PlanPHP & Laravel
PHP 8.6 reaches release candidate with stricter session defaults
There was no RC1: the first release candidate is RC2, shipped September 24. The feature list is frozen, and three session defaults change.

What to do
Add the 8.6 RC to your CI matrix now and search for session configuration and the newly deprecated functions.
There was no RC1: a release script bumped the API version numbers at the wrong step, so the release managers skipped that tag. The schedule now: RC2 shipped September 24, then RC3 on October 8, RC4 on October 22, RC5 on November 5 and the final release on November 19.
The hard feature freeze was September 22, so the feature list is set: partial function application, clamp(), a Time\Duration class, a new Io\Poll polling API, URI builders, and TLS session resumption and early data in OpenSSL streams.
The change most likely to bite is the session defaults:
- session.use_strict_mode is now 1.
- session.cookie_httponly is now 1, so JavaScript can no longer read the session cookie.
- session.cookie_samesite is now "Lax".
New deprecations include return inside finally, returning a value from __construct() or __destruct(), the third argument of define(), spl_object_hash() (use spl_object_id()), is_double(), is_long(), is_integer() and doubleval(), strcoll(), SORT_LOCALE_STRING, metaphone() and mbregex.