langfuse / langfuse/langfuse-python

[HTTPXodus] Consider migrating from `httpx` to `httpx2` (the actively maintained fork)

Aperta
#1,855 0 commenti 0 reazioni 1 assegnatario Vedi su GitHub

@hassiebp ci sta già lavorando.

Dal 4/9/2026.

improvement sdk-python security
Lingua principale
Python
Stelle
468
Fork
349
Merge medio
12h 16m
PR unite (30g)
27

Descrizione

Closes #0

🏷️ Part of HTTPXodus — a community effort to help major Python projects plan their path off the stalled httpx stable line onto httpx2, the actively maintained fork by Pydantic Services. One coordinated PR per project — no drive-by changes.

What is httpx2

httpx2 is a fork of httpx 0.28.1 maintained by Pydantic Services Inc., with the original httpx author Tom Christie involved. It is actively released (v2.0.0 → v2.12.0 since May 2026) and keeps a compatible public API:

import httpx2 as httpx  # or just `import httpx2` — the API is identical
r = httpx2.get("https://example.org")

Why migrate — the benefits

  1. Active maintenance — regular releases, reviewed PRs, funded maintainer team; vs httpx's 21-month stable-line stall.
  2. Modern TLS by default — certificates verified against the OS trust store instead of bundled certifi.
  3. New capabilities — built-in Server-Sent Events (client.sse()), WebSocket support (httpx2[ws]).
  4. Ecosystem alignment — Starlette, FastAPI, OpenAI Python SDK, Anthropic Python SDK, MCP Python SDK have all migrated or dual-supported httpx2.

Risks of staying on httpx

  • Security exposure: no stable-line releases means no stable-line security fixes. If a CVE lands in 0.28.x today, there is no maintained branch to patch.
  • Dependency conflicts: packages that pin httpx<1.0 already conflict with migrated peers; the longer the wait, the worse the resolver pain.
  • Compounding migration cost: the gap between 0.28.x and whatever httpx 1.0 becomes keeps growing; migrating to httpx2 now is a small, well-documented step (official migration guide: https://pydantic.dev/docs/httpx2/get-started/migration/).

What migration could look like here

langfuse already requires python>=3.10,<4.0, which is exactly the floor for httpx2. The only direct httpx constraint in pyproject.toml is "httpx>=0.15.4,<1.0", which has no <1.0 upper-bound conflict in the dependency tree today (no resolved version of httpx2 would satisfy it) but should be relaxed as part of the migration.

A dual-import path works cleanly here because the public API surface used in langfuse/ is exactly the surface httpx2 mirrors:

  • httpx.Client(...) / httpx.AsyncClient(...) — constructor signatures match
  • httpx.Response / httpx.Request — used for fixture construction in tests
  • httpx.HTTPStatusError / httpx.Timeout / httpx.Limits — all compatible
  • No internal cross-module state or httpx-module-identity assertions

A draft branch with the dual-import change (12 files, +45 / −11) is ready at ProgrammerPlus1998/langfuse-python on httpxodus/httpx2-migration. Happy to open a PR if the maintainers are interested; equally happy to close this if you'd rather wait for httpx 1.0 stable. 🙏

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.