Skip to content

chore(deps): update dependency openapi_first to v4 - #1034

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/openapi_first-4.x
Open

renovate[bot] wants to merge 1 commit into
masterfrom
renovate/openapi_first-4.x

Conversation

@renovate

@renovate renovate Bot commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
openapi_first (changelog) "~>2.0" → "~>4.0" age confidence

Release Notes

ahx/openapi_first (openapi_first)

v4.0.0

Compare Source

This release has no stricter or less strict request validation. It changes mostly internal stuff and adds a Sinatra integration. It's a major version, but it should be safe to upgrade.

Breaking changes
  • Uploaded files are no longer read during request validation. Before, the whole content of every multipart/form-data part that was sent as a file was read into memory, which allowed a single large upload to any documented multipart route to exhaust the memory of the server process. Such a field is now passed through as Rack parsed it ({ filename:, type:, name:, tempfile:, head: }), which is the same shape that Sinatra and Hanami hand to your application. Use parsed_body['file'][:tempfile] to read or stream the file.
    • The content of these fields is not validated anymore, so minLength, maxLength or pattern on a field that was sent as a file are ignored.
    • An after_request_body_property_validation hook sees an empty String instead of the file.
    • Fields that were not sent as a file, and fields with a JSON contentType in the encoding map, are read and validated as before.
  • The openapi_parameters gem was merged into openapi_first and is not a dependency anymore. Parameter parsing now lives in openapi_first itself. If you registered a parser for parameters that use a content field, use OpenapiFirst::ParameterContentParsers.register instead of OpenapiParameters::ContentParsers.register.
  • Changed: OpenapiFirst::ResponseHeader (returned by Response#headers, renamed from OpenapiFirst::Header) exposes parameter, an OpenapiFirst::Parameter, instead of node.
  • Changed: OpenapiFirst::Request#parameters returns the parameters that are defined for a request as OpenapiFirst::Parameter objects, which expose name, location, schema, required?, deprecated?, style, explode? and media_type.
Removed deprecations
  • Removed: OpenapiFirst::Configuration#request_validation_raise_error and #response_validation_raise_error (both reader and writer), deprecated since 3.0.0. Pass raise_error: to middlewares instead.
  • Removed: OpenapiFirst::Test::Configuration#coverage_formatter, #coverage_formatter=, #coverage_formatter_options and #coverage_formatter_options=, deprecated since 3.4.0. Use #coverage_reporter / #coverage_reporter_options instead.
  • Removed: OpenapiFirst::Test::Coverage::TerminalFormatter, deprecated since 3.4.0. Use OpenapiFirst::Test::Coverage::TerminalReporter instead.
  • Removed: The formatter: keyword of OpenapiFirst::Test.report_coverage, deprecated since 3.4.0. Use reporter: instead.
  • Removed: OpenapiFirst::Test::Coverage::TerminalReporter#format, deprecated since 3.4.0. Use #report instead.
Added
  • Added: API coverage now reports skipped requests and responses.

  • Added: OpenAPI 3.2 documents are accepted, but not fully supported yet. They are handled using the OpenAPI 3.1 rules, so features introduced in 3.2 may be ignored. Loading such a document prints a warning. Operations defined under additionalOperations are routed. See #​469.

  • Added: Show all covered endpoints in HTML coverage reporter and filter covered/uncovered endpoints.

  • Added: Sinatra integration (OpenapiFirst::Sinatra)
    A Sinatra extension to define routes by referencing OpenAPI operations:

      require 'openapi_first/sinatra'
    
      class PetsApi < Sinatra::Base
        register OpenapiFirst::Sinatra
        openapi 'openapi.yaml'
    
        operation :index_pets do |params|
          json index_pets(params[:filter])
        end
    
        operation :create_pet do
          pet = create_pet(parsed_body)
          headers['Location'] = operation_url(:show_pet, petId: pet.id)
          status :created
          json pet
        end
    
        operation :show_pet do |params|
          json show_pet(params[:petId])
        end
      end

    The HTTP method and path for each route come from the operationId.
    Request validation is called automatically for these operations.

Fixed
  • Fixed: Validating against a schema from a referenced file raised ArgumentError in OpenAPI 3.0 documents when a top-level key of that file collides with a JSON Schema keyword, such as $ref: 'parameters.yaml#/id'. The containing file is no longer parsed as a schema itself, so such keys work like any other now. See #​348.
  • Fixed: $refs nested inside the schema of a parameter or a response header are resolved now, so these values are unpacked and converted as described. Before, only a $ref at the top level of the schema was resolved. See #​450.
  • Fixed: The JSON schema of a parameter that uses a content field with a $ref'd schema is resolved now.
  • Fixed: Loading a document no longer raises NoMethodError when a parameter has neither schema nor content.
  • Fixed: Repeated values for a query parameter that describes an object or uses content (?filter=a&filter=b) raised a NoMethodError or TypeError. The values are validated against the schema now, which returns an :invalid_query failure.
  • Fixed: A parameter with style: matrix raised a NoMethodError if its value did not contain the parameter name, or contained it more than once. Such values are parsed like their explode counterpart now.
  • Fixed: A parameter with style: matrix, or a path parameter that describes an object, raised an ArgumentError if its value had an invalid %-encoding. Such values are validated against the schema now.
  • Fixed: A path, header or cookie parameter that uses a content field with a value that could not be parsed as that media type (e.g. 007 as application/json) was converted using the parameter's schema type anyway, which could make an invalid value pass schema validation (e.g. as the integer 7). Such values are left as they are now, so schema validation rejects them as before.
  • Fixed: Reduced memory retained by a loaded Definition. Response headers with a schema no longer keep the whole raw document node alive, and a couple of build-time-only hashes were replaced with more compact structures.

v3.4.3

Compare Source

Fixed: Loading a document no longer raises NoMethodError: undefined method 'schema' for nil when a Media Type Object has no schema (e.g. it only declares an example). schema is optional in a Media Type Object; such media types now impose no body-schema constraint.

v3.4.2

Compare Source

Fixed: Parsing of JSON-formatted query params issue #​476 (thanks @​Drowze)

v3.4.1

Compare Source

Fixed: Added missing ERB and css file to the gem

v3.3.1

Compare Source

  • Optimized caching towards reducing retained memory after calling OpenapiFirst.load without using a global cache. (Removed OpenapiFirst.clear_cache!.)
  • Require ruby >= 3.3.0

v3.3.0

Compare Source

  • OpenapiFirst will now cache the contents of files that have been loaded. If you need to reload your OpenAPI definition for tests or server hot reloading, you can call OpenapiFirst.clear_cache!.
  • Optimized OpenapiFirst::Router#match for faster path matching and reduced memory allocation.

v3.2.1

Compare Source

  • Don't raise UnknownQueryParameterError if request is ignored in tests. Fixes #​441.

v3.2.0

Changed
  • Changed OpenapiFirst::Test to track the request after the app has handled the request. See PR #​434. You can restore the old behavior with
  include OpenapiFirst::Test::Methods[MyApp, validate_request_before_handling: true]
Added
  • Added OpenapiFirst::ValidatedRequest#unknown? and OpenapiFirst::ValidatedResponse#unknown?
  • Added new hook: after_response_body_property_validation
  • Added support for a static path_prefix value to be set on the creation of a Definition. See PR #​432:
    OpenapiFirst.configure do |config|
      config.register('openapi/openapi.yaml' path_prefix: '/weather')
    end
  • Added OpenapiFirst::Test::Configuration#ignore_response_error and #ignore_request_error to configure which request/response errors should not raise an error during testing:
    OpenapiFirst::Test.setup do |test|
      test.ignore_request_error do |validated_request|
        # Ignore unknown requests on certain paths
        validated_request.path.start_with?('/api/v1') && validated_request.unknown?
      end
      
      test.ignore_response_error do |validated_response, rack_request|
        # Ignore invalid response bodies on certain paths
        validated_request.path.start_with?('/api/legacy/stuff') && validated_request.error.type ==  :invalid_body      
      end
    end

v3.1.1

  • Changed: Return uniqe errors in default error responses

v3.1.0

Compare Source

openapi_first/test
Changed
  • OpenapiFirst::Test now raises OpenapiFirst::Test::UnknownQueryParameterError when it sees unknown query parameters. Note that OpenapiFirst ("core") still allows unknown query parameters.
  • OpenapiFirst::Test does not track requests/responses unless the OAD was registered via OpenapiFirst::Test.register (or OpenapiFirst.register)

v3.0.1

Compare Source

  • Add missing gem dependency "drb", which is no longer installed by default with newer rubies. This is used in openapi_first/test to make parallel tests work.

v3.0.0

Compare Source

openapi_first
Changed
  • Breaking: Trailing slashes are no longer ignored in dynamic paths. See #​403.
    Before this change GET /things/24/ matched /things/{id}:, but it no longer does.
  • Breaking: Failure type :response_not_found was split into two more specific types :response_content_type_not_found and :response_status_not_found. This should be mostly internal stuff. So if your custom error response used response_not_found, you will have to adapt.
  • Deprecated configuration fields request_validation_raise_error and response_validation_raise_error. Please pass the raise_error: option to the middlewares directly.
Added
  • Added support to register OADs globally via:
    OpenapiFirst.configure { |config| config.register('openapi.yaml')  }
    This makes the spec argument in middlewares optional and removes the necessity to load the OAD in the same place where you use the middlewares and adds a cache for parsed OADs.
Removed
  • Removed deprecated methods which produced a warning since 2.0.0.
  • Removed OpenapiFirst::Configuration#clone. Use #child instead.
  • It's no longer supported to remove locally added hooks during runtime.
Fixed
  • Update dependency openapi_parameters to >= 0.7.0, because that version supports unpacking parameters the use style: deepObject with explode: true.
  • Make OpenapiFirst::Test.setup more robust by adding OpenapiFirst::Configuration#child so it does not matter if you load our OAD before callig OpenapiFirst::Test.setup.
openapi_first/test
Changed
  • OpenapiFirst::Test.app now returns an instance of OpenapiFirst::Test::App, instead of Rack::Builer and delegates methods other than #call to the original app. This wrapper adds validated requests, responses to the rack env at env[OpenapiFirst::Test::REQUEST], env[OpenapiFirst::Test::RESPONSE]. This makes it possible to test Rails engines. Thanks to Josh! See #​410.
  • OpenapiFirst::Test now falls back to using globally registered OADs if nothing was registered inside OpenapiFirst::Test.setup.
  • 401er and 500er status are okay to not be described.
Added
  • The Coverage feature in OpenapiFirst::Test now supports parallel tests via a DRB client/sever. Thanks to Richard! See #​394.
  • Added OpenapiFirst::Test Configuration options which are useful when adopting OpenAPI:
    • ignore_unknown_response_status = true to make API coverage no longer complain about undefined response statuses it sees during a test run.
    • minimum_coverage= is no longer deprecated. This is useful when gradually adopting OpenAPI
  • ignored_unknown_status= to overwrite the whole list of ignored unknown status at once
Removed
  • Removed internally used Test::Coverage.current_run, .plans, .install, .uninstall. If you are using these, use OpenapiFirst::Test.setup instead.
Fixed
  • Make OpenapiFirst::Test.setup more robust by adding OpenapiFirst::Configuration#child so it does not matter if you load our OAD before callig OpenapiFirst::Test.setup.

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@codecov-commenter

codecov-commenter commented Sep 18, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 94.76%. Comparing base (e7a52bc) to head (f355feb).
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@            Coverage Diff             @@
##           master    #1034      +/-   ##
==========================================
- Coverage   94.79%   94.76%   -0.04%     
==========================================
  Files         460      459       -1     
  Lines       15834    15778      -56     
==========================================
- Hits        15010    14952      -58     
- Misses        824      826       +2     
Flag Coverage Δ
postgres ?
sqlite 94.76% <ø> (+<0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@renovate
renovate Bot enabled auto-merge (squash) September 24, 2026 19:37
@renovate
renovate Bot force-pushed the renovate/openapi_first-4.x branch 2 times, most recently from 6585271 to e25ba44 Compare September 24, 2026 19:37
@renovate
renovate Bot force-pushed the renovate/openapi_first-4.x branch from e25ba44 to 4a594ea Compare October 2, 2026 11:13
@renovate
renovate Bot force-pushed the renovate/openapi_first-4.x branch from 4a594ea to f355feb Compare October 7, 2026 21:42

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant