🚀 Added
- Dependency inference unwraps
result/dataenvelopes that carry metadata such asstatusortime. - Dependency inference treats
PUT /items/{name}as the creator when nothingPOSTs to/items.
🐛 Fixed
CLI
- Return exit code 2 for run-wide configuration errors.
- Report custom handler startup errors with a clean message.
- Stateful worker hangs after Ctrl-C from custom handlers.
pytest plugin
- Keep reports separate for identical schemas with different report configurations.
- Reports including results from an identical schema that did not configure reports.
Python API
ImportErroronfrom schemathesis.checks import content_type_conformance(and other built-in checks) before a schema is loaded.schemathesis.checkreturn type: decorated functions and classes keep their own type.base_urlpassed toCase.callignored for WSGI applications.
Stateful testing
- Memory growing without bound during long runs with a time limit.
- Crash in dependency inference for Open API 3.1 references to boolean schemas.
- Crash in dependency inference for Open API 3.1 boolean schemas inside
anyOfandoneOf. - Crash in dependency inference for response references targeting non-object values.
- Inferred links reading foreign keys from responses that do not declare them.
Data generation
- Hanging, or failing a health check, on arrays with a large
minItems. - Crash while processing patterns beside string length bounds too large for regex engines.
- "Failed Health Check" in negative mode for string path parameters carrying keywords of other types.
- Missing negative multipart bodies for binary fields with multiple content types.
- Preserve case-sensitive cookie parameter names.
- Dictionary bindings on body paths ignored through recursive
$refschemas.
Coverage phase
- Hanging on unique arrays with a large
minItems. - Crashes and invalid positive cases from YAML binary keyword values.
- Invalid positive cases for large arrays and objects beside
prefixItems,if, orunevaluatedProperties. - Missing positive cases for satisfiable numeric
multipleOfschemas with large bounds.
Request serialization
- Send binary Open API 3.2
querystringparameters as percent-encoded raw queries. - Captured array path parameters ignoring their declared Open API style.
Schema handling
- Report malformed Open API
serversdefinitions as clean loading errors. - Report infinite recursive and unresolvable references as clean errors.
- Report empty or non-object Open API parameter
contentas a clean error. - Stalls of up to 30s per document carrying an unreachable
$schemaURL.
negative_data_rejection
- False positive when path and query numeric values are both valid on the wire.
- Missed failures for invalid single-element arrays in query, header or cookie parameters.
- Missed failures for invalid array or object query, header and cookie parameters.
- Missed failures when an array parameter with a valid element accompanies invalid ones.
- Missed failures for invalid path parameters beside undeclared query parameters.
- Missed failures for numeric strings violating
minimumor other bounds.
Others
- False
unsupported_methodfailures when a rate limiter answers an undeclared method with429 Too Many Requests. checks.enabled = falsenot disabling custom checks.- Report undecodable JSON response bodies as JSON parsing errors.
- Missing closing delimiter in reproduce cURL commands for empty multipart bodies.