Skip to content

Update dependency guzzlehttp/guzzle to v7.15.1 - autoclosed#39

Closed
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/guzzlehttp-guzzle-7.x-lockfile
Closed

Update dependency guzzlehttp/guzzle to v7.15.1 - autoclosed#39
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/guzzlehttp-guzzle-7.x-lockfile

Conversation

@renovate

@renovate renovate Bot commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
guzzlehttp/guzzle (source) 7.12.37.15.1 age confidence

Release Notes

guzzle/guzzle (guzzlehttp/guzzle)

v7.15.1

Compare Source

Security

v7.15.0

Compare Source

Added
  • Added Multiplexing::NONE support as a client, cURL multi handler, and conditional request option
Changed
  • Adjusted guzzlehttp/psr7 version constraint to ^2.13
  • Use locale-independent ASCII folding for all case normalization and comparison
  • Bound cURL upload reads to the declared Content-Length
  • Sanitize the cURL error text exposed through exception handler context
  • Fail closed when a named cURL multi connection cap cannot be applied
  • Reject the request-level CURLOPT_SHARE cURL option when named connection caps are configured
  • Strengthen old-libcurl SOCKS isolation for raw CURLOPT_PRE_PROXY and opaque share handles
  • Isolate HTTP proxy tunnels from opaque shared connection caches
  • Trigger runtime deprecations for previously deprecated functionality in 7.1.0
Deprecated
  • Deprecated Utils::jsonDecode() and Utils::jsonEncode() in favor of native JSON functions
  • Deprecated passing CURLMOPT_PIPELINING in the cURL multi handler options array
  • Deprecated passing CURLOPT_PROXYHEADER without cURL proxy header separation support
Fixed
  • Defer cURL requests created from multi callbacks until native execution unwinds
  • Fail synchronous waits from native cURL callbacks promptly instead of self-deadlocking
  • Guard cURL multi handle removal against progress callbacks re-entering the handler
  • Scope promise waits on the cURL multi handler to the awaited transfer
  • Strip Content-Length and Transfer-Encoding when redirects discard the request body
  • Stop re-applying the delay request option to followed redirects

v7.14.2

Compare Source

Security

v7.14.1

Compare Source

Changed
  • Adjusted guzzlehttp/psr7 version constraint to ^2.12.5
Fixed
  • Fail closed when a proxy tunnel isolation cURL option cannot be applied
  • Normalize Stringable proxy credential values before computing connection-reuse section signatures
  • Restore conservative credential redaction for unparseable proxies with multiple @ separators
  • Redact request URI credentials from the stream handler connection error message
  • Reject enabled response streaming (stream => true) on cap-configured stream handlers
  • Distinguish CurlMultiHandler and StreamHandler outcomes in connection-cap custom-handler guidance
  • Reject raw cURL options that conflict with explicit multiplexing guarantees
  • Stop explicit multiplexing conflict checks faulting on non-array cURL multi options values
  • Reject required multiplexing when the final CURLOPT_HTTPAUTH mask permits NTLM
  • Require an integer CURLMOPT_PIPELINING when combined with explicit multiplexing
  • Check the required multiplexing cleartext proxy rule against the final cURL configuration
  • Bound cURL multi handler blocking selects by the earliest pending request delay
  • Stop synchronous cURL multi handler waits blocking on other transfers once the target has settled
  • Stop cURL multi completion processing double-settling promises canceled from completion callbacks
  • Run ready promise queue tasks before sleeping for delayed cURL multi requests
  • Avoid integer overflow in cURL multi delay timing on 32-bit platforms
  • Roll back failed cURL multi handle attachment instead of leaving requests pending
  • Release the cURL easy handle when the on_stats callback throws
  • Normalize response trailer field names to lowercase with values in wire order
  • Retain response trailers only when an on_trailers callback is configured
  • Validate the on_trailers callback before starting a cURL transfer
  • Reject the on_trailers request option on the stream handler, which cannot observe trailers
  • Match cookies, proxy schemes, auth types, and header names with locale-independent ASCII folding
  • Reject proxy option values that Guzzle cannot classify identically to ext-curl

v7.14.0

Compare Source

Added
  • Added the on_trailers request option to expose parsed HTTP response trailers
  • Added the multiplex request option with Multiplexing::* modes to control or require HTTP/2 multiplexing
  • Added rejection of explicit multiplex requests when CURLMOPT_PIPELINING disables multiplexing
  • Added the max_host_connections and max_total_connections client and cURL multi handler options
Changed
  • Redirects that discard the request body no longer require it to be rewindable
  • Synchronous cURL multi handler requests no longer wait for other queued transfers
  • Section SOCKS proxy connections by credentials on libcurl before 7.69.0
  • Reject request-level CURLOPT_SHARE when combined with authenticated SOCKS proxy configuration
  • Redact proxy userinfo containing raw control bytes in cURL errors
  • Check linked curl/libcurl NTLM support before applying NTLM auth
  • Clarify that NTLM is deprecated by both Guzzle and curl/libcurl
  • Remove deprecation for the raw cURL CURLOPT_CERTINFO option
  • Warn when a cURL multi option cannot be applied
Deprecated
  • Deprecate the raw CURLOPT_PIPEWAIT cURL option in favour of the multiplex request option
  • Deprecate unknown handler constructor options
  • Deprecate invalid select_timeout cURL multi handler option values
  • Deprecate raw cURL multi connection cap options in favour of the named options

v7.13.3

Compare Source

Changed
  • Adjusted guzzlehttp/promises version constraint to ^2.5.1
  • Adjusted guzzlehttp/psr7 version constraint to ^2.12.4
  • Pass explicit trim characters ahead of the PHP 8.6 trim default change
Fixed
  • Stop matching cookie domains against hosts with a trailing newline
  • Reject HTTP status codes and certificate type extensions with a trailing newline
  • Treat PCRE engine failures as invalid cookie names during cookie validation
  • Report PCRE engine failures when formatting log messages
  • Report PCRE engine failures when splitting no_proxy values

v7.13.2

Compare Source

Fixed
  • Stop the cURL multi handler busy-waiting on request delays shorter than one second
  • Stop cURL HEAD requests with request bodies hanging on responses that declare a content length
  • The cURL handler no longer transmits request bodies on HEAD requests
  • Preserve response headers when a response includes HTTP trailers
  • Harden cURL response header block detection when HTTP trailers are received
  • Corrected the PSR-7 class names in the Pool iterator exception
  • Redirect body rewind failures no longer leak a bare RuntimeException

v7.13.1

Compare Source

Fixed
  • Allow middleware to rewrite partial URIs before transports validate them

v7.13.0

Compare Source

Added
  • Added the crypto_method_max request option to cap the maximum TLS protocol version
  • Added HTTP QUERY redirect support, preserving method and body on 301 and 302
Changed
  • Section proxy tunnel connection reuse by credential so distinct credentials never share a tunnel
  • Isolate concurrent foreign cURL proxy tunnels added while another owner's tunnel is active
  • Route credentialed HTTP(S) proxy Proxy-Authorization headers through cURL proxy header handling
  • Reject request-level CURLOPT_SHARE when combined with authenticated HTTP/HTTPS proxy tunnel configuration
  • Remove deprecation for raw cURL CURLOPT_PREREQFUNCTION callbacks when defined by PHP cURL
  • Route TLS 1.2 crypto_method requests to the stream handler when cURL cannot select TLS 1.2
  • Reject final request URIs missing a scheme or host before transfer
Deprecated
  • Deprecate invalid protocols, force_ip_resolve, delay, cookies, and allow_redirects values

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot changed the title Update dependency guzzlehttp/guzzle to v7.13.0 Update dependency guzzlehttp/guzzle to v7.13.1 Jun 30, 2026
@renovate
renovate Bot force-pushed the renovate/guzzlehttp-guzzle-7.x-lockfile branch 2 times, most recently from 76bd0ab to 8cfb8d9 Compare July 5, 2026 20:38
@renovate renovate Bot changed the title Update dependency guzzlehttp/guzzle to v7.13.1 Update dependency guzzlehttp/guzzle to v7.13.2 Jul 5, 2026
@renovate
renovate Bot force-pushed the renovate/guzzlehttp-guzzle-7.x-lockfile branch from 8cfb8d9 to 4d4a4c2 Compare July 8, 2026 19:31
@renovate renovate Bot changed the title Update dependency guzzlehttp/guzzle to v7.13.2 Update dependency guzzlehttp/guzzle to v7.13.3 Jul 8, 2026
@renovate renovate Bot changed the title Update dependency guzzlehttp/guzzle to v7.13.3 Update dependency guzzlehttp/guzzle to v7.14.0 Jul 9, 2026
@renovate
renovate Bot force-pushed the renovate/guzzlehttp-guzzle-7.x-lockfile branch 2 times, most recently from 649518d to dd201df Compare July 13, 2026 02:02
@renovate renovate Bot changed the title Update dependency guzzlehttp/guzzle to v7.14.0 Update dependency guzzlehttp/guzzle to v7.14.1 Jul 13, 2026
@renovate
renovate Bot force-pushed the renovate/guzzlehttp-guzzle-7.x-lockfile branch from dd201df to e9a4de6 Compare July 14, 2026 22:52
@renovate renovate Bot changed the title Update dependency guzzlehttp/guzzle to v7.14.1 Update dependency guzzlehttp/guzzle to v7.14.2 Jul 14, 2026
@renovate
renovate Bot force-pushed the renovate/guzzlehttp-guzzle-7.x-lockfile branch from e9a4de6 to 6e65466 Compare July 17, 2026 13:34
@renovate renovate Bot changed the title Update dependency guzzlehttp/guzzle to v7.14.2 Update dependency guzzlehttp/guzzle to v7.15.0 Jul 17, 2026
@renovate renovate Bot changed the title Update dependency guzzlehttp/guzzle to v7.15.0 Update dependency guzzlehttp/guzzle to v7.15.1 Jul 18, 2026
@renovate
renovate Bot force-pushed the renovate/guzzlehttp-guzzle-7.x-lockfile branch from 6e65466 to dc018ac Compare July 18, 2026 14:07
@renovate renovate Bot changed the title Update dependency guzzlehttp/guzzle to v7.15.1 Update dependency guzzlehttp/guzzle to v7.15.1 - autoclosed Jul 21, 2026
@renovate renovate Bot closed this Jul 21, 2026
@renovate
renovate Bot deleted the renovate/guzzlehttp-guzzle-7.x-lockfile branch July 21, 2026 12:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants