Immutable
release. Only release title and notes can be modified.
🚨 Important security updates for all users
Yet another set of security updates 🤠
First off, if you upgraded to v4.4.0 -- please update again
I greatly apologize: But I swear I had the "latest release" box selected when I released v4.4.0 (it's checked by default). I noticed when I ran the release it didn't appear as the latest release. I went in had had to edit it for it to display correctly.
What I didn't know: This caused the CI versions of v4.4.0 to actually checkout v4.3.5 (the "latest release" according to GitHub) -- which didn't have the security updates that I published 🙃
This means the security updates were not shipped for:
- NGINX
- Composer
Thank you to the community members who reached out to let me know about this. I apologize for the confusion, but I will take note on my part to verify this better on each release.
Franken PHP upgraded to v1.12.3
- Addresses CVE-2026-45062 (high, CVSS 8.1)
- Other features noted in FrankenPHP v1.12.3 release notes
Full Changelog: v4.4.0...v4.4.1