# Changelog

> Every released version, with its date and what changed in it.

Source: https://boring-observability.dev/requizon/docs/changelog
Section: Reference — Requizon documentation (version 0.5)
Updated: 2026-10-07

---

Every released version of Requizon, newest first, with what changed in each. Releases are published to the private Composer registry at `requizon.composer.sh`; `composer update boring-o11y/requizon` moves you to the newest release your version constraint allows.

## All releases

| Version | Date | Headline |
| --- | --- | --- |
| [**0.5.0**](#v0-5-0) | 2 Oct 2026 | PostgreSQL, SQLite and MariaDB, and failures right now |
| [**0.4.0**](#v0-4-0) | 20 Sep 2026 | A request list scoped to its window |
| [**0.3.0**](#v0-3-0) | 18 Sep 2026 | Headers, per-API redaction and query strings |
| [**0.2.0**](#v0-2-0) | 15 Sep 2026 | First public release |

## 0.5.0 — 2 October 2026

**Added — PostgreSQL, SQLite and MariaDB.** `requizon:aggregate` used to refuse anything but MySQL, and the dashboard reads the rollup it builds. The rollup now upserts its buckets through Eloquent, so it runs on MySQL 8.0.19+, MariaDB 10.5+, PostgreSQL 9.5+ and SQLite 3.24+. See [Installation](https://boring-observability.dev/requizon/docs/installation#requirements).

**Added — failures right now.** Every dashboard page opens with the failures of the last 15 minutes by type, and the overview and paths tables carry that count per row, sorting whatever is failing now to the top. The stretch is `dashboard.recent_minutes`, or `REQUIZON_RECENT_MINUTES`. See [The dashboard](https://boring-observability.dev/requizon/docs/dashboard#right-now).

**Changed — the dashboard counts the hour under way.** Charts and tables read the hourly rollup as far as it goes and the detail rows after it, so a call shows up on the overview as soon as it is recorded rather than once the hour is rolled up. `requizon:aggregate` now rolls up the current hour too, up to a minute before the run, which keeps the stretch read from detail rows to a few minutes.

**Added — `paths.rewrite`.** Maps `Str::is()` patterns, matched against the raw path, to the path to record instead. It is for identifiers the normaliser cannot see, such as `/files/4313261196505276_DSCF0122.jpg`, which would otherwise add a rollup row per file. Rewritten paths still go through `paths.patterns`. See [Paths and table size](https://boring-observability.dev/requizon/docs/paths#rewrite).

**Added — `requizon:merge-paths`.** A paths setting only applies to calls recorded after it changes. This command puts every stored path through the current config, renames detail rows and folds old hourly buckets into their new ones. `--dry-run` lists every path that would move and where to. It refuses to run while `Requizon::resolvePathUsing()` is set unless you pass `--ignore-path-resolver`. See [Paths and table size](https://boring-observability.dev/requizon/docs/paths#merge-paths).

**Changed — the paths page is bounded.** It used to load every distinct path an API had, and a host whose URLs carry identifiers the normaliser misses could run PHP out of memory. The table now keeps the `dashboard.max_paths` (500) paths with the most failures, then the most requests, and says so when it cuts. A path failing right now keeps its row however it ranks. On a host with a path per call the page went from 16.5 s to about 0.8 s.

**Added — `recording.response_body_read_bytes`.** How far a response body is read for the failure detector and for redaction, separately from how much of it is stored. It defaults to 256 KB. See [Failure detection](https://boring-observability.dev/requizon/docs/failure-detection#detector-cost).

**Fixed — paths that differ only in case.** MySQL and MariaDB grouped `/files/abc` and `/files/AbC` as one path under their default collation, and the slowest-paths chart could crash on them. The host and path columns compare byte for byte there now.

**Fixed — response bodies read from the middle of the stream.** A body something else had already started reading was handed to the failure detector from where that read stopped. It is read from the start now.

## 0.4.0 — 20 September 2026

**Changed — the request list covers the selected window.** Every other table on the dashboard already did. The list now counts the same period as the charts above it, and a date range still replaces the window.

**Changed — the request list pages by cursor.** Offset paging counted every matching row to work out a last page. Keyset paging drops the count, so a deep page costs what the first does: on 868k detail rows for one host, the first page went from 2.0 s to 12 ms. Pages carry no numbers any more, only newer and older.

**Fixed — a slow overview on a year of rollups.** The overview grouped the hourly stats by API and host with no index on the hour to do it with. One is added, and the overview went from 0.77 s to 10 ms on 1.17M detail rows.

## 0.3.0 — 18 September 2026

**Added — request and response headers.** Retry-After, X-RateLimit-* and a provider's request id are often what you need when an integration fails. `recording.headers.request` and `.response` each take `none`, `failures` or `all`, defaulting to none for requests and failures for responses. Authorization, Cookie, api-key headers and anything matching the parameter redaction rules keep their name with the value masked. The Details panel lists them above the params and the body. See [Recording headers](https://boring-observability.dev/requizon/docs/headers).

**Added — redaction per API.** An entry in the `apis` map can carry `redact` (substrings) and `redact_exact` (whole names), added to the global lists for that API alone, so one provider's `l` and `p` parameters can be masked without every other API losing them. `Requizon::redactUsing()` covers what key names cannot express, and runs after the name rules. See [Redaction and stored data](https://boring-observability.dev/requizon/docs/redaction#per-api).

**Changed — failed response bodies are redacted.** A failed response body that parses as JSON or a form goes through the same rules as the request, so a 401 from a token endpoint no longer keeps its credentials. A body with nothing to mask keeps its own formatting.

**Added — query strings for every method.** The query string is stored in its own `query_params` column whatever the method, and the body in `request_params` whenever one is sent. A POST keeps its `?expand[]` and a GET with a JSON body keeps the body. The Details panel shows them as Query and Body.

**Changed — tables are prefixed `requizon_`.** They can no longer collide with an application's own tables, and the migrations create and drop them unconditionally.

## 0.2.0 — 15 September 2026

First public release. Requizon records every outbound call made through Laravel's HTTP client, and any Guzzle stack you push its middleware onto, with an hourly rollup and a dashboard at `/requizon`. See [Installing Requizon](https://boring-observability.dev/requizon/docs/installation).

## Staying current

```bash
# Move to the newest release your constraint allows
composer update boring-o11y/requizon

# Check what you are on
composer show boring-o11y/requizon

# List every published version
composer show boring-o11y/requizon --all
```


## Common questions

### What is the latest version of Requizon?

0.5.0, released on 2 October 2026. It runs on PostgreSQL, SQLite and MariaDB as well as MySQL, opens every dashboard page with the failures of the last 15 minutes, counts the hour under way from detail rows, and adds paths.rewrite and requizon:merge-paths for keeping the paths page bounded.

### How do I update Requizon to the latest version?

Run composer update boring-o11y/requizon. That moves you to the newest release your version constraint allows. Every purchase includes twelve months of upgrades.
