Skip to content

Java SDK v0.6.1

Choose a tag to compare

@nicolasiscoding nicolasiscoding released this 30 Jul 12:57
· 23 commits to main since this release

Patch release: dependency security sweep across every SDK, plus restored Dependabot coverage.

See #54 and Change Request #55 for the full write-up.

Security fixes

SDK Advisory closed
py httpx>=0.24.0 permitted httpcore<1.0.9 → h11<0.15 — CRITICAL request smuggling (GHSA-vqfr-h8mv-ghfj). Floor raised to httpx>=0.28.1.
php guzzle ^7.8 permitted 7.8–7.15.0, carrying 7 advisories published Jun–Jul 2026 (proxy-auth header leak, silent HTTPS-proxy downgrade, cookie-scope confusion, unbounded-cookie DoS). Raised to ^7.15.2, which also pulls psr7 ^2.13 and clears 4 more.

Both were version-constraint floors, so downstream resolvers were free to land on a known-bad version. go, java and ruby were already clean — verified, not assumed.

Dependency updates

jest 29→30, @types/node 24→26, TypeScript 5.6→6.0.3, testify 1.9.0→1.11.1, gson 2.10.1→2.14.0, junit 5.10.1→5.14.4, plus picomatch and @babel/core in both lockfiles.

Tooling

Dependabot previously only ever reported npm advisories. Alerts match the dependency graph, which needs an exact resolved version — and npm was the only ecosystem supplying one. Fixed by committing composer.lock / Gemfile.lock, pinning the resolved Python tree, and submitting the resolved Maven tree from CI.

Compatibility

No API changes. The only source edits were internal: moduleResolution → node16, and a zero-copy toBlobPart() helper needed because @types/node 26 made Buffer an invalid BlobPart. The published JS output is verified still CommonJS.

Verification

Unit tests all six green — js 306 · php 341 · py 319 · java 305 · ruby 303 · go ok — plus all six SDKs exercised live against the production API, and the upload path byte-diffed over a real socket including a non-zero-byteOffset buffer view.