fix(deps): update dependency org.http4k:http4k-bom to v6.56.0.0#9
Open
renovate[bot] wants to merge 1 commit into
Open
fix(deps): update dependency org.http4k:http4k-bom to v6.56.0.0#9renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
2 times, most recently
from
June 21, 2025 00:12
bbe585b to
91158dc
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
June 29, 2025 14:42
91158dc to
a961cd3
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
September 6, 2025 22:49
a961cd3 to
edb6a5a
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
September 14, 2025 12:33
edb6a5a to
451f62d
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
September 24, 2025 18:02
451f62d to
eb35811
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
October 6, 2025 13:00
eb35811 to
0286d2a
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
October 23, 2025 03:54
0286d2a to
cac9966
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
October 23, 2025 13:12
cac9966 to
b378608
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
October 23, 2025 22:59
b378608 to
2d46455
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
October 31, 2025 18:49
2d46455 to
4921c57
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
November 8, 2025 21:44
4921c57 to
00fda34
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
November 9, 2025 18:34
00fda34 to
8f281d2
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
November 18, 2025 02:47
8f281d2 to
a488b55
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
November 19, 2025 00:48
a488b55 to
0608c41
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
December 30, 2025 06:09
c96d027 to
fbb2e10
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
January 13, 2026 21:57
fbb2e10 to
e978612
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
January 22, 2026 21:30
e978612 to
b6a8c5f
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
January 31, 2026 21:14
b6a8c5f to
0f63577
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
February 9, 2026 10:41
0f63577 to
34ff943
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
February 10, 2026 23:30
34ff943 to
f734729
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
February 15, 2026 13:08
f734729 to
41f9c91
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
February 16, 2026 02:39
41f9c91 to
bc9efde
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
February 20, 2026 20:23
bc9efde to
d2fcb1f
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
February 23, 2026 00:36
d2fcb1f to
2481451
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
February 23, 2026 22:05
2481451 to
8ea65f7
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
March 8, 2026 05:24
8ea65f7 to
7707ce4
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
March 9, 2026 20:57
7707ce4 to
04fdd82
Compare
renovate
Bot
force-pushed
the
renovate/org.http4k-http4k-bom-6.x
branch
from
March 15, 2026 01:21
04fdd82 to
5d1bedf
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
6.12.0.0→6.56.0.0Release Notes
http4k/http4k (org.http4k:http4k-bom)
v6.56.0.0Compare Source
data-on:click,data-bind:foo,data-computed:total) instead of the removed 0.x hyphen form.UpdateResult.ConditionFailedis now adata classcarrying the item to report back, rather than adata object.DeleteItemis now evaluated. TheConditionExpressionwas previously ignored outright, so a guarded delete always succeeded against the fake - including insidetransactWriteItems, where a failing condition now correctly cancels the transaction.PutItem,UpdateItemandDeleteItemgainReturnValuesOnConditionCheckFailure, so a failed conditional write can return the record which blocked it (DynamoDB reports it in the error body). The enum andTransactWriteItem's support for it already existed.v6.55.0.0Compare Source
getRelativePath()Content-Lengthheader no longer produces a duplicateContent-Lengthon the outgoing request.multipart/mixedparts are now rejected with aParseErrorinstead of being parsed recursively, bounding parser stack usage on crafted inputs. The unbounded 3-argumentStreamingMultipartFormParts.parseoverload now applies a default 10MB stream-length cap.;,,and control characters can no longer be interpreted as additional cookie attributes; the same characters are stripped fromDomain/Pathattributes. Existing quoting of normal values is unchanged.DefaultCookieStoragenow only accepts aSet-CookieDomainthat domain-matches the origin host, and rejects dotless public-suffix domains (e.g.com), so a response from one host can no longer plant cookies scoped to another. Host-only and exact-host cookies (e.g.localhost,example.co.uk) are unaffected.ServerFilters.HttpRebindProtection.MppVerifier.verifynow receives the server-issuedChallengealongside theCredential, so verifiers can bind the payment to the challenge the server issued (checkingid/opaque,expiresand single-use), closing a bypass/replay gap. The HTTP, MCP and tool filters now reject a credential whose payment fields (realm/method/intent/request) don't match an offered challenge, before invoking the verifier. A malformedAuthorization: Paymentheader now returns a402malformed-credentialproblem instead of a500.Passkeys.passwordless(...)now defaults touserVerification = REQUIRED./,\or.., so should be treated as untrusted; clearer warnings on the deliberately-looseReverseProxyHostMatcher.Containsand onCorsPolicy.UnsafeGlobalPermissive.Body.webForm/form parsing no longer truncates field values containing=(e.g. base64 padding); the value is now preserved intact.BAD_REQUESTresponse body.__ow_methodnow returnsNOT_IMPLEMENTEDinstead of throwing an NPE.resourceForlambda; when supplied, a payment is rejected with402unlesspayload.resourcematches, so a payment signed for one resource can't be replayed against another. Off by default (standard behaviour unchanged).Cachingrenderer now applies the same canonical-path containment check asHotReload, rejecting template paths that escape the base directory.URLConnectionHttpClientnow accepts aBodyMode(defaulting toMemory), allowing responses to be streamed rather than always buffered fully into memory.v6.54.0.0Compare Source
HttpGitHubwill now properly authorize requests. H/T @oharaandrew314GetAuthedUserEmailsandGetAuthedUserPublicEmailsactions. H/T @oharaandrew314FakeGitHubfor all supported actions. H/T @oharaandrew314v6.53.0.0Compare Source
v6.52.0.0Compare Source
ServerFilters.DigestAuthandDigestAuthProvidernow can have aDigestAlgorithmenum (MD5/SHA_256).PushNotificationSender.Httpnow takes aPushNotificationUrlPolicy.DiscoveredMcpOAuthrejects cross-originresource_metadataand the legacyauth_serverdirective fromWWW-Authenticate; discovery now falls through to.well-known/oauth-protected-resourceat the resource origin.X402ToolFilterandMcpFilters.X402PaymentRequirednow take aSettlementMode.RoutingJsonRpcHandlernow caps batch requests at 100 elements; oversized batches are rejected with a singleInvalid Requesterror instead of being processed.HttpRequest.asHttp4k()returnsnullfor an unrecognised HTTP method (wasIllegalArgumentException); the fallback controller responds with501 Not Implementedin that case.Storage.Disknow canonicalises and containment-checks thekeyparameter onget/set/remove; keys whose resolved path escapes the configured directory are silently treated as missing.Storage.Httpnow URL-encodes thekeybefore interpolating it into the request path.Storage.Jdbcnow escapesLIKEmetacharacters (%,_,\) inkeyPrefix, sokeySet("%")/removeAll("%")no longer over-match. Implemented via Exposed'sLikePattern.ofLiteral.Storage.Redisnow escapes glob metacharacters (*,?,[,],\) inkeyPrefix, sokeySet("*")/removeAll("*")no longer over-match.DiskLocation.Temp/Permanent) are created with owner-only POSIX permissions where the underlying filesystem supports them.InputStream.chunkedSseSequence()now caps the in-progress message buffer(10 MB by default).AuthServerDiscovery.fromProtectedResourcenow requires the metadataresourceto match the expected resource at a path-segment boundary,SseMessage.Event.toMessage()).ApiGatewayV1,ApplicationLoadBalancer, andApiGatewayRestresponse adapters now also emitmultiValueHeaders, preserving duplicate response headers (e.g. multipleSet-Cookie).HmacSha256.Signerrejects aWebhookIdcontaining the signing delimiter.;HmacSha256.Verifierreturnsfalsefor the same.DirectoryResourcesinRecursivemode no longer permits reading a sibling.Storage.InMemory().removeAll(keyPrefix)now returnstrueonly when at least one key was actually removed (was returningtruewhenever the map was non-empty, even if no keys matched the prefix).Storage.Http().keySet(keyPrefix)no longer returns{""}when the server replies with an empty body; empty lines are filtered out.SafeConstructorinstead ofConstructor.multipartIterator()now selects theboundarydirective fromContent-Typeby name.DiskLocation.Temp/Permanentno longer use the multipartfilenameas the on-disk temp-file prefix.MultipartFormBody.from(...)now closes the underlyingDiskLocationon parse failure.SseMessage.Data.toMessage()andSseMessage.Event.toMessage()now safer.DigestCredential.fromHeaderno longer throws on anAuthorizationheader containing only the scheme; the request now receives the standard challenge instead of a 500.IllegalArgumentException.FreemarkerTemplates.safeConfiguration(...)now setsnewBuiltinClassResolver = TemplateClassResolver.SAFER_RESOLVERand disables?apiMermaidDiagramViewno longer renders captured Mermaid source with?no_escFreemarkerTemplates.safeConfiguration(...)factory.v6.51.0.0Compare Source
DigestAuthReceiverto generate challenge response with correct URI. H/T @oharaandrew314maxDecompressedSize: Longparameter toRequestFilters.GunZip,ResponseFilters.GunZip,ServerFilters.GZip,ServerFilters.GZipContentTypes,ClientFilters.GZip,ClientFilters.AcceptGZip, and the underlyingBody.gunzippedStream.v6.50.0.0Compare Source
Pug4jTemplates.HotReloadnow canonicalizes the resolved template path againstbaseTemplateDirand rejects anyViewModel.template()that escapes the base.DigestAuthProvider.verifynow also rejects credentials whoseuriparameter does not match the actual request URL.SecureRandomby default.openidscope (previously onlyCodeIdToken) andvalidateNonceAfterTokenfail-closes when the token-endpoint id_token is missing or its nonce mismatches.defaultXmlParsingConfignow setsdisallow-doctype-declandFEATURE_SECURE_PROCESSING, soBody.xml()/asXmlDocument()reject any document with a<!DOCTYPE>.ServerFilters.VerifyWebhookSignaturenow also rejects messages whosewebhook-timestampis more thantoleranceaway fromclock.instant()(default tolerance5.minutes, clockClock.systemUTC()), per the Standard Webhooks scheme. Captures of valid webhooks can no longer be replayed indefinitely. Pass aClock.fixed(...)to control timing in tests.MultipartFormBody.from,multipartIterator()andBody.multipartForm(...)cap the body at 10MB and 1000 parts by default. PassmaxStreamLength/maxPartCountto override.X-Forwarded-For: client, proxy1, proxy2) now reach the handler intact. True multi-values continue to flow viamultiValueHeaders.Header.X_HUB_SIGNATURE_256lens no longer crashes on anX-Hub-Signature-256header missing thesha256=prefix;VerifyGitHubSignatureSha256now returns401for malformed signatures instead of500.AzureClientnow attaches the API key as an outboundAuthorization: Bearerheader (was wired to the inboundServerFilters.BearerAuthchecker.Secret.toString()andSecret.hashCode()no longer expose a stable hash of the plaintext (wasSecret(hashcode = <Arrays.hashCode-of-plaintext>));Secret.equalsreturnsfalsefor non-Secretinputs instead of throwingClassCastException.ParseErrorinstead of crashing withNullPointerException.user:pass@userInfo from request URIs before writing them to span attributes (url.full, legacyhttp.url) and the default span name, so basic-auth-in-URL credentials no longer reach the tracing backend.code_challengeis stored at authorize and an S256code_verifieris required at token.code_challenge_method=plainis rejected per RFC 7636 §7.2./and\runs, neutralizing open-redirects of the form//evil.comand/\evil.com.AuthRequestis re-validated atAuthenticationComplete; CSRF/nonce compare is null/blank-safe; severalredirectUri!!NPEs replaced with typedInvalidAuthorizationRequest.requirePkce: Boolean = falseonOAuthServer. Whentrue, every authorize/token exchange must use PKCE (recommended per RFC 9700).AuthServerDiscoveryrejects a scheme-less resource pointing at root.requirePkceis exposed on the underlyingGenerateAccessToken/GenerateAccessTokenForGrantType/AuthorizationCodeAccessTokenGenerator, mitigating potential PKCE downgrade.DigestAuthProvider.verifynow hashes with the configuredalgorithminstead of hardcoded MD5.hidden()so their raw value no longer surfaces intoString().v6.49.0.0Compare Source
reverseProxy()/reverseProxyRouting()now default toExacthost matching instead ofContains, so a request Host header that merely contains a configured virtual host (e.g.host1.evil.comfor vhosthost1) no longer routes to it. Passmatcher = Containsto opt back into substring matching.ExecutorService.withRequestTracing()applies adefaultTimeout(60s by default, configurable) to the untimedinvokeAll/invokeAnyso a slow or dead task can no longer pin pool threads indefinitely. No code change needed; only affects callers whose tasks legitimately ran longer than default.Header.AUTHORIZATION_BASIC/Request.basicAuthentication()now returnnullfor any malformed Basic credentials (wrong scheme, invalid base64, or no colon in the decoded value) instead of manufacturingCredentials("", ""). Lets callers reliably distinguish absent/invalid credentials from genuinely empty ones.413 Request Entity Too Large. Duplicate and modify theNettyclass if you need a different limit.ServerFilters.GZip/RequestFilters.GunZipnow get a413 Request Entity Too Large, and decompressing elsewhere throwsSizeLimitExceededException. Duplicate and modify theGzipfunctions if you need a different limit.ServerFilters.Corsno longer emits the spec-invalidAccess-Control-Allow-Origin: *together withAccess-Control-Allow-Credentials: true.bearerToken()extracts the token for any casing of theBearerscheme (e.g.BEARER), instead of returning the raw header value.ResourceLoader.ClasspathSha256(withhashandhmac) and deprecateHmacSha256, whosehashwas misleadingly unkeyed SHA-256. ReplaceHmacSha256.hash/hmacSHA256withSha256.hash/Sha256.hmac.v6.48.0.0Compare Source
v6.47.2.0Compare Source
FakeKMSto generate keys with an injectableSecureRandom; allowing for deterministic testing.v6.47.1.0Compare Source
v6.47.0.0Compare Source
v6.46.1.0Compare Source
v6.46.0.0Compare Source
Intercept {}form is nowIntercept.http {}v6.45.1.0Compare Source
v6.45.0.0Compare Source
RefreshingOAuthToken,AutoDiscoveryOAuthTokenrefactored with pluggable OAuth flow and refresh filters. TheoAuthFlowFilterparameter no longer has a default — use theOAuthProviderConfigorCredentialsoverloads for the previous behaviour. ParameteroauthCredentialsrenamed toclientCredentials.ClientFilters.OAuthJwtAssertionfor RFC 7523 JWT assertion grants (SEP-990 ID-JAG enterprise auth).DRAFT-2026-v1features (as of 04/26).DiscoveredMcpOAuthnow supports pluggable OAuth flow and refresh filters for custom grant types (e.g. JWT assertion for enterprise IdP).Header.ALLOWlens for RFC 9110Allowheader.Header.X_ACCEL_BUFFERINGlens withXAccelBufferingenum.v6.44.0.0Compare Source
McpHandlernow takesMcpRequest/McpResponse(sealed:Ok/Accepted/Unknown). CustomMcpHandlerandMcpFilterimplementations will need adjusting.objectto class.McpOpenTelemetrySpanModifiersrenamed toMcpOpenTelemetrySpanModifier(singular). Methods now takeMcpRequest/McpResponseinstead ofMcpJsonRpcRequest/McpJsonRpcResponse, giving access to session and HTTP request context. Dispatch bymethodfield removed — modifiers use typedischecks instead.Client.updateTask()no longer takes atimeoutparameter. AddedClient.requestRoots().ToolResponse.ElicitationRequired.elicitationstype changed fromList<McpElicitations.Request.Url>toList<McpElicitations.Request.Params.Url>.TestMcpClient.useClient()to get a pre-started instance.ReturnResponsebehaviour. H/T @jamieredding.v6.43.0.0Compare Source
ServerToolsand co are now constructed viatools(). Simply replace the calls - the as the rest of the behaviour is unchanges.to pass it directly into progress calls. This makes it explicit that callers without progress tokens will not be able to track progress.
FollowRedirectsno longer follows HTTPS to HTTP redirects, preventing possible credential leakage over unencrypted connections.v6.42.0.0Compare Source
RenderMcpAppparameters might break anything using named params.v6.41.0.0Compare Source
InitializeHandler.ClientCapabilities.v6.40.1.0Compare Source
build/http4k-verify/for independent inspection and audit.build/http4k-verify/verification-report.jsonwith per-module signature status and exported file paths.clearHttp4kVerificationCacheGradle task to force re-verification of all artifacts.v6.40.0.0Compare Source
id("org.http4k.verify").v6.39.1.0Compare Source
v6.39.0.0Compare Source
ResourceResponse,PromptResponse, andCompletionResponseare now sealed interfaces withOkandErrorsubtypes. Construct viaResourceResponse.Ok(...)etc.SamplingResponseandElicitationResponsegain a newErrorsubtype. Error variants take amessage: Stringand round-trip through the protocol using a custom domain error code (-32050), allowing http4k clients to reconstruct*.Erroron the client side rather than surfacing them asMcpError.Protocol.v6.38.0.0Compare Source
/pluginin Claude Code.v6.37.0.0Compare Source
OpenTelemetrySemanticConventionsfor attribute naming. This may break some observability. It is possible to revert to the old versions by passingLegacyHttp4kConventionsto the OTel filters instead. It is worth studying the new conventions to see if they are suitable for your use case.defaultSpanNamer. This affected client filter span naming.http4k-ops-opentelemetry: Add
OpenTelemetryClockshim to allow the control of time inside OpenTelemetry APIs.v6.36.0.0Compare Source
v6.35.0.0Compare Source
v6.34.0.0Compare Source
AutoOpenTelemetryEventsfor plugging the http4k event system into OpenTelemetry backends. Supports both span-based and log events.v6.33.0.0Compare Source
mcp()as a replacement formcpHttpStreaming()as this is now the standard implementation. Simple replacementv6.32.0.0Compare Source
accommodate.
through the filter chain.
v6.31.1.0Compare Source
v6.31.0.0Compare Source
application/octet-streamfor unknown content types. H/T @andy-barlowasServer()to convert any singular ServerCapability into a serverv6.30.1.0Compare Source
v6.30.0.0Compare Source
v6.29.0.0Compare Source
v6.28.1.0Compare Source
v6.28.0.0Compare Source
URL Form Elicitations and Sampling upgrades. Plus conformance updates to the latest MCP conformance tests. Also support for MCP Apps spec, allowing UIs to be
usable inside Claude Code and friends. Small tweaks to the API surface which should be simple to fix.
and co)
v6.27.0.0Compare Source
v6.26.1.0Compare Source
SecretsManagerRotationEvent. H/T @oharaandrew314v6.26.0.0Compare Source
v6.25.1.0Compare Source
v6.25.0.0Compare Source
v6.24.1.0Compare Source
v6.24.0.0Compare Source
v6.23.1.0Compare Source
v6.23.0.0Compare Source
v6.22.0.0Compare Source
v6.21.1.0Compare Source
the MCP conformance tests.
v6.21.0.0Compare Source
spec.
v6.20.2.1Compare Source
v6.20.2.0Compare Source
v6.20.1.0Compare Source
AwsRequestPreSigner. H/T @torfinnbersetv6.20.0.3Compare Source
v6.20.0.2Compare Source
v6.20.0.1Compare Source
v6.20.0.0Compare Source
to not support JSON RPC). This simplifies integration points.
v6.19.0.0Compare Source
v6.18.1.0Compare Source
into multiple data events, now they are preserved in a single event.
v6.18.0.1Compare Source
v6.17.0.0Compare Source
http4k-ai-mcp-*. Please change your imports and dependencies toreflect this.
notably:
Fragmentsare now calledElements, and the number of SSE events has been reduced from 5 to 2 (datastar-patch-elements anddatastar-patch-signals). See the D* docs for more details. You can of course continue to use the old API by using an old version of this module.
ChallengeResponsesin the response is now aMap<String, String>instead of the incorrectMap<ChallengeName, String>. H/T @alphahoConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.