Bump libraryVersion.okhttp3 from 3.11.0 to 4.8.1
Bumps libraryVersion.okhttp3 from 3.11.0 to 4.8.1.
Updates logging-interceptor from 3.11.0 to 4.8.1
Changelog
Sourced from logging-interceptor's changelog.
Version 4.8.1
2020-08-06
- Fix: Don't crash in
HeldCertificate.Builderwhen creating certificates on older versions of Android, including Android 6. We were using a feature ofSimpleDateFormatthat wasn't available in those versions!Version 4.8.0
2020-07-11
New: Change
HeldCertificate.Builderto use its own ASN.1 certificate encoder. This is part of our effort to remove the okhttp-tls module's dependency on Bouncy Castle. We think Bouncy Castle is great! But it's a large dependency (6.5 MiB) and its security provider feature impacts VM-wide behavior.New: Reduce contention for applications that make a very high number of concurrent requests. Previously OkHttp used its connection pool as a lock when making changes to connections and calls. With this change each connection is locked independently.
Upgrade: [Okio 2.7.0][okio_2_7_0].
implementation("com.squareup.okio:okio:2.7.0")Fix: Avoid log messages like "Didn't find class org.conscrypt.ConscryptHostnameVerifier" when detecting the TLS capabilities of the host platform.
Fix: Don't crash in
HttpUrl.topPrivateDomain()when the hostname is malformed.Fix: Don't attempt Brotli decompression if the response body is empty.
Version 4.7.2
2020-05-20
- Fix: Don't crash inspecting whether the host platform is JVM or Android. With 4.7.0 and 4.7.1 we had a crash
IllegalArgumentException: Not a Conscrypt trust managerbecause we depended on initialization order of companion objects.Version 4.7.1
2020-05-18
- Fix: Pass the right arguments in the trust manager created for
addInsecureHost(). Without the
Commits
fc6c29cPrepare for release 4.8.1.506e840Implement DER constraints on date formats (#6213)a70e992Prepare for release 4.8.0.cf367d9Add defensive checks for malformed ASN.1 DER (#6180)0e0f3a2Push OkHttp 3.14.x into the sea. It is no longer supported. (#6179)7c9cfd6Fix typo (#6178)4bfa33eUpgrade to Okio 2.7.0 (#6175)c4cbb57Don't crash on unknown GeneralName types. (#6170)19e9a8fDrop support for indefinite length in DER (#6166)c04b57eAdd limits to what length values DerReader supports (#6164)- Additional commits viewable in compare view
Updates okhttp from 3.11.0 to 4.8.1
Changelog
Sourced from okhttp's changelog.
Version 4.8.1
2020-08-06
- Fix: Don't crash in
HeldCertificate.Builderwhen creating certificates on older versions of Android, including Android 6. We were using a feature ofSimpleDateFormatthat wasn't available in those versions!Version 4.8.0
2020-07-11
New: Change
HeldCertificate.Builderto use its own ASN.1 certificate encoder. This is part of our effort to remove the okhttp-tls module's dependency on Bouncy Castle. We think Bouncy Castle is great! But it's a large dependency (6.5 MiB) and its security provider feature impacts VM-wide behavior.New: Reduce contention for applications that make a very high number of concurrent requests. Previously OkHttp used its connection pool as a lock when making changes to connections and calls. With this change each connection is locked independently.
Upgrade: [Okio 2.7.0][okio_2_7_0].
implementation("com.squareup.okio:okio:2.7.0")Fix: Avoid log messages like "Didn't find class org.conscrypt.ConscryptHostnameVerifier" when detecting the TLS capabilities of the host platform.
Fix: Don't crash in
HttpUrl.topPrivateDomain()when the hostname is malformed.Fix: Don't attempt Brotli decompression if the response body is empty.
Version 4.7.2
2020-05-20
- Fix: Don't crash inspecting whether the host platform is JVM or Android. With 4.7.0 and 4.7.1 we had a crash
IllegalArgumentException: Not a Conscrypt trust managerbecause we depended on initialization order of companion objects.Version 4.7.1
2020-05-18
- Fix: Pass the right arguments in the trust manager created for
addInsecureHost(). Without the
Commits
fc6c29cPrepare for release 4.8.1.506e840Implement DER constraints on date formats (#6213)a70e992Prepare for release 4.8.0.cf367d9Add defensive checks for malformed ASN.1 DER (#6180)0e0f3a2Push OkHttp 3.14.x into the sea. It is no longer supported. (#6179)7c9cfd6Fix typo (#6178)4bfa33eUpgrade to Okio 2.7.0 (#6175)c4cbb57Don't crash on unknown GeneralName types. (#6170)19e9a8fDrop support for indefinite length in DER (#6166)c04b57eAdd limits to what length values DerReader supports (#6164)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) -
@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language -
@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language -
@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language -
@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language -
@dependabot badge mewill comment on this PR with code to add a "Dependabot enabled" badge to your readme
Additionally, you can set the following in your Dependabot dashboard:
- Update frequency (including time of day and day of week)
- Pull request limits (per update run and/or open at any time)
- Out-of-range updates (receive only lockfile updates, if desired)
- Security updates (receive only security updates, if desired)