Download Latest Version Released version 2.12.1 source code.zip (138.0 kB) Google Add to Preferred Sources
Home / v2.12.1
Name Modified Size InfoDownloads / Week
Parent folder
README.md 2026-08-18 3.4 kB
Released version 2.12.1 source code.tar.gz 2026-08-18 91.9 kB
Released version 2.12.1 source code.zip 2026-08-18 138.0 kB
Totals: 3 Items   233.2 kB 0

A hardening release that follows 2.12.0. The Dumper learns to speak modern PHP – virtual hooked properties, WeakReference, PHP 8.5 URI objects – any HTTP client can now ask for markdown output with a single header, and a long list of fixes makes the Bar, the session and the logger behave under concurrency, broken storage and hostile input.

✨ New Features

  • The Dumper now understands modern PHP constructs – PHP 8.4 virtual hooked properties render as {virtual} instead of the misleading unset, WeakReference shows its target (or (dead)), PHP 8.5 Uri\Rfc3986\Uri and Uri\WhatWg\Url expand into address and components, closures reveal the class of their bound $this, and lazy objects expose their eagerly-initialized private and protected properties without throwing
  • cURL handles are dumped again – now via CurlHandle, not the long-gone resource type
  • X-Tracy-Agent request header – non-browser agents (curl, HTTP clients, CI jobs) can ask for markdown output without the webdriver cookie, and a non-HTML response carries the markdown BlueScreen straight in the body
  • editor: false in the Nette configuration finally disables editor links; previously the value was silently ignored

🐛 Bug Fixes

  • Tracy's fetch() wrapper no longer drops the options argument and no longer mutates the caller's Request object – AJAX calls reach the server exactly as your code wrote them
  • The XMLHttpRequest patch stopped stacking a load listener on every open() call, and a dump with a broken payload no longer aborts the initialization of every other dump on the page
  • A corrupt localStorage / sessionStorage entry no longer breaks the Bar and Toggle initialization
  • Toggle links can be activated from the keyboard again
  • Dumper::$keysToHide and the scrubber now also apply to properties returned by __debugInfo() and custom object exporters – sensitive values no longer slip through
  • Debugger::dump() with return: true respects $keysToHide and passes the options in CLI mode
  • The email throttle is now atomic and honest: an invalid $emailSnooze interval throws instead of silently flooding your inbox, concurrent requests can no longer both send the same notification, and the snooze window restarts only after the mail was really sent
  • TracyToPsrLoggerAdapter no longer logs an exception twice when the accompanying message adds no information, and casts Stringable messages to string
  • FileSession hardening – session files are created with mode 0600, unserialization refuses objects, the cookie gets SameSite=Lax plus the secure flag on HTTPS, and concurrent garbage collection no longer emits warnings
  • BlueScreen no longer triggers autoloading of class names it finds in an exception message
  • The exception fallback output is HTML-escaped in HTML mode
  • A repeated DeferredContent::enable() after output has started is a harmless no-op instead of an exception
  • The Dumper's exposer ordering comparator is a valid total order and understands interface-keyed exposers, so custom exposers are picked deterministically
  • Removed legacy browser workarounds (IE getAttribute flag, keyCode, navigator.platform, document.write() in the panel popup) and evalScripts() no longer leaves executed <script> clones behind in the DOM
Source: README.md, updated 2026-08-18