Laravel 2,157 follows semantic versioning. A major release arrives once a year, around the first quarter, and is the only kind allowed to break your code. Minor and patch releases ship as often as weekly and must not: 13.0.0 was tagged on 17 March 2026, and by 22 September the framework had reached 13.33.0. That is why composer.json requires "laravel/framework": "^13.17", which accepts every later 13.x release and never 14.0. Each major release gets 18 months of bug fixes and 2 years of security fixes.
| Version | PHP | Released | Bug fixes until | Security fixes until |
|---|---|---|---|---|
| 10 | 8.1-8.3 | 14 Feb 2023 | 6 Aug 2024 | 4 Feb 2025 |
| 11 | 8.2-8.4 | 12 Mar 2024 | 3 Sep 2025 | 12 Mar 2026 |
| 12 | 8.2-8.5 | 24 Feb 2025 | 13 Aug 2026 | 24 Feb 2027 |
| 13 | 8.3-8.5 | 17 Mar 2026 | Q3 2027 | 17 Mar 2028 |
Laravel 10 and 11 are out of support. Laravel 12 lost bug fixes on 13 August 2026 and gets security patches only until February 2027, so an application on 12 has five months to upgrade. Laravel 13 is the only line receiving bug fixes, which is why this chapter uses it. Budget one major upgrade each spring; two at once is far harder. Note that named arguments are outside the compatibility promise: Str::limit(value: $s, limit: 20) can break when a parameter is renamed.