skip to content

Yearly Majors & Support

Laravel ships one major release a year with 18 months of bug fixes and two years of security fixes; Laravel 13 needs PHP 8.3. Interviewers ask how you would plan and run a major upgrade.

on this pageshow

explore

questions

6

How often does Laravel ship a major release, and how long does each major receive bug fixes and security fixes?

level: juniorimportance: must knowfreq 55%

answer

  1. one major a year, around Q1
  2. 18 months of bug fixes
  3. 2 years of security fixes
  4. Laravel 13: March 17th, 2026
  5. 12 is security-only after August 2026

basics

~20 s

Laravel releases one major version a year, around the first quarter. Each major gets bug fixes for 18 months and security fixes for 2 years; Laravel 13 (March 2026) is covered for security until March 17th, 2028.

solid answer

~40 s

Laravel ships a new major of `laravel/framework` every year, around Q1, while minor and patch releases can come out as often as weekly. The support policy is the same for every major: **bug fixes for 18 months, security fixes for 2 years**. Laravel 13 was released on March 17th, 2026, gets bug fixes until Q3 2027 and security fixes until March 17th, 2028. Laravel 12 (February 24th, 2025) stopped getting bug fixes on August 13th, 2026 and gets security fixes until February 24th, 2027, so by late 2026 it is in its security-only phase. Laravel 11 and 10 are past end of life. Each major also has a supported PHP range: Laravel 13 accepts PHP 8.3 to 8.5. Other first-party libraries give bug fixes only to their latest major.

go deeper

for a junior

Memorise the pattern: one major a year, 18 months of bug fixes, 2 years of security fixes, and PHP 8.3 as Laravel 13's minimum.

for a middle

Be able to read the support table for a given date and say which majors get bug fixes, which get only security fixes, and which are end of life.

for a senior

Turn the windows into a schedule: when a major enters its security-only phase, the upgrade should already be planned, and the PHP floor checked on every server.

for a principal

Use the overlapping windows as a portfolio budget: how far behind any app may fall, and what happens when an app hits end of life before its upgrade lands.

## The cadence Laravel's release notes describe two speeds: - **Major releases** of `laravel/framework` come out **once a year, around the first quarter**. Laravel 10 arrived in February 2023, 11 in March 2024, 12 in February 2025 and 13 in March 2026. - **Minor and patch releases** (13.1, 13.2 ... 13.34) can come out **as often as every week**, and the policy says they should never contain breaking changes. So a team on Laravel 13 receives a steady flow of 13.x releases with fixes and small features, and faces one planned major upgrade a year. ## The support windows Every major gets the same two windows, counted from its release date: 1. **Bug fixes for 18 months.** Ordinary defects are fixed and released as 13.x updates. 2. **Security fixes for 2 years.** After the bug-fix window closes, only security issues are patched, until the second anniversary. 3. **End of life** after that: no fixes of any kind. The published table in the 13.x release notes: | Version | PHP | Released | Bug fixes until | Security fixes until | |---|---|---|---|---| | 10 | 8.1 - 8.3 | February 14th, 2023 | August 6th, 2024 | February 4th, 2025 | | 11 | 8.2 - 8.4 | March 12th, 2024 | September 3rd, 2025 | March 12th, 2026 | | 12 | 8.2 - 8.5 | February 24th, 2025 | August 13th, 2026 | February 24th, 2027 | | 13 | 8.3 - 8.5 | March 17th, 2026 | Q3 2027 | March 17th, 2028 | Reading the table at the end of September 2026: - **13** is fully supported. - **12** is in its **security-only** phase: its bug-fix window closed on August 13th, 2026. - **11** and **10** are **end of life**; a municipal permit portal still on 10 has had no security patches since February 2025. ## Why the windows overlap Because a new major arrives roughly every 12 months and each one is supported for 24, two majors are usually covered at once. That gives teams a year in which they can upgrade at their own pace while the previous major still gets security patches. The 18-month bug-fix window means the previous major also keeps getting ordinary fixes for about six months after the new one ships. ## The PHP column Each major supports a range of PHP versions. Laravel 13 needs **PHP 8.3 or newer** and is listed up to 8.5. The range matters twice: a major cannot run below its floor, and a server stuck on an old PHP version blocks the framework upgrade. How PHP's own versions are supported is a PHP question; the Laravel question is which PHP range each major accepts. ## Other first-party packages The release notes add one more rule: for the other first-party libraries (Sanctum, Horizon, Telescope and the rest), **only the latest major release receives bug fixes**. Packages have their own major numbers that do not follow the framework's (Sanctum 4, Passport 13, Livewire 4), so an app should track them separately. ## Checking what an app runs Two quick checks tell you where an app stands: - `php artisan --version` prints the framework version, for example `Laravel Framework 13.34.0`. - The `laravel/framework` entry in `composer.lock` shows the exact installed release. Compare the major with the support table and today's date. A useful rule of thumb for planning: an app on the latest major has well over a year of bug-fix coverage left; an app on the previous major is in its last months of fixes; anything older is on borrowed time. Interviewers often follow up by asking what you would do with an app that is already past end of life, which leads straight into upgrade planning. ## What interviewers look for - The numbers: yearly majors, 18 months of bug fixes, 2 years of security fixes. - The current minimum PHP version for Laravel 13: 8.3. - The ability to say which majors are supported **today**, rather than reciting the table. - The practical reading: staying within one major of the latest release keeps an app inside a supported window with time to spare.

  • A Laravel 12 app is running in October 2026. What support does it still get?
    Only security fixes. Laravel 12's bug-fix window ended on August 13th, 2026 and its security window runs until February 24th, 2027. Ordinary defects found now will be fixed only in Laravel 13, so the team should plan the upgrade before the security window closes rather than after.
  • Why do two Laravel majors usually receive security patches at the same time?
    Majors arrive about 12 months apart and each gets 24 months of security fixes, so the previous major is still covered for about a year after the new one ships. That overlap is the upgrade window: time to move without running an unpatched framework.

saying these in an interview costs you the question

  • Laravel ships a new major every six months
  • Every Laravel major is a long-term-support release with three years of fixes
  • Laravel 13 runs on PHP 8.2
  • Security fixes stop as soon as the next major is released
  • First-party packages give bug fixes to every major they ever shipped
open as a page

How would you move a municipal permit portal from Laravel 10 to Laravel 13, and why upgrade one major at a time?

level: seniorimportance: must knowfreq 50%

basics

~20 s

Move PHP to 8.3 first, since Laravel 10 through 13 all support it, then upgrade 10 to 11, 11 to 12 and 12 to 13, following each upgrade guide and getting tests green after every hop.

open as a page

What did Laravel 11's slim application skeleton change for new apps, and does an app upgraded from Laravel 10 have to adopt it?

level: middleimportance: should knowfreq 45%

basics

~20 s

Laravel 11 gave new apps a much smaller skeleton: no app-level kernel classes, middleware and exceptions configured in bootstrap/app.php, one service provider, and opt-in config, API and broadcasting files. Upgraded apps may keep their Laravel 10 structure.

open as a page

Under Laravel's versioning scheme, what may a minor laravel/framework release such as 13.34 change, and why are named arguments a risk?

level: middleimportance: should knowfreq 32%

basics

~20 s

A minor release like 13.34 may add features and fix bugs but should never contain breaking changes; those wait for the next major. Named arguments are excluded from that promise, because Laravel may rename method parameters in any release.

open as a page

When upgrading a Laravel app from 12 to 13, why is bumping laravel/framework not the whole upgrade, and what does comparing against the new skeleton add?

level: seniorimportance: should knowfreq 24%

basics

~20 s

The framework package changes framework code, but an app's config files, bootstrap files and composer.json were copied from the laravel/laravel skeleton and do not update themselves. The upgrade guide plus a 12.x-to-13.x skeleton diff shows which of those to change.

open as a page

You run a dozen Laravel apps for a city government on mixed majors; what upgrade cadence would you set, and what trade-offs does it involve?

level: principalimportance: nice to knowfreq 18%

basics

~20 s

Take minor releases continuously and schedule each app's major upgrade within a fixed window after Laravel's yearly Q1 release, so no app reaches its security-only phase unplanned; order the work by risk and exposure, not by app age.

open as a page