Skip to content

build(deps): bump mint (security), sourceror, spitfire - #206

Merged
epinault merged 2 commits into
masterfrom
maint/update-deps-default
Sep 23, 2026
Merged

epinault merged 2 commits into
masterfrom
maint/update-deps-default

Conversation

@epinault

Copy link
Copy Markdown
Contributor

Summary

Routine dependency update (default scope: security + patch/minor). All direct
dependencies in mix.exs (benchee, credo, dialyxir, ex_doc, igniter)
were already at their latest allowed version — everything here is a transitive
dependency bump within existing constraints.

Package Current Target Class Why
mint 1.10.0 1.10.1 security EEF-CVE-2026-82672 / GHSA-rj5m-69wp-cxq9 — unvalidated chunk-size line tail in Mint's HTTP/1 client could enable response smuggling against strict intermediaries on pooled connections. Pulled in via igniter -> req -> finch -> mint.
sourceror 1.12.2 1.12.3 safe (patch) Bug fix: properly calculate ranges for special atoms and docs. Dev-only, transitive via igniter.
spitfire 0.4.1 0.4.2 safe (patch) Bug fix: add :format metadata to atoms. Dev-only, transitive via igniter.

No majors were available to hold, and no deprecation warnings were introduced —
no source changes were needed in this repo.

Verification

  • mix compile --warnings-as-errors — clean
  • mix test --warnings-as-errors --cover — 150 passed, 93.62% coverage (threshold 90%)
  • mix credo --strict --format=oneline — clean
  • mix format --check-formatted — clean
  • mix deps.unlock --check-unused — clean
  • mix hex.audit — no retired or security-advisory packages remaining

Test plan

  • CI (.github/workflows/ci.yml) will re-run the same checks listed above

🤖 Generated with Claude Code by Emmanuel Pinault

epinault added 2 commits September 23, 2026 08:41
EEF-CVE-2026-82672 / GHSA-rj5m-69wp-cxq9: unvalidated chunk-size line
tail in Mint's HTTP/1 client could enable response smuggling against
strict intermediaries on pooled connections. Transitive dependency via
igniter -> req -> finch -> mint; no call-site changes needed.

Co-Authored-By: Emmanuel Pinault <dev@pinault-family.us>
Both are transitive dev-only dependencies pulled in by igniter.
Patch releases: sourceror fixes range calculation for special atoms
and docs; spitfire adds :format metadata to atoms. No behavioral
change affecting this repo, no call-site changes needed.

Co-Authored-By: Emmanuel Pinault <dev@pinault-family.us>
@epinault
epinault merged commit aa54a92 into master Sep 23, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

1 participant