@@ -281,6 +281,19 @@ create new projects. If you use Composer, you need to tell the exact version:
281281
282282 $ composer create-project symfony/skeleton:"6.4.*" my_project_directory
283283
284+ With an already existing project, you can restrict Symfony packages to one
285+ LTS version by:doc: `using Symfony Flex in your project </setup/flex >`
286+ and setting the ``extra.symfony.require `` config:
287+
288+ ..code-block ::terminal
289+
290+ $ composer config extra.symfony.require "5.4.*"
291+
292+ ..warning ::
293+
294+ Tools like dependabot may ignore this setting and upgrade the Symfony dependencies,
295+ see this `GitHub issue about dependabot `_.
296+
284297The Symfony Demo application
285298----------------------------
286299
@@ -315,6 +328,7 @@ Learn More
315328.. _`Install Composer` :https://getcomposer.org/download/
316329.. _`install the Symfony CLI` :https://symfony.com/download
317330.. _`symfony-cli/symfony-cli GitHub repository` :https://github.com/symfony-cli/symfony-cli
331+ .. _`GitHub issue about dependabot` :https://github.com/dependabot/dependabot-core/issues/4631
318332.. _`The Symfony Demo Application` :https://github.com/symfony/demo
319333.. _`Symfony Flex` :https://github.com/symfony/flex
320334.. _`PHP security advisories database` :https://github.com/FriendsOfPHP/security-advisories