Recent Releases of https://github.com/savonrb/savon
https://github.com/savonrb/savon - v2.17.5
[2.17.5] - 2026-09-09
Security
Savon::Model.operationsand.all_operationsnow reject names that normalize to reserved model methods withArgumentError, before defining any methods. This prevents a WSDL operation namedclientfrom overwriting the client accessor and causing unbounded recursion. Call operations with reserved names explicitly throughmodel.client.call(:client, ...).
- Ruby
Published by pcai 26 days ago
https://github.com/savonrb/savon - v2.17.4
Restore WS-Addressing headers and fix :wsse_signature resolution
Fixed
- WS-Addressing headers are populated from the WSDL again (#1057). With
use_wsa_headers: trueand no explicit:soap_actionor:endpoint, Savon emitted empty<wsa:Action xsi:nil="true"/>and<wsa:To xsi:nil="true"/>elements instead of the operation's SOAPAction and service endpoint. Up to 2.16.0 those values were populated as a side effect of building the HTTP request. The 2.17.0 transport refactor removed that step. - A global
:hostoverride no longer rewrites the WSDL's endpoint. Resolving the request endpoint with:hostset replaced host and port of the parsed WSDL address in place, visible as a permanently changedclient.wsdl.endpointafter the first call. Endpoint and SOAPAction resolution moved intoSavon::EffectiveOptions, which applies the override to a copy and never touches the WSDL document. - A local
:wsse_signatureno longer crashes when set tofalse. Passingwsse_signature: falseto a call raisedNoMethodError: undefined method 'have_document?' for falsewhile building the WSSE header. The envelope builder and the SOAP header also resolved the option with different rules, so they could disagree on which signature applies. Both now read it throughSavon::EffectiveOptions, the one place that resolves options settable in both the global and the local scope. A falsy local:wsse_signaturefalls back to the global one. Setting a signature object in either scope is unaffected.
Deprecated
Savon::Builder::WSA_NAMESPACE. WS-Addressing emission moved intoSavon::Addressing, which owns the namespace asSavon::Addressing::NAMESPACE. The constant onSavon::Builderstays available as an alias and will be removed in Savon 3.
Changelog: https://github.com/savonrb/savon/blob/main/CHANGELOG.md
Commits: https://github.com/savonrb/savon/compare/v2.17.3...v2.17.4
- Ruby
Published by rubiii 3 months ago
https://github.com/savonrb/savon - v2.17.3
Fix Savon::HTTPError compatibility with Faraday transport
Fixed
Savon::HTTPErrorworks with the Faraday transport (#1050). When a the WSDL could not be fetched undertransport: :faraday,Savon::HTTPError#to_sand#to_hashraisedNoMethodError: undefined method 'code'because they were handed a rawFaraday::Response, which exposes#statusrather than#code. Transports now normalize adapter-specific response objects intoSavon::Transport::Responsebefore they reachSavon::HTTPError.
Changelog: https://github.com/savonrb/savon/blob/main/CHANGELOG.md
Commits: https://github.com/savonrb/savon/compare/v2.17.2...v2.17.3
- Ruby
Published by rubiii 3 months ago
https://github.com/savonrb/savon - v2.17.2
Fix CVE-2026-53510 and restore 2.17.0 cookie regressions
Fixed
- Fix CVE-2026-53510
Savon::Modelgenerated SOAP operation methods by interpolating operation names into Ruby source passed tomodule_eval. An attacker who can control the operation names of a WSDL, can inject Ruby code that executes in the application process. This affects only the.all_operationsclass method provided bySavon::Modelto automatically register all operations provided by the WSDL. ConfiguringSavon::Modelwith trusted operation names via.operationsis safe. Thanks to @connorshea for securely disclosing this, providing a proof and a great report. :cookiesrequest option works again. The 2.17.0 transport refactor reimplemented cookie handling on top ofArray#map, which broke callers passing an object that responds to#cookiesand lost cookie-name de-duplication viaHTTPI::CookieStore. The HTTPI transport delegates toHTTPI::Request#set_cookiesagain, restoring both shapes.response.http.cookiesworks again. 2.17.0'sSavon::Transport::Responseonly exposedcode,headers, andbody. The HTTPI transport now returnsArray<HTTPI::Cookie>(matching 2.12.1). The Faraday transport returnsHash<String, String>so Faraday callers do not need HTTPI types.:attachmentsnow works with a user-supplied:xmlenvelope (#761). Multipart support shipped in 2.13.0 but only wrapped envelopes Savon built itself. When a caller passed their own:xml, attachments were silently dropped.
Added
- Faraday
:cookiesoption accepts aStringorHash. Strings are used verbatim, Hashes are formatted as"name=value; name=value". Round-trippable with the Faraday response shape. - Three Nori response-parsing options exposed as Savon globals:
:empty_tag_value(defaultnil),:convert_dashes_to_underscores(defaulttrue), and:scrub_xml(defaulttrue). Defaults match Nori's own for backwards compatibility.
Changed
- Minimum Nori version is now
~> 2.7(was~> 2.4). Needed for the new parsing options (:empty_tag_valuearrived in Nori 2.6.0,:scrub_xmlin 2.7.0). The 2.5–2.7 series also brings fixes callers benefit from automatically: invalid byte sequences parse instead of raising, REXML no longer turns<inside CDATA into<,xs:date/xs:time/xs:dateTimetypecasting was corrected, and Nori stopped monkey-patchingStringandObject. - Faraday migration hints are now value-aware and verified. Each hint prints the caller's actual option value and spells out the full gem/require/setup where needed. Fixed several incorrect examples and added tests to verify every hint.
Deprecated
- Deprecated the global and local
:multipartoptions. They have been no-ops since v2.13.0. Specifically since commit 4e7ae5e. Savon detects multipart responses by checking theContent-Typeheader.
Security advisory: https://github.com/savonrb/savon/security/advisories/GHSA-mx5j-mp4f-g8jg
Changelog: https://github.com/savonrb/savon/blob/main/CHANGELOG.md
Commits: https://github.com/savonrb/savon/compare/v2.17.1...v2.17.2
- Ruby
Published by rubiii 4 months ago
https://github.com/savonrb/savon - v2.17.1
- Fix: https://github.com/savonrb/savon/pull/1008 - The HTTPI and Faraday transports no longer set an explicit Content-Length request header. The underlying HTTP library already computes it from the body; sending it as well produced a duplicate header on adapters that do not deduplicate (e.g. httpclient), which some servers reject.
- Fix: Requests using attachments were sent with a plain text/xml Content-Type instead of multipart/related. The 2.17.0 transport refactor assembled the request headers before the multipart body was built, leaving Builder#multipart empty at header time, so servers received a multipart body labelled as plain XML. 2.16.x and earlier are unaffected.
Changelog: https://github.com/savonrb/savon/blob/main/CHANGELOG.md
Commits: https://github.com/savonrb/savon/compare/v2.17.0...v2.17.1
- Ruby
Published by rubiii 5 months ago
https://github.com/savonrb/savon - v2.17.0
Add opt-in Faraday transport
Callers who set transport: :faraday get a memoized Faraday::Connection via client.faraday and full control over middleware, SSL, auth, and timeouts. Callers who do not set this option see no behavior change. HTTPI remains the default for 2.x.
- Add:
transport: :faradayglobal option. Defaults to:httpi(#992). - Add:
client.faradayreturns a memoizedFaraday::Connectionfor configuring middleware, SSL, auth, and timeouts when using the Faraday transport. - Add:
Savon.clientraises iftransport: :faradayis set but the faraday gem is not installed, or if any httpi-specific global option (proxy, timeouts,ssl, auth,adapter) is set alongside it. All conflicts are reported with their Faraday equivalents. - Change: Observers must return
Savon::Transport::Response(ornil) instead ofHTTPI::Response. ReturningHTTPI::Responsestill works but emits a deprecation warning. - Unblocks:
- redirect following for WSDL fetches via
faraday-follow-redirectsmiddleware (#1033, savonrb/wasabi#18) - digest authentication via
faraday-digestauthmiddleware (#1021, savonrb/httpi#250) - proxy authentication with special characters in passwords (#941)
- and setting an
Acceptheader for WSDL requests from Rails apps (savonrb/wasabi#115)
- redirect following for WSDL fetches via
Changelog: https://github.com/savonrb/savon/blob/v2.x/CHANGELOG.md
Commits: https://github.com/savonrb/savon/compare/v2.16.0...v2.17.0
- Ruby
Published by rubiii 5 months ago
https://github.com/savonrb/savon - v2.16.0
Restore compatibility
If you stayed on 2.12.1 because a later version broke something, this release is for you. The fixes below target the most commonly reported upgrade blockers. Existing code should work without modification.
- Fix: Restore
Savon::Response#hashremoved in 2.14.0 (#985). Callers on 2.12.1 that useresponse.hashget the soap body back instead of Ruby's integer object id. A deprecation warning is emitted on each call. Use#full_hashgoing forward. - Fix: Require wasabi >= 5.1.0 (#1015, #1016). Wasabi 4.x used message names as soap body element names and SOAPAction header values instead of operation names (savonrb/wasabi#122), causing servers to return a fault or reject the action for operations whose message name carried an
Insuffix. - Fix: Stop dumping all WSDL namespaces into every soap envelope (#1014, #942). 2.13.0 injected every namespace from the entire WSDL document into each request, including structural ones that have no place in a request body. Strict servers reject envelopes with unexpected or duplicate declarations.
- Fix: Raise a proper
SOAPFaultinstead of a raw exception whensoap:Faultcontains invalid encoding (#923). - Fix:
SOAPFault.present?was ignoring itsxmlargument and always operating on the instance's own body. - Change: Added Ruby 3.4 (#1024) and Ruby 4.0 (#1039) to the CI test matrix.
Changelog: https://github.com/savonrb/savon/blob/v2.x/CHANGELOG.md
Commits: https://github.com/savonrb/savon/compare/v2.15.1...v2.16.0
- Ruby
Published by rubiii 5 months ago
https://github.com/savonrb/savon - v3.0.0.rc2
What's Changed
- MTOM support with tests by @pcai in https://github.com/savonrb/savon/pull/1012
- Upgrade notes on ssl_verify_mode by @ehutzelman in https://github.com/savonrb/savon/pull/1013
- Pass the provided Savon/custom logger to Faraday by @larskanis in https://github.com/savonrb/savon/pull/1017
- Add ruby 3.4 to CI by @doconnor-clintel in https://github.com/savonrb/savon/pull/1024
- Restore support for SSL Ciphers by @doconnor-clintel in https://github.com/savonrb/savon/pull/1020
- Drop ruby 3.0 from CI by @doconnor-clintel in https://github.com/savonrb/savon/pull/1025
- Don't block minor updates to faraday by @larskanis in https://github.com/savonrb/savon/pull/1028
- Add gzip middleware when Accept-Encoding includes gzip by @kjeldahl in https://github.com/savonrb/savon/pull/1030
- Add option to provide connection middlewares. by @amartinfraguas in https://github.com/savonrb/savon/pull/1026
New Contributors
- @ehutzelman made their first contribution in https://github.com/savonrb/savon/pull/1013
- @doconnor-clintel made their first contribution in https://github.com/savonrb/savon/pull/1024
- @kjeldahl made their first contribution in https://github.com/savonrb/savon/pull/1030
- @amartinfraguas made their first contribution in https://github.com/savonrb/savon/pull/1026
Full Changelog: https://github.com/savonrb/savon/compare/v3.0.0.rc1...v3.0.0.rc2
- Ruby
Published by pcai about 1 year ago
https://github.com/savonrb/savon - v3.0.0.rc1
What's Changed
- HTTPI to Faraday by @LukeIGS in https://github.com/savonrb/savon/pull/998
Full Changelog: https://github.com/savonrb/savon/compare/v2.15.1...v3.0.0.rc1
- Ruby
Published by pcai about 2 years ago
https://github.com/savonrb/savon - v2.15.1
What's Changed
- Ruby 3.0+ is required in the gemspec.
- Require httpi 4.x - older versions rely on
Rack::Utils::HeaderHashwhich is removed in Rack 3.0.
Full Changelog: https://github.com/savonrb/savon/compare/v2.15.0...v2.15.1
- Ruby
Published by pcai about 2 years ago
https://github.com/savonrb/savon - v2.15.0
What's Changed
- Drop support for ruby 2.7 and below. Added Ruby 3.2 and 3.3 to test matrix.
- Allows wasabi v5.x, which now supports faraday
New Contributors
- @sarahsehr made their first contribution in https://github.com/savonrb/savon/pull/997
Full Changelog: https://github.com/savonrb/savon/compare/v2.14.0...v2.15.0
- Ruby
Published by pcai over 2 years ago
https://github.com/savonrb/savon - v2.14.0
- BC BREAKING Fix: https://github.com/savonrb/savon/pull/985 Renamed Savon::Response#hash to Savon::Response#full_hash
- BC BREAKING Fix: https://github.com/savonrb/savon/pull/988 Savon no longer monkeypatches String#snakecase
- Fix: https://github.com/savonrb/savon/pull/989 Do not include xmlns from WSDL, which breaks some servers
- Ruby
Published by pcai almost 4 years ago
https://github.com/savonrb/savon - v2.13.1
- Fix: #977 Prevent "xmlns:xmlns" namespace but allow "xmlns" namespace.
- Ruby
Published by pcai about 4 years ago
https://github.com/savonrb/savon - v2.13.0
- Drop support for ruby 2.6 and below. Added Ruby 3.0 and 3.1 to test matrix.
- Fix: #868 Remove
xmlns:wsa's already added elsewhere; select Content-Type HTTP header based on SOAP version. - Fix: #943 Read all namespaces from wsdl definition if document exists
- Feature: #920 Add a
write_timeoutsetter for HTTP requests - Feature: #930 Add options for SSL min_version/max_version support
- Feature: #931 Add
log_headersoption
- Ruby
Published by pcai about 4 years ago
https://github.com/savonrb/savon - v2.12.1
- Fix: #917 elementFormDefault="qualified" regression
- Fix: #875 Fix detecting Soap 1.1 Fault when faultcode and faultstring are empty
- Ruby
Published by pcai over 6 years ago
https://github.com/savonrb/savon - v2.12.0
- Drop support for ruby 2.1 and below.
- Fix: #822 Raise correct error when SOAP envelope only contains a string
- Fix: #833 Fixes boolean handling regression introduced in 2.11.2
- Feature: #794, add global option ssl_ciphers.
- Feature: #753 Add headers configuration to WSDLRequest#build
- Feature: #812 Allow
proxyoption to benil. - Feature: #838 Added ssl_ca_path and ssl_cert_store to globals
- Ruby
Published by pcai over 8 years ago
https://github.com/savonrb/savon - v2.11.2
- Fix: #676 Fixes handling of
content!andattributes! - Fix: #800 Fix exception calling
SOAPFault#to_swhen http.body is empty - Fix: #757 Logging: Use filter without automatic pretty printing
- Fix: #771 Restore support for cookies when using custom headers
- Feature: #744 Add support for rpc encoded wsdl
- Feature: #742 Add support for local request headers
- Feature: #704 Add possibility to pass attribute delete_namespace_attributes to Nori
- Ruby
Published by pcai about 9 years ago