How often does Laravel ship a major release, and how long does each major receive bug fixes and security fixes?
answer
- one major a year, around Q1
- 18 months of bug fixes
- 2 years of security fixes
- Laravel 13: March 17th, 2026
- 12 is security-only after August 2026
basics
~20 sLaravel releases one major version a year, around the first quarter. Each major gets bug fixes for 18 months and security fixes for 2 years; Laravel 13 (March 2026) is covered for security until March 17th, 2028.
solid answer
~40 sLaravel ships a new major of `laravel/framework` every year, around Q1, while minor and patch releases can come out as often as weekly. The support policy is the same for every major: **bug fixes for 18 months, security fixes for 2 years**. Laravel 13 was released on March 17th, 2026, gets bug fixes until Q3 2027 and security fixes until March 17th, 2028. Laravel 12 (February 24th, 2025) stopped getting bug fixes on August 13th, 2026 and gets security fixes until February 24th, 2027, so by late 2026 it is in its security-only phase. Laravel 11 and 10 are past end of life. Each major also has a supported PHP range: Laravel 13 accepts PHP 8.3 to 8.5. Other first-party libraries give bug fixes only to their latest major.
go deeper
Memorise the pattern: one major a year, 18 months of bug fixes, 2 years of security fixes, and PHP 8.3 as Laravel 13's minimum.
Be able to read the support table for a given date and say which majors get bug fixes, which get only security fixes, and which are end of life.
Turn the windows into a schedule: when a major enters its security-only phase, the upgrade should already be planned, and the PHP floor checked on every server.
Use the overlapping windows as a portfolio budget: how far behind any app may fall, and what happens when an app hits end of life before its upgrade lands.
## The cadence Laravel's release notes describe two speeds: - **Major releases** of `laravel/framework` come out **once a year, around the first quarter**. Laravel 10 arrived in February 2023, 11 in March 2024, 12 in February 2025 and 13 in March 2026. - **Minor and patch releases** (13.1, 13.2 ... 13.34) can come out **as often as every week**, and the policy says they should never contain breaking changes. So a team on Laravel 13 receives a steady flow of 13.x releases with fixes and small features, and faces one planned major upgrade a year. ## The support windows Every major gets the same two windows, counted from its release date: 1. **Bug fixes for 18 months.** Ordinary defects are fixed and released as 13.x updates. 2. **Security fixes for 2 years.** After the bug-fix window closes, only security issues are patched, until the second anniversary. 3. **End of life** after that: no fixes of any kind. The published table in the 13.x release notes: | Version | PHP | Released | Bug fixes until | Security fixes until | |---|---|---|---|---| | 10 | 8.1 - 8.3 | February 14th, 2023 | August 6th, 2024 | February 4th, 2025 | | 11 | 8.2 - 8.4 | March 12th, 2024 | September 3rd, 2025 | March 12th, 2026 | | 12 | 8.2 - 8.5 | February 24th, 2025 | August 13th, 2026 | February 24th, 2027 | | 13 | 8.3 - 8.5 | March 17th, 2026 | Q3 2027 | March 17th, 2028 | Reading the table at the end of September 2026: - **13** is fully supported. - **12** is in its **security-only** phase: its bug-fix window closed on August 13th, 2026. - **11** and **10** are **end of life**; a municipal permit portal still on 10 has had no security patches since February 2025. ## Why the windows overlap Because a new major arrives roughly every 12 months and each one is supported for 24, two majors are usually covered at once. That gives teams a year in which they can upgrade at their own pace while the previous major still gets security patches. The 18-month bug-fix window means the previous major also keeps getting ordinary fixes for about six months after the new one ships. ## The PHP column Each major supports a range of PHP versions. Laravel 13 needs **PHP 8.3 or newer** and is listed up to 8.5. The range matters twice: a major cannot run below its floor, and a server stuck on an old PHP version blocks the framework upgrade. How PHP's own versions are supported is a PHP question; the Laravel question is which PHP range each major accepts. ## Other first-party packages The release notes add one more rule: for the other first-party libraries (Sanctum, Horizon, Telescope and the rest), **only the latest major release receives bug fixes**. Packages have their own major numbers that do not follow the framework's (Sanctum 4, Passport 13, Livewire 4), so an app should track them separately. ## Checking what an app runs Two quick checks tell you where an app stands: - `php artisan --version` prints the framework version, for example `Laravel Framework 13.34.0`. - The `laravel/framework` entry in `composer.lock` shows the exact installed release. Compare the major with the support table and today's date. A useful rule of thumb for planning: an app on the latest major has well over a year of bug-fix coverage left; an app on the previous major is in its last months of fixes; anything older is on borrowed time. Interviewers often follow up by asking what you would do with an app that is already past end of life, which leads straight into upgrade planning. ## What interviewers look for - The numbers: yearly majors, 18 months of bug fixes, 2 years of security fixes. - The current minimum PHP version for Laravel 13: 8.3. - The ability to say which majors are supported **today**, rather than reciting the table. - The practical reading: staying within one major of the latest release keeps an app inside a supported window with time to spare.
- A Laravel 12 app is running in October 2026. What support does it still get?Only security fixes. Laravel 12's bug-fix window ended on August 13th, 2026 and its security window runs until February 24th, 2027. Ordinary defects found now will be fixed only in Laravel 13, so the team should plan the upgrade before the security window closes rather than after.
- Why do two Laravel majors usually receive security patches at the same time?Majors arrive about 12 months apart and each gets 24 months of security fixes, so the previous major is still covered for about a year after the new one ships. That overlap is the upgrade window: time to move without running an unpatched framework.
saying these in an interview costs you the question
- Laravel ships a new major every six months
- Every Laravel major is a long-term-support release with three years of fixes
- Laravel 13 runs on PHP 8.2
- Security fixes stop as soon as the next major is released
- First-party packages give bug fixes to every major they ever shipped