Skip to content

chore(deps): bump symfony/ux-autocomplete from 3.4.0 to 3.5.1 - #153

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/composer/symfony/ux-autocomplete-3.5.1
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/composer/symfony/ux-autocomplete-3.5.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps symfony/ux-autocomplete from 3.4.0 to 3.5.1.

Release notes

Sourced from symfony/ux-autocomplete's releases.

v3.5.1

No release notes provided.

v3.5.0

Changelog (symfony/ux-autocomplete@v3.4.0...v3.5.0)

Changelog

Sourced from symfony/ux-autocomplete's changelog.

CHANGELOG

3.5

  • Add support for Symfony 8.2's standalone AssetMapperBundle
  • Translate the optgroup labels returned by the AJAX endpoint, so group_by can use translation keys
  • Add EntityAutocompleterInterface::getTranslationDomain() to choose the translation domain used for the optgroup labels
  • Decouple the package from Doctrine ORM: add AutocompleterInterface, OptionsAwareAutocompleterInterface, AutocompleteChoiceType and #[AsAutocompleteField] so any data source can back an autocomplete field. The Doctrine ORM API stays fully supported
  • Add the ux_autocomplete route, served by AutocompleteController. The ux_entity_autocomplete route alias is deprecated
  • Add a max_options option to control how many options the dropdown displays at once
  • Add support for Twig 4

3.2

  • Fix the XSS vulnerability fix introduced in 3.1, which was broken on PostgreSQL. See section 2.36.2 below for details.

3.1

  • Use hash_equals() to compare the extra_options checksum to prevent timing attacks
  • Fix XSS vulnerability where data returned from AJAX endpoints was rendered without HTML escaping. See section 2.36 below for details.

3.0

  • Minimum required Symfony version is now 7.4
  • Minimum required PHP version is now 8.4
  • Remove ParentEntityAutocompleteType in favor of BaseEntityAutocompleteType
  • Remove ExtraLazyChoiceLoader in favor of Symfony\Component\Form\ChoiceList\Loader\LazyChoiceLoader from Symfony Form >=7.2
  • Add parameter $security to AutocompleteResultsExecutor::__construct()
  • Remove BC layer for EntityAutocompleterInterface::getAttributes() and EntityAutocompleterInterface::getGroupBy()

2.36.2

  • Fix the autocomplete search query throwing an exception on PostgreSQL because of the ESCAPE '\' clause introduced in 2.36; a backslash-free LIKE escape character is now used.

2.36

  • Escape LIKE wildcards (% and _) in the autocomplete search query so user input can no longer alter the matching behavior of the generated SQL query.

  • Fix XSS vulnerability where data returned from AJAX endpoints was rendered without HTML escaping. Values from the text field of AJAX responses are now escaped by default.

    Possible BC break: if your endpoint legitimately returns HTML in the text field (e.g., for rich content), opt in via the options_as_html option:

     #[AsEntityAutocompleteField]
     class IngredientAutocompleteType extends AbstractType
     {
         public function configureOptions(OptionsResolver $resolver): void

... (truncated)

Commits
  • e9ff3cf Bump npm packages to v3.5.1
  • e321c1e Bump npm packages to v3.5.0
  • 87b3f11 [Autocomplete][Cropperjs][Dropzone][Icons][LiveComponent][Map][Pagination][St...
  • 1085b15 [Autocomplete] Add a max_options option to control how many options the dropd...
  • 25df0ee [Autocomplete][Chartjs][Cropperjs][Dropzone][LiveComponent][Map][Notify][Reac...
  • 5e1d360 [Autocomplete] Make search test fixtures deterministic
  • e6b2560 [StimulusBundle] Detect the standalone AssetMapper bundle
  • 917ab3e Ignore the generated config/schema.json, and check .gitattributes stay in sync
  • 21bd48e [Autocomplete] Decouple from Doctrine ORM, support any data source
  • 682a5cb [Autocomplete] Translate the optgroup labels returned by the AJAX endpoint
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update php code labels Oct 1, 2026
Bumps [symfony/ux-autocomplete](https://github.com/symfony/ux-autocomplete) from 3.4.0 to 3.5.1.
- [Release notes](https://github.com/symfony/ux-autocomplete/releases)
- [Changelog](https://github.com/symfony/ux-autocomplete/blob/3.x/CHANGELOG.md)
- [Commits](symfony/ux-autocomplete@v3.4.0...v3.5.1)

---
updated-dependencies:
- dependency-name: symfony/ux-autocomplete
  dependency-version: 3.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/composer/symfony/ux-autocomplete-3.5.1 branch from fb6576f to 188ec3b Compare October 1, 2026 14:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants