Releases: xyo-financial/sdk-rust
Release list
v2.1.0
🚀 v2.1.0 Enterprise Banking Security & Distributed Tracing
v2.1.0 introduces enterprise-grade banking security, enhanced async ergonomics, zero-panic runtime guarantees, and production-ready telemetry to the XYO Financial Rust SDK (xyo-sdk).
Key Highlights
- 64 KiB Error Body Read Cap: Prevents unbounded memory allocation or denial-of-service vulnerabilities when consuming unexpected HTTP error response bodies.
- HTTP-Date Retry-After Parsing: Full support for parsing both integer seconds and RFC 2822 / HTTP-Date timestamp headers during rate limiting (
429 Too Many Requests) handling. - Lazy Streaming Batch Iterator: Offloads CPU-intensive archive extraction, decompression, and JSON parsing in
download_enrichment_collectionto background worker pools with memory-bounded chunk streaming. - OpenAPI Crate Clippy Allowances: Pre-configured Clippy lint suppressions in auto-generated transport bindings to ensure clean compiler builds under strict
-D warningssettings. - Pure OpenAPI Isolation: Enforces a strict architecture separating low-level OpenAPI transport bindings (
xyo-openapi-client) from high-level, ergonomic async Rust APIs (xyo-sdk).
🛠 What's Changed
Features & Security Hardening
- ClientBuilder & Fluent Configuration: Builder pattern (
Client::builder()) supporting custom HTTP timeouts, connection pool limits, customreqwestclients, and multi-cloud security policies. - Dynamic Token Rotation: Support for runtime secret and API key rotation via
Client::with_token_suppliercallbacks without client re-instantiation. - Structured Tracing Telemetry: Integrated
tracinginstrumentation across client invocations, batch submissions, and status polling. - Zero-Trust Security Defenses:
- Strict domain allowlists (
DEFAULT_PERMITTED_HOSTS) for tarball downloads. - Tar bomb and Zip-Slip path traversal mitigations (
DEFAULT_MAX_TAR_ENTRIES,DEFAULT_MAX_ENTRY_BYTES,DEFAULT_MAX_ARCHIVE_BYTES). - CWE-113 CRLF header injection validation on custom headers.
- SSRF URL scheme restriction to
http/https. - Sensitive credential masking (
[REDACTED]) inDebugoutput.
- Strict domain allowlists (
- Error Handling & Classification: Programmatic error query methods (
is_auth(),is_rate_limited(),is_server_error(),is_retryable(),is_not_found()).
Detailed Commit Log
b6e23c0chore(release): bump version to 2.1.0 (#35)54737a9Automated SDK Update (#34)8677bb0feat: support v2.0.0 tracing parameters in client wrapper and use create-pull-request in generate workflow11c15f3fix(docs): use absolute raw github URL for mascot (#32)1c1b3e2docs(readme): add Axum and Tokio framework integration recipes (#31)1a265ebchore(docs): update mascot image to sleek neon design (#30)8ab8c63style(readme): standardize header structure to match PHP SDK standard (#29)429916edocs(readme): simplify headings and summary phrasing (#28)602884fdocs(security): add Rust MSRV and Edition support schedule SVG and 3-month proactive policy8c39d6ddocs: polish markdown section headings and standardize emojis (#27)1cc9effdocs(changelog): audit historical tags and document unreleased changes (#26)29e010aci: add GitHub release workflow (#25)0c659e5fix(sdk): zero panic vectors, thread-safe test harness, and client-side validation (#24)d3c7fcffeat(sdk): strict zero-trust domain allowlist and raw header dispatch (#23)9670af9feat(sdk): structured tracing telemetry and error classification (#22)5bd2ba6feat(sdk): enterprise hardening, ClientBuilder, and async stream optimizations (#21)e752d88feat(sdk): add EnrichmentRequest validation, CWE-113 CRLF defense, and dynamic token rotation (#20)12d91bdfeat(sdk): enforce zero trust domain validation and eliminate SSRF error preview (#18)eb90bbffeat(sdk): enterprise banking resilience, tar bomb mitigations, SSRF, and WAF diagnostics (#17)399bbf8docs(license): align LICENSE with exact standard Apache 2.0 text for licensecheck compliance
📦 Installation & Usage
Add xyo-sdk to your Cargo.toml:
cargo add xyo-sdk@2.1.0Or add it manually:
[dependencies]
xyo-sdk = "2.1.0"
tokio = { version = "1.38", features = ["full"] }Quickstart Example
use xyo_sdk::{Client, EnrichmentRequest};
#[tokio::main]
async fn main() -> Result<(), Box<dyn std::error::Error>> {
let client = Client::new("YOUR_BEARER_TOKEN", None)?;
let request = EnrichmentRequest::new(
"BARCLAYS BANK PLC LONDON UK",
Some("GB".to_string()),
)?;
let response = client.enrich_transaction(request).await?;
println!("Merchant Name: {:?}", response.merchant_name);
Ok(())
}v2.0.0
Release Notes: v2.0.0
The XYO Financial SDK for Rust v2.0.0 is a major architectural overhaul that transitions the entire SDK from a synchronous prototype to an institutional-grade, fully asynchronous, non-blocking library natively integrated with Tokio, Reqwest, and OpenAPI specifications.
🚨 Breaking Changes & Migration Guide
- Native Async/Await (Tokio): All SDK calls are now non-blocking and asynchronous. You must run the SDK within an async runtime (e.g.
#[tokio::main]). - Deprecation & Removal of
xyo-http: The raw, customxyo-httpcrate has been completely removed in favor ofreqwest(withrustls-tls), bringing native HTTP/2 connection pooling, keep-alive connections, and robust TLS handling out of the box. - Modernized
ClientInterface:Client::new(bearer_token, base_url)replaces the old config object initialization.- Methods updated to idiomatic async names:
client.enrich_transaction(content, country_code).awaitclient.enrich_transactions(requests, api_user).awaitclient.get_enrichment_status(id, api_user).await
- Licensing: Re-licensed to Apache License 2.0 (
Apache-2.0).
✨ New Features & Enhancements
⚡ Async & High-Throughput Engine
- Tokio & Reqwest Integration: Native non-blocking I/O capable of handling thousands of concurrent transaction enrichment requests across worker pools and async web frameworks (Axum, Actix-web).
- Thread-Safe by Design:
ClientisSend + Sync, designed to be shared across threads as an application singleton.
📦 In-Memory Tar/Gzip Bulk Archive Decompression
download_enrichment_collection: Added a helper that streams and unpacks bulk.tar.gzarchive results directly in-memory usingflate2andtar, returning strongly typedVec<EnrichmentResponse>without writing temporary files to disk.
🤖 OpenAPI Codegen Integration (xyo-openapi-client)
- Scoped Workspace Crate: Codegen crate configured and published under the unique namespace
xyo-openapi-client(v2.0.0) to avoid public crates.io naming collisions. - Deterministic Code Generation: Integrated
@openapitools/openapi-generator-cliwith anopenapitools.jsonconfiguration and workspace crateopenapi/. - Automated Spec Sync: Added
.github/workflows/generate.ymlsupportingrepository_dispatchandworkflow_dispatchtriggers for automated OpenAPI schema updates fromxyo-financial/specs.
🧪 Comprehensive Integration Test Suite
- WireMock Test Suite: Added
tests/client_test.rs(>1,000 lines of tests) validating:- Single and bulk transaction enrichment
- Bulk job status polling (
Ready,Pending,Failed) - Bearer token authentication and custom header injection
- HTTP status error mapping (400, 401, 403, 404, 429, 500, 503)
- End-to-end
.tar.gzarchive generation and in-memory decompression
📖 Runnable Examples & Quickstarts
Added standalone, runnable examples under examples/:
examples/quickstart.rs: Single transaction enrichment walkthrough.examples/bulk_enrichment.rs: Batch submission, status polling, and archive download.examples/error_handling.rs: Robust error matching and inspection.
🔒 Security & Governance
- Zero
unsafeCode: 100% safe Rust code with verified dependency boundaries. - Security Policy: Added
SECURITY.mddefining vulnerability reporting processes. - Enterprise Governance: Expanded
CONTRIBUTING.mdwith deterministic build steps and cross-repo spec generation documentation. - Support Channel: Updated official support email to
support@syniol.com.
📦 Dependency Highlights
[dependencies]
xyo-sdk = "2.0.0"
tokio = { version = "1", features = ["rt-multi-thread", "macros"] }xyo-openapi-client = "2.0.0"reqwest = "0.11"(rustls-tls,json,stream)tokio = "=1.38.0"flate2 = "1.0"tar = "0.4"serde = "1.0.219"serde_json = "1.0.143"
v1.1.9
Release Notes: v1.1.9
🔄 Repository & Organization Migration
- GitHub Repository URL: Migrated repository URLs to
https://github.com/xyo-financial/sdk-rustacrossCargo.toml,xyo-http/Cargo.toml, andREADME.md. - Badges & Assets: Updated GitHub Actions CI workflow badges and documentation image links in
README.mdto point to the new organization repository.
🚀 Version Bump
- xyo-sdk: Incremented version from
1.1.8to1.1.9inCargo.toml. - xyo-http: Incremented version from
1.1.8to1.1.9inxyo-http/Cargo.toml. - example: Updated
xyo-sdkdependency to1.1.9inexample/Cargo.toml. - Lockfiles: Updated
Cargo.lockandexample/Cargo.lockto reflect version1.1.9. - Changelog: Added
CHANGELOG.mddocumenting recent release history and changes.
v1.1.8
Here is the changelog comparing 20-july-2026-release to main. This content has also been saved to CHANGELOG.md:
Changelog
All notable changes to the XYO Financial SDK for Rust will be documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
[1.1.8] - 2026-07-20
🚀 Version Bump
- xyo-sdk: Incremented package version from
1.1.7to1.1.8in Cargo.toml. - xyo-http: Incremented package version from
1.1.7to1.1.8in xyo-http/Cargo.toml. - Dependencies: Updated
xyo-httpworkspace dependency requirement to1.1.8in root Cargo.toml and updatedxyo-sdkdependency requirement to1.1.8in example/Cargo.toml. - Lockfiles: Synchronized Cargo.lock and example/Cargo.lock to reflect version
1.1.8.
📄 Licensing
- Relicensed to BSD 3-Clause: Relicensed the project to the
BSD 3-Clause License(BSD-3-Clause). - LICENSE: Replaced license terms in LICENSE with the standard BSD 3-Clause License text for Syniol Limited.
- Package Manifests: Set SPDX
licensefield to"BSD-3-Clause"in Cargo.toml and xyo-http/Cargo.toml. - Documentation: Updated license notices in README.md and xyo-http/README.md.
⚙️ CI/CD & Workflows
- Publish Workflow: Updated push tag filter to
v[0-9]+.[0-9]+.[0-9]+in .github/workflows/crates_xyo_http_publish.yml.
1.1.7
Release Notes: v1.1.7
This is a maintenance release focused on updating documentation, licensing, and repository contribution policies. There are no functional code changes to the SDK client in this release.
📝 Licensing Updates
- Migrated to MIT License: The SDK and
xyo-httpclient have officially transitioned from theApache-2.0license to theMITLicense. - Documentation Sync: The repository
LICENSEfile has been replaced to reflect the MIT terms, and theREADME.mdhas been updated to explicitly state the new license.
🔒 Repository Policy
- Strict Contribution Guidelines: Updated
CONTRIBUTING.mdto explicitly state that the repository is closed to external contributions. A highly visible notice was added to inform outside developers that Pull Requests are exclusively restricted to Syniol Limited engineering staff.
🎨 Branding & Documentation
- New Official Mascots: Added high-fidelity, enterprise-grade AI concepts of the Rust mascot tailored for the financial sector.
- Mascot Concept Docs: Introduced a new
docs/mascot_concepts.mdpresentation file and bundled the accompanyingsleek_neonandplatinum_geometricimage assets into thedocs/directory for internal branding reference.
1.1.6
Release Notes: v1.1.6
This release introduces critical security patches and a massive architectural refactor to make the Rust SDK robust, panic-free, and enterprise-ready.
🔒 Security Updates
- Enforced TLS (HTTPS): Migrated the underlying transport layer from plain-text TCP sockets (Port 80) to secure, encrypted TLS streams (Port 443) using
native-tls. Financial payloads are now securely encrypted in transit. - Header Injection & Authentication: Fixed a critical defect where the API key was not being transmitted. The
xyo-httpclient now natively supports dynamic header injection, guaranteeing theAuthorization: Bearer <key>header is present on every secured request.
🛠 Architectural Refactoring & Stability
- Zero-Panic Guarantee: Eradicated all reckless
.unwrap()calls across theclient.rscodebase. JSON serialization/deserialization failures and network I/O errors are now safely wrapped and returned as standardClientErrorresults. The SDK will no longer panic the host process. - Robust HTTP/1.1 Parsing: The bespoke
xyo-httpparser was completely overhauled. It no longer arbitrarily splits the entire response body string by\r\n(which broke on JSON payloads containing newlines). It now correctly boundaries headers at\r\n\r\nand relies on safe byte extraction for the payload. - Safe Content-Length Calculation: The
Content-Lengthheader is now strictly calculated using.as_bytes().len()instead of string length, ensuring payload sizes do not desync when multibyte UTF-8 characters are present. - Structured
HttpResponse: The HTTP client now returns a strongly-typedHttpResponsestruct (containing thestatus_codeandbody) instead of a raw String, eliminating massive heap allocation/cloning bottlenecks that previously occurred during response parsing.
🚀 API Changes
- Idiomatic Signatures: The
enrich_transaction_collectionmethod was refactored. It now accepts an idiomatic slice&[EnrichmentRequest]rather than forcing the caller to allocate an awkwardVec<&EnrichmentRequest>.
1.1.5
Release Notes: v1.1.5
This release delivers secure HTTPS communication, fixes Docker compilation issues for Alpine/musl environments, and cleans up compiler warnings.
🚀 What's New in v1.1.5
1. 🔒 HTTPS Migration
- TLS Integration: Upgraded the client from plain HTTP (port 80) to HTTPS (port 443) using
native-tls. All SDK traffic toapi.xyo.financialis now encrypted in transit. - Double CRLF Line Endings: Corrected HTTP header endings to the RFC-compliant
\r\n\r\nformat.
2. 🐳 Docker Build Fixes
- Alpine Static Linking Support: Added
openssl-devandopenssl-libs-staticto theDockerfile's Alpine package list. This enables the compiler to find the necessary C headers and static libraries (libssl.a,libcrypto.a) to statically linkopenssl-sysonmusltargets.
3. 📦 Dependency & Compatibility Pinning
- Cargo 1.75+ Compatibility: Downgraded
native-tlstov0.2.11andgetrandomtov0.3.0in the workspace lockfile. This avoids pulling in newer crates that require the unreleasededition2024Cargo feature, ensuring the SDK builds on older toolchains.
4. 🧪 Testing & CI Improvements
- Time-Travel Resiliency: Added
XYO_SDK_DANGER_ACCEPT_INVALID_CERTSenvironment variable support. This allows integration tests to bypass certificate expiration checks when running in environments with skewed system clocks, while keeping production connections 100% secure.
5. 🧹 Code Quality
- Warning Cleanups: Removed the unused
mutkeyword ontcp_stream_socket. - Robust I/O: Replaced
write()withwrite_all()to guarantee full request transmission. - Panic Prevention: Removed unsafe
.unwrap()calls on socketflush()andshutdown().
1.1.4
Release Notes: v1.1.4
This release addresses a critical issue in the HTTP client module (xyo-http) regarding socket timeouts and persistent connections, alongside several robustness and performance improvements.
🚀 What's New in v1.1.4
1. Fix Indefinite Request Blocking & Premature Timeouts
Previously, the SDK did not explicitly signal the server to close the connection, causing read_to_string to block indefinitely due to HTTP/1.1 persistent connection defaults. A temporary 100ms read timeout was used as a workaround, which caused slow requests to fail prematurely.
- Added
Connection: closeHeader: Instructs the server to close the TCP connection immediately after transmitting the response. The client now receives an EOF and completes the read instantly. - Increased Default Timeout: Increased the socket read timeout from
100msto10s(Duration::from_secs(10)). This prevents premature timeouts on slower network paths or complex queries, while fast requests still return immediately.
2. RFC-Compliant HTTP Formatting
- Corrected HTTP header endings from
\r\n\nto the standard double CRLF (\r\n\r\n) to prevent parsing issues on stricter upstream proxies and servers.
3. Production-Grade Robustness
- Guaranteed Writes: Replaced
tcp_stream_socket.write()withwrite_all()to guarantee the entire payload is written to the socket, avoiding partial write issues. - Panic Prevention: Removed
.unwrap()on socketflush()andshutdown(). If the remote host closes the socket early, the SDK now handles it gracefully instead of panicking. - Proper Error Propagation: All I/O errors during connection, configuration, writing, and reading are now properly captured and returned as
HttpClientErrorrather than being silently ignored.
📦 Dependency Updates
- Upgraded
xyo-httpandxyo-sdktov1.1.4across the workspace and examples.
1.1.3
Stable Release
Stable release with complete error handling