Locks mint 1.10.2 to clear four advisories - #126
Merged
Merged
Conversation
mix.lock moved mint from 1.10.0 to 1.10.2, the narrowest release that carries the fixes for EEF-CVE-2026-92103, EEF-CVE-2026-82672, EEF-CVE-2026-91043 and EEF-CVE-2026-94194. mint reaches this package only through finch and goth, the optional GCP KMS token server. No other lock line and no requirement in mix.exs changed, and a published package does not carry its lock, so a host resolves its own mint. Refs: enc-4ewh
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs: enc-4ewh
What changed
One line of
mix.lock: mint moves from 1.10.0 to 1.10.2. No other lock line changed (hpax stays at 1.0.4, finch at 0.23.0, goth at 1.4.5) andmix.exsis untouched, so no dependency requirement moved.mint reaches this package only transitively, through finch and goth, the optional token server for the GCP KMS provider. A published package does not ship its lock, so a host resolves its own mint; this change clears the advisories for this repo's own development, test and CI builds.
Advisories cleared
mix deps.getat the base reported mint 1.10.0 as vulnerable under four advisories, and OSV names the first fixed version of each:max_frame_size; fixed in 1.10.2.max_header_list_size; fixed in 1.10.2.After the change,
mix deps.getlists mint 1.10.2 with no vulnerable package, andmix hex.auditreports no retired or security-advisory package.Provenance
The narrowest update was chosen: mint 1.10.2, the patch release that carries all four fixes and keeps mint's hpax requirement at
~> 0.1.1 or ~> 0.2.0 or ~> 1.0.mix deps.update mintalone would have taken mint 1.11.0, which requires hpax~> 1.1and so would also have moved hpax 1.0.4 to 1.1.0. The 1.10.2 line was produced by mix itself (a temporary requirement inmix.exs, reverted byte-equal before commit), with the hpax line restored to its locked value afterwards.No changelog fragment:
changelog.d/README.mdwrites one only for a change someone calling the public API could notice, and a library's lock does not reach its users.Review
In-turn review (a lock-only change under the review threshold): the diff is one removed and one added line in
mix.lock, the added line is the entry mix wrote for mint 1.10.2 with its hex checksums, and a freshmix deps.getfetched mint 1.10.2 against it;git diff origin/main -- mix.exsis empty; each advisory's fixed version was read from OSV and is at or below 1.10.2.Gate
Full
mix qualitygreen on the committed tree: format, compile with warnings as errors, doc links, unused dependencies, Credo, docs, tests (684 of 684) and Dialyzer.