Repository navigation
chore(deps): update dependency openapi_first to v4 - #1034
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #1034 +/- ##
==========================================
- Coverage 94.79% 94.76% -0.04%
==========================================
Files 460 459 -1
Lines 15834 15778 -56
==========================================
- Hits 15010 14952 -58
- Misses 824 826 +2
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
renovate
Bot
force-pushed
the
renovate/openapi_first-4.x
branch
2 times, most recently
from
September 24, 2026 19:37
6585271 to
e25ba44
Compare
renovate
Bot
force-pushed
the
renovate/openapi_first-4.x
branch
from
October 2, 2026 11:13
e25ba44 to
4a594ea
Compare
renovate
Bot
force-pushed
the
renovate/openapi_first-4.x
branch
from
October 7, 2026 21:42
4a594ea to
f355feb
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
"~>2.0"→"~>4.0"Release Notes
ahx/openapi_first (openapi_first)
v4.0.0Compare Source
This release has no stricter or less strict request validation. It changes mostly internal stuff and adds a Sinatra integration. It's a major version, but it should be safe to upgrade.
Breaking changes
multipart/form-datapart that was sent as a file was read into memory, which allowed a single large upload to any documented multipart route to exhaust the memory of the server process. Such a field is now passed through as Rack parsed it ({ filename:, type:, name:, tempfile:, head: }), which is the same shape that Sinatra and Hanami hand to your application. Useparsed_body['file'][:tempfile]to read or stream the file.minLength,maxLengthorpatternon a field that was sent as a file are ignored.after_request_body_property_validationhook sees an empty String instead of the file.contentTypein theencodingmap, are read and validated as before.openapi_parametersgem was merged into openapi_first and is not a dependency anymore. Parameter parsing now lives in openapi_first itself. If you registered a parser for parameters that use acontentfield, useOpenapiFirst::ParameterContentParsers.registerinstead ofOpenapiParameters::ContentParsers.register.OpenapiFirst::ResponseHeader(returned byResponse#headers, renamed fromOpenapiFirst::Header) exposesparameter, anOpenapiFirst::Parameter, instead ofnode.OpenapiFirst::Request#parametersreturns the parameters that are defined for a request asOpenapiFirst::Parameterobjects, which exposename,location,schema,required?,deprecated?,style,explode?andmedia_type.Removed deprecations
OpenapiFirst::Configuration#request_validation_raise_errorand#response_validation_raise_error(both reader and writer), deprecated since 3.0.0. Passraise_error:to middlewares instead.OpenapiFirst::Test::Configuration#coverage_formatter,#coverage_formatter=,#coverage_formatter_optionsand#coverage_formatter_options=, deprecated since 3.4.0. Use#coverage_reporter/#coverage_reporter_optionsinstead.OpenapiFirst::Test::Coverage::TerminalFormatter, deprecated since 3.4.0. UseOpenapiFirst::Test::Coverage::TerminalReporterinstead.formatter:keyword ofOpenapiFirst::Test.report_coverage, deprecated since 3.4.0. Usereporter:instead.OpenapiFirst::Test::Coverage::TerminalReporter#format, deprecated since 3.4.0. Use#reportinstead.Added
Added: API coverage now reports skipped requests and responses.
Added: OpenAPI 3.2 documents are accepted, but not fully supported yet. They are handled using the OpenAPI 3.1 rules, so features introduced in 3.2 may be ignored. Loading such a document prints a warning. Operations defined under
additionalOperationsare routed. See #469.Added: Show all covered endpoints in HTML coverage reporter and filter covered/uncovered endpoints.
Added: Sinatra integration (OpenapiFirst::Sinatra)
A Sinatra extension to define routes by referencing OpenAPI operations:
The HTTP method and path for each route come from the operationId.
Request validation is called automatically for these operations.
Fixed
ArgumentErrorin OpenAPI 3.0 documents when a top-level key of that file collides with a JSON Schema keyword, such as$ref: 'parameters.yaml#/id'. The containing file is no longer parsed as a schema itself, so such keys work like any other now. See #348.$refs nested inside the schema of a parameter or a response header are resolved now, so these values are unpacked and converted as described. Before, only a$refat the top level of the schema was resolved. See #450.contentfield with a$ref'd schema is resolved now.NoMethodErrorwhen a parameter has neitherschemanorcontent.content(?filter=a&filter=b) raised aNoMethodErrororTypeError. The values are validated against the schema now, which returns an:invalid_queryfailure.style: matrixraised aNoMethodErrorif its value did not contain the parameter name, or contained it more than once. Such values are parsed like theirexplodecounterpart now.style: matrix, or a path parameter that describes an object, raised anArgumentErrorif its value had an invalid%-encoding. Such values are validated against the schema now.contentfield with a value that could not be parsed as that media type (e.g.007asapplication/json) was converted using the parameter's schema type anyway, which could make an invalid value pass schema validation (e.g. as the integer7). Such values are left as they are now, so schema validation rejects them as before.Definition. Response headers with a schema no longer keep the whole raw document node alive, and a couple of build-time-only hashes were replaced with more compact structures.v3.4.3Compare Source
Fixed: Loading a document no longer raises
NoMethodError: undefined method 'schema' for nilwhen a Media Type Object has noschema(e.g. it only declares anexample).schemais optional in a Media Type Object; such media types now impose no body-schema constraint.v3.4.2Compare Source
Fixed: Parsing of JSON-formatted query params issue #476 (thanks @Drowze)
v3.4.1Compare Source
Fixed: Added missing ERB and css file to the gem
v3.3.1Compare Source
OpenapiFirst.loadwithout using a global cache. (RemovedOpenapiFirst.clear_cache!.)v3.3.0Compare Source
OpenapiFirst will now cache the contents of files that have been loaded. If you need to reload your OpenAPI definition for tests or server hot reloading, you can callOpenapiFirst.clear_cache!.OpenapiFirst::Router#matchfor faster path matching and reduced memory allocation.v3.2.1Compare Source
UnknownQueryParameterErrorif request is ignored in tests. Fixes #441.v3.2.0Changed
Added
OpenapiFirst::ValidatedRequest#unknown?andOpenapiFirst::ValidatedResponse#unknown?after_response_body_property_validationpath_prefixvalue to be set on the creation of a Definition. See PR #432:OpenapiFirst::Test::Configuration#ignore_response_errorand#ignore_request_errorto configure which request/response errors should not raise an error during testing:v3.1.1v3.1.0Compare Source
openapi_first/test
Changed
OpenapiFirst::Test::UnknownQueryParameterErrorwhen it sees unknown query parameters. Note thatOpenapiFirst("core") still allows unknown query parameters.OpenapiFirst::Test.register(orOpenapiFirst.register)v3.0.1Compare Source
v3.0.0Compare Source
openapi_first
Changed
Before this change
GET /things/24/matched/things/{id}:, but it no longer does.:response_not_foundwas split into two more specific types:response_content_type_not_foundand:response_status_not_found. This should be mostly internal stuff. So if your custom error response usedresponse_not_found, you will have to adapt.request_validation_raise_errorandresponse_validation_raise_error. Please pass theraise_error:option to the middlewares directly.Added
specargument in middlewares optional and removes the necessity to load the OAD in the same place where you use the middlewares and adds a cache for parsed OADs.Removed
OpenapiFirst::Configuration#clone. Use#childinstead.Fixed
openapi_parametersto >= 0.7.0, because that version supports unpacking parameters the usestyle: deepObjectwithexplode: true.OpenapiFirst::Test.setupmore robust by addingOpenapiFirst::Configuration#childso it does not matter if you load our OAD before calligOpenapiFirst::Test.setup.openapi_first/test
Changed
OpenapiFirst::Test.appnow returns an instance ofOpenapiFirst::Test::App, instead ofRack::Builerand delegates methods other than#callto the original app. This wrapper adds validated requests, responses to the rack env atenv[OpenapiFirst::Test::REQUEST],env[OpenapiFirst::Test::RESPONSE]. This makes it possible to test Rails engines. Thanks to Josh! See #410.OpenapiFirst::Testnow falls back to using globally registered OADs if nothing was registered insideOpenapiFirst::Test.setup.Added
OpenapiFirst::Testnow supports parallel tests via a DRB client/sever. Thanks to Richard! See #394.OpenapiFirst::TestConfiguration options which are useful when adopting OpenAPI:ignore_unknown_response_status = trueto make API coverage no longer complain about undefined response statuses it sees during a test run.minimum_coverage=is no longer deprecated. This is useful when gradually adopting OpenAPIignored_unknown_status=to overwrite the whole list of ignored unknown status at onceRemoved
Test::Coverage.current_run, .plans, .install, .uninstall. If you are using these, useOpenapiFirst::Test.setupinstead.Fixed
OpenapiFirst::Test.setupmore robust by addingOpenapiFirst::Configuration#childso it does not matter if you load our OAD before calligOpenapiFirst::Test.setup.Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.