chore(deps): update dependency req to ~> 0.7 - #44
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
Contributor
Author
|
renovate
Bot
force-pushed
the
renovate/req-0.x
branch
from
July 28, 2026 08:52
65950be to
e722fef
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
~> 0.5→~> 0.7Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
wojtekmach/req (req)
v0.7.1Compare Source
cache: true/[cache] step. It will be removed in Req v0.8. I plan a comprehensive cache solution for Req v1.0+.v0.7.0Compare Source
[
Req]: AddReq.new(req, options).[
Req]: Treat URL userinfo as Basic Authentication.[
Req], [Req.Request]: Deprecateadapter: funin favour ofadapter: mod.[
Req.Request]: (BREAKING CHANGE) Removecurrent_request_stepsfield.[
Req.Request]: Fix redacting remaining auth values.(BREAKING CHANGE) Replace
run_finchstep with [Req.Finch] adapter module.(BREAKING CHANGE) Replace
put_plugandrun_plugsteps with [Req.Plug] adapter module.[
Req.Finch]: Supportfinch: options.[
Req.Finch]: Support:request_timeout.[
Req.Finch]: Fix handling duplicate response headers.[
Req.Finch]: Deprecatefinch: namein favour offinch: [name: name].[
Req.Finch]: Deprecatepool_timeout: valuein favour offinch: [pool_timeout: value].[
Req.Finch]: Deprecatepool_max_idle_time: valuein favour offinch: [pool_max_idle_time: value].[
Req.Finch]: Deprecate:finch_request.[
Req.Plug]: Handle individual response body chunks.[
Req.Plug]: Support non-UTF8 request params.[
Req.Plug]: Put original request private data inconn.private.[
Req.Test]: Allow descendant processes.[
Req.Test]: Fix concurrent plug fetches immediately after switching to shared mode.[
compress_body]: Do nothing when request content-encoding is already set.[
compress_body]: Update multipart boundary when re-running the step.[
compressed], [decode_body]: Replace optionalezstddependency with Erlang/OTP 28+built-in
:zstd.[
decode_body]: Deprecate:decode_jsonin favour of setting a custom JSONdecoder via
:decoders:before:
after:
[
encode_body]: (BREAKING CHANGE) Automatically change GET to POST when request body is set.[
put_aws_sigv4]: Excludeaccept-encoding,x-amzn-trace-id, andhop-by-hop headers from the signature.
[
put_aws_sigv4]: Correctly sign duplicate header values.[
put_params]: (BREAKING CHANGE) Overwrite existing query params instead of appending.[
put_path_params]: Preserve the path template when re-running the step.[
redirect]: Strip userinfo from redirect locations and log a warning.Previously, redirecting to a URL with userinfo (e.g.
http://user:pass@host)kept the userinfo in the request URL (without converting it to auth). It is
now dropped so credentials supplied by the redirecting server aren't sent.
[
redirect]: Clear the request body, body options, and content headers whenchanging POST to GET after a 301, 302, or 303 response.
[
retry]: Use jitter by default.[
retry]: Honor configured:retry_delayoverRetry-After.(BREAKING CHANGE) Remove deprecated
follow_redirectsstep.(BREAKING CHANGE) Remove deprecated
outputstep.Require Elixir 1.15 or later.
v0.6.3Compare Source
Req.Test]: Fix race conditionv0.6.2Compare Source
v0.6.1Compare Source
[
compressed], [decompress_body]: Disable automatic decompressionDecompression is now opt-in by setting
compressed: true.v0.6.0Compare Source
[
encode_body]: Security fix for:form_multipartheader injection(GHSA-px9f-whj3-246m).
The multipart encoder interpolated the per-part
name,filename, andcontent_typeinto the part headers without escaping, so anattacker-controlled value could inject extra headers or smuggle additional
parts into the request. These values are now escaped per RFC 7578 / WHATWG
form-data (
", CR, and LF are percent-encoded).Thanks to @PJUllrich for reporting it.
[
decode_body]: Drop automatic zip/tar/tgz/gz/zst/csv decoding,(GHSA-655f-mp8p-96gv).
Req previously auto-decoded archive and compressed response bodies (
zip,tar,tgz,gz,zst, andcsv) based on the server-suppliedcontent-type, materialising the full decompressed contents in memory withno size cap. An attacker-controlled (or redirect-reachable) endpoint could
return a tiny "decompression bomb" that expanded to gigabytes and exhausted
the node's memory.
Now only JSON is decoded by default. Other formats are opt-in via the new
:decodersoption, which defaults to[:json, :json_api]. Setting itreplaces the default (include
:jsonto keep JSON decoding), andfalsedisables all decoding:
opt into archives (only for endpoints you trust):
v0.5.18Compare Source
[
run_finch]: Allow :finch option with IPv6 URLs.[
run_finch]: NormalizeFinch.TransportErrorandFinch.HTTPError(introduced in Finch v0.22.0) into
Req.TransportErrorandReq.HTTPError.[
retry]: Automatically retry on:pool_not_available.Require Finch ~> 0.21.0 or ~> 0.22.0.
v0.5.17Compare Source
[
retry]: Use default delay ifretry-afteris "negative"Previously, we were only handling "negative" retry-after in "http date"
format and slept for zero seconds. We were crashing on retry-after with
negative seconds.
Now, we're using the default delay (1s, 2s, 4s, ...) in either format.
v0.5.16Compare Source
Req.Test]: Fixverify_on_exit!accidentally using Mox nameauth]: Support MFArgsauth]: Support digest authput_aws_sigv4]: Support MFArgsput_path_params]: Encode:path_paramseven with reserved charactersput_path_params]: Set:path_params_templateon empty paramsrun_plug]: Handle compressed request bodyConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.