Skip to content

build(deps): bump mint (security), finch, hpax - #207

Open
epinault wants to merge 4 commits into
masterfrom
maint/update-deps-default
Open

epinault wants to merge 4 commits into
masterfrom
maint/update-deps-default

Conversation

@epinault

@epinault epinault commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Updated

Package From To Notes
mint 1.10.1 1.11.0 Security: EEF-CVE-2026-94194, EEF-CVE-2026-91043 (HIGH), EEF-CVE-2026-92103
finch 0.23.0 0.24.0 minor
hpax 1.0.4 1.1.0 transitive

All direct deps were already up to date; only transitive updates in mix.lock. No call-site changes.

Verified: compile --warnings-as-errors, mix test (150 passed), format check, credo --strict, mix hex.audit clean. The repo has no precommit alias, so these checks stood in for it.

Note: the branch name already existed on origin from a merged PR (#206), so main was merged into it.

🤖 Generated with Claude Code by Emmanuel Pinault

epinault added 4 commits September 23, 2026 08:41
EEF-CVE-2026-82672 / GHSA-rj5m-69wp-cxq9: unvalidated chunk-size line
tail in Mint's HTTP/1 client could enable response smuggling against
strict intermediaries on pooled connections. Transitive dependency via
igniter -> req -> finch -> mint; no call-site changes needed.

Co-Authored-By: Emmanuel Pinault <dev@pinault-family.us>
Both are transitive dev-only dependencies pulled in by igniter.
Patch releases: sourceror fixes range calculation for special atoms
and docs; spitfire adds :format metadata to atoms. No behavioral
change affecting this repo, no call-site changes needed.

Co-Authored-By: Emmanuel Pinault <dev@pinault-family.us>
…x 1.1.0

Mint 1.11.0 resolves advisories EEF-CVE-2026-94194, -91043, -92103.
No call-site changes needed.

Co-Authored-By: Emmanuel Pinault <dev@pinault-family.us>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

1 participant