build(deps): bump mint to 1.10.1 - #110
Merged
Merged
Conversation
Mint 1.10.0 carries EEF-CVE-2026-82672, a medium-severity flaw where an unvalidated chunk-size line tail lets a response be smuggled past strict intermediaries on a pooled connection. It reaches this library transitively through req and finch, and the lock file is not part of the published package, so nothing released is affected and no consumer resolves against this pin. What it does govern is CI and local development — which now exercise the webhook delivery added in 0.3.0 through an HTTP client that posts to caller-supplied URLs, so running that on a known-vulnerable client is the wrong default. Dependabot will not do this on its own: mint is not declared here, so the mix ecosystem's version updates skip it, and GitHub's advisory database carries no alert to trigger a security update. The warning comes from hex.pm's own audit against the Erlang Ecosystem Foundation database.
|
Reviewed — no high-confidence issues found. LGTM. |
TCK Compliance ResultsResult: passed - failures match the tracked baseline. TCK run complete — 0 known failure(s), matching test/tck/expected-failures.txt. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Bumps
mint1.10.0 → 1.10.1, clearing EEF-CVE-2026-82672 (MEDIUM) frommix deps.get.Type of change
What the advisory is
An unvalidated chunk-size line tail in Mint's HTTP/1 client lets a response be smuggled past strict intermediaries on a pooled connection.
Scope — deliberately narrow
Mint reaches this library transitively (
req→finch→mint ~> 1.8); it is not declared inmix.exs. Andmix.lockis not in the package'sfiles:list, so:~> 1.8and already get 1.10.1.mix.exschanges, so no changelog entry — consistent with how the joken bump was handled.What this pin does govern is CI and local development. 0.3.0 shipped webhook delivery that POSTs to caller-supplied URLs through Req → Finch → Mint, so running that path on a known-vulnerable HTTP client is the wrong default even in dev.
Why dependabot won't do this
Worth recording, since the obvious assumption is that it would:
.github/dependabot.ymlusespackage-ecosystem: mix, whose version updates operate on direct deps inmix.exs. Mint isn't one.vulnerability-alertsandautomated-security-fixesboth on), butGET /dependabot/alertsis empty — GitHub's advisory database has no entry for this. The warning comes from hex.pm's audit against the Erlang Ecosystem Foundation database, which dependabot doesn't consume.So transitive Elixir advisories from the EEF feed need catching by hand;
mix deps.getoutput is the signal.Verified
mix deps.getno longer reports advisories.mix test654 passed,mix qualityclean,bin/tck all0 known failures.