From aaaf3c280e48ee88dbca95c5509a6c9c36649fd4 Mon Sep 17 00:00:00 2001 From: Michael Grosse Huelsewiesche Date: Tue, 22 Sep 2026 18:57:28 -0400 Subject: [PATCH] Note the new request headers in the 3.5.5 release notes 3.5.5 started sending Authorization and X-Retry-Count. Customers whose proxies allowlist request headers had uploads rejected by the equivalent analytics-next change, so the shipped entry should say so. --- CHANGELOG.md | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 95d2bdfe..5069a8c4 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,4 +1,11 @@ # Version 3.5.5 (June 30, 2026) + +> **Upgrade note: new request headers and proxy allowlists.** This version sends two +> request headers that 3.5.4 did not: `Authorization` (HTTP Basic, carrying your write +> key) and `X-Retry-Count` (on retries only). If your traffic to Segment goes through a +> proxy, gateway or WAF that allowlists request headers, add both or uploads will be +> rejected. + - [New](https://github.com/segmentio/analytics-java/pull/531) Unified HTTP response handling and retry behavior - Retryable statuses (429, 408, 410, 460, 5xx except 501/505/511) check Retry-After header first, fall back to exponential backoff - Retry-After supports numeric seconds and RFC 7231 HTTP-date format, capped at 300s