Potential breaking changes
- A minor release before 1.0 may contain incompatible changes.
0.33.0 → 0.34.0
- The changelog explicitly labels a breaking change.
⚠️ Breaking Changes & Deprecations
v0.34.0 — September 13, 2026
This release hardens request configuration and proxy handling, adds caller diagnostics and cancellation context, and tightens TypeScript header types.
⚠️ Breaking Changes & Deprecations
- Header Types: TypeScript now rejects header values that are Promises, functions, or objects with custom toString() methods. Resolve promises, call functions, or explicitly convert objects before assigning header values. Supported scalar, array, and grouped headers remain available. (#11209)
- Proxy Routing: NO_PROXY / no_proxy entries now support IPv4 and IPv6 CIDR ranges. Previously ineffective ranges now cause matching IP destinations to bypass the proxy; review existing ranges when upgrading. (#11172)
🔒 Security Fixes
- Request Configuration: Prevent inherited properties from influencing form serializer options, default request methods, headers on interceptor-returned configs, and HTTP redirect hooks. Applications relying on inherited options must define those values as own properties. (#11172)
- Hostname Processing: Replace quadratic regular-expression backtracking in proxy bypass hostname normalization with a linear scan, preventing excessive processing of crafted redirect hostnames. (#11172)