🔧 Changed
- Report operations answered mostly with
429as rate-limited, not as a schema validation mismatch. - Suggest the JSON Pointer form for dotted link body expressions like
$response.body.0.id. - Additional-properties hint offers closing the schema or ignoring unknown fields, without blaming the schema.
🐛 Fixed
False negative_data_rejection in the coverage phase
- Nullable and
allowEmptyValueparameters. - Nullable string header and cookie parameters.
- String header and cookie parameters with
items. minimum/maximumon string parameters.- Parameter enum entries like
"1"undertype: boolean. - Header and cookie enums like
"true". 0sent to boolean header and cookie parameters.
Others
- Empty object query values sent as a literal
{}over WSGI. - Random credentials for alternative security schemes sent alongside configured auth, breaking re-authentication.
- False
negative_data_rejectionfor unknown query parameters besideallowEmptyValuestring values like0. - Non-ASCII bytes in generated
Bearertokens for valid test cases. - Error feedback ignoring Jackson
Unrecognized field "x"rejections from Spring APIs. - Coverage phase crashing on header or cookie array/object examples with non-Latin-1 or newline characters.
- Negative cases negating annotation keywords like
titleordeprecatedinstead of constraints. - Exploded object query parameters overwriting a declared query parameter of the same name.
- Crash when the cache holds an entry for a method removed from a path still in the schema.
- Pooled values paired with the wrong parent when names differ, like
idandproject_id. st replaymarking cases as fixed when the crash file has masked values likepassword. #5141- Unmasked request body fields like
passwordin reproduction commands. request-timeoutfrom the config file ignored byst runandst fuzz.- Coverage phase sending parameter examples that
format: floatprecision pushes out of range.