encryption contracts and exception classes

The encryption contract layer now includes dedicated exception classes (EncryptException, DecryptException) and refined interfaces (Encrypter, StringEncrypter). The Encrypter interface exposes methods for encryption/decryption with optional serialization control, key retrieval, and marks sensitive parameters. The StringEncrypter interface provides dedicated methods for encrypting and decrypting strings without serialization, improving developer experience for string-only use cases.

src/Illuminate/Contracts/Encryption · high confidence

New exception handling contracts for reporting control and silent exceptions

The framework introduces two new interfaces in the Debug contract namespace to refine exception handling. The \ExceptionHandler\ interface now explicitly defines the \shouldReport(Throwable $e)\ method, allowing implementations to determine whether a specific exception should be logged or reported, while also standardizing the \report\, \render\, and \renderForConsole\ signatures. Additionally, the new \ShouldntReport\ marker interface enables developers to mark specific exception classes as silent, signaling that they should not be reported by the exception handler.

src/Illuminate/Contracts/Debug · high confidence

New exception renderer UI components

The exception renderer now uses a new set of Blade components to display error details with a modern, responsive design. This includes a new layout with light/dark mode support, syntax-highlighted code frames, and collapsible sections for the exception trace, previous exceptions, and query logs. The UI also features clickable file references, copy-to-clipboard functionality for URLs and markdown, and pagination for large query sets.

src/Illuminate/Foundation/resources/exceptions/renderer/components · high confidence

New exception renderer with enhanced trace details and query logging

The application now uses a new exception renderer located in src/Illuminate/Foundation/Exceptions/Renderer. This renderer provides improved error pages by displaying previous exceptions in the chain, correctly handling closures and standalone functions in stack traces, and including executed SQL queries with their bindings. It also supports Vite auto-refresh for faster development iteration and allows copying error details as Markdown.

src/Illuminate/Foundation/Exceptions/Renderer · high confidence

New routing exception classes for specific error scenarios

The routing layer now includes dedicated exception classes to handle distinct failure modes more precisely. A new \BackedEnumCaseNotFoundException\ is thrown when a route parameter bound to a backed enum does not match a valid case. \InvalidSignatureException\ is used to reject signed routes with invalid signatures, returning a 403 status. \MissingRateLimiterException\ provides specific error messages when a named rate limiter or a model-based rate limiter is not defined. \StreamedResponseException\ wraps exceptions occurring during streamed responses, ensuring they render as empty responses rather than breaking the stream. Finally, \UrlGenerationException\ is thrown with detailed context when required parameters are missing during URL generation.

src/Illuminate/Http/Exceptions, src/Illuminate/Routing/Exceptions · high confidence

Pagination component rewritten with cursor pagination and Tailwind views

The pagination system has been completely refactored to support cursor (keyset) pagination alongside traditional offset pagination, introducing new classes like AbstractCursorPaginator, CursorPaginator, and Cursor. The default styling has shifted from Bootstrap to Tailwind CSS, with new default views (pagination::tailwind) and the removal of the legacy BootstrapPresenter and Environment classes. The service provider now registers resolvers for page and cursor state via PaginationState and allows publishing of the new Tailwind views, while the underlying paginator classes now implement modern interfaces like Htmlable, Stringable, and JsonSerializable.

src/Illuminate/Pagination · high confidence

Pagination contracts updated with generics, new methods, and improved type hints

The pagination interfaces (Paginator, CursorPaginator, LengthAwarePaginator) now include PHPDoc generics for better IDE support and type safety. New methods have been added to the contracts: isEmpty() and isNotEmpty() for checking item presence, hasMorePages() for cursor pagination, and through() for data transformation. Conditional return types have been added to methods like fragment() to improve type inference. These changes enhance developer experience when working with pagination in Laravel applications.

src/Illuminate/Contracts/Pagination · high confidence

Queue connectors rewritten to support new queue features and modernized configurations

The queue connectors in src/Illuminate/Queue/Connectors have been significantly updated to support new queue capabilities and modernize configuration options. New connectors have been added for Background, Deferred, and Failover queue types, enabling users to dispatch jobs in the background, defer job processing until after database transactions commit, or implement failover logic across multiple queue connections. Existing connectors have been enhanced: the SQS connector now supports named credential providers (ECS, instance profile) and credential caching across processes for improved performance and security; the Beanstalkd connector now supports configurable timeouts, ports, and blocking pop operations; the Redis connector accepts custom connection names, blocking timeouts, and migration batch sizes; the Database connector passes the after\_commit flag to support transactional job dispatching; and the Sync connector now respects the after\_commit configuration. The Iron connector has been replaced with a Null connector, removing the deprecated IronMQ dependency.

src/Illuminate/Queue/Connectors · high confidence

Queue events now expose richer context for monitoring and debugging

The queue event classes in \src/Illuminate/Queue/Events\ have been expanded to provide significantly more detail to listeners. Worker lifecycle events (\WorkerStopping\, \WorkerIdle\, \WorkerInterrupted\, \WorkerStarting\) now expose connection names, queue names, worker options, exit statuses, processing counts, timestamps, and memory usage. Job processing events (\JobProcessed\, \JobAttempted\, \JobReleased\, \JobReleasedAfterException\) now include processing duration, exceptions, and backoff delays. New events like \JobDebounced\, \JobInterrupted\, \UniqueJobSkipped\, and \QueueFailedOver\ provide visibility into debouncing, interruptions, uniqueness constraints, and failover scenarios. Additionally, queue pause/resume events (\QueuePaused\, \QueueResumed\, \WorkerQueuePaused\, \WorkerQueueResumed\) now expose connection and queue details, enabling more granular monitoring of queue states.

src/Illuminate/Queue/Events · high confidence

Queue jobs now implement the Job contract and expose inspection metadata

All queue job classes (DatabaseJob, RedisJob, SqsJob, BeanstalkdJob, SyncJob, and FakeJob) now implement the Illuminate\\Contracts\\Queue\\Job contract, replacing the legacy abstract fire() method with standard interface methods like getJobId(), getRawBody(), and attempts(). This enables consistent job introspection and testing, supported by new helper classes: InspectedJob for viewing job details (UUID, queue, attempts, payload) and JobName for resolving job class and method names from payloads. The base Job class now tracks deletion, release, and failure states, and the DatabaseJob implementation uses a new DatabaseJobRecord wrapper to manage job data.

src/Illuminate/Queue/Jobs · high confidence

Redesigned local exception page with syntax highlighting and copy functionality

The local exception renderer has been completely overhauled to provide a richer debugging experience. The new interface features syntax highlighting for PHP, SQL, and JSON code snippets, making stack traces and query logs easier to read. It includes a 'Copy as Markdown' button and fallback copy buttons for individual code blocks, allowing developers to quickly share error details. The layout now supports previous exceptions, displays request headers and body data, and respects safe-area insets for mobile devices. Additionally, the ASCII art logo is now excluded from non-browser contexts to prevent clutter in CLI output.

src/Illuminate/Foundation/resources/exceptions/renderer · high confidence

Redis connection layer refactored with serialization support and command observability

The Redis connection implementation has been restructured to introduce a new \Connection\ base class and a \PacksPhpRedisValues\ trait, enabling native PhpRedis serialization and compression support (including LZF and ZSTD) for cluster and standard connections. This change also adds \CommandExecuted\ and \CommandFailed\ events, allowing users to observe and debug Redis command performance and failures via the \listen()\ and \listenForFailures()\ methods. Additionally, the \PhpRedisClusterConnection\ now properly scans all master nodes and handles \flushdb\ across the cluster, while \PredisClusterConnection\ provides equivalent \keys\ and \flushdb\ support.

src/Illuminate/Redis/Connections · high confidence

Redis connectors now support phpredis retry/backoff options and Predis scalar retry configuration

The PhpRedis connector now reads and applies the new \max\_retries\, \backoff\_algorithm\, \backoff\_base\, and \backoff\_cap\ configuration options to the underlying phpredis client, enabling fine-grained control over connection retry behavior. Simultaneously, the Predis connector has been updated to accept scalar retry configuration arrays, automatically converting them into Predis retry instances (requiring predis/predis 3.4.0+), which allows users to define retry strategies directly in their configuration files without manual instantiation.

src/Illuminate/Redis/Connectors · high confidence

Redis layer rewritten to use phpredis by default with modernized service provider

The Redis component has been completely rewritten to replace the legacy raw-socket \Database\ class with a connector-based architecture using \PhpRedis\ (and \Predis\) drivers, making \phpredis\ the default client. The \RedisManager\ now implements the \Factory\ contract and accepts explicit driver and configuration parameters, while the \RedisServiceProvider\ has been updated to implement \DeferrableProvider\, register the \redis.connection\ alias, and default to the \phpredis\ client. Legacy exception classes (\CommandException\, \ConnectionException\) and the old \Database\ implementation have been removed.

src/Illuminate/Redis · high confidence

Refactor JSON API resources into dedicated response classes

The JSON API resource system has been restructured to improve separation of concerns and extensibility. The previous monolithic implementation is replaced by a hierarchy of specialized classes: \JsonResource\ handles single resource serialization and wrapping (including a new \$forceWrapping\ static property), \ResourceCollection\ manages collections and pagination logic, and \AnonymousResourceCollection\ allows for dynamic collection creation with key preservation. New response classes, \ResourceResponse\ and \PaginatedResourceResponse\, encapsulate the HTTP response generation, allowing developers to customize pagination information and query parameter preservation more granularly. This change also introduces the \preserveKeys\ method to maintain array indices in collections and ensures that \ResourceCollection\ implements \Countable\ for standard PHP compatibility.

src/Illuminate/Http/Resources/Json · high confidence

Refactor controller middleware to a modern, interface-based system

The controller middleware system has been completely overhauled: the legacy \Controller\ base class and its associated \FilterParser\, \Before\, and \After\ filter classes have been removed in favor of a new \Middleware\ value object and a \HasMiddleware\ interface. Users now define controller middleware by implementing the \HasMiddleware\ interface and returning an array of \Middleware\ instances, closures, or strings, replacing the old \beforeFilter\/\afterFilter\ method calls. The new \Middleware\ class supports method scoping via \only()\ and \except()\ methods, providing a more explicit and type-safe way to attach middleware to specific controller actions.

src/Illuminate/Routing/Controllers · high confidence

Refactored Eloquent Factory internals with new relationship and sequence classes

The Eloquent Factory system has been restructured to improve type safety and relationship handling. New dedicated classes have been introduced: \BelongsToManyRelationship\ and \BelongsToRelationship\ now encapsulate the logic for creating and managing pivot data and parent associations, while the \Relationship\ class handles child relationships (HasOne/HasMany/Morph). A new \CrossJoinSequence\ class extends the existing \Sequence\ class to support cross-joined data generation. Additionally, a \UseModel\ attribute has been added to allow explicit model binding on factory classes, and the \HasFactory\ trait has been updated to support this attribute alongside the existing static factory property.

src/Illuminate/Database/Eloquent/Factories · high confidence

Refactored controller and middleware generation commands

The \make:controller\ and \make:middleware\ Artisan commands have been rewritten to use the modern \GeneratorCommand\ base class and Symfony's \\#\[AsCommand\]\ attribute, replacing the legacy \MakeControllerCommand\ which is removed. This change introduces support for generating various controller types (invokable, singleton, resource, API) via specific flags, allows automatic model generation when using the \--model\ or \--parent\ options, and ensures generated controllers correctly handle the presence or absence of a base \Controller\ class. The new implementation also standardizes stub resolution and integrates with Laravel's prompt system for interactive model creation.

src/Illuminate/Routing/Console · high confidence

Refactored core HTTP middleware into new classes and traits

The middleware layer in src/Illuminate/Foundation/Http/Middleware has been reorganized into distinct, specialized components. CSRF protection is now handled by the new PreventRequestForgery class, which introduces origin verification via the Sec-Fetch-Site header and deprecates the old VerifyCsrfToken and ValidateCsrfToken classes. Maintenance mode logic is centralized in PreventRequestsDuringMaintenance, which utilizes a new ExcludesPaths trait to allow URI exclusions. Request data transformation is split into TransformsRequest, TrimStrings (which now supports wildcard patterns and skip callbacks), and ConvertEmptyStringsToNull (also with skip callbacks). Additionally, new middleware HandlePrecognitiveRequests and InvokeDeferredCallbacks have been added to support Laravel Precognition and deferred callback execution, respectively.

src/Illuminate/Foundation/Http/Middleware · high confidence

Refactored migration commands to modern Laravel console standards

The migration Artisan commands have been rewritten to use the modern Symfony Console signature format and attributes, replacing the legacy \fire()\ lifecycle method with \handle()\. This update introduces a new \migrate:fresh\ command to drop all tables and re-run migrations, adds a \TableGuesser\ to automatically infer table names from migration filenames, and standardizes behavior across commands like \migrate:rollback\ and \migrate:reset\ by adding confirmation prompts, \--force\ flags, and support for multiple migration paths. Additionally, the old \MakeCommand\ has been removed in favor of the updated \MigrateMakeCommand\.

src/Illuminate/Database/Console/Migrations · high confidence

Refactored password reset system with token repositories and throttling

The password reset mechanism has been restructured to use dedicated token repositories (CacheTokenRepository and DatabaseTokenRepository) that implement a new TokenRepositoryInterface, allowing for flexible storage backends. This change introduces configurable token expiration and throttling (to prevent rapid successive reset requests) directly into the repository layer. The PasswordBroker now dispatches a PasswordResetLinkSent event upon sending reset links and utilizes a Timebox to limit execution duration. Additionally, sensitive parameters like tokens and keys are marked with the \#\[SensitiveParameter\] attribute, and the PasswordResetServiceProvider has been moved and made deferrable.

src/Illuminate/Auth/Passwords · high confidence

Routing events converted to plain objects with promoted properties

The core routing events (Routing, RouteMatched, PreparingResponse, ResponsePrepared) are now plain PHP classes using constructor property promotion instead of inheriting from a base Event class. This simplifies the event structure and removes the previous inheritance overhead, meaning listeners should expect standard object instances with public properties for request, response, and route data.

src/Illuminate/Routing/Events · high confidence

Scheduler refactored with cache-based mutexes and sub-minute scheduling support

The console scheduler has been restructured to use a cache-based locking strategy for preventing overlapping tasks, introducing new \CacheEventMutex\ and \CacheSchedulingMutex\ classes that allow specifying custom cache stores via a \useStore\ method. This change enables sub-minute scheduling (e.g., \everySecond\, \everyFiveSeconds\) by tracking execution times and using atomic cache operations or locks. Additionally, the \Schedule\ class now supports grouping events with \PendingEventAttributes\ to apply lifecycle callbacks and filters to multiple tasks at once, and new commands like \schedule:clear-cache\, \schedule:finish\, and \schedule:interrupt\ have been added to manage mutex state and background task completion.

src/Illuminate/Console/Scheduling · high confidence

Seeder stub now uses native PHP type declarations

The stub file for the \make:seeder\ command has been updated to use native PHP 8.0+ type declarations. Specifically, the \run\ method now includes a \void\ return type, ensuring generated seeders adhere to modern PHP standards.

src/Illuminate/Database/Console/Seeds/stubs · high confidence

Support contracts refactored and expanded

The support contracts in src/Illuminate/Contracts/Support have been standardized and extended. Several legacy interfaces (Arrayable, Jsonable, MessageProvider, Renderable) were renamed to remove the 'Interface' suffix and moved to the correct namespace. New contracts were introduced to define specific behaviors: CanBeEscapedWhenCastToString for controlling string escaping, HasOnceHash for computing hashes for 'once' functions, DeferrableProvider for service provider definitions, DeferringDisplayableValue for resolving deferred display values, Htmlable for HTML content, and ValidatedData for validated input data. The MessageBag contract was significantly expanded to include methods for removing messages (forget), checking emptiness (isEmpty, isNotEmpty), and retrieving raw messages (getMessages), while also implementing the Countable interface.

src/Illuminate/Contracts/Support · high confidence

Translation component rewritten with native pluralization and JSON support

The translation system has been refactored to remove the dependency on Symfony's translation component, replacing it with a native \MessageSelector\ for pluralization and a new \FileLoader\ that supports multiple paths and JSON translation files. The \Translator\ class now implements its own loading logic, and the \TranslationServiceProvider\ has been updated to implement \DeferrableProvider\ for deferred loading. New classes like \ArrayLoader\, \PotentiallyTranslatedString\, and \CreatesPotentiallyTranslatedStrings\ have been added to support in-memory translations and lazy translation evaluation, while the legacy \SymfonyTranslator\ wrapper has been removed.

src/Illuminate/Translation · high confidence

Translation contracts moved to Illuminate\\Contracts and expanded

The translation interfaces have been relocated from the implementation namespace to the contracts namespace (Illuminate\\Contracts\\Translation). The Translator interface now explicitly supports float values in the choice method, and the Loader interface has been renamed from LoaderInterface to Loader, adding new methods to register JSON translation paths and retrieve registered namespaces. Additionally, a new HasLocalePreference interface has been introduced to allow entities to specify their preferred locale.

src/Illuminate/Contracts/Translation · high confidence

Unified schema introspection processors with consistent return shapes

The database query processors for MySQL, PostgreSQL, SQLite, SQL Server, and MariaDB have been refactored to provide a standardized, consistent structure for schema metadata. Column listings now include explicit fields for collation, data type names, and generated column expressions (stored vs. virtual), while index and foreign key queries return normalized details such as unique constraints, primary status, and referential actions. The base Processor class also introduces dedicated methods for processing schemas, tables, views, and user-defined types, ensuring that schema inspection results are uniform across all supported database drivers.

src/Illuminate/Database/Query/Processors · high confidence

Updated cache table migration stubs

The cache migration stub has been updated to use a primary key for the cache key column instead of a unique index, changed the value column type from TEXT to MEDIUMTEXT, and switched the expiration column to a big integer to prevent year 2038 overflow issues. Additionally, the stub now includes a migration for the cache\_locks table, which defines its own key, owner, and expiration columns.

src/Illuminate/Cache/Console/stubs · high confidence

Updated database queue migration stubs

The migration stubs for the queue system have been updated to reflect current schema requirements. The jobs table stub now uses unsigned small integers for the attempts column and unsigned integers for timestamp fields, while the failed jobs stub includes a composite index on connection, queue, and failed\_at for improved polling performance. Additionally, a new batches stub has been added to support job batching, featuring a name column and medium text for options to accommodate larger batch configurations.

src/Illuminate/Queue/Console/stubs · high confidence

Updated database session migration stub with native types and longText payload

The database session migration stub has been updated to use PHP 8.0+ native return type declarations (void) and the \foreignId()\ helper for the user\_id column. Additionally, the payload column type has been changed from text to longText to accommodate larger session data, and the migration now uses \dropIfExists\ for safer cleanup.

src/Illuminate/Session/Console/stubs · high confidence

Updated default configuration files for Laravel 11+ skeleton

The default configuration files in the \config/\ directory have been updated to reflect the modern Laravel skeleton structure. Key changes include switching the default cache and session drivers from \file\ to \database\, adding support for new broadcasting drivers like Reverb and Mercure, introducing a \monthly\ log channel, and enabling \rehash\_on\_login\ for password hashing. The database configuration now includes a dedicated \mariadb\ driver, Postgres transaction pooler support, and configurable SQLite pragmas, while the queue configuration adds a \deferred\ driver and SQS overflow storage options.

config · high confidence

Updated facade stub template to use native PHP type declarations

The stub file for generating new Facade classes has been updated to include native PHP return type declarations (specifically \string\ on \getFacadeAccessor\). This ensures that any new facades generated from this template adhere to modern PHP typing standards, improving static analysis compatibility and code clarity for developers scaffolding new components.

src/Illuminate/Foundation/stubs · high confidence

Updated factory stub to use PHP 8 native type declarations

The factory stub template has been updated to use PHP 8 native return type declarations (e.g., \public function definition(): array\) and modern PHPDoc generics (\@extends Factory\<{{ model }}\>\) for better IDE support and type safety. This change affects the code generated by the \make:factory\ command, ensuring that newly created model factories adhere to current PHP standards.

src/Illuminate/Database/Console/Factories/stubs · high confidence

Updated frontend exception renderer with syntax highlighting and dark mode support

The Laravel exception page now features syntax highlighting for code snippets and queries, along with support for light and dark color schemes (including safe area insets for mobile devices). The build process has been updated to trigger a rebuild when package-lock.json changes, and dependencies such as esbuild, Vite, and Rollup have been bumped.

src/Illuminate/Foundation/resources/exceptions/renderer/dist · high confidence

Updated notification migration stub to use UUID primary keys and anonymous classes

The stub for the notifications table migration has been updated to define the primary key as a UUID instead of an auto-incrementing integer, and the 'read' status is now stored as a nullable timestamp ('read\_at') rather than a boolean. Additionally, the migration class now uses PHP native type declarations and anonymous class syntax, and the rollback method safely uses 'dropIfExists' to prevent errors if the table does not exist.

src/Illuminate/Notifications/Console/stubs · high confidence

Test coverage

Add trait for configuring database migration commands in tests; Added InvalidArgumentException for testing argument validation; Added PHPStan type tests for Eloquent and core components; Added testing attribute classes for setup, teardown, seeding, and unit tests; Added testing helpers for creating fake HTTP files; Added tests for new PHPUnit constraint classes in src/Illuminate/Testing/Constraints; Expanded test coverage across framework components; New testing fakes for Bus, Events, Mail, Queue, Notifications, and Exception Handling.

Dependencies

Laravel 13 component dependency constraints and PHP 8.3 requirement

The Illuminate framework components have been updated to require PHP 8.3 and target version 13.0 of internal dependencies. This change introduces Symfony 7.4 and 8.0 compatibility across Console, Cookie, Filesystem, and other components, while also updating specific library constraints such as \laravel/prompts\ to ^0.3.11, \nunomaduro/termwind\ to ^2.0, and \brick/math\ to support versions 0.14.2 through 1.0.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 58.

Lenses

  • Code Health 84
  • Architecture 95
  • Maturity 46
  • Readiness 83
  • Security 80
  • Accessibility 53

Changes since last survey

  • 300 commits — 240 feature/other, 60 fixes

By area

  • src/Illuminate — 239 commits
  • (root) — 16 commits
  • .github/workflows — 11 commits
  • tests/Foundation — 7 commits
  • tests/Integration — 7 commits
  • tests/Database — 6 commits
  • (repo) — 5 commits
  • tests/Support — 2 commits
  • config/database.php — 1 commit
  • tests/AfterEachTestSubscriber.php — 1 commit
  • tests/Cache — 1 commit
  • tests/Console — 1 commit
  • tests/Http — 1 commit
  • tests/Image — 1 commit
  • tests/Validation — 1 commit

Notable commits

  • fix: Apply fixes from StyleCI (#61256)
  • fix: Apply fixes from StyleCI (#61427)
  • fix: Apply fixes from StyleCI (#61470)
  • fix: Apply fixes from StyleCI (#61638)
  • fix: Fix PHPUnit and Mockery deprecations in tests (#61244)
  • fix: Fix Redis pipeline facade annotation (#61173)
  • fix: Fix Redis tagged cache write ordering (#61385)
  • fix: Fix SQLite schema dumps containing shadow tables (#61637)
  • fix: Fix SelfBuilding build stack cleanup after exceptions (#61454)
  • fix: Fix addToMiddlewarePriorityAfter() placing middleware at the end when the referenced middleware is first (#61567)
  • fix: Fix incorrect $startTime type in Worker::stopIfNecessary docblock (#61347)
  • fix: Fix nested includes not being limited when maxRelationshipDepth is zero (#61297)
  • fix: Fix parameter docblocks that contradict the native signature (#61457)
  • fix: Fix resource loading (#61322)
  • fix: Fix resource loading (#61323)
  • fix: Fix validation stalling for minutes on large arrays (#60908) (#61232)
  • fix: Revert "Use strict comparison for contains validation rule (#61320)" (#61330)
  • fix: Revert "[13.x] Consolidate tearDown boilerplate into AfterEachTestSubscriber (#61245)" (#61262)
  • fix: Revert "feat: add orWhereKey and orWhereKeyNot to Eloquent Builder (#61154)" (#61236)
  • fix: [12.x] Fix TypeError in userFromRecaller() when the recaller matches no user (#61397)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

laravel/framework was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit a9cf9996942ff525e63f5c6b789466f4749bb996 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-be726e82e277.