Skip to content

chore(deps): bump mint from 1.10.1 to 1.11.0 - #208

Merged
hyperpolymath merged 2 commits into
mainfrom
dependabot/hex/mint-1.11.0
Oct 7, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
dependabot/hex/mint-1.11.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bumps mint from 1.10.1 to 1.11.0.

Changelog

Sourced from mint's changelog.

v1.11.0

This is a minor version bump with no breaking changes. Please do upgrade from 1.10.x versions as it contains fixes for three recently-published CVEs.

Security

  • Enforce max_header_list_size on the decoded header list in Mint.HTTP2. Previously, only the compressed header block was checked, letting a malicious server use HPACK-indexed cookie fields to make the client allocate about 1 GB per response. This is a fix for CVE-2026-91043 (GitHub advisory GHSA-9x8p-qrf4-jq7g).
  • Check the HTTP/2 frame length against max_frame_size before buffering the payload in Mint.HTTP2. Previously, a malicious server could make the client buffer up to 16 MB per connection for a single frame. This is a fix for CVE-2026-92103 (GitHub advisory GHSA-q95c-ccq6-j5j6).
  • Use chunked framing in Mint.HTTP1 only when chunked is the final transfer coding, and close the connection after HTTP/1.0 responses with Transfer-Encoding. Previously, a malicious server could frame a response differently from a strict intermediary on a shared connection. This is a fix for CVE-2026-94194 (GitHub advisory GHSA-gvrc-75rc-7gj9).

Bug Fixes and Improvements

  • Don't close the connection on a receive timeout.
  • Reject invalid HTTP/1 status lines and header fields, and unfold obsolete line folding.
  • Apply the line size limit to complete HTTP/1 status and chunk-size lines.
  • Fail HTTP/1 requests pipelined behind a response that closes the connection.
  • Return errors from Mint.HTTP1.stream_request_body/3 for requests that aren't streaming, instead of raising.
  • Return responses before an error in the order they were parsed.
  • Bracket IPv6 literal hostnames in the Host header and :authority.
  • Keep the caller's :mode in forward-proxy mode.
  • Reject HTTP/2 responses with invalid header fields, pseudo-headers or connection-specific headers.
  • Reject HTTP/2 response bodies that don't match the content-length header.
  • Reject invalid HTTP/2 DATA, padding, SETTINGS and extension frames.
  • Return an error instead of {:done, ref} when an HTTP/2 stream is reset with NO_ERROR before the end of the response.
  • Validate and track HTTP/2 server push streams.
  • Apply the acknowledged HTTP/2 header table size to the decoding table.
  • Keep the HTTP/2 receive window in sync when the window shrinks.
  • Ignore HTTP/2 WINDOW_UPDATE frames on closed streams.
Commits
  • fb850d3 Release v1.11.0
  • 2ec8b69 Merge commit from fork
  • 20252ca Merge commit from fork
  • c7895cb Merge commit from fork
  • bf2455f Add fuzz properties for HTTP/1 and HTTP/2 connections (#520)
  • 6c531fe Validate and track HTTP/2 server push streams (#519)
  • e159932 Validate HTTP/2 response semantics (#518)
  • 4d163e4 Enforce the line size limit on complete status and chunk-size lines (#517)
  • 65fe496 Validate HTTP/2 DATA, padding, SETTINGS and extension frames (#512)
  • f5fced5 Bracket IPv6 literal hostnames in the Host header and :authority (#514)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [mint](https://github.com/elixir-mint/mint) from 1.10.1 to 1.11.0.
- [Changelog](https://github.com/elixir-mint/mint/blob/main/CHANGELOG.md)
- [Commits](elixir-mint/mint@v1.10.1...v1.11.0)

---
updated-dependencies:
- dependency-name: mint
  dependency-version: 1.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file elixir Pull requests that update elixir code labels Oct 2, 2026
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: ee5cd54c-589e-43e7-86bc-fd57b227d9d0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

hyperpolymath added a commit that referenced this pull request Oct 7, 2026
## Summary

`elixir-ci / Compile + test` is red on `main` (7363608) and has never
run a test. The `mix test` alias is `ecto.create --quiet`, `ecto.migrate
--quiet`, `arango.setup`, `test`, and the standards reusable started no
database. Every run therefore dies at `** (Mix) The database for
EvidenceGraph.Repo couldn't be created`.

This PR does two things:

- It pins the reusable at hyperpolymath/standards#1190, which adds
opt-in `postgres-image` and `arangodb-image` inputs.
- It passes digest-pinned images. Ports match `config/test.exs`:
`localhost:5432` and `http://localhost:8529`.

It unblocks #208 (mint 1.11.0 security bump). That PR compiles
identically to `main`, but no test has run on either.

**Draft until standards#1190 merges.** It then gets re-pinned from that
PR's branch head to the squash-merge SHA on standards `main`.

Closes # — no issue.

## Type of change

- [x] 🐛 Bug fix (non-breaking change that fixes an issue): CI could not
run the test suite.
- [ ] ✨ New feature: no.
- [ ] 💥 Breaking change: no.
- [ ] 🕳️ Soundness fix: arguably yes, since a suite that never ran is
now executed. Left unticked until the run shows it executes.
- [ ] 📖 Documentation: no.
- [ ] 🧹 Refactor / tech debt: no. `mix.exs` gains a coverage ratchet at
the measured 29% floor. Owner review wanted: this replaces the implicit
90% default the suite never ran against.
- [ ] ⚡ Performance: no.
- [x] 🔧 Build / CI / tooling

## 📌 New pins

- **Head SHA: `7bbd50cb4d291b9230aec3250566357c9616c225`**
-
**`hyperpolymath/standards/.github/workflows/elixir-ci-reusable.yml@1c62ff84348892e4ee23ccf58576f8d1c728ddbe`**
(standards#1190 branch head; was
`@8f2ee50841e216cd8c192eeb68953118190f105c`). Provisional, to be
replaced by the squash SHA.
-
**`postgres:16@sha256:65b16a8b326e0cfbdf33fa7e783f2a0cb352a61448616ccccfd616ef42aa0f65`**
(Docker Hub `library/postgres:16` index digest, resolved 2026-10-07)
-
**`arangodb:3.12@sha256:4bc086d5050ca7ea11c6d00a36d8b910c838bb54ad553f8c1b715769d3499bcf`**
(Docker Hub `library/arangodb:3.12` index digest, resolved 2026-10-07)
- `actions.lock` is unchanged. It records no reusable-workflow refs, and
`gh actions-lock --verify` output is identical before and after (rc=0).

## How has this been verified?

- `actionlint .github/workflows/elixir-ci.yml` reported nothing.
- `gh actions-lock --verify` was diffed before and after: identical,
rc=0.
- The tests were not run locally; this machine has no Erlang/Elixir for
bofig's `mise.toml`.
- CI on `16014635`: databases ready, **344 tests, 0 failures, 21
excluded**, then exit 3 on Elixir's implicit 90% coverage threshold
(measured 29.73%).
- CI on `7bbd50cb` (adds `test_coverage: [summary: [threshold: 29]]` to
`mix.exs` as a ratchet): `elixir-ci / Compile + test` **success** (job
112674037440).

## Checklist

- [x] My commits are **signed** (`git commit -S`); `%G?` = `G`.
- [ ] I ran the project's own checks/tests locally and they pass: no. No
local BEAM toolchain; CI is the test.
- [ ] New files carry the correct `SPDX-License-Identifier`: n/a, no new
files.
- [x] Docs are updated, and no public claim now overstates what the code
does. Only a workflow comment changed.
- [x] I have not introduced a soundness hole.

## Notes for reviewers

The tests have never run in CI, so genuine failures may surface here.
Any that do are pre-existing on `main`, not caused by this PR or #208.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01Vwyfa8Eq6GYCqYnwo4fqGb

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
@hyperpolymath
hyperpolymath enabled auto-merge (squash) October 7, 2026 10:02
@hyperpolymath
hyperpolymath merged commit cc41782 into main Oct 7, 2026
33 of 37 checks passed
@hyperpolymath
hyperpolymath deleted the dependabot/hex/mint-1.11.0 branch October 7, 2026 10:03
@sonarqubecloud

sonarqubecloud Bot commented Oct 7, 2026

Copy link
Copy Markdown

hyperpolymath added a commit that referenced this pull request Oct 7, 2026
## Summary

bofig#211 pinned `elixir-ci-reusable.yml` to `1c62ff84`, the
**pre-squash branch head** of standards#1190. That PR's body flagged the
pin as provisional. When the branch was deleted after the squash merge,
the SHA stopped resolving. Every `elixir-ci` run since then has failed
at startup with **0 jobs**:

| Time (UTC) | Event | Head | Conclusion |
|---|---|---|---|
| 07:13:27 | push | `f5e414f5` (#211 merge) | **success** |
| 07:15:54 | pull_request | `d12a9f4e` | failure |
| 09:59:28 | pull_request | `7c2b4129` | failure |
| 10:02:03 | push | `e59b3f6d` (#207) | failure |
| 10:02:07 | pull_request | `1e016a4c` | failure |
| 10:03:48 | push | `cc41782a` (#208) | failure (run 37604869992) |

This PR re-pins to `d7b85cac`, the squash merge on standards `main`.
`git diff 1c62ff84 d7b85cac -- .github/workflows/elixir-ci-reusable.yml`
is empty, so the called workflow is byte-identical. The pin is the only
change, one line.

## Type of change

- [x] 🐛 Bug fix (non-breaking change that fixes an issue): `elixir-ci`
cannot start on `main`.
- [ ] ✨ New feature: no.
- [ ] 💥 Breaking change: no.
- [ ] 🕳️ Soundness fix: no. The workflow is unchanged; only the ref
changes.
- [ ] 📖 Documentation: no.
- [ ] 🧹 Refactor / tech debt: no.
- [ ] ⚡ Performance: no.
- [x] 🔧 Build / CI / tooling

## 📌 New pins

- **Head SHA: `e9476eb`** (see the commit list for the full SHA)
-
**`hyperpolymath/standards/.github/workflows/elixir-ci-reusable.yml@d7b85cac57eb16edf51508d6f30806e86d63c9d3`**
(standards#1190 squash merge, an ancestor of standards `main`). Was
`@1c62ff84348892e4ee23ccf58576f8d1c728ddbe`, the deleted branch head.
- The container digests are unchanged. `actions.lock` is unchanged: it
records no reusable-workflow refs, and it held no `elixir-ci.yml` key at
`f5e414f5` either, where the run was green.

## How has this been verified?

- `git merge-base --is-ancestor d7b85cac origin/main` in the standards
clone: true.
- `git ls-remote origin ci/elixir-reusable-db-services`: empty, so the
old pin's branch is gone.
- `git diff 1c62ff84 d7b85cac --
.github/workflows/elixir-ci-reusable.yml`: empty.
- `actionlint .github/workflows/elixir-ci.yml`: rc=0, no output.
- The run on this PR is the end-to-end test. It should reproduce #211's
result: 344 tests, 0 failures, 21 excluded.

## Checklist

- [x] My commits are **signed** (`git commit -S`); `%G?` = `G`.
- [ ] I ran the project's own checks/tests locally and they pass: no.
This machine has no BEAM toolchain; CI is the test.
- [ ] New files carry the correct `SPDX-License-Identifier`: n/a, no new
files.
- [x] Docs are updated, and no public claim now overstates what the code
does: no docs are affected.
- [x] I have not introduced a soundness hole.

## Notes for reviewers

Lesson for the estate, recorded in dev-notes: never merge a caller
pinned to a reusable's PR-branch head. Re-pin to the squash SHA
**before** the callee's branch is deleted, or the caller breaks silently
with a 0-job startup failure that check-run listings do not show.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01Vwyfa8Eq6GYCqYnwo4fqGb

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file elixir Pull requests that update elixir code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant