Skip to content

build(deps): bump mint to 1.10.1 - #110

Merged
maxekman merged 1 commit into
mainfrom
max/bump-mint
Sep 25, 2026
Merged

maxekman merged 1 commit into
mainfrom
max/bump-mint

Conversation

@maxekman

Copy link
Copy Markdown
Contributor

Summary

Bumps mint 1.10.0 → 1.10.1, clearing EEF-CVE-2026-82672 (MEDIUM) from mix deps.get.

Type of change

  • Bug fix
  • New feature
  • Breaking change
  • Refactor / chore
  • Documentation

What the advisory is

An unvalidated chunk-size line tail in Mint's HTTP/1 client lets a response be smuggled past strict intermediaries on a pooled connection.

Scope — deliberately narrow

Mint reaches this library transitively (req → finch → mint ~> 1.8); it is not declared in mix.exs. And mix.lock is not in the package's files: list, so:

  • Nothing published is affected. Consumers resolve mint themselves against ~> 1.8 and already get 1.10.1.
  • Nothing in mix.exs changes, so no changelog entry — consistent with how the joken bump was handled.

What this pin does govern is CI and local development. 0.3.0 shipped webhook delivery that POSTs to caller-supplied URLs through Req → Finch → Mint, so running that path on a known-vulnerable HTTP client is the wrong default even in dev.

Why dependabot won't do this

Worth recording, since the obvious assumption is that it would:

  • .github/dependabot.yml uses package-ecosystem: mix, whose version updates operate on direct deps in mix.exs. Mint isn't one.
  • Security updates are enabled (vulnerability-alerts and automated-security-fixes both on), but GET /dependabot/alerts is empty — GitHub's advisory database has no entry for this. The warning comes from hex.pm's audit against the Erlang Ecosystem Foundation database, which dependabot doesn't consume.

So transitive Elixir advisories from the EEF feed need catching by hand; mix deps.get output is the signal.

Verified

mix deps.get no longer reports advisories. mix test 654 passed, mix quality clean, bin/tck all 0 known failures.

Mint 1.10.0 carries EEF-CVE-2026-82672, a medium-severity flaw where an
unvalidated chunk-size line tail lets a response be smuggled past strict
intermediaries on a pooled connection.

It reaches this library transitively through req and finch, and the lock
file is not part of the published package, so nothing released is
affected and no consumer resolves against this pin. What it does govern
is CI and local development — which now exercise the webhook delivery
added in 0.3.0 through an HTTP client that posts to caller-supplied
URLs, so running that on a known-vulnerable client is the wrong default.

Dependabot will not do this on its own: mint is not declared here, so
the mix ecosystem's version updates skip it, and GitHub's advisory
database carries no alert to trigger a security update. The warning
comes from hex.pm's own audit against the Erlang Ecosystem Foundation
database.
@claude

claude Bot commented Sep 23, 2026

Copy link
Copy Markdown

Reviewed — no high-confidence issues found. LGTM.

@github-actions

Copy link
Copy Markdown

TCK Compliance Results

Result: passed - failures match the tracked baseline.

TCK run complete — 0 known failure(s), matching test/tck/expected-failures.txt.

             A2A TCK Compatibility Report              
═══════════════════════════════════════════════════════
SUT: http://localhost:9999
Timestamp: 2026-09-23T10:05:20.301513+00:00

OVERALL COMPATIBILITY: 76.8%

┌─────────────┬────────┬────────┬─────────┬───────┐
│ Level       │ Passed │ Failed │ Skipped │ Total │
├─────────────┼────────┼────────┼─────────┼───────┤
│ MUST        │     75 │     22 │      17 │   114 │
│ SHOULD      │      7 │      4 │       0 │    11 │
│ MAY         │      4 │      0 │       0 │     4 │
└─────────────┴────────┴────────┴─────────┴───────┘

BY TRANSPORT:
  agent_card:    10/10 ✓
  grpc:          0/72 (72 skipped) ✓
  jsonrpc:       93/100 (7 skipped) ✓
  http_json:     3/83 (80 skipped) ✓

═══════════════════════════════════════════════════════


- Generated html report: file:///home/runner/work/a2a-elixir/a2a-elixir/.tck/reports/tck_report.html -
99 passed, 166 skipped in 31.59s
Command: /home/runner/work/a2a-elixir/a2a-elixir/.tck/.venv/bin/python -m pytest tests/compatibility/ --sut-host=http://localhost:9999 --tb=short --transport=jsonrpc -q --compatibility-report=reports/compatibility --html=reports/tck_report.html --self-contained-html --junitxml=reports/junitreport.xml


========================================
TCK run complete — 0 known failure(s), matching test/tck/expected-failures.txt.
Stopping server (PID 2669)...

@maxekman
maxekman merged commit ea71190 into main Sep 25, 2026
8 checks passed
@maxekman
maxekman deleted the max/bump-mint branch September 25, 2026 11:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant