chore(deps): update dependency guzzlehttp/guzzle to v8 - #255
chore(deps): update dependency guzzlehttp/guzzle to v8#255renovate-bot-cbcoutinho[bot] wants to merge 1 commit into
Conversation
|
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Claude finished @renovate-bot-cbcoutinho[bot]'s task in 1m 54s —— View job Reviewing PR #255
SummaryThis PR only bumps the Why the lock update actually fails
Consequence if this merged with the stale lock file: Actual breaking-change exposure (for when this does become resolvable)Good news: the blast radius in this repo is narrow.
The full RecommendationDon't merge yet — this matches Renovate's own "You probably do not want to merge this PR as-is" warning. Let Renovate keep retrying (it will re-run once No code changes accompany this PR, so no additional test coverage is required beyond the existing suites passing against a correctly resolved lock file once the upstream conflict is resolved. |
bf6cc7b to
e0fb749
Compare
|



This PR contains the following updates:
^7.0→^8.0Release Notes
guzzle/guzzle (guzzlehttp/guzzle)
v8.1.0Compare Source
Added
CURLOPT_SEEKFUNCTIONChanged
guzzlehttp/promisesversion constraint to^3.0.2guzzlehttp/psr7version constraint to^3.1no_proxyrules against IPv4 hosts written in the shorthand a transport reads as an addressv8.0.3Compare Source
Changed
guzzlehttp/psr7version constraint to^3.0.1v8.0.2Compare Source
Changed
guzzlehttp/promisesversion constraint to^3.0.1Fixed
StreamHandlerresolving numeric IPv4 hosts differently from cURL handlers on macOS and WindowsStreamHandlerTLS peer names and proxy authorities for numeric IPv4 hosts on all platformsv8.0.1Compare Source
Security
Hostheader values that are not printable ASCII (GHSA-v5mv-p594-2x33)Hostheader after client URI rewrites (GHSA-v5mv-p594-2x33)v8.0.0Compare Source
Added
SensitiveParametermetadata to credential-bearing parameters so PHP 8.2+ redacts their values in exception tracesMultiplexing::NONEsupport as a client, cURL multi handler, and conditional request optionConnectTimeoutExceptionfor connect-phase timeouts, extendingConnectExceptionNetworkExceptionfor no-response network failuresNetworkTimeoutExceptionfor no-response transport timeoutsResponseTransferException, withResponseTimeoutExceptionfor response-transfer timeoutsrequest_factory,response_factory,stream_factory, anduri_factoryrequest optionsclose()lifecycle methods to the built-in cURL handlers and concrete cURL factoryHandlerClosedExceptionfor pending transfers rejected byCurlMultiHandler::close()TransportSharing::PERSISTENT_PREFERandTransportSharing::PERSISTENT_REQUIRE)ProxyOptionsfor proxy option resolutionResponseExceptionfor request failures with responsesChanged
__Secure-and__Host-prefix requirements on response cookiesFileCookieJarandSessionCookieJarpersistence against unsafe unserializationFileCookieJarcookie files to owner-only permissionsRuntimeExceptionUtilstime, timeout, IDN, and environment helpers to dedicated internal classesguzzlehttp/promisesversion constraint to^3.0guzzlehttp/psr7version constraint to^3.0Content-Typeboundary parameters when requiredSetCookiemethodsstringreturn type toSetCookie::__toString()force_ip_resolve, protocols, anddelayranges at the client boundarynoentry as final even without a scheme-specific proxy entryRequestException, notInvalidArgumentException, for an unavailable proxy or TLS featureno_proxy/NO_PROXYfrom the environment in the stream handler, including*to disable proxyinghttps://or SOCKS proxy in the stream handler, matching itsproxyoption behaviorProxy-Authorizationon every routeProxy-Authorizationfield, including empty, on stream proxiesCURLOPT_PROXYHEADERwithout proxy header separation supporton_headerscallbacksPooliterable key as a trailing argument to per-request observer callbacksidn_conversion,retries, and built-in handleron_statsoption values before usequeryandform_paramsoptionsbodyoptionExpect: 100-Continueinjection to HTTP/1.1 requests onlySetCookieconstructor field types instead of coercing themnullas an omitted path or name when clearing cookiesauthrequest option arraysauthrequest optionauthrequest option when following cross-origin redirectsRefererheader to the origin on cross-origin redirectsHandlerStack::remove()argumentsPoolrequest collections to be iterableDomainattribute as host-only cookiesMax-AgeoverExpireswhen both attributes are presentCookieJar::getCookieByName()Max-Agecookie values instead of truncating themContent-Lengthand combinations withTransfer-EncodingTransfer-Encodingmetadata and coalesced framing inprogresson newer PHPLocationvalues inBadResponseExceptioncrypto_methodoption through the SSL context so it consistently controls the minimum TLS versionTransferExceptionand its subclassesNetworkExceptionConnectException, with connect timeouts asConnectTimeoutExceptionNetworkException, with timeouts asNetworkTimeoutExceptionResponseExceptionResponseTransferExceptionsinkoption or reads trailing bytes for responses that cannot carry a bodyContent-Length, including decoded gzip/deflateContent-Lengthcasings and preserve encoded values on decoded responsesResponseException101 Switching Protocolsbefore the final responseResponseExceptionand skip non-seekable sink rewindsResponseExceptionGuzzleHttp\Exception\InvalidArgumentExceptionfor invalid built-in handler optionssink, and HTTP/3 setup failures asRequestExceptionConnectTimeoutExceptionfor connect timeoutsNetworkTimeoutExceptionfor cURL no-response timeout errorsResponseTimeoutExceptionfor response-aware transfer timeoutstimeoutoption as a total transfer deadline in the stream handler when it buffers the responsetimeoutdeadlinedefault_socket_timeoutini setting in the stream handlerread_timeoutas an idle timeout for every request stage, defaulting to 60 secondsconnect_timeoutset to0disabling itUser-AgentandFromheader values from theuser_agentandfromini settingsRequestExceptionorResponseExceptionby phaseResponseExceptionorRequestExceptionby phasesinkas caller-owned in the built-in cURL and stream handlersLocationheadersprogresscallbacks to abort transfers with truthy return valuesprogresscallback arguments to integer byte countsprogressthrowables withResponseExceptionwhen a response exists, otherwiseRequestExceptionon_statsCURLOPT_XFERINFOFUNCTIONfor built-in cURL progress callbacks when availableMessageFormatterfinal and requiredMiddleware::log()formatters to implementMessageFormatterInterfaceCurlFactory,CurlHandler,CurlMultiHandler,MockHandler, andStreamHandlerfinalGuzzleHttp\Handler\Proxyfinalon_trailerscallbacks, reject non-callableon_trailersvalues, and wrapon_trailerscallback exceptions inResponseExceptionmultiplexdefaults toMultiplexing::WAIT)CURLOPT_PIPEWAITcURL option at themultiplexrequest optionCURLMOPT_PIPELININGin favour of themultiplexcURL multi handler optionCURLOPT_HTTPAUTHmask permits NTLMselect_timeoutcURL multi handler option valuesSet-Cookiestrings with RFC 6265 whitespace trimmingSet-Cookieattributes that require a value when parsingRemoved
Client::__call(); use the typed HTTP verb methods orrequest()/requestAsync()ClientInterface::getConfig(); the concreteClient::getConfig()remains availableGUZZLE_CURL_SELECT_TIMEOUTenvironment variable; useCurlMultiHandler'sselect_timeoutoptionhandlerrequest option; configure the handler on the clientCurlMultiHandler::$_mh; passCURLMOPT_*values through constructoroptionsinsteadRedirectMiddleware::$defaultSettings; useRedirectMiddleware::DEFAULT_SETTINGSRetryMiddleware::exponentialDelay()methodRequestException::wrapException()methodUtils::describeType()methodUtils::jsonDecode()andUtils::jsonEncode()in favor of native JSON functionsGuzzleHttpnamespace functions in favor of native or class equivalentsUtils::defaultCaBundle(); rely on the system trust store or pass a bundle path via theverifyoptionHandlerStack::__toString()RequestException::getHandlerContext()andConnectException::getHandlerContext()RequestException; useResponseExceptionUtils::isHostInNoProxy(); useProxyOptionshelpers for Guzzle 8 no-proxy matchingUtils::isUriInNoProxy(); useProxyOptions::isUriInNoProxy()Handler\Proxy::wrapTlsFallback(); the default handler stack selects the cURL or stream handler by TLS support automaticallyConfiguration
📅 Schedule: (in timezone Europe/Amsterdam)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.