Skip to content

v0.5.0

Choose a tag to compare

@codebyray codebyray released this 20 Jul 01:00
· 10 commits to main since this release
5a9204f

v0.5.0

⚠️ Breaking: narrower Laravel/PHP support

This release intentionally drops Laravel 10 and 11 support and raises the PHP floor to 8.2.

Both Laravel majors are past their security-support window (Laravel 10 is fully EOL; Laravel 11's security support ended March 2026), and current releases in both lines carry unpatched CVEs — meaning a fresh composer install against either is now blocked outright by Composer's own security-advisory audit for most consumers. This isn't a preference change; it's the ecosystem itself telling us those versions shouldn't be recommended for new installs anymore.

If you're on Laravel 10/11: stay on v0.4.x and prioritize upgrading Laravel — that's the more urgent fix regardless of this package.

Now supported: Laravel ^12.0 | ^13.0, PHP ^8.2, Livewire ^3.0 | ^4.0 — every combination verified via CI on every push.

✨ Added

  • Optional authorizeAbility prop. Set it to a Gate/Policy ability name and the component will call Gate::authorize() against the target model before any mutating action (uploadFiles, remove, saveEdit, and the media:attach handler). Left unset, behavior is unchanged from prior versions — this is opt-in and fully backward-compatible. See the Authorization section in the README.
  • CI. GitHub Actions now runs the full PHP × Laravel × Livewire test matrix on every push and PR.

🐛 Fixed

  • README/composer.json said "Livewire v3" despite ^3.0 || ^4.0 already being supported.

Upgrading

No code changes required if you're already on Laravel 12/13 + PHP 8.2+. If you're on Laravel 10/11 or PHP 8.1, hold on v0.4.x until you've upgraded your app.

Full Changelog: v0.4.0...v0.5.0