Skip to content

build(deps): Bump http from 5.3.1 to 6.0.3#319

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/bundler/http-6.0.3
Open

build(deps): Bump http from 5.3.1 to 6.0.3#319
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/bundler/http-6.0.3

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 21, 2026

Bumps http from 5.3.1 to 6.0.3.

Release notes

Sourced from http's releases.

v6.0.3

Full Changelog: httprb/http@v6.0.2...v6.0.3

v6.0.2

What's Changed

Full Changelog: httprb/http@v6.0.1...v6.0.2

v6.0.1

Full Changelog: httprb/http@v6.0.0...v6.0.1

v6.0.0

What's Changed

... (truncated)

Changelog

Sourced from http's changelog.

[6.0.3] - 2026-04-20

Fixed

  • Ship RBS signatures for downstream consumers. Previously only sig/http.rbs was packaged, but it referenced LLHttp::Parser and LLHttp::Delegate (defined only in the unshipped sig/deps.rbs), causing Cannot find type LLHttp::Delegate errors in Steep when loading library "http". Public LLHttp stubs are now shipped in sig/llhttp.rbs, and sig/manifest.yaml declares stdlib dependencies so consumers don't need to re-list them.

[6.0.2] - 2026-03-20

Fixed

  • Fix RBS syntax error.

Changed

  • Improve gem push workflow security and reliability.

[6.0.1] - 2026-03-16

Changed

  • Exclude test files from gem package, reducing gem size by 50% (from 175 KB to 87 KB).

[6.0.0] - 2026-03-16

Changed

  • Merged http-form_data gem into the main http gem. The HTTP::FormData module (including Part, File, Multipart, Urlencoded, and CompositeIO) is now shipped directly with http instead of being a separate dependency. The public API is unchanged.

Fixed

  • Inflater no longer raises Zlib::BufError when a response declares Content-Encoding: gzip (or deflate) but the body is not valid compressed data. This commonly occurred when following redirects with auto_inflate enabled, because the redirect response had a Content-Encoding header but a non-compressed body. (#621)
  • Persistent connections now auto-flush unread response bodies before sending the next request, instead of raising StateError. Bodies up to 1 MiB are drained transparently; larger bodies cause the connection to close and reopen. This prevents the silent body clobbering described in #371, where an unread response body would return "" after a subsequent request. (#371)
  • Response#content_length now handles duplicate Content-Length headers per RFC 7230 Section 3.3.2. When all values are identical, they are collapsed into

... (truncated)

Commits
  • 0d2303d Release v6.0.3
  • fd174e2 Ship RBS signatures for downstream consumers
  • 10a257a Ignore .mutant directory
  • dd89cb1 Work around sigstore-ruby JRuby signing failure
  • d0886c9 Release v6.0.2
  • 042606b Improve gem push workflow security and reliability
  • 8e8eca9 Fix RBS syntax error
  • 866cb87 Release v6.0.1
  • 1ae2a60 Add mutant to default rake task and pass --since main flag
  • c39f85f Reduce gem package size by excluding non-essential files
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update Ruby code labels Apr 21, 2026
Bumps [http](https://github.com/httprb/http) from 5.3.1 to 6.0.3.
- [Release notes](https://github.com/httprb/http/releases)
- [Changelog](https://github.com/httprb/http/blob/main/CHANGELOG.md)
- [Commits](httprb/http@v5.3.1...v6.0.3)

---
updated-dependencies:
- dependency-name: http
  dependency-version: 6.0.3
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/bundler/http-6.0.3 branch from 303abcd to 2faead7 Compare April 22, 2026 19:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update Ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants