Skip to content

chore(deps): bump mint from 1.10.0 to 1.10.1 in the prod group across 1 directory - #944

Merged
yordis merged 1 commit into
masterfrom
dependabot/hex/prod-906e6d28ef
Sep 28, 2026
Merged

yordis merged 1 commit into
masterfrom
dependabot/hex/prod-906e6d28ef

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the prod group with 1 update in the / directory: mint.

Updates mint from 1.10.0 to 1.10.1

Changelog

Sourced from mint's changelog.

v1.10.1

Security

  • Validate chunk extensions in HTTP/1 chunked responses in Mint.HTTP1. Previously, any bytes between the chunk size and the CRLF were accepted, letting a malicious server frame a chunked response differently from a strict intermediary on a shared connection. This is a fix for CVE-2026-82672 (GitHub advisory GHSA-rj5m-69wp-cxq9).

Bug Fixes and Improvements

  • Close TCP sockets on errors in HTTP/1.
  • Keep HTTP/1.0 CONNECT tunnel sockets open.
Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file elixir Pull requests that update Elixir code labels Sep 27, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 27, 2026 01:22
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file elixir Pull requests that update Elixir code labels Sep 27, 2026
@cursor

cursor Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

PR Summary

Low Risk
Lockfile-only dependency bump with a targeted HTTP/1 security fix; low integration risk but affects outbound HTTP parsing for Mint-based adapters.

Overview
Updates locked dependencies so mint moves from 1.10.0 to 1.10.1 and its transitive hpax dependency from 1.0.4 to 1.1.0 in mix.lock. No application code changes.

The mint release addresses CVE-2026-82672 by tightening validation of HTTP/1 chunked response extensions in Mint.HTTP1, plus minor HTTP/1 behavior fixes (closing TCP sockets on errors, keeping HTTP/1.0 CONNECT tunnel sockets open). For Tesla users on the Mint adapter (via Finch/Mint), this is primarily a security and HTTP client stack update.

Reviewed by Cursor Bugbot for commit da54f7f. Bugbot is set up for automated code reviews on this repo. Configure here.

@github-actions github-actions Bot added the chore label Sep 27, 2026
@github-actions
github-actions Bot enabled auto-merge (squash) September 27, 2026 01:22
@yordis

yordis commented Sep 28, 2026

Copy link
Copy Markdown
Member

@dependabot rebase

Bumps the prod group with 1 update in the / directory: [mint](https://github.com/elixir-mint/mint).


Updates `mint` from 1.10.0 to 1.10.1
- [Changelog](https://github.com/elixir-mint/mint/blob/main/CHANGELOG.md)
- [Commits](elixir-mint/mint@v1.10.0...v1.10.1)

---
updated-dependencies:
- dependency-name: mint
  dependency-version: 1.10.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump mint from 1.10.0 to 1.10.1 in the prod group chore(deps): bump mint from 1.10.0 to 1.10.1 in the prod group across 1 directory Sep 28, 2026
@dependabot
dependabot Bot force-pushed the dependabot/hex/prod-906e6d28ef branch from daee9b8 to da54f7f Compare September 28, 2026 11:17
@yordis
yordis disabled auto-merge September 28, 2026 11:44
@yordis
yordis merged commit 8d0ee3a into master Sep 28, 2026
14 of 15 checks passed
@yordis
yordis deleted the dependabot/hex/prod-906e6d28ef branch September 28, 2026 11:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

chore dependencies Pull requests that update a dependency file elixir Pull requests that update Elixir code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant