Skip to content

build(deps): Bump http from 5.3.1 to 6.0.2#303

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/bundler/http-6.0.2
Open

build(deps): Bump http from 5.3.1 to 6.0.2#303
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/bundler/http-6.0.2

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 23, 2026

Bumps http from 5.3.1 to 6.0.2.

Release notes

Sourced from http's releases.

v6.0.2

What's Changed

Full Changelog: httprb/http@v6.0.1...v6.0.2

v6.0.1

Full Changelog: httprb/http@v6.0.0...v6.0.1

v6.0.0

What's Changed

... (truncated)

Changelog

Sourced from http's changelog.

[6.0.2] - 2026-03-20

Fixed

  • Fix RBS syntax error.

Changed

  • Improve gem push workflow security and reliability.

[6.0.1] - 2026-03-16

Changed

  • Exclude test files from gem package, reducing gem size by 50% (from 175 KB to 87 KB).

[6.0.0] - 2026-03-16

Changed

  • Merged http-form_data gem into the main http gem. The HTTP::FormData module (including Part, File, Multipart, Urlencoded, and CompositeIO) is now shipped directly with http instead of being a separate dependency. The public API is unchanged.

Fixed

  • Inflater no longer raises Zlib::BufError when a response declares Content-Encoding: gzip (or deflate) but the body is not valid compressed data. This commonly occurred when following redirects with auto_inflate enabled, because the redirect response had a Content-Encoding header but a non-compressed body. (#621)
  • Persistent connections now auto-flush unread response bodies before sending the next request, instead of raising StateError. Bodies up to 1 MiB are drained transparently; larger bodies cause the connection to close and reopen. This prevents the silent body clobbering described in #371, where an unread response body would return "" after a subsequent request. (#371)
  • Response#content_length now handles duplicate Content-Length headers per RFC 7230 Section 3.3.2. When all values are identical, they are collapsed into a single valid value. When values conflict, nil is returned instead of raising TypeError. (#566)
  • HTTP 1xx informational responses (e.g. 100 Continue) are now transparently skipped, returning the final response. This was a regression introduced when the parser was migrated from http-parser to llhttp. (#667)
  • Redirect loop detection now considers cookies, so a redirect back to the same URL with different cookies is no longer falsely detected as an endless loop. Fixes cookie-dependent redirect flows where a server sets a cookie on one hop and expects it on the next. (#544)
  • Per-operation timeouts (HTTP.timeout(read: n, write: n, connect: n)) no longer default unspecified values to 0.25 seconds. Omitted timeouts now mean

... (truncated)

Commits
  • d0886c9 Release v6.0.2
  • 042606b Improve gem push workflow security and reliability
  • 8e8eca9 Fix RBS syntax error
  • 866cb87 Release v6.0.1
  • 1ae2a60 Add mutant to default rake task and pass --since main flag
  • c39f85f Reduce gem package size by excluding non-essential files
  • 26f26c4 Switch gem release to OIDC API key role with JRuby support
  • 5d1ff43 Release v6.0.0
  • 1dbc20d Merge form_data into http
  • e68bddc Override release task to skip gem push (handled by CI)
  • Additional commits viewable in compare view

@dependabot dependabot bot added dependencies Pull requests that update a dependency file ruby Pull requests that update Ruby code labels Mar 23, 2026
@dependabot dependabot bot force-pushed the dependabot/bundler/http-6.0.2 branch 3 times, most recently from 3883a25 to 57cafac Compare March 27, 2026 19:42
Bumps [http](https://github.com/httprb/http) from 5.3.1 to 6.0.2.
- [Release notes](https://github.com/httprb/http/releases)
- [Changelog](https://github.com/httprb/http/blob/main/CHANGELOG.md)
- [Commits](httprb/http@v5.3.1...v6.0.2)

---
updated-dependencies:
- dependency-name: http
  dependency-version: 6.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot force-pushed the dependabot/bundler/http-6.0.2 branch from 57cafac to ecbc02d Compare March 29, 2026 18:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update Ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants