Skip to content

chore(deps): bump mint from 1.10.1 to 1.11.0 in /elixir-orchestration - #298

Merged
hyperpolymath merged 1 commit into
mainfrom
dependabot/hex/elixir-orchestration/mint-1.11.0
Oct 4, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
dependabot/hex/elixir-orchestration/mint-1.11.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown
Contributor

Bumps mint from 1.10.1 to 1.11.0.

Changelog

Sourced from mint's changelog.

v1.11.0

This is a minor version bump with no breaking changes. Please do upgrade from 1.10.x versions as it contains fixes for three recently-published CVEs.

Security

  • Enforce max_header_list_size on the decoded header list in Mint.HTTP2. Previously, only the compressed header block was checked, letting a malicious server use HPACK-indexed cookie fields to make the client allocate about 1 GB per response. This is a fix for CVE-2026-91043 (GitHub advisory GHSA-9x8p-qrf4-jq7g).
  • Check the HTTP/2 frame length against max_frame_size before buffering the payload in Mint.HTTP2. Previously, a malicious server could make the client buffer up to 16 MB per connection for a single frame. This is a fix for CVE-2026-92103 (GitHub advisory GHSA-q95c-ccq6-j5j6).
  • Use chunked framing in Mint.HTTP1 only when chunked is the final transfer coding, and close the connection after HTTP/1.0 responses with Transfer-Encoding. Previously, a malicious server could frame a response differently from a strict intermediary on a shared connection. This is a fix for CVE-2026-94194 (GitHub advisory GHSA-gvrc-75rc-7gj9).

Bug Fixes and Improvements

  • Don't close the connection on a receive timeout.
  • Reject invalid HTTP/1 status lines and header fields, and unfold obsolete line folding.
  • Apply the line size limit to complete HTTP/1 status and chunk-size lines.
  • Fail HTTP/1 requests pipelined behind a response that closes the connection.
  • Return errors from Mint.HTTP1.stream_request_body/3 for requests that aren't streaming, instead of raising.
  • Return responses before an error in the order they were parsed.
  • Bracket IPv6 literal hostnames in the Host header and :authority.
  • Keep the caller's :mode in forward-proxy mode.
  • Reject HTTP/2 responses with invalid header fields, pseudo-headers or connection-specific headers.
  • Reject HTTP/2 response bodies that don't match the content-length header.
  • Reject invalid HTTP/2 DATA, padding, SETTINGS and extension frames.
  • Return an error instead of {:done, ref} when an HTTP/2 stream is reset with NO_ERROR before the end of the response.
  • Validate and track HTTP/2 server push streams.
  • Apply the acknowledged HTTP/2 header table size to the decoding table.
  • Keep the HTTP/2 receive window in sync when the window shrinks.
  • Ignore HTTP/2 WINDOW_UPDATE frames on closed streams.
Commits
  • fb850d3 Release v1.11.0
  • 2ec8b69 Merge commit from fork
  • 20252ca Merge commit from fork
  • c7895cb Merge commit from fork
  • bf2455f Add fuzz properties for HTTP/1 and HTTP/2 connections (#520)
  • 6c531fe Validate and track HTTP/2 server push streams (#519)
  • e159932 Validate HTTP/2 response semantics (#518)
  • 4d163e4 Enforce the line size limit on complete status and chunk-size lines (#517)
  • 65fe496 Validate HTTP/2 DATA, padding, SETTINGS and extension frames (#512)
  • f5fced5 Bracket IPv6 literal hostnames in the Host header and :authority (#514)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [mint](https://github.com/elixir-mint/mint) from 1.10.1 to 1.11.0.
- [Changelog](https://github.com/elixir-mint/mint/blob/main/CHANGELOG.md)
- [Commits](elixir-mint/mint@v1.10.1...v1.11.0)

---
updated-dependencies:
- dependency-name: mint
  dependency-version: 1.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file elixir Pull requests that update elixir code labels Oct 3, 2026
@coderabbitai

coderabbitai Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 5032fd44-359d-4e9b-a5e5-1b236a24ebb2

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit d5f7905 into main Oct 4, 2026
21 of 24 checks passed
@hyperpolymath
hyperpolymath deleted the dependabot/hex/elixir-orchestration/mint-1.11.0 branch October 4, 2026 19:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file elixir Pull requests that update elixir code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant