NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #1269 most downloaded on Packagist
The sabre/http library provides utilities for dealing with http requests and responses.
Last release 4 months ago
31 May 2026
Release timing varies
gaps range from 9 days to 12 months
Nearly every release is documented
notes for 57 of 58 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
63 releases · first in 2012
This release drops support for PHP 7.4 8.0 and 8.1
This release drops support for PHP 7.4 8.0 and 8.1
This release continues to support PHP 7.4 and 8.0 through 8.5
This release continues to support PHP 7.4 and 8.0 through 8.5
One column per quarter.
7.0.5 (2025-09-09) #257 properly compute absolute URL ( @skjnldsv )
7.0.4 (2024-09-06) #227 Remove redundant PHP doc to make cs-fixer pass ( @phil-davis ) #229 ci: Create dependabot.yml ( @DeepDiver1975 ) #231 Add PHP
* #215 Improve CURLOPT_HTTPHEADER Setting Assignment (@amrita-shrestha)
* #203 Add phpstan phpunit strict-rules (@phil-davis)
* #207 fix: handle client disconnect properly with ignore_user_abort true (@kesselb)
* #198 Allow sabre/uri major version 3 ( @phil-davis )
6.0.5 (2026-04-27) #267 chore (ci): add CI for PHP 8.5 on 6.0 branch ( @phil-davis ) #274 test: adjust code style ( @phil-davis ) #275 fix(http/client
6.0.4 (2025-09-09) #260 properly compute absolute URL ( @skjnldsv )
6.0.3 (2024-09-06) #228 Remove redundant PHP doc to make cs-fixer pass ( @phil-davis ) #236 adjust for php-cs-fixer 3.54.0 ( @phil-davis ) #249 add PH
* #215 Improve CURLOPT_HTTPHEADER Setting Assignment (@amrita-shrestha)
* #207 fix: handle client disconnect properly with ignore_user_abort true (@kesselb)
* #191 Create .gitattributes (@cedric-anne) * #176 Test enhancement (from original PR #98) (@peter279k) * #192 Set min PHP to 7.4 and add type declara
5.1.13 (2025-09-09) #262 properly compute absolute URL ( @skjnldsv )
This release just has code-style changes applied by php-cs-fixer major version 3. No change to behavior.
This release just has code-style changes applied by php-cs-fixer major version 3.
No change to behavior.
5.1.11 (2024-07-26) #241 PHP 8.4 compliance ( @phil-davis )
* #225 Enhance tests/bootstrap.php to find autoloader in more environments (@phil-davis)
* #223 skip testParseMimeTypeOnInvalidMimeType (@phil-davis)
* #215 Improve CURLOPT_HTTPHEADER Setting Assignment (@amrita-shrestha)
* #98 and #176 Add more tests (@peter279k) * #207 fix: handle client disconnect properly with ignore_user_abort true (@kesselb)
* #187 Allow testSendToGetLargeContent peak memory usage to be specified externally (@phil-davis) * #188 Fix various small typos and grammar (@phil-da
* #184 Remove 4GB file size workaround for 32bit OS / Stream Videos on IOS (@schoetju)
* #182 Fix encoding detection on PHP 8.1 (@come-nc)
* #179 version bump that was missed in 5.1.2 (@phil-davis)
* #169 Ensure $_SERVER keys are read as strings (@fredrik-eriksson) * #170 Fix deprecated usages on PHP 8.1 (@cedric-anne) * #175 Add resource size to
* #160: Added support for PHP 8.0 (@phil-davis)
Added support for PHP 7.4, dropped support for PHP 7.0 (@phil-davis)
* #138: Fixed possible infinite loop (@dpakach, @vfreex, @phil-davis) * #136: Improvement regex content-range (@ho4ho)
* #133: Fix short Content-Range download - Regression from 5.0.3 (@phil-davis)
* #119: Significantly improve file download speed by enabling mmap based stream_copy_to_stream (@vfreex)
* #125: Fix Strict Error if Response Body Empty (@WorksDev, @phil-davis)
* #121: fix "Trying to access array offset on value of type bool" in 7.4 (@remicollet) * #115: Reduce memory footprint when parsing HTTP result (@Gaso
* #99: Previous CURL opts are not persisted anymore (@christiaan) * Final release
Removed URLUtil class. It was deprecated a long time ago, and most of its functions moved to the sabre/uri package.
URLUtil class. It was deprecated a long time ago, and most of
its functions moved to the sabre/uri package.Util class. Most of its functions moved to the functions.php
file.$method and $uri arguments when constructing a Request object
are now required.Sapi::getRequest() is called, we default to setting the HTTP Method
to CLI.500 instead of null,
so if it's not changed, it will be emitted as 500.charset="UTF-8" on Basic authentication challenges per
[rfc7617][rfc7617].SERVER_PROTOCOL HTTP/2.0 (@jens1o)Nothing published for this version
* #74, #77: Work around 4GB file size limit at 32-Bit systems
* #72: Handling clients that send invalid Content-Length headers.
Content-Length headers.The client now sets a default User-Agent header identifying this library.
getBodyAsString now returns at most as many bytes as the contents of
the Content-Length header. This allows users to pass much larger strings
without having to copy and truncate them.User-Agent header identifying this library.This package now supports sabre/event 3.0.
The async client wouldn't wait() for new http requests being started after the (previous) last request in the queue was resolved.
wait() for new http requests being started
after the (previous) last request in the queue was resolved.Sabre\HTTP\Auth\Bearer, to easily extract a OAuth2 bearer token.Deprecated: All static functions from Sabre\HTTP\URLUtil and Sabre\HTTP\Util moved to a separate functions.php, which is also autoloaded. The old func…
Sabre\HTTP\URLUtil and
Sabre\HTTP\Util moved to a separate functions.php, which is also
autoloaded. The old functions are still there, but will be removed in a
future version. (#49)Deprecated Sabre\HTTP\Util::parseHTTPDate, use Sabre\HTTP\parseDate().
Prefer header, as defined in [RFC7240][rfc7240].Sabre\HTTP\Util::parseHTTPDate, use Sabre\HTTP\parseDate().Sabre\HTTP\Util::toHTTPDate use Sabre\HTTP\toDate().This includes fixes released in version 3.0.5.
getCredentials returns null if incomplete. (@Hywan)Added 421 Misdirected Request from the HTTP/2.0 spec.
Request::getPath().sabre/uri package for uri handling.421 Misdirected Request from the HTTP/2.0 spec.* #47 #35: When re-using the client and doing any request after a HEAD request, the client discards the body.
HEAD
request, the client discards the body.* #38: The Authentication helpers no longer overwrite any existing WWW-Authenticate headers, but instead append new headers. This ensures that multipl
WWW-Authenticate headers, but instead append new headers. This ensures
that multiple authentication systems can exist in the same environment.Hiding Authorization header value from Request::__toString.
Authorization header value from Request::__toString.When parsing Accept: headers, we're ignoring invalid parts. Before we would throw a PHP E_NOTICE.
Accept: headers, we're ignoring invalid parts. Before we
would throw a PHP E_NOTICE.* Minor change in unittests.
getHeaders() now returns header values as an array, just like psr/http.
getHeaders() now returns header values as an array, just like psr/http.hasHeader().Changed: Util::negotiate() is now deprecated. Use Util::negotiateContentType() instead.
setHeaders() does not wipe out every existing header
anymore.Request::getHeaderAsArray() and Response::getHeaderAsArray() to
get a hold off multiple headers with the same name.getHeader(), and there's more than 1 header with that name, we
concatenate all these with a comma.addHeader() will now preserve an existing header with that name, and add a
second header with the same name.URLUtil::resolve() to make resolving relative urls super easy.Util::negotiate() is now deprecated. Use
Util::negotiateContentType() instead.Changed: No longer escaping @ in urls when it's not needed.
Fixed: Now throwing an error when a Request object is being created with arguments that were valid for sabre/http 1.0. Hopefully this will aid with de
Fixed: Potential security problem in the client.
Fixed: getBodyAsString on an empty body now works.
Removed: Request::createFromPHPRequest. This is now handled by Sapi::getRequest.
Added: Asynchronous HTTP client. See examples/asyncclient.php.
__toString() method that
serializes the objects into a standard HTTP message. This is mainly for
debugging purposes.Added: HTTP Status 451 Unavailable For Legal Reasons. Fight government censorship!
Fixed: Doing a GET request with the client uses the last used HTTP method instead.
Your coding agent can read these notes before it upgrades. Set up the MCP server →