Skip to content

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Dec 13, 2021

Bumps retrofit from 2.4.0 to 2.5.0.

Changelog

Sourced from retrofit's changelog.

Version 2.5.0 (2018-11-18)

  • New: Built-in support for Kotlin's Unit type. This behaves the same as Java's Void where the body content is ignored and immediately discarded.
  • New: Built-in support for Java 8's Optional and CompletableFuture types. Previously the 'converter-java8' and 'adapter-java8' dependencies were needed and explicitly adding Java8OptionalConverterFactory and/or Java8CallAdapterFactory to your Retrofit.Builder in order to use these types. Support is now built-in and those types and their artifacts are marked as deprecated.
  • New: Invocation class provides a reference to the invoked method and argument list as a tag on the underlying OkHttp Call. This can be accessed from an OkHttp interceptor for things like logging, analytics, or metrics aggregation.
  • New: Kotlin extension for Retrofit which allows you call create passing the interface type only as a generic parameter (e.g., retrofit.create<MyService>()).
  • New: Added Response.success overload which allows specifying a custom 2xx status code.
  • New: Added Calls.failure overload which allows passing any Throwable subtype.
  • New: Minimal R8 rules now ship inside the jar requiring no client configuration in the common case.
  • Fix: Do not propagate fatal errors to the callback. They are sent to the thread's uncaught exception handler.
  • Fix: Do not enqueue/execute an otherwise useless call when the RxJava type is disposed by onSubscribe.
  • Fix: Call RxJavaPlugins assembly hook when creating an RxJava 2 type.
  • Fix: Ensure both the Guava and Java 8 Optional converters delegate properly. This ensures that converters registered prior to the optional converter can be used for deserializing the body type.
  • Fix: Prevent @Path values from participating in path-traversal. This ensures untrusted input passed as a path value cannot cause you to make a request to an un-intended relative URL.
  • Fix: Simple XML converter (which is deprecated) no longer wraps subtypes of RuntimeException or IOException when it fails.
  • Fix: Prevent JAXB converter from loading remote entities and DTDs.
  • Fix: Correctly detect default methods in interfaces on Android (API 24+). These still do not work, but now a correct exception will be thrown when detected.
  • Fix: Report more accurate exceptions when a @QueryName or @QueryMap precedes a @Url parameter.
  • Update OkHttp dependency to 3.12.
Commits
  • 40621bf [maven-release-plugin] prepare release parent-2.5.0
  • 8bd6c99 Prepare next development version
  • 5d6650a Merge pull request #2967 from square/jakew/robo/2018-11-18
  • 23592bc Merge pull request #2968 from square/jakew/okhhtp/2018-11-18
  • 01e024b Update OkHttp to 3.12
  • 7d8dd16 Update Robolectric
  • f0cad11 Merge pull request #2962 from square/jakew/completable-future-android/2018-11-16
  • bc62069 Merge pull request #2963 from square/jakew/nullability/2018-11-16
  • 7dcac1d Merge pull request #2964 from square/jakew/header-tests/2018-11-16
  • 07cb4ae Add tests for form and multipart header values and overrides
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [retrofit](https://github.com/square/retrofit) from 2.4.0 to 2.5.0.
- [Release notes](https://github.com/square/retrofit/releases)
- [Changelog](https://github.com/square/retrofit/blob/master/CHANGELOG.md)
- [Commits](square/retrofit@parent-2.4.0...parent-2.5.0)

---
updated-dependencies:
- dependency-name: com.squareup.retrofit2:retrofit
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Dec 13, 2021
@michaelcoll michaelcoll merged commit 14d4857 into master Dec 13, 2021
@dependabot dependabot bot deleted the dependabot/maven/com.squareup.retrofit2-retrofit-2.5.0 branch December 13, 2021 18:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant