sabre/http
The sabre/http library provides utilities for dealing with http requests and responses.
7.1.0
16M downloads/mo
#1149 most downloaded on Packagist
sabre-io/http
What this package is like to depend on
Last release 2 months ago
31 May 2026
Release timing varies
gaps range from 9 days to 12 months
Nearly every release is documented
notes for 57 of 58 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
63 releases · first in 2012
6 releases in the last 12 months
see the full history below
Release timeline
63 releases · Oct 2012 to May 2026Releases
latest 60 of 63-
7.1.031 May 2026Release notes
Open source →7.1.0 (2026-05-31)
- #280 chore: support PHP 8.2 and up ( @phil-davis )
- #282 test: migrate to phpunit 11 ( @phil-davis )
This release drops support for PHP 7.4 8.0 and 8.1
Release notes
Open source →- #280 chore: support PHP 8.2 and up ( @phil-davis )
- #282 test: migrate to phpunit 11 ( @phil-davis )
-
7.0.627 Apr 2026Release notes
Open source →7.0.6 (2026-04-27)
- #259 chore (ci): add CI for PHP 8.5 on 6.0 branch ( @phil-davis )
- #273 test: adjust code style ( @phil-davis )
- #272 fix(http/client): prefer CURLOPT_PROTOCOLS_STR over deprecated bitmask constants ( @ralflang )
- #255 chore: update to phpstan major version 2
- #278 chore: add rector ( @phil-davis )
This release continues to support PHP 7.4 and 8.0 through 8.5
Release notes
Open source →- #259 chore (ci): add CI for PHP 8.5 on 6.0 branch ( @phil-davis )
- #273 test: adjust code style ( @phil-davis )
- #272 fix(http/client): prefer CURLOPT_PROTOCOLS_STR over deprecated bitmask constants ( @ralflang )
- #255 chore: update to phpstan major version 2
- #278 chore: add rector ( @phil-davis )
-
7.0.509 Sep 2025 -
7.0.406 Sep 2024Release notes
Open source →7.0.4 (2024-09-06)
- #227 Remove redundant PHP doc to make cs-fixer pass ( @phil-davis )
- #229 ci: Create dependabot.yml ( @DeepDiver1975 )
- #231 Add PHP 8.3 to CI ( @phil-davis )
- #234 use php-cs-fixer 3.51 ( @phil-davis )
- #235 adjust for php-cs-fixer 3.54.0 ( @phil-davis )
- #237 stop exporting php-cs-fixer config ( @phil-davis )
- #247 tool changes - add PHP 8.4 to CI ( @phil-davis )
Release notes
Open source →- #227 Remove redundant PHP doc to make cs-fixer pass ( @phil-davis )
- #229 ci: Create dependabot.yml ( @DeepDiver1975 )
- #231 Add PHP 8.3 to CI ( @phil-davis )
- #234 use php-cs-fixer 3.51 ( @phil-davis )
- #235 adjust for php-cs-fixer 3.54.0 ( @phil-davis )
- #237 stop exporting php-cs-fixer config ( @phil-davis )
- #247 tool changes - add PHP 8.4 to CI ( @phil-davis )
-
7.0.317 Aug 2023 -
7.0.227 Jun 2023 -
7.0.126 Jun 2023Release notes
Open source →- #207 fix: handle client disconnect properly with ignore_user_abort true (@kesselb)
-
7.0.026 Sep 2022 -
6.0.527 Apr 2026Release notes
Open source →6.0.5 (2026-04-27)
- #267 chore (ci): add CI for PHP 8.5 on 6.0 branch (@phil-davis)
- #274 test: adjust code style (@phil-davis)
- #275 fix(http/client): prefer CURLOPT_PROTOCOLS_STR over deprecated bitmask constants (@ralflang)
Release notes
Open source →- #267 chore (ci): add CI for PHP 8.5 on 6.0 branch (@phil-davis)
- #274 test: adjust code style (@phil-davis)
- #275 fix(http/client): prefer CURLOPT_PROTOCOLS_STR over deprecated bitmask constants (@ralflang)
-
6.0.409 Sep 2025 -
6.0.306 Sep 2024Release notes
Open source →6.0.3 (2024-09-06)
- #228 Remove redundant PHP doc to make cs-fixer pass ( @phil-davis )
- #236 adjust for php-cs-fixer 3.54.0 ( @phil-davis )
- #249 add PHP 8.3 and 8.4 to CI of 6.0 branch ( @phil-davis )
Release notes
Open source →- #228 Remove redundant PHP doc to make cs-fixer pass ( @phil-davis )
- #236 adjust for php-cs-fixer 3.54.0 ( @phil-davis )
- #249 add PHP 8.3 and 8.4 to CI of 6.0 branch ( @phil-davis )
-
6.0.217 Aug 2023 -
6.0.126 Jun 2023Release notes
Open source →- #207 fix: handle client disconnect properly with ignore_user_abort true (@kesselb)
-
6.0.031 Aug 2022Release notes
Open source →- #191 Create .gitattributes (@cedric-anne)
- #176 Test enhancement (from original PR #98) (@peter279k)
- #192 Set min PHP to 7.4 and add type declarations (@phil-davis)
- #194 Adjust type declarations a little bit (@phil-davis)
-
5.1.1309 Sep 2025 -
5.1.1227 Aug 2024Release notes
Open source →5.1.12 (2024-08-27)
- #243 add cs-fixer v3 (@phil-davis)
This release just has code-style changes applied by php-cs-fixer major version 3.
No change to behavior. -
5.1.1126 Jul 2024 -
5.1.1018 Aug 2023Release notes
Open source →- #225 Enhance tests/bootstrap.php to find autoloader in more environments (@phil-davis)
-
5.1.917 Aug 2023 -
5.1.817 Aug 2023 -
5.1.726 Jun 2023Release notes
Open source →- #98 and #176 Add more tests (@peter279k)
- #207 fix: handle client disconnect properly with ignore_user_abort true (@kesselb)
-
5.1.615 Jul 2022Release notes
Open source →- #187 Allow testSendToGetLargeContent peak memory usage to be specified externally (@phil-davis)
- #188 Fix various small typos and grammar (@phil-davis)
- #189 Fix typo in text of status code 203 'Non-Authoritative Information' (@phil-davis)
-
5.1.509 Jul 2022Release notes
Open source →- #184 Remove 4GB file size workaround for 32bit OS / Stream Videos on IOS (@schoetju)
-
5.1.424 Jun 2022 -
5.1.304 Nov 2021 -
5.1.203 Nov 2021Release notes
Open source →- #169 Ensure $_SERVER keys are read as strings (@fredrik-eriksson)
- #170 Fix deprecated usages on PHP 8.1 (@cedric-anne)
- #175 Add resource size to CURL options in client (from #172 ) (@Dartui)
-
5.1.103 Oct 2020 -
5.1.031 Jan 2020Release notes
Open source →- Added support for PHP 7.4, dropped support for PHP 7.0 (@phil-davis)
- Updated testsuite for phpunit8, added phpstan coverage (@phil-davis)
- Added autoload-dev for test classes (@C0pyR1ght)
-
5.0.528 Nov 2019Release notes
Open source →- #138: Fixed possible infinite loop (@dpakach, @vfreex, @phil-davis)
- #136: Improvement regex content-range (@ho4ho)
-
5.0.409 Oct 2019Release notes
Open source →- #133: Fix short Content-Range download - Regression from 5.0.3 (@phil-davis)
-
5.0.308 Oct 2019Release notes
Open source →- #119: Significantly improve file download speed by enabling mmap based stream_copy_to_stream (@vfreex)
-
5.0.212 Sep 2019 -
5.0.111 Sep 2019Release notes
Open source →- #121: fix "Trying to access array offset on value of type bool" in 7.4 (@remicollet)
- #115: Reduce memory footprint when parsing HTTP result (@Gasol)
- #114: Misc code improvements (@mrcnpdlk)
- #111, #118: Added phpstan analysis (@DeepDiver1975, @staabm)
- #107: Tested with php 7.3 (@DeepDiver1975)
-
5.0.004 Jun 2018Release notes
Open source →- #99: Previous CURL opts are not persisted anymore (@christiaan)
- Final release
-
5.0.0-alpha116 Feb 2018 pre-releaseRelease notes
Open source →- Now requires PHP 7.0+.
- Supports sabre/event 4.x and 5.x
- Depends on sabre/uri 2.
- hhvm is no longer supported starting this release.
- #65: It's now possible to supply request/response bodies using a callback functions. This allows very high-speed/low-memory responses to be created. (@petrkotek).
- Strict typing is used everywhere this is applicable.
- Removed
URLUtilclass. It was deprecated a long time ago, and most of its functions moved to thesabre/uripackage. - Removed
Utilclass. Most of its functions moved to thefunctions.phpfile. - #68: The
$methodand$uriarguments when constructing a Request object are now required. - When
Sapi::getRequest()is called, we default to setting the HTTP Method toCLI. - The HTTP response is now initialized with HTTP code
500instead ofnull, so if it's not changed, it will be emitted as 500. - #69: Sending
charset="UTF-8"on Basic authentication challenges per [rfc7617][rfc7617]. - #84: Added support for
SERVER_PROTOCOL HTTP/2.0(@jens1o)
-
v4.2.423 Feb 2018Nothing published for this version
-
4.2.312 Jun 2017 -
4.2.202 Jan 2017 -
4.2.106 Jan 2016Release notes
Open source →- #56:
getBodyAsStringnow returns at most as many bytes as the contents of theContent-Lengthheader. This allows users to pass much larger strings without having to copy and truncate them. - The client now sets a default
User-Agentheader identifying this library.
- #56:
-
4.2.004 Jan 2016 -
4.1.004 Sep 2015Release notes
Open source →- The async client wouldn't
wait()for new http requests being started after the (previous) last request in the queue was resolved. - Added
Sabre\HTTP\Auth\Bearer, to easily extract a OAuth2 bearer token.
- The async client wouldn't
-
4.0.020 May 2015Release notes
Open source →- Deprecated: All static functions from
Sabre\HTTP\URLUtilandSabre\HTTP\Utilmoved to a separatefunctions.php, which is also autoloaded. The old functions are still there, but will be removed in a future version. (#49)
- Deprecated: All static functions from
-
4.0.0-alpha319 May 2015 pre-releaseRelease notes
Open source →- Added a parser for the HTTP
Preferheader, as defined in [RFC7240][rfc7240]. - Deprecated
Sabre\HTTP\Util::parseHTTPDate, useSabre\HTTP\parseDate(). - Deprecated
Sabre\HTTP\Util::toHTTPDateuseSabre\HTTP\toDate().
- Added a parser for the HTTP
-
4.0.0-alpha218 May 2015 pre-releaseRelease notes
Open source →- #45: Don't send more data than what is promised in the HTTP content-length. (@dratini0).
- #43:
getCredentialsreturns null if incomplete. (@Hywan) - #48: Now using php-cs-fixer to make our CS consistent (yay!)
- This includes fixes released in version 3.0.5.
-
4.0.0-alpha125 Feb 2015 pre-releaseRelease notes
Open source →- #41: Fixing bugs related to comparing URLs in
Request::getPath(). - #41: This library now uses the
sabre/uripackage for uri handling. - Added
421 Misdirected Requestfrom the HTTP/2.0 spec.
- #41: Fixing bugs related to comparing URLs in
-
3.0.511 May 2015Release notes
Open source →- #47 #35: When re-using the client and doing any request after a
HEADrequest, the client discards the body.
- #47 #35: When re-using the client and doing any request after a
-
3.0.410 Dec 2014Release notes
Open source →- #38: The Authentication helpers no longer overwrite any existing
WWW-Authenticateheaders, but instead append new headers. This ensures that multiple authentication systems can exist in the same environment.
- #38: The Authentication helpers no longer overwrite any existing
-
3.0.303 Dec 2014 -
3.0.210 Oct 2014Release notes
Open source →- When parsing
Accept:headers, we're ignoring invalid parts. Before we would throw a PHP E_NOTICE.
- When parsing
-
3.0.129 Sep 2014 -
3.0.023 Sep 2014Release notes
Open source →getHeaders()now returns header values as an array, just like psr/http.- Added
hasHeader().
-
2.1.0-alpha115 Sep 2014 pre-releaseRelease notes
Open source →- Changed: Copied most of the header-semantics for the PSR draft for representing HTTP messages. [Reference here][psr-http].
- This means that
setHeaders()does not wipe out every existing header anymore. - We also support multiple headers with the same name.
- Use
Request::getHeaderAsArray()andResponse::getHeaderAsArray()to get a hold off multiple headers with the same name. - If you use
getHeader(), and there's more than 1 header with that name, we concatenate all these with a comma. addHeader()will now preserve an existing header with that name, and add a second header with the same name.- The message class should be a lot faster now for looking up headers. No more array traversal, because we maintain a tiny index.
- Added:
URLUtil::resolve()to make resolving relative urls super easy. - Switched to PSR-4.
- #12: Circumventing CURL's FOLLOW_LOCATION and doing it in PHP instead. This fixes compatibility issues with people that have open_basedir turned on.
- Added: Content negotiation now correctly support mime-type parameters such as charset.
- Changed:
Util::negotiate()is now deprecated. UseUtil::negotiateContentType()instead. - #14: The client now only follows http and https urls.
-
2.0.414 Jul 2014Release notes
Open source →- Changed: No longer escaping @ in urls when it's not needed.
- Fixed: #7: Client now correctly deals with responses without a body.
-
2.0.317 Apr 2014Release notes
Open source →- Now works on hhvm!
- Fixed: Now throwing an error when a Request object is being created with arguments that were valid for sabre/http 1.0. Hopefully this will aid with debugging for upgraders.
-
2.0.209 Feb 2014 -
2.0.109 Jan 2014Release notes
Open source →- Fixed: getBodyAsString on an empty body now works.
- Fixed: Version string
-
2.0.008 Jan 2014Release notes
Open source →- Removed: Request::createFromPHPRequest. This is now handled by Sapi::getRequest.
-
2.0.0alpha602 Jan 2014Release notes
Open source →- Added: Asynchronous HTTP client. See examples/asyncclient.php.
- Fixed: Issue #4: Don't escape colon (:) when it's not needed.
- Fixed: Fixed a bug in the content negotiation script.
- Fixed: Fallback for when CURLOPT_POSTREDIR is not defined (mainly for hhvm).
- Added: The Request and Response object now have a
__toString()method that serializes the objects into a standard HTTP message. This is mainly for debugging purposes. - Changed: Added Response::getStatusText(). This method returns the human-readable HTTP status message. This part has been removed from Response::getStatus(), which now always returns just the status code as an int.
- Changed: Response::send() is now Sapi::sendResponse($response).
- Changed: Request::createFromPHPRequest is now Sapi::getRequest().
- Changed: Message::getBodyAsStream and Message::getBodyAsString were added. The existing Message::getBody changed its behavior, so be careful.
-
2.0.0alpha507 Nov 2013Release notes
Open source →- Added: HTTP Status 451 Unavailable For Legal Reasons. Fight government censorship!
- Added: Ability to catch and retry http requests in the client when a curl error occurs.
- Changed: Request::getPath does not return the query part of the url, so everything after the ? is stripped.
- Added: a reverse proxy example.
-
2.0.0alpha407 Aug 2013Release notes
Open source →- Fixed: Doing a GET request with the client uses the last used HTTP method instead.
- Added: HttpException
- Added: The Client class can now automatically emit exceptions when HTTP errors occurred.