Skip to content

chore(deps-dev): Update guzzlehttp/psr7 requirement from ^2.6 to ^2.6 || ^3.0 - #72

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/composer/guzzlehttp/psr7-tw-2.6or-tw-3.0
Open

chore(deps-dev): Update guzzlehttp/psr7 requirement from ^2.6 to ^2.6 || ^3.0#72
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/composer/guzzlehttp/psr7-tw-2.6or-tw-3.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 28, 2026

Copy link
Copy Markdown

Updates the requirements on guzzlehttp/psr7 to permit the latest version.

Release notes

Sourced from guzzlehttp/psr7's releases.

3.1.0

Added

  • Add Utils::redactUriForMessage() and Utils::redactUriStringForMessage() for URI diagnostics
  • Add support for PHP 8.6

Changed

  • Omit rejected header values and sensitive URI components from automatic exception messages
Changelog

Sourced from guzzlehttp/psr7's changelog.

3.1.0 - 2026-08-24

Added

  • Add Utils::redactUriForMessage() and Utils::redactUriStringForMessage() for URI diagnostics
  • Add support for PHP 8.6

Changed

  • Omit rejected header values and sensitive URI components from automatic exception messages

3.0.1 - 2026-08-24

Fixed

  • Prefix relative paths that begin with a colon segment with ./ instead of throwing
  • Apply the /. prefix for authority-less // paths to percent-encoding normalizations as well
  • Keep colon-leading first path segments when reading the paths of scheme-less non-native URIs
  • Stop throwing when removing the default file host strands a // path, prefixing it with /.

3.0.0 - 2026-07-20

Added

  • Add DiagnosticValue::escape() to escape controls and malformed UTF-8 in diagnostics
  • Add GuzzleHttp\Psr7\Exception\TimeoutException for timed-out stream operations
  • Add GuzzleHttp\Psr7\Utils::redactUserInfoInString() to redact the userinfo of a raw URI string within text
  • Promote GuzzleHttp\Psr7\Rfc3986 to public API with isValid*() predicates and canonicalizeIpv6()
  • Add GuzzleHttp\Psr7\UriNormalizer::CANONICALIZE_IPV6_HOST to PRESERVING_NORMALIZATIONS

Changed

  • Require psr/http-message:^2.0 and add native parameter and return types
  • Require psr/http-factory:^1.1
  • Reject native PHP serialization of stream implementations
  • Preserve request method casing, except ServerRequest::fromGlobals() still uppercases
  • Reject empty arrays and non-string values as header values
  • Reject invalid uploaded file trees and invalid parsed body values
  • Reject uploaded file specs missing tmp_name, size, or error
  • Reject non-integer and negative uploaded file error values
  • Reject invalid stream/upload sizes, buffer high-water marks, and dropping-stream limits
  • Rewind seekable uploaded-file streams before copying in UploadedFile::moveTo()
  • Reject negative read() lengths across all stream implementations
  • Detect the + flag anywhere in a mode for Stream::isReadable()/isWritable()
  • Reject empty strings returned by PumpStream source callables
  • Discard buffered bytes on PumpStream close and detach
  • Restore the original stream position after Message::bodySummary()
  • Allow null for the Message::bodySummary() truncation length to use the default
  • Validate LimitStream offset/limit and track non-seekable offset by bytes skipped
  • Make FnStream close and detach terminal, calling close callbacks at most once

... (truncated)

Commits
  • a3059ba Release 3.1.0
  • cf5d5de Merge remote-tracking branch 'origin/3.0' into 3.1
  • a7c1d4a Release 3.0.1
  • 3698982 Add PHP 8.6 to the CI matrix and version guidance (#882)
  • 4229885 Merge branch '3.0' into 3.1
  • 086457f Prefix stranded file host paths with /. instead of throwing (#881)
  • e7203cc Merge branch '3.0' into 3.1
  • 130e5c4 Keep a colon-leading first path segment when reading scheme-less non-native U...
  • 75010c3 Prefix relative paths that begin with a colon segment instead of throwing (#879)
  • 98db496 Harden automatic exception diagnostics (#875)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Updates the requirements on [guzzlehttp/psr7](https://github.com/guzzle/psr7) to permit the latest version.
- [Release notes](https://github.com/guzzle/psr7/releases)
- [Changelog](https://github.com/guzzle/psr7/blob/3.1/CHANGELOG.md)
- [Commits](guzzle/psr7@2.6.0...3.1.0)

---
updated-dependencies:
- dependency-name: guzzlehttp/psr7
  dependency-version: 3.1.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update php code labels Aug 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants