* 3.x:
Skip the sandbox `__toString` check on arguments whose PHP parameter type cannot implicitly coerce to string
Fix CS
Bump version
Prepare the 3.27.1 release
Fix inconsistent array access with a Stringable key
Preserve IteratorAggregate identity in sandbox __toString walker
Fix tests
Bump version
Prepare the 3.27.0 release
Fix sandbox filter/tag/function allow-list bypass when sandbox state changes between renders
Document new support for any expression as a dynamic mapping key
Fix sandbox __toString policy bypass via dynamic mapping keys
Fix deprecation notices in tests
Guard sandbox `__toString` walker against self-referencing iterables
Fix sandbox `__toString` bypass via `Stringable` + `Traversable` containers
Fix sandbox `__toString` bypass via the `in` and `not in` operators
Fix sandbox __toString bypass via Traversable in join/replace filters
Mark new SourcePolicyInterface column filter tests as @group legacy
Fix sandbox bypass in the "column" filter under SourcePolicyInterface
Fix sandbox bypass in deprecated internal wrappers
# Conflicts:
# CHANGELOG
# src/Environment.php
# src/Node/Expression/ArrayExpression.php
# src/Node/Expression/CallExpression.php
# src/Resources/core.php
# src/Template.php
# src/Util/CallableArgumentsExtractor.php
# src/Util/ReflectionCallable.php
# tests/Extension/SandboxTest.php
# tests/Resources/LegacyCoreTest.php
# tests/TemplateTest.php
* origin/3.x:
Add a `needs_is_sandboxed` option for filters, functions, and tests
Bump version
Make embeds deterministic
[Doc] Document loose comparison in the `in` operator
[Doc] Reword whitespace control note about first-newline removal
Stop publishing extra package minor versions with no changes
Lazy load EscaperRuntime in EscaperExtension
Fix typo
Replace parent-child analogy in `doc/tags/extends.rst`
doc: Add missing toctree entries and fix ordering
Fix CHANGELOG
Bump version
Prepare the 3.24.0 release
* 3.x:
[Doc] Document about `html` and `html_attr` strategies
Improve date methods phpdoc
Fix deprecation messages
Use a more precise return type in AbstractTwigCallable
fix the handling of predefined arguments in CallExpression
Allow Twig callable arguments to use camel or snake names
fix intl-extra tests
fix typo
* 3.x:
Rename a variable for more clarity
Set IteratorAggregate generics for Node
Add cross-link
Let's no deprecate the attribute function yet
Add more precise types for the registration of safe classes
Clarify coding standards
Fix markup
Fix markup
Clarify docs for the u filter
Allow to use a dynamic attribute on the . operator via ()
Remove most usage of foo/bar/baz in the docs
Tweak docs
Add StringCastUnary
* 3.x:
Remove obsolete code
Deprecate Environment::mergeGlobals()
Bump version
Prepare the 3.13.0 release
Fix wrong format of `Environment::VERSION_ID` constant
Fix minor things
Fix CS
Fix isset in ForLoopNode
Fix iterable return type
Improve exception expectations reliability
* 3.x:
Fix doc markup
Add an example on how to iterate over a string
Remove NodeCaptureInterface from TypesNode
Use CPP in full code base
Add types tag
Bump version
Bump version
Prepare the 3.12.0 release
Fix CS
Add conditional return types to `ensureTraversable`
Add return type `isTraitable`