NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #7 most downloaded on Packagist
PSR-7 message implementation that also provides common utility methods
Last release 1 months ago
24 Aug 2026
Release timing varies
gaps range from 8 days to 8 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
71 releases · first in 2015
Add Utils::redactUriForMessage() and Utils::redactUriStringForMessage() for URI diagnostics
Utils::redactUriForMessage() and Utils::redactUriStringForMessage() for URI diagnosticsPrefix relative paths that begin with a colon segment with ./ instead of throwing
./ instead of throwing/. prefix for authority-less // paths to percent-encoding normalizations as wellfile host strands a // path, prefixing it with /.One column per quarter.
Removed deprecated Header::normalize() method
DiagnosticValue::escape() to escape controls and malformed UTF-8 in diagnosticsGuzzleHttp\Psr7\Exception\TimeoutException for timed-out stream operationsGuzzleHttp\Psr7\Utils::redactUserInfoInString() to redact the userinfo of a raw URI string within textGuzzleHttp\Psr7\Rfc3986 to public API with isValid*() predicates and canonicalizeIpv6()GuzzleHttp\Psr7\UriNormalizer::CANONICALIZE_IPV6_HOST to PRESERVING_NORMALIZATIONSpsr/http-message:^2.0 and add native parameter and return typespsr/http-factory:^1.1ServerRequest::fromGlobals() still uppercasestmp_name, size, or errorerror valuesUploadedFile::moveTo()read() lengths across all stream implementations+ flag anywhere in a mode for Stream::isReadable()/isWritable()PumpStream source callablesPumpStream close and detachMessage::bodySummary()null for the Message::bodySummary() truncation length to use the defaultLimitStream offset/limit and track non-seekable offset by bytes skippedFnStream close and detach terminal, calling close callbacks at most onceFnStream close callbacks during destructor cleanupCachingStream::close() idempotent, preserving remote cleanup after detachCachingStream cursor when a SEEK_END target on an unknown-size stream is rejectedUri::getPath() and origin-form request targetsfile URIs with rootless paths without the // separatorfile URIs with empty paths as file: instead of the unparseable file://// paths with /.UriResolver::relativize() when an empty-path target requires oneUriResolver::relativize() when it would inherit the base fragmentUriResolver::relativize() when an equal-path target's last path segment contains a colonUri::fromParts() ports instead of casting themws and wss schemesws and wss default ports in UriComparator::isCrossOrigin() port comparisonsUtils::redactUserInfo()$_SERVER by REQUEST_METHOD, using target authority before SERVER_PORTREQUEST_URI targets in ServerRequest::fromGlobals()HTTP_HOST and malformed SERVER_PORT in ServerRequest::getUriFromGlobals()REQUEST_METHOD and SERVER_PROTOCOL server values in ServerRequest::fromGlobals()Host and normalize leading-zero ports in Message::parseRequest()Host headers and validate present values for all request-target formsMessage::parseRequest()Host header in Request::withUri() when the URI changes or Host is emptyHost headers synthesized by Message::toString()Message::toString() from the request URIHost headers set by Utils::modifyRequest() URI changesOPTIONS * and CONNECT authority-form request targets in Message::parseRequest()Request::withRequestTarget()Utils::streamFor()Query::build()Query::build() and MultipartStream contentsUtils::streamFor()Utils::streamFor() now rejects non-string scalar bodiesUri::withQueryValues() now rejects non-string valuesUtils::modifyRequest() change valuesUtils::copyToStream() to throw when destination streams cannot make progressTimeoutException from Stream read/write and Utils copy/hash/readLine on stream timeoutsTimeoutException from AppendStream::read(), CachingStream::read(), and Utils::tryGetContents() on stream timeoutsTimeoutException from InflateStream when the decoded source stream times outInflateStream::close()Utils::copyToStream()OverflowException when stream byte counts or offsets exceed PHP_INT_MAXStreamWrapper runtime failures to PHP stream failure valuesContent-Length to multipart/form-data parts (RFC 7578 §4.8)Content-Disposition parameters and reject unsafe boundaries and part headersMultipartStream part header valuesMultipartStream boundary '0' instead of replacing it with a generated boundarywithHost(), including userinfo formsUri construction, fromParts(), and withHost()UriComparator::isCrossOrigin()CAPITALIZE_PERCENT_ENCODING and DECODE_UNRESERVED_CHARACTERS to userinfo and hostHeader::splitList()Header::parse()ralouphie/getallheaders dependencyHeader::normalize() methodPrefix relative paths that begin with a colon segment with ./ instead of throwing
./ instead of throwingTrigger a runtime deprecation for previously deprecated functionality in 2.3.0
Utils:: asciiToLower, asciiToUpper, asciiUcFirst, caselessEquals, caselessContainsCompare header names and hosts with locale-independent ASCII lowercasing
Pass explicit trim characters ahead of the PHP 8.6 trim default change
// as paths in Message::parseRequest()Validate the URI host so getHost() matches the URI authority ( GHSA-c2w2-prh8-qm98 )
getHost() matches the URI authority (GHSA-c2w2-prh8-qm98)Report URI parsing, filtering, and normalization PCRE failures explicitly
Reject CR/LF in HTTP method, protocol version, and reason phrase ( GHSA-vm85-hxw5-5432 )
Deprecated non-finite float values in Query::build() that guzzlehttp/psr7 3.0 rejects
Query::build() that guzzlehttp/psr7 3.0 rejectsUtils::streamFor(); cast them to a string for 3.0Uri::withQueryValues() values; cast them to a string for 3.0Fixed non-finite float values emitting coercion warnings on PHP 8.5
Deprecated invalid PSR-7 arguments that guzzlehttp/psr7 3.0 will require native types for
Utils::modifyRequest() to reject conflicting URI and Host header changes in the same callHeader::parse() to split semicolon-separated parameters without repeated regular expression lookaheadsUriComparator::isCrossOrigin() so only HTTP and HTTPS missing ports receive implicit default portsUtils::modifyRequest() change values that guzzlehttp/psr7 3.0 will rejectUtils::copyToStream() to retry short destination writes instead of dropping the unwritten remainderHeader::parse() splitting of semicolon-separated parameters with escaped quotesApply UriNormalizer percent-encoding normalizations to URI fragments
UriNormalizer percent-encoding normalizations to URI fragmentsLimitStream::getSize() return 0 for slices past the underlying stream endAppendStream::read() return an empty string when no streams are attachedCachingStream::read() throw on an incomplete cache-target write instead of silently corrupting replaysCachingStream::seek() from looping indefinitely when the remote stream makes no progressFixed URI parsing for IPv6 literals containing embedded IPv4 addresses
Reject control and whitespace characters in URI host components (GHSA-hq7v-mx3g-29hw)
ServerRequest::fromGlobals() robust against unexpected HTTP header value types in $_SERVERFix Utils::modifyRequest() with numeric header names
Utils::modifyRequest() with numeric header namesHarden ServerRequest::fromGlobals() against malformed $_SERVER values
ServerRequest::fromGlobals() against malformed $_SERVER valuesStreamWrapper::getResource() cannot create a resourceUtils::modifyRequest()UriResolver::resolve()Uri::__toString() side-effect-freeFix parsing of relative path references containing a colon in a non-initial path segment
CachingStream::detach() returning an incomplete resource before the decorated stream has been fully readMessage::bodySummary() returning null when truncating printable UTF-8 bodies inside a multibyte characterAdded nested array expansion support to MultipartStream
MultipartStream@return static to MessageTrait methodsSee also the change log for changes.
Encode + signs in Uri::withQueryValue() and Uri::withQueryValues() to prevent them being interpreted as spaces
+ signs in Uri::withQueryValue() and Uri::withQueryValues() to prevent them being interpreted as spacesSee also the change log for changes.
Allow empty lists as header values
See also the change log for changes.
Fixed uppercase IPv6 addresses in URI
See also the change log for changes.
Add Utils::redactUserInfo() method
Utils::redactUserInfo() methodQuery::buildSee also the change log for changes.
Make StreamWrapper::stream_stat() return false if inner stream's size is null
StreamWrapper::stream_stat() return false if inner stream's size is nullSee also the change log for changes.
Fixed another issue with the fact that PHP transforms numeric strings in array keys to ints
call_user_func* with native callsSee also the change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
application/octet-stream if we are unable to guess the content type for a multipart file uploadSee change log for changes.
See change log for changes.
.acc files to audio/aacSee change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
ServerRequest::normalizeNestedFileSpecMessage::bodySummary when preg_match failsSee change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
UriComparator::isCrossOrigin methodSee change log for changes.
See change log for changes.
Header::splitList methodUtils::tryGetContents methodStream::getContents methodSee change log for changes.
See change log for changes.
Message::parseRequestUri for numeric headersfread into runtime exceptionsSee change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
uri metadatadata:// streamsHeader::normalize()See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
Uri object from a malformed URI will no longer throw a generic
InvalidArgumentException, but rather a MalformedUriException, which inherits from the former
for backwards compatibility. Callers relying on the exception being thrown to detect invalid
URIs should catch the new exception.null in caching stream size if remote size is nullSee change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
See change log for changes.
@final annotation to prepare for 2.0php://input and curl-ext is not installedUtils::tryFopen() on PHP 8See change log for changes.
See change log for changes.
Message:bodySummary()1.6.0 introduced a few type assertions to enforce types defined by PSR-7. Unfortunately that break the library for users not strictly following the PS
1.6.0 introduced a few type assertions to enforce types defined by PSR-7. Unfortunately that break the library for users not strictly following the PSR-7 standard. Since the users impacted by this change seems to be rather large, this hotfix reverts that change with the note that we will reapply it in 2.0.0, so fixing this is recommended regardless of which version you use.
Details are in #282 and #283
Version 1.6.0 is released which will likely be the last minor release in 1.x. We're focussing 2.0 now with support for psr/http-factory, PHP 7.2 requi
Version 1.6.0 is released which will likely be the last minor release in 1.x. We're focussing 2.0 now with support for psr/http-factory, PHP 7.2 requirement and type declarations.
^3.0 of ralouphie/getallheaders dependency (#244)php://input in ServerRequest (#247)userInfo component of an URI (#253)Check body size when getting the message summary
Get the summary of a body only if it is readable
Deprecated parsing folded header lines as per RFC 7230
After a really long waiting period, 1.5.0 is finally here with the following changes:
get_message_body_summary function in order to get the message summary3gp and mkv mime typesAppendStream::detach to not close streamsInflateStream preserves isSeekable attribute of the underlying streamServerRequest::getUriFromGlobals to support URLs in query parametersSeveral other fixes and improvements.
Your coding agent can read these notes before it upgrades. Set up the MCP server →