Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
PRODUCT FAMILYFRAMEWORKPARTIAL

Api Platform

API Platform

API Platform is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Lifecycle status

No support or retirement date is shown unless BlackTree can link it to a registered publisher source. A missing date means that a boundary is not publicly stated, has not yet been extracted, or still needs source routing. It does not mean the product is supported indefinitely.

Product overview

API Platform is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Application development components
  • Versioned runtime or build interfaces
  • Security and compatibility maintenance

Typical use

Used by software teams to build, run or maintain applications.

Deployment

Included in source projects, application dependencies, build systems or managed runtimes.

Lifecycle records

ReleaseBoundaryDate
Lifecycle policyOfficial lifecycle policy; no bounded date foundNot dated by publisher

Official sources

PARTIAL

API Platform official lifecycle source

Checked automatically.

Extracted 1 lifecycle record(s), including 0 bounded date record(s), from the registered official source.

Open publisher source

Package vulnerability advisories

api-platform/core's secured properties may be accessible within collections

Fixed: 3.0.12, 3.1.3, 2.7.10

GraphQL grant on a property might be cached with different objects

Fixed: 4.0.22, 3.4.17, 4.1.5

GraphQL query operations security can be bypassed

Fixed: 4.0.22, 3.4.17, 4.1.5

API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)

Fixed: 4.1.30, 4.2.26, 4.3.12

API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate

Fixed: 4.1.29, 4.2.25, 4.3.8

API Platform Core can leak exceptions message that may contain sensitive information

Fixed: 3.2.5

API Platform Core does not call GraphQl securityAfterResolver

Fixed: 3.3.15

Incorrect Access Control vulnerability in api-platform/core

Fixed: 2.2.10, 2.3.6