0. Release Notes (1.4.x)
1.4.1
Release notes for Apache Pekko HTTP 1.4.1. See GitHub Milestone for 1.4.1 for a fuller list of changes.
This is a bug fix release. It includes a number of hardening changes to the HTTP parsing and rendering code.
Bug Fixes
- SSE: allow Unicode line terminators (PR1186)
- Use
Locale.ROOTfortoLowerCase/toUpperCaseand in theRouteTestheader lookup (PR1224) - Parse
Content-Lengthas digits with surrounding whitespace only (PR1243) - Render
Content-Lengthfor HEAD responses with a declared length (PR1244) - HTTP/2: bound incoming header blocks with
max-header-list-size(PR1247) - Count repeated
Connectionheaders towardsmax-header-count(PR1268) - Compare path elements when checking that a served file is below the base directory (PR1269)
- Prevent CRLF injection through chunk trailers and extensions (PR1270)
- HTTP/2: drop header fields containing CR, LF or NUL (PR1271)
- Drop rendered headers containing NUL as well as CR and LF (PR1272)
Dependency Changes
There are no dependency changes in this release.
1.4.0
Release notes for Apache Pekko HTTP 1.4.0. See GitHub Milestone for 1.4.0 for a fuller list of changes.
It is strongly recommended that you avoid using Pekko 1.0.x jars with this release, you should use Pekko 1.1.x jars (or later 1.x releases) where possible. We don’t expect there to be problems running with Pekko 1.0.x jars but Pekko HTTP 1.4 jars are built with Pekko 1.1 jars.
Changes
- Don’t rely on Pekko Core ccompat (PR890)
- Correct Content-Length rendering based on method+status (PR968)
- Ensure end() is called on Inflaters and Deflaters to allow earlier tidy up of resources (#1133)
Dependency Changes
Most of the dependency changes are small patch level upgrades. Some exceptions include:
- Jackson 2.21.5
1.4.1