Repository navigation
Java SDK v0.6.1
Patch release: dependency security sweep across every SDK, plus restored Dependabot coverage.
See #54 and Change Request #55 for the full write-up.
Security fixes
| SDK | Advisory closed |
|---|---|
| py | httpx>=0.24.0 permitted httpcore<1.0.9 → h11<0.15 — CRITICAL request smuggling (GHSA-vqfr-h8mv-ghfj). Floor raised to httpx>=0.28.1. |
| php | guzzle ^7.8 permitted 7.8–7.15.0, carrying 7 advisories published Jun–Jul 2026 (proxy-auth header leak, silent HTTPS-proxy downgrade, cookie-scope confusion, unbounded-cookie DoS). Raised to ^7.15.2, which also pulls psr7 ^2.13 and clears 4 more. |
Both were version-constraint floors, so downstream resolvers were free to land on a known-bad version. go, java and ruby were already clean — verified, not assumed.
Dependency updates
jest 29→30, @types/node 24→26, TypeScript 5.6→6.0.3, testify 1.9.0→1.11.1, gson 2.10.1→2.14.0, junit 5.10.1→5.14.4, plus picomatch and @babel/core in both lockfiles.
Tooling
Dependabot previously only ever reported npm advisories. Alerts match the dependency graph, which needs an exact resolved version — and npm was the only ecosystem supplying one. Fixed by committing composer.lock / Gemfile.lock, pinning the resolved Python tree, and submitting the resolved Maven tree from CI.
Compatibility
No API changes. The only source edits were internal: moduleResolution → node16, and a zero-copy toBlobPart() helper needed because @types/node 26 made Buffer an invalid BlobPart. The published JS output is verified still CommonJS.
Verification
Unit tests all six green — js 306 · php 341 · py 319 · java 305 · ruby 303 · go ok — plus all six SDKs exercised live against the production API, and the upload path byte-diffed over a real socket including a non-zero-byteOffset buffer view.