Skip to content

chore(deps): bump org.apache.httpcomponents.core5:httpcore5 from 5.4 to 5.4.1 in the httpcomponents5 group#2431

Merged
kthoms merged 1 commit into
release/1.1.xfrom
dependabot/maven/release/1.1.x/httpcomponents5-0fec8ef173
Feb 23, 2026
Merged

chore(deps): bump org.apache.httpcomponents.core5:httpcore5 from 5.4 to 5.4.1 in the httpcomponents5 group#2431
kthoms merged 1 commit into
release/1.1.xfrom
dependabot/maven/release/1.1.x/httpcomponents5-0fec8ef173

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Feb 21, 2026

Copy link
Copy Markdown
Contributor

Bumps the httpcomponents5 group with 1 update: org.apache.httpcomponents.core5:httpcore5.

Updates org.apache.httpcomponents.core5:httpcore5 from 5.4 to 5.4.1

Changelog

Sourced from org.apache.httpcomponents.core5:httpcore5's changelog.

Release 5.4.1

This maintenance release fixes a latency regression in the async transport caused by TCP_NODELAY failing to be set. Several other bugs have also been fixed affecting connection management, HTTP/2 exception handling and propagation, and so forth.

Change Log

  • Regression: Ensure TCP-specific socket options are set correctly in the async transport. Contributed by Ryan Schmitt

  • Bug fix: Prevent integer overflow in LaxConnPool so that negative numbers are not reported in the thread pool statistics. Contributed by Ryan Schmitt

  • Bug fix: Loop over and close expired connections in LaxConnPool instead of returning them. Contributed by Ryan Schmitt

  • Bug fix: Respect the PoolReusePolicy.FIFO in StrictConnPool. Contributed by Ryan Schmitt

  • Bug fix: Corrected exception propagation in protocol negotiators' exception handling code. Contributed by Oleg Kalnichevski

  • Bug fix: Fix SOCKS handshake to fail on EOF. (#604) Contributed by Arturo Bernal

  • Bug fix: Handle CancelledKeyException thrown by abort method of the H2 stream. Contributed by Oleg Kalnichevski

  • Bug fix: Fix race condition in ComplexCancellable. Contributed by Ryan Schmitt

  • Bug fix: In MonitoringResponseOutOfOrderStrategy, always perform a blocking read to check for data. Contributed by Ryan Schmitt

  • Bug fix: Corrected exception propagation to individual H2 streams in case of an unexpected error with the H2 connection. Contributed by Oleg Kalnichevski

  • Regression: Restored SocketSupport and marked it deprecated. Contributed by Oleg Kalnichevski

Commits
  • c728dd8 HttpCore 5.4.1 release
  • b5e2b02 Update release notes for HttpCore 5.4.1 release
  • 17ce37a Ensure TCP-specific socket options are set
  • a33904a LaxConnPool: Prevent integer overflow in getTotalStats()
  • 92dbfea LaxConnPool: Loop over expired connections
  • 0d9d1aa StrictConnPool: Fix FIFO implementation
  • 7230a04 Bug fix: Corrected exception propagation in protocol negotiators exception ha...
  • 2b8615d Fix SOCKS handshake to fail on EOF. (#604)
  • 5d96deb Bug fix: Handle CancelledKeyException thrown by abort method of the H2 stream
  • 15e9de4 ComplexCancellable: Fix race condition
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

@dependabot dependabot Bot added this to the 1.1.1 milestone Feb 21, 2026
@dependabot dependabot Bot added the dependencies:maven Updates of Maven dependencies label Feb 21, 2026
@kthoms

kthoms commented Feb 23, 2026

Copy link
Copy Markdown
Contributor

@dependabot rebase

Bumps the httpcomponents5 group with 1 update: [org.apache.httpcomponents.core5:httpcore5](https://github.com/apache/httpcomponents-core).


Updates `org.apache.httpcomponents.core5:httpcore5` from 5.4 to 5.4.1
- [Changelog](https://github.com/apache/httpcomponents-core/blob/rel/v5.4.1/RELEASE_NOTES.txt)
- [Commits](apache/httpcomponents-core@rel/v5.4...rel/v5.4.1)

---
updated-dependencies:
- dependency-name: org.apache.httpcomponents.core5:httpcore5
  dependency-version: 5.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: httpcomponents5
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/maven/release/1.1.x/httpcomponents5-0fec8ef173 branch from 9fa4f6a to 873f059 Compare February 23, 2026 07:37
@kthoms kthoms merged commit 035a734 into release/1.1.x Feb 23, 2026
16 checks passed
@dependabot dependabot Bot deleted the dependabot/maven/release/1.1.x/httpcomponents5-0fec8ef173 branch February 23, 2026 21:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies:maven Updates of Maven dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant