Skip to content

v1.1.17

@gibiw gibiw tagged this 20 Aug 14:34
Bump guzzlehttp/guzzle 7.10.0 -> 7.15.3, guzzlehttp/psr7 2.9.0 -> 2.13.0
and guzzlehttp/promises 2.3.0 -> 2.5.2 to resolve 13 open Dependabot
advisories (host-based check bypass, cookie scope and CRLF injection
issues, proxy header leaks, unbounded response cookies).

Also raise the declared constraints to ^7.15.2 and ^2.12.3 so consumers
of the library cannot resolve to the vulnerable versions; the psr7 1.x
branch is dropped because it is unpatched and already incompatible with
guzzle 7.15.
Assets 2
Loading