Skip to content
This repository was archived by the owner on Aug 25, 2025. It is now read-only.

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Mar 25, 2025

Bumps h2 from 0.3.26 to 0.4.8.

Release notes

Sourced from h2's releases.

v0.4.8

What's Changed

New Contributors

Thanks

v0.4.7

What's Changed

  • Fix treating HEADERS frames with a non-zero content-length but END_STREAM flag as malformed.
  • Fix notifying the stream task when automatically reset on receipt of a stream error.

New Contributors

Thanks

Full Changelog: hyperium/h2@v0.4.6...v0.4.7

v0.4.6

What's Changed

  • Add current_max_send_streams() and current_max_recv_streams() to client::SendRequest.
  • Fix sending a PROTOCOL_ERROR instead of REFUSED_STREAM when receiving oversized headers.
  • Fix notifying a PushPromise task properly.
  • Fix notifying a stream task when reset.

New Contributors

Thanks

... (truncated)

Changelog

Sourced from h2's changelog.

0.4.8 (February 18, 2025)

  • Fix handling implicit stream resets at the more correct time.
  • Fix window size decrements of send-closed streams.
  • Fix reclaiming of reserved capacity when streams are closed.
  • Fix to no longer call poll_flush after poll_shutdown.
  • Fix busy loop in task when poll_shutdown returns pending.

0.4.7 (November 19, 2024)

  • Fix treating HEADERS frames with a non-zero content-length but END_STREAM flag as malformed.
  • Fix notifying the stream task when automatically reset on receipt of a stream error.

0.4.6 (August 19, 2024)

  • Add current_max_send_streams() and current_max_recv_streams() to client::SendRequest.
  • Fix sending a PROTOCOL_ERROR instead of REFUSED_STREAM when receiving oversized headers.
  • Fix notifying a PushPromise task properly.
  • Fix notifying a stream task when reset.

0.4.5 (May 17, 2024)

  • Fix race condition that sometimes hung connections during shutdown.
  • Fix pseudo header construction for CONNECT and OPTIONS requests.

0.4.4 (April 3, 2024)

  • Limit number of CONTINUATION frames for misbehaving connections.

0.4.3 (March 15, 2024)

  • Fix flow control limits to not apply until receiving SETTINGS ack.
  • Fix not returning an error if IO ended without close_notify.
  • Improve performance of decoding many headers.

0.4.2 (January 17th, 2024)

  • Limit error resets for misbehaving connections.
  • Fix selecting MAX_CONCURRENT_STREAMS value if no value is advertised initially.

0.4.1 (January 8, 2024)

  • Fix assigning connection capacity which could starve streams in some instances.

0.4.0 (November 15, 2023)

  • Update to http 1.0.
  • Remove deprecated Server::poll_close().

0.3.22 (November 15, 2023)

... (truncated)

Commits
  • 2dc3078 v0.4.8
  • 07e528f Fix poll_flush after poll_shutdown (#836)
  • 02eb53b fix: handle implicit resets at the right time (#833)
  • e348cf3 Fix window size decrement of send-closed streams (#830)
  • 8dc26ad fix: busy loop on shutdown (#834)
  • b109803 Fix reclaiming reserved capacity (#832)
  • d7c56f4 tests: simplify window_size_decremented_past_zero (#829)
  • 3bce93e chore: remove unnecessary type conversion (#822)
  • cffea95 v0.4.7
  • 3ac6016 fix: notify_recv after send_reset() in reset_on_recv_stream_err() to ensure l...
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [h2](https://github.com/hyperium/h2) from 0.3.26 to 0.4.8.
- [Release notes](https://github.com/hyperium/h2/releases)
- [Changelog](https://github.com/hyperium/h2/blob/master/CHANGELOG.md)
- [Commits](hyperium/h2@v0.3.26...v0.4.8)

---
updated-dependencies:
- dependency-name: h2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file rust Pull requests that update Rust code labels Mar 25, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update Rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant