Important Fixes
karate.call()with a real HTTP request no longer repeats the first response when called in a loop with updated params (2.1.1 → 2.1.2 regression) #3030karate runwithkarate-pom.jsonno longer runs every feature twice (2.1.2 standalone) #3041- A feature-level
@failtag is inherited by every scenario in the feature (v1 → v2 regression) #3029 karate.read()no longer corrupts.xlsxand other Office / zip-based files #3021read()accepts a dynamic, concatenated path expression #3022- Browser file upload restored via
inputFile()for both CDP and W3C backends #3015 byte[]variables are no longer shared by reference throughcallonce/callSinglecaches, and primitive arrays no longer crash on unchecked casts #3014- Error output shows the file name and line number everywhere #3024
- Cucumber JSON report scenarios carry
start_timestampagain #3047 optional('#missing').click()does nothing for an absent element instead of throwing #3042driver.script()no longer adds an extra invocation to an arrow IIFE #3046JSON.stringify()keeps the quotes when serializing a scalar string #3043- An explicitly constructed
java.lang.StringkeepshashCodeandequalsIgnoreCase#3045 - The Java
Stringconstructor works when its byte-array argument is a method call #3044 - Mock server:
pathParams,requestUrlBaseandrequestMethodare treated as untrusted request data like the other request variables, and the file session store rejects crafted session ids #3064 - An
Errorthrown past a step now fails its scenario instead of reading as passed
New Features & Enhancements
- JS engine: class static initialization blocks,
structuredCloneandperformance.nowglobals, and many spec-conformance fixes - Match:
match,karate.matchandassertfire aMATCH_EXITrun event for listeners - HTTP:
Http.quiet()for callers that treat a 4xx/5xx as a normal outcome; a mock'sresponse.bodycan be mutated in place - Run events: every scenario execution carries a run-unique
executionIndex, and a listener failure no longer keeps an event out of the stream - Gatling: the log replay names each scenario and descends into called features
- Logging: the bundled
logback.xmlsets only parent loggers, so the default console matches the docs;logging.consoleprecedence is documented #3031 - Server mode:
ka:data,ka:vals,ka:dispatchand theka:→hx-*helpers escape values that would end the attribute - Security docs:
SECURITY.mdnow states the scope for reports — Karate, including the mock server, is test tooling for trusted networks only - Dependency bumps: netty 4.2.18.Final, jackson-bom 2.22.3, slf4j 2.0.20, logback 1.6.4
View the complete list of all issues fixed in this release.
Full Changelog: v2.1.2...v2.1.3
Important: refer 2.0.0 release notes for those upgrading from 1.X
Artifacts
- Maven artifacts
- Standalone JAR (download below)
- CVE / SBOM report (download below)