Skip to content

Maintenance: Mint 1.11 security floor, dependency updates, drop Elixir <1.17 / OTP <27, docs pass - #2

Merged
stuartc merged 8 commits into
mainfrom
deps-update
Oct 4, 2026
Merged

stuartc merged 8 commits into
mainfrom
deps-update

Conversation

@stuartc

@stuartc stuartc commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

Maintenance release: dependency updates, a Mint security floor, dropping Elixir 1.15, and a docs pass. Each commit stands on its own and can be reviewed separately.

Security

mix hex.audit flagged six published advisories against the locked Mint 1.9.3 (two HIGH). They cover HTTP/1 response smuggling and memory/CPU exhaustion from a malicious upstream, which applies directly to a proxy talking to untrusted servers. Mint 1.11.0 is the lowest release that fixes all six: CVE-2026-82728, CVE-2026-82729, CVE-2026-82672, CVE-2026-94194, CVE-2026-91043, CVE-2026-92103.

The lock only protects this repo, so the requirement in mix.exs goes from ~> 1.9 to ~> 1.11 to stop downstream apps resolving a vulnerable Mint.

Two cowlib advisories remain on 2.20.0 (the latest release). cowlib only comes in through bypass, so it's test-only and doesn't ship with Philter.

Changes

  • Update dependencies: lock-only bump to Mint 1.11.0, hpax, plug_crypto, cowboy/cowlib and dev tooling. ranch stays on 1.x because plug_cowboy pins it (test-only).

  • Require Mint 1.11 or later: the floor bump above, with a changelog entry.

  • Drop Elixir 1.15 and 1.16, and OTP 26: Elixir 1.15 and OTP 26 are outside their security-patch windows. cowlib 2.20 (test-only, via bypass) needs OTP 27, and Elixir 1.16 can't run on OTP 27, so 1.16 goes too. mix.exs now needs ~> 1.17, and CI covers 1.17–1.20 on OTP 27–29. Elixir 1.20.4 is the current release and CI's '1.20' already picks it up.

  • Refresh CLAUDE.md and README: checked against the code. Fixes a README handler example that didn't compile (missing require Logger), the allowed_hosts description (hosts are still resolved and only skip the block check), and several stale claims in CLAUDE.md about the request flow, when handle_response_finished/2 runs, and when observations land in conn.private.

  • Fix stale docs left over from the Finch transport: ProxyPlug now links to proxy/2 for its options rather than keeping a partial copy, and its observations example (which couldn't run after forward) is replaced with the handler approach. Also fixes the Handler, Config and proxy/2 docs, removes a comment about the deleted Dialyzer ignore file, and deletes the unused Philter.ConnCase.

  • Keep one log capture handler installed for the whole test run: fixes a flaky race on Elixir 1.17 where Philter.LogCapture adding and removing :logger handlers per capture crashed Logger.flush/0 in other async tests with {:not_found, id}.

Not in this PR

Config.finch_name/1 and the :finch_name config key are deprecated and ignored but still public. Removing them is a breaking change, so it's left for 0.5.

Testing

mix ci passes locally on Elixir 1.20.3 / OTP 29 (237 tests, plus format, credo and dialyzer). mix docs builds without warnings. The other Elixir/OTP versions are covered by the CI matrix.

Picks up Mint 1.11.0, which fixes six published advisories (CVE-2026-82728,
CVE-2026-82729, CVE-2026-82672, CVE-2026-91043, CVE-2026-92103,
CVE-2026-94194), plus cowboy/cowlib, hpax, plug_crypto and dev tooling.
Earlier versions carry HTTP/1 response-smuggling and memory/CPU exhaustion
advisories that apply directly to a proxy talking to untrusted upstreams.
The lock only protects this repo; the floor protects downstream apps.
1.15 is outside Elixir's security-patch window. CI now covers 1.16-1.20 on
OTP 26-29.
ProxyPlug now points at proxy/2 for its options instead of keeping a partial
copy, and its observations example (which could never run after forward) is
replaced with the handler route. Handler, Config and proxy/2 docs now match
current behaviour for reused_connection?, allowed_hosts, rejected requests and
error paths. Removes a comment about a deleted Dialyzer ignore file and the
unused Philter.ConnCase test helper.
Adding and removing a :logger handler per capture raced with Logger.flush/0
on Elixir 1.17, which lists handlers then reads each one's config; a handler
removed by another async test in between crashed it with {:not_found, id}.
The handler now stays installed and routes on the logging process's
dictionary, which works because :logger runs handlers in the caller.
cowlib 2.20, pulled in by bypass for tests, uses maybe expressions that need
OTP 27. OTP 26 is outside OTP's own support window, and Elixir 1.16 can't run
on OTP 27, so the minimum becomes Elixir 1.17 on OTP 27.
@stuartc stuartc changed the title Maintenance: Mint 1.11 security floor, dependency updates, drop Elixir 1.15, docs pass Maintenance: Mint 1.11 security floor, dependency updates, drop Elixir <1.17 / OTP <27, docs pass Oct 4, 2026
@stuartc
stuartc merged commit dc1d6cb into main Oct 4, 2026
6 checks passed
@stuartc
stuartc deleted the deps-update branch October 4, 2026 06:24
@stuartc stuartc mentioned this pull request Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant