Skip to content

Locks mint 1.10.2 to clear four advisories - #126

Merged
johnnyt merged 1 commit into
mainfrom
enc-4ewh-mint-lock-advisory
Sep 30, 2026
Merged

johnnyt merged 1 commit into
mainfrom
enc-4ewh-mint-lock-advisory

Conversation

@johnnyt

@johnnyt johnnyt commented Sep 30, 2026

Copy link
Copy Markdown
Member

Refs: enc-4ewh

What changed

One line of mix.lock: mint moves from 1.10.0 to 1.10.2. No other lock line changed (hpax stays at 1.0.4, finch at 0.23.0, goth at 1.4.5) and mix.exs is untouched, so no dependency requirement moved.

mint reaches this package only transitively, through finch and goth, the optional token server for the GCP KMS provider. A published package does not ship its lock, so a host resolves its own mint; this change clears the advisories for this repo's own development, test and CI builds.

Advisories cleared

mix deps.get at the base reported mint 1.10.0 as vulnerable under four advisories, and OSV names the first fixed version of each:

  • EEF-CVE-2026-92103 (medium): the HTTP/2 client buffers oversized frames up to 16 MiB before enforcing max_frame_size; fixed in 1.10.2.
  • EEF-CVE-2026-82672 (medium): an unvalidated chunk-size line tail in the HTTP/1 client; fixed in 1.10.1.
  • EEF-CVE-2026-91043 (high): HPACK-indexed cookie fields in HTTP/2 responses bypass max_header_list_size; fixed in 1.10.2.
  • EEF-CVE-2026-94194 (medium): the HTTP/1 client applies chunked framing when chunked is not the final transfer coding; fixed in 1.10.2.

After the change, mix deps.get lists mint 1.10.2 with no vulnerable package, and mix hex.audit reports no retired or security-advisory package.

Provenance

The narrowest update was chosen: mint 1.10.2, the patch release that carries all four fixes and keeps mint's hpax requirement at ~> 0.1.1 or ~> 0.2.0 or ~> 1.0. mix deps.update mint alone would have taken mint 1.11.0, which requires hpax ~> 1.1 and so would also have moved hpax 1.0.4 to 1.1.0. The 1.10.2 line was produced by mix itself (a temporary requirement in mix.exs, reverted byte-equal before commit), with the hpax line restored to its locked value afterwards.

No changelog fragment: changelog.d/README.md writes one only for a change someone calling the public API could notice, and a library's lock does not reach its users.

Review

In-turn review (a lock-only change under the review threshold): the diff is one removed and one added line in mix.lock, the added line is the entry mix wrote for mint 1.10.2 with its hex checksums, and a fresh mix deps.get fetched mint 1.10.2 against it; git diff origin/main -- mix.exs is empty; each advisory's fixed version was read from OSV and is at or below 1.10.2.

Gate

Full mix quality green on the committed tree: format, compile with warnings as errors, doc links, unused dependencies, Credo, docs, tests (684 of 684) and Dialyzer.

mix.lock moved mint from 1.10.0 to 1.10.2, the narrowest release that
carries the fixes for EEF-CVE-2026-92103, EEF-CVE-2026-82672,
EEF-CVE-2026-91043 and EEF-CVE-2026-94194. mint reaches this package
only through finch and goth, the optional GCP KMS token server. No
other lock line and no requirement in mix.exs changed, and a published
package does not carry its lock, so a host resolves its own mint.

Refs: enc-4ewh
@johnnyt
johnnyt merged commit acb8e24 into main Sep 30, 2026
1 check passed
@johnnyt
johnnyt deleted the enc-4ewh-mint-lock-advisory branch September 30, 2026 12:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant