A summary of data about the Ruby ecosystem.

Recent Releases of https://github.com/savonrb/savon

https://github.com/savonrb/savon - v2.17.5

[2.17.5] - 2026-09-09

Security

  • Savon::Model.operations and .all_operations now reject names that normalize to reserved model methods with ArgumentError, before defining any methods. This prevents a WSDL operation named client from overwriting the client accessor and causing unbounded recursion. Call operations with reserved names explicitly through model.client.call(:client, ...).

- Ruby
Published by pcai 26 days ago

https://github.com/savonrb/savon - v2.17.4

Restore WS-Addressing headers and fix :wsse_signature resolution

Fixed

  • WS-Addressing headers are populated from the WSDL again (#1057). With use_wsa_headers: true and no explicit :soap_action or :endpoint, Savon emitted empty <wsa:Action xsi:nil="true"/> and <wsa:To xsi:nil="true"/> elements instead of the operation's SOAPAction and service endpoint. Up to 2.16.0 those values were populated as a side effect of building the HTTP request. The 2.17.0 transport refactor removed that step.
  • A global :host override no longer rewrites the WSDL's endpoint. Resolving the request endpoint with :host set replaced host and port of the parsed WSDL address in place, visible as a permanently changed client.wsdl.endpoint after the first call. Endpoint and SOAPAction resolution moved into Savon::EffectiveOptions, which applies the override to a copy and never touches the WSDL document.
  • A local :wsse_signature no longer crashes when set to false. Passing wsse_signature: false to a call raised NoMethodError: undefined method 'have_document?' for false while building the WSSE header. The envelope builder and the SOAP header also resolved the option with different rules, so they could disagree on which signature applies. Both now read it through Savon::EffectiveOptions, the one place that resolves options settable in both the global and the local scope. A falsy local :wsse_signature falls back to the global one. Setting a signature object in either scope is unaffected.

Deprecated

  • Savon::Builder::WSA_NAMESPACE. WS-Addressing emission moved into Savon::Addressing, which owns the namespace as Savon::Addressing::NAMESPACE. The constant on Savon::Builder stays available as an alias and will be removed in Savon 3.

Changelog: https://github.com/savonrb/savon/blob/main/CHANGELOG.md
Commits: https://github.com/savonrb/savon/compare/v2.17.3...v2.17.4

- Ruby
Published by rubiii 3 months ago

https://github.com/savonrb/savon - v2.17.3

Fix Savon::HTTPError compatibility with Faraday transport

Fixed

  • Savon::HTTPError works with the Faraday transport (#1050). When a the WSDL could not be fetched under transport: :faraday, Savon::HTTPError#to_s and #to_hash raised NoMethodError: undefined method 'code' because they were handed a raw Faraday::Response, which exposes #status rather than #code. Transports now normalize adapter-specific response objects into Savon::Transport::Response before they reach Savon::HTTPError.

Changelog: https://github.com/savonrb/savon/blob/main/CHANGELOG.md
Commits: https://github.com/savonrb/savon/compare/v2.17.2...v2.17.3

- Ruby
Published by rubiii 3 months ago

https://github.com/savonrb/savon - v2.17.2

Fix CVE-2026-53510 and restore 2.17.0 cookie regressions

Fixed

  • Fix CVE-2026-53510 Savon::Model generated SOAP operation methods by interpolating operation names into Ruby source passed to module_eval. An attacker who can control the operation names of a WSDL, can inject Ruby code that executes in the application process. This affects only the .all_operations class method provided by Savon::Model to automatically register all operations provided by the WSDL. Configuring Savon::Model with trusted operation names via .operations is safe. Thanks to @connorshea for securely disclosing this, providing a proof and a great report.
  • :cookies request option works again. The 2.17.0 transport refactor reimplemented cookie handling on top of Array#map, which broke callers passing an object that responds to #cookies and lost cookie-name de-duplication via HTTPI::CookieStore. The HTTPI transport delegates to HTTPI::Request#set_cookies again, restoring both shapes.
  • response.http.cookies works again. 2.17.0's Savon::Transport::Response only exposed code, headers, and body. The HTTPI transport now returns Array<HTTPI::Cookie> (matching 2.12.1). The Faraday transport returns Hash<String, String> so Faraday callers do not need HTTPI types.
  • :attachments now works with a user-supplied :xml envelope (#761). Multipart support shipped in 2.13.0 but only wrapped envelopes Savon built itself. When a caller passed their own :xml, attachments were silently dropped.

Added

  • Faraday :cookies option accepts a String or Hash. Strings are used verbatim, Hashes are formatted as "name=value; name=value". Round-trippable with the Faraday response shape.
  • Three Nori response-parsing options exposed as Savon globals: :empty_tag_value (default nil), :convert_dashes_to_underscores (default true), and :scrub_xml (default true). Defaults match Nori's own for backwards compatibility.

Changed

  • Minimum Nori version is now ~> 2.7 (was ~> 2.4). Needed for the new parsing options (:empty_tag_value arrived in Nori 2.6.0, :scrub_xml in 2.7.0). The 2.5–2.7 series also brings fixes callers benefit from automatically: invalid byte sequences parse instead of raising, REXML no longer turns &lt; inside CDATA into <, xs:date/xs:time/xs:dateTime typecasting was corrected, and Nori stopped monkey-patching String and Object.
  • Faraday migration hints are now value-aware and verified. Each hint prints the caller's actual option value and spells out the full gem/require/setup where needed. Fixed several incorrect examples and added tests to verify every hint.

Deprecated

  • Deprecated the global and local :multipart options. They have been no-ops since v2.13.0. Specifically since commit 4e7ae5e. Savon detects multipart responses by checking the Content-Type header.

Security advisory: https://github.com/savonrb/savon/security/advisories/GHSA-mx5j-mp4f-g8jg
Changelog: https://github.com/savonrb/savon/blob/main/CHANGELOG.md
Commits: https://github.com/savonrb/savon/compare/v2.17.1...v2.17.2

- Ruby
Published by rubiii 4 months ago

https://github.com/savonrb/savon - v2.17.1

  • Fix: https://github.com/savonrb/savon/pull/1008 - The HTTPI and Faraday transports no longer set an explicit Content-Length request header. The underlying HTTP library already computes it from the body; sending it as well produced a duplicate header on adapters that do not deduplicate (e.g. httpclient), which some servers reject.
  • Fix: Requests using attachments were sent with a plain text/xml Content-Type instead of multipart/related. The 2.17.0 transport refactor assembled the request headers before the multipart body was built, leaving Builder#multipart empty at header time, so servers received a multipart body labelled as plain XML. 2.16.x and earlier are unaffected.

Changelog: https://github.com/savonrb/savon/blob/main/CHANGELOG.md
Commits: https://github.com/savonrb/savon/compare/v2.17.0...v2.17.1

- Ruby
Published by rubiii 5 months ago

https://github.com/savonrb/savon - v2.17.0

Add opt-in Faraday transport

Callers who set transport: :faraday get a memoized Faraday::Connection via client.faraday and full control over middleware, SSL, auth, and timeouts. Callers who do not set this option see no behavior change. HTTPI remains the default for 2.x.

  • Add: transport: :faraday global option. Defaults to :httpi (#992).
  • Add: client.faraday returns a memoized Faraday::Connection for configuring middleware, SSL, auth, and timeouts when using the Faraday transport.
  • Add: Savon.client raises if transport: :faraday is set but the faraday gem is not installed, or if any httpi-specific global option (proxy, timeouts, ssl, auth, adapter) is set alongside it. All conflicts are reported with their Faraday equivalents.
  • Change: Observers must return Savon::Transport::Response (or nil) instead of HTTPI::Response. Returning HTTPI::Response still works but emits a deprecation warning.
  • Unblocks:
    • redirect following for WSDL fetches via faraday-follow-redirects middleware (#1033, savonrb/wasabi#18)
    • digest authentication via faraday-digestauth middleware (#1021, savonrb/httpi#250)
    • proxy authentication with special characters in passwords (#941)
    • and setting an Accept header for WSDL requests from Rails apps (savonrb/wasabi#115)

Changelog: https://github.com/savonrb/savon/blob/v2.x/CHANGELOG.md
Commits: https://github.com/savonrb/savon/compare/v2.16.0...v2.17.0

- Ruby
Published by rubiii 5 months ago

https://github.com/savonrb/savon - v2.16.0

Restore compatibility

If you stayed on 2.12.1 because a later version broke something, this release is for you. The fixes below target the most commonly reported upgrade blockers. Existing code should work without modification.

  • Fix: Restore Savon::Response#hash removed in 2.14.0 (#985). Callers on 2.12.1 that use response.hash get the soap body back instead of Ruby's integer object id. A deprecation warning is emitted on each call. Use #full_hash going forward.
  • Fix: Require wasabi >= 5.1.0 (#1015, #1016). Wasabi 4.x used message names as soap body element names and SOAPAction header values instead of operation names (savonrb/wasabi#122), causing servers to return a fault or reject the action for operations whose message name carried an In suffix.
  • Fix: Stop dumping all WSDL namespaces into every soap envelope (#1014, #942). 2.13.0 injected every namespace from the entire WSDL document into each request, including structural ones that have no place in a request body. Strict servers reject envelopes with unexpected or duplicate declarations.
  • Fix: Raise a proper SOAPFault instead of a raw exception when soap:Fault contains invalid encoding (#923).
  • Fix: SOAPFault.present? was ignoring its xml argument and always operating on the instance's own body.
  • Change: Added Ruby 3.4 (#1024) and Ruby 4.0 (#1039) to the CI test matrix.

Changelog: https://github.com/savonrb/savon/blob/v2.x/CHANGELOG.md
Commits: https://github.com/savonrb/savon/compare/v2.15.1...v2.16.0

- Ruby
Published by rubiii 5 months ago

https://github.com/savonrb/savon - v3.0.0.rc2

What's Changed

New Contributors

Full Changelog: https://github.com/savonrb/savon/compare/v3.0.0.rc1...v3.0.0.rc2

- Ruby
Published by pcai about 1 year ago

https://github.com/savonrb/savon - v3.0.0.rc1

What's Changed

Full Changelog: https://github.com/savonrb/savon/compare/v2.15.1...v3.0.0.rc1

- Ruby
Published by pcai about 2 years ago

https://github.com/savonrb/savon - v2.15.1

What's Changed

  • Ruby 3.0+ is required in the gemspec.
  • Require httpi 4.x - older versions rely on Rack::Utils::HeaderHash which is removed in Rack 3.0.

Full Changelog: https://github.com/savonrb/savon/compare/v2.15.0...v2.15.1

- Ruby
Published by pcai about 2 years ago

https://github.com/savonrb/savon - v2.15.0

What's Changed

  • Drop support for ruby 2.7 and below. Added Ruby 3.2 and 3.3 to test matrix.
  • Allows wasabi v5.x, which now supports faraday

New Contributors

Full Changelog: https://github.com/savonrb/savon/compare/v2.14.0...v2.15.0

- Ruby
Published by pcai over 2 years ago

https://github.com/savonrb/savon - v2.14.0

- Ruby
Published by pcai almost 4 years ago

https://github.com/savonrb/savon - v2.13.1

  • Fix: #977 Prevent "xmlns:xmlns" namespace but allow "xmlns" namespace.

- Ruby
Published by pcai about 4 years ago

https://github.com/savonrb/savon - v2.13.0

  • Drop support for ruby 2.6 and below. Added Ruby 3.0 and 3.1 to test matrix.
  • Fix: #868 Remove xmlns:wsa's already added elsewhere; select Content-Type HTTP header based on SOAP version.
  • Fix: #943 Read all namespaces from wsdl definition if document exists
  • Feature: #920 Add a write_timeout setter for HTTP requests
  • Feature: #930 Add options for SSL min_version/max_version support
  • Feature: #931 Add log_headers option

- Ruby
Published by pcai about 4 years ago

https://github.com/savonrb/savon - v2.12.1

  • Fix: #917 elementFormDefault="qualified" regression
  • Fix: #875 Fix detecting Soap 1.1 Fault when faultcode and faultstring are empty

- Ruby
Published by pcai over 6 years ago

https://github.com/savonrb/savon - v2.12.0

  • Drop support for ruby 2.1 and below.
  • Fix: #822 Raise correct error when SOAP envelope only contains a string
  • Fix: #833 Fixes boolean handling regression introduced in 2.11.2
  • Feature: #794, add global option ssl_ciphers.
  • Feature: #753 Add headers configuration to WSDLRequest#build
  • Feature: #812 Allow proxy option to be nil.
  • Feature: #838 Added ssl_ca_path and ssl_cert_store to globals

- Ruby
Published by pcai over 8 years ago

https://github.com/savonrb/savon - v2.11.2

  • Fix: #676 Fixes handling of content! and attributes!
  • Fix: #800 Fix exception calling SOAPFault#to_s when http.body is empty
  • Fix: #757 Logging: Use filter without automatic pretty printing
  • Fix: #771 Restore support for cookies when using custom headers
  • Feature: #744 Add support for rpc encoded wsdl
  • Feature: #742 Add support for local request headers
  • Feature: #704 Add possibility to pass attribute delete_namespace_attributes to Nori

- Ruby
Published by pcai about 9 years ago