Skip to content

Update rest-assured to v6 - #58

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-rest-assured
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-rest-assured

Conversation

@renovate

@renovate renovate Bot commented May 11, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
io.rest-assured:json-path (source) 5.5.7 → 6.1.0 age confidence
io.rest-assured:rest-assured (source) 5.5.7 → 6.1.0 age confidence

Release Notes

rest-assured/rest-assured (io.rest-assured:json-path)

v6.1.0

  • Strip sensitive headers (Authorization and Cookie) when a redirect crosses to a different host, so a token or session isn't leaked to the redirect target. This is on by default and can be turned off with RedirectConfig.stripSensitiveHeadersOnCrossHostRedirect(false) (#​1873). Thanks to the University of Sydney security research team (Liyi Zhou, Ziyue Wang, Strick, Maurice, and Chenchen Yu) for the report.
  • Fix JsonPath "properties" spread over a list of objects returning null when the first element lacks a "properties" key (e.g. a GeoJSON feature carrying only a geometry), a regression from the Groovy 5 migration (fixes #​1875) (thanks to HDPark95 for PR #​1878). Thanks to haskiindahouse for the report.
  • Fix JsonPath returning null or Groovy meta-data for a nested "properties" navigation over a list of objects (e.g. items.properties.properties.x) on Groovy 5, because the list spread result was a plain list instead of the proxy list that carries the "properties" workaround forward (fixes #​1879) (thanks to kdelay for PR #​1880)
  • Fix JsonPath returning -Infinity for finite negative JSON numbers whose magnitude exceeds Float.MAX_VALUE under the default FLOAT_AND_DOUBLE number configuration. The float/double selection compared the signed value against Float.MAX_VALUE, so any such negative number fell into the float branch and overflowed; it now compares the magnitude and promotes to double regardless of sign (fixes #​1874) (thanks to kdelay for PR #​1877). Thanks to haskiindahouse for the report.
  • Decode JSON responses without an explicit charset as UTF-8 also when the content-type has parameters (e.g. "application/json; version=1") or is a "+json" type (e.g. "application/problem+json", "application/hal+json"). These used to fall back to the default content charset, which garbled non-ASCII characters in the body and in logged responses (related to #​1885)
  • Fix MalformedURLException when a request URL has no slash before a query string that contains another URL, e.g. get("https://example.com?redirect=https://example.com/callback") (fixes #​1836) (thanks to renechoi for PR #​1881)
  • Apply user-configured SSL settings (such as relaxed HTTPS validation, trust/key stores and certificate authentication) when an http request is redirected to https. Previously they were only applied if the original request used https, so the redirected request failed with "PKIX path building failed". For a request that starts as http the SSL settings are only applied when REST Assured's default http client factory is used, so an https scheme registered by a custom HttpClientConfig.httpClientFactory is kept (fixes #​790)
  • Don't let request specific SSL settings (SSLConfig such as relaxed HTTPS validation, or certificate authentication) leak into later requests when the http client instance is reused (HttpClientConfig.reuseHttpClientInstance()). The client's original https scheme is restored after each request and https connections established with request specific SSL settings are no longer kept alive for reuse.
  • json-schema-validator now supports JSON Schema draft-06, draft-07, 2019-09 and 2020-12 (e.g. const, if/then/else, propertyNames, prefixItems, $defs) using the networknt json-schema-validator (com.networknt:json-schema-validator 2.0.8, which is now a dependency of the module, together with slf4j-api). The draft is taken from the "$schema" keyword of the schema, so draft-03/draft-04 schemas are validated exactly as before. Schemas without "$schema" are still validated as draft-04 unless another version is configured, e.g. matchesJsonSchemaInClasspath("schema.json").using(JsonSchemaVersion.DRAFT_2020_12) or JsonSchemaValidatorSettings.schemaVersion(..). Note that: (1) schemas that already declared a draft-06+ "$schema" were previously validated with draft-04 semantics (newer keywords were ignored) and are now validated according to their declared draft, (2) a configured JsonSchemaFactory and checkedValidation only apply to draft-03/draft-04 schemas, (3) "format" is annotation-only (not validated) in 2019-09 and 2020-12, as required by those specifications (fixes #​1823)
  • Add ResponseSpecBuilder.expectHeader(String, ResponseAwareMatcher) and ResponseSpecification.header(String, ResponseAwareMatcher), so a reusable response specification can match a header against a value taken from the response, e.g. expectHeader("Location", response -> endsWith("/users/" + response.path("id"))) (fixes #​1884) (thanks to seethinajayadileep for PR #​1887)
  • java.time values (LocalDate, Instant, OffsetDateTime, Duration, ZoneId and so on) used as path, query or form parameters, headers or cookies are now sent as their ISO-8601 toString() instead of being run through the object mapper, which quoted them or failed without the JSR-310 module (fixes #​1781) (thanks to seethinajayadileep for PR #​1888)
  • A value object used as a parameter, header or cookie value that the object mapper serializes to a plain JSON string (for example a record with a @​JsonValue accessor) is now sent without the surrounding JSON quotes (fixes #​1818)
  • Add support for the HTTP QUERY method (a safe, idempotent method that carries a request body), e.g. given().body(..).when().query("/search"). Method.QUERY and query(..) overloads are added to RestAssured, RequestSender/RequestSpecification, RestAssuredMockMvc and RestAssuredWebTestClient (fixes #​1872)
  • Fix path parameters in the Spring WebTestClient module: an unnamed path parameter that isn't a String, e.g. get("/posts/{id}", 42L), no longer fails with a ClassCastException and is serialized the same way as a named path parameter, and path parameter values are no longer encoded twice, so a value such as "John Doe" or "100%" reaches the server unchanged instead of as "John%20Doe" or "100%25" (fixes #​1824) (thanks to hantsy for PR #​1825)
  • Fix failures when the default locale is Turkish (tr-TR), such as an exception for every response with status code 400 or above and OPTIONS requests sent from a filter or HTTP methods given in lower case, e.g. request("options", ..), not working, by using Locale.ROOT for internal upper and lower case conversions. Cookie.toString() now also formats the Expires attribute as "EEE, dd MMM yyyy HH:mm:ss zzz" in English instead of using the default locale's short date format (thanks to rdmrtn for PR #​1889)
  • MultiPartSpecBuilder.charset(Charset) now rejects byte[] and InputStream content with an IllegalArgumentException, like charset(String) already did, instead of silently ignoring the charset (fixes #​1691) (thanks to seethinajayadileep for PR #​1886)
  • Fix XmlPath and JsonPath not handling a hyphenated element or key name combined with a negative (from-the-end) list index, e.g. "root.some-list[-1]". XmlPath threw "The parameter ... was used but not defined" and JsonPath returned null (fixes #​1876) (thanks to kdelay for PR #​1882)
  • Fix unnamed path parameters in the Spring MockMvc module not being serialized like named ones, so a value object such as a record with a @​JsonValue accessor passed by position, e.g. get("/users/{id}", new Id(42)), was sent as its toString() ("Id[42]") instead of its serialized value ("42"). Note that, as for named path parameters, any other object that isn't a simple value (number, string, boolean, enum, UUID, java.time value etc) passed by position is now serialized by the object mapper instead of using its toString(). In both the Spring MockMvc and WebTestClient modules this also works for multipart requests, since unnamed path parameters are serialized using the explicitly set content type, like named ones, and not the derived "multipart/form-data" (fixes #​1905)
  • Fix query parameters in the Spring WebTestClient module not reaching the server as given: a value containing "+", "&", "=" or "{...}", e.g. queryParam("name", "a+b"), was received as "a b", truncated at "&" or failed as a missing URI variable. Query parameters, as well as params and form params that are added to the query string, are now strictly encoded (so reserved characters such as "!" or "," in a value are now sent percent-encoded), and a query parameter without a value, e.g. queryParam("flag"), is sent as "flag" instead of the name of an internal class (fixes #​1904)
  • The charset given to MultiPartSpecBuilder.charset(..) is now sent in the Content-Type of a File multi-part (e.g. "text/plain; charset=UTF-8"). Previously it was silently ignored for File content and only applied to String content. Other parameters of the part mime-type (e.g. "application/xml; version=2") are now also kept when a charset is specified, instead of being dropped (fixes #​1903)
  • Fix XmlPath and JsonPath not handling a list range with a negative end that is followed by more path, e.g. "root.some-list[0..-1].sub-el" or "list[-2..-1].x". The dots in the range were treated as path separators, so XmlPath threw "The parameter ... was used but not defined" (or a Groovy compilation error) and JsonPath returned null or failed. JsonPath now also supports a range on a root array, e.g. "[0..1].x", and chained indexes after a hyphenated name, e.g. "some-list[0][1].x" (fixes #​1906)

v6.0.1

  • Fix a JsonPath denial-of-service where oversized numeric literals in untrusted JSON were parsed into arbitrarily large BigIntegers, an O(n^2) CPU and heap cost. JSON number tokens are now capped at 1000 characters by default, configurable via JsonPathConfig.numberLengthLimit and JsonConfig.numberLengthLimit (a negative value disables the check). Thanks to Brian Lee (PhD security researcher, Georgia Tech SSLab) for the private report.
  • Use custom Jackson 3 object mapper in JsonPath (#​1858) (thanks to gkiel for PR)
  • Fix Spring MockMvc cookie handling with Jakarta-only servlet APIs (fixes #​1853)
  • Use Jackson 3 mapper in JsonPath deserialization when Jackson 3 is the only Jackson on the classpath (#​1865) (thanks to dickerpulli for PR)
  • Add JsonPath.using(Jackson3ObjectMapperFactory) overload (#​1861) (thanks to Anusha-7254 for PR)
  • Fix typo in duplicate-finder-maven-plugin phase property (#​1866) (thanks to metacosm for PR)
  • Fix incorrect serialization of enum constants declared with a body when used as query/path parameters (#​1799)
  • The spring-mock-mvc and spring-web-test-client modules now target Spring Framework 7 and no longer expose their own Spring version as a transitive dependency (the Spring dependencies are declared optional), so they no longer drag Spring 5 onto a Spring Boot 4 / Spring Framework 7 classpath. This removes the need for manual Spring exclusions on Spring Boot 4 (fixes #​1853, #​1868). Thanks to spencerarq for the detailed investigation.

v6.0.0

  • spring-mock-mvc module now supports Spring 7.x
  • spring-web-test-client now supports Spring 7.x
  • Upgraded commons-lang3 from 3.18.0 to 3.19.0
  • The spring modules now required Spring 5.3+ (previously 5.1 was required)
  • New minimum Java baseline is now 17
  • New minimum Groovy base is now 5.x
  • Support for Jackson 3 object mapping
  • Support for Yasson 3 object mapping
  • Support for jakarta JsonB/Johnzon 3 object mapping
  • Migrate json-path fully to Java, bypass GroovyShell for evaluation (#​1844) (thanks to Michael Edgar for PR)
    • This fixed some nasty memory leaks when using JsonPath heavily in long running processes
  • Stop resetting ResponseParserRegistrar during build (#​1759, #​1505, #​1207 & #​978) (thanks to Marc Easen for PR)
  • Skip Null filters in FilterContextImpl (#​1834) (thanks to Boyarshinov Alexander for PR)
  • Upgraded Kotlin extension module to use Kotlin 2.2.21

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 9am on Monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot changed the title Update rest-assured to v6 (major) Update rest-assured to v6 May 12, 2026
@renovate
renovate Bot force-pushed the renovate/major-rest-assured branch from 966c17e to 9d09270 Compare June 2, 2026 01:03
@sonarqubecloud

sonarqubecloud Bot commented Jun 2, 2026

Copy link
Copy Markdown

@renovate
renovate Bot force-pushed the renovate/major-rest-assured branch from 9d09270 to 31fad8e Compare July 10, 2026 21:59
@sonarqubecloud

Copy link
Copy Markdown

@renovate
renovate Bot force-pushed the renovate/major-rest-assured branch from 31fad8e to d426725 Compare September 13, 2026 03:48
@renovate
renovate Bot force-pushed the renovate/major-rest-assured branch from d426725 to b80b897 Compare September 25, 2026 01:18
@renovate
renovate Bot force-pushed the renovate/major-rest-assured branch from b80b897 to 1daf131 Compare October 9, 2026 23:21
@renovate
renovate Bot force-pushed the renovate/major-rest-assured branch from 1daf131 to 05766e5 Compare October 10, 2026 02:41
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants