Skip to content

Bump hackney from 4.7.4 to 4.8.1 - #92

Merged
michelboaventura merged 1 commit into
mainfrom
dependabot/hex/hackney-4.8.1
Sep 28, 2026
Merged

michelboaventura merged 1 commit into
mainfrom
dependabot/hex/hackney-4.8.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps hackney from 4.7.4 to 4.8.1.

Release notes

Sourced from hackney's releases.

hackney 4.8.1

Changed

  • Update quic to 2.0.1, which compiles on Windows again. Its NIF build and clean hooks ran through sh, which Windows lacks, so the compile failed there for anything that reaches quic, hackney included. Windows runs on OTP crypto.

hackney 4.8.0

Fixed

  • hackney:send_request/2 works on HTTP/2 and HTTP/3. Those protocols answer a request with the body included, which the function did not handle, so it failed with a case_clause. It returns the connection on every protocol now, so the response is read with body/1 or pulled with stream_body/1.
  • Several callers reading responses on one HTTP/2 or HTTP/3 connection each get their own. The read was resolved from the connection's last stream rather than the caller's, so on HTTP/2 all but one caller got {error, no_stream}, and on HTTP/3 two callers could be handed each other's body.
  • A caller reading an HTTP/3 response with body/1 or stream_body/1 is answered when the server resets its stream, instead of waiting for its own timeout. Needs quic 2.0.0, the first release to report a peer RESET_STREAM.
  • A pooled HTTP/2 connection no longer closes when the caller that opened it exits. It stayed owned by that caller, so its exit failed every other caller's request on the connection with {error, closed}. A shared connection now has no owner: each stream is tied to its own caller and is reset if that caller dies, and the connection closes itself once it has had no open stream for the pool timeout (#937, thanks @​smartinio).
  • Unregistering a pooled HTTP/2 connection no longer leaks its per-host slot. The pool dropped its monitor on the connection, so the slot was never released when the connection stopped.
  • A response that crosses a reset of its stream no longer closes the HTTP/2 connection. h2 dropped the header block of that response without decoding it, so the next response on the connection failed with COMPRESSION_ERROR.
  • The response to an HTTP/3 streaming upload can be read. After start_response/1, body/1 returned {error, invalid_state} and stream_body/1 returned {error, no_stream}: the body went to the start_response/1 caller as a second reply and was lost. When the response headers arrived before start_response/1 was called, it could wait forever.
  • HTTP/3 response headers carry one :status. quic_h3 passes the status separately and keeps it in the header list, and hackney prepended its own, so every response reached the low-level {h3, _, {stream_headers, ...}} consumer with the pseudo-header twice, which RFC 9114 4.3.1 makes a malformed response. Requests through hackney:request/5 were not affected: pseudo-headers are filtered before the caller sees them.
  • An HTTP/3 connection that goes away reports why. quic_h3 sends the reason with its close event, and the handler only matched the older shape without

... (truncated)

Changelog

Sourced from hackney's changelog.

4.8.1 - 2026-09-25

Changed

  • Update quic to 2.0.1, which compiles on Windows again. Its NIF build and clean hooks ran through sh, which Windows lacks, so the compile failed there for anything that reaches quic, hackney included. Windows runs on OTP crypto.

4.8.0 - 2026-09-24

Fixed

  • hackney:send_request/2 works on HTTP/2 and HTTP/3. Those protocols answer a request with the body included, which the function did not handle, so it failed with a case_clause. It returns the connection on every protocol now, so the response is read with body/1 or pulled with stream_body/1.
  • Several callers reading responses on one HTTP/2 or HTTP/3 connection each get their own. The read was resolved from the connection's last stream rather than the caller's, so on HTTP/2 all but one caller got {error, no_stream}, and on HTTP/3 two callers could be handed each other's body.
  • A caller reading an HTTP/3 response with body/1 or stream_body/1 is answered when the server resets its stream, instead of waiting for its own timeout. Needs quic 2.0.0, the first release to report a peer RESET_STREAM.
  • A pooled HTTP/2 connection no longer closes when the caller that opened it exits. It stayed owned by that caller, so its exit failed every other caller's request on the connection with {error, closed}. A shared connection now has no owner: each stream is tied to its own caller and is reset if that caller dies, and the connection closes itself once it has had no open stream for the pool timeout (#937, thanks @​smartinio).
  • Unregistering a pooled HTTP/2 connection no longer leaks its per-host slot. The pool dropped its monitor on the connection, so the slot was never released when the connection stopped.
  • A response that crosses a reset of its stream no longer closes the HTTP/2 connection. h2 dropped the header block of that response without decoding it, so the next response on the connection failed with COMPRESSION_ERROR.
  • The response to an HTTP/3 streaming upload can be read. After start_response/1, body/1 returned {error, invalid_state} and stream_body/1 returned {error, no_stream}: the body went to the start_response/1 caller as a second reply and was lost. When the response headers arrived before start_response/1 was called, it could wait forever.
  • HTTP/3 response headers carry one :status. quic_h3 passes the status separately and keeps it in the header list, and hackney prepended its own, so every response reached the low-level {h3, _, {stream_headers, ...}} consumer with the pseudo-header twice, which RFC 9114 4.3.1 makes a malformed response. Requests through hackney:request/5 were not affected: pseudo-headers are filtered before the caller sees them.

... (truncated)

Commits
  • d9129f8 Merge pull request #950 from benoitc/release/4.8.1
  • 20faebc Release 4.8.1
  • e41c32d Merge pull request #949 from benoitc/release/4.8.0
  • 555b599 Release 4.8.0
  • 65cc092 Merge pull request #948 from benoitc/test/h3-headers-and-timing
  • 701c5da Cover the HTTP/3 side of the header fix, and widen a test's margins
  • d90bbb9 Merge pull request #935 from lennartschoch/fix/strip-connection-headers-h2
  • 27126d4 Merge pull request #934 from lennartschoch/fix/cancel-idle-timeout-on-checkout
  • b191b13 Merge pull request #947 from benoitc/fix/send-request-body
  • 12b084f Merge branch 'master' into fix/send-request-body
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [hackney](https://github.com/benoitc/hackney) from 4.7.4 to 4.8.1.
- [Release notes](https://github.com/benoitc/hackney/releases)
- [Changelog](https://github.com/benoitc/hackney/blob/master/NEWS.md)
- [Commits](benoitc/hackney@4.7.4...4.8.1)

---
updated-dependencies:
- dependency-name: hackney
  dependency-version: 4.8.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file elixir Pull requests that update elixir code labels Sep 28, 2026
@michelboaventura
michelboaventura merged commit a81325e into main Sep 28, 2026
16 checks passed
@michelboaventura
michelboaventura deleted the dependabot/hex/hackney-4.8.1 branch September 28, 2026 19:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file elixir Pull requests that update elixir code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant