Repository navigation
Maintenance: Mint 1.11 security floor, dependency updates, drop Elixir <1.17 / OTP <27, docs pass - #2
Merged
Merged
Conversation
Picks up Mint 1.11.0, which fixes six published advisories (CVE-2026-82728, CVE-2026-82729, CVE-2026-82672, CVE-2026-91043, CVE-2026-92103, CVE-2026-94194), plus cowboy/cowlib, hpax, plug_crypto and dev tooling.
Earlier versions carry HTTP/1 response-smuggling and memory/CPU exhaustion advisories that apply directly to a proxy talking to untrusted upstreams. The lock only protects this repo; the floor protects downstream apps.
1.15 is outside Elixir's security-patch window. CI now covers 1.16-1.20 on OTP 26-29.
ProxyPlug now points at proxy/2 for its options instead of keeping a partial copy, and its observations example (which could never run after forward) is replaced with the handler route. Handler, Config and proxy/2 docs now match current behaviour for reused_connection?, allowed_hosts, rejected requests and error paths. Removes a comment about a deleted Dialyzer ignore file and the unused Philter.ConnCase test helper.
Adding and removing a :logger handler per capture raced with Logger.flush/0
on Elixir 1.17, which lists handlers then reads each one's config; a handler
removed by another async test in between crashed it with {:not_found, id}.
The handler now stays installed and routes on the logging process's
dictionary, which works because :logger runs handlers in the caller.
cowlib 2.20, pulled in by bypass for tests, uses maybe expressions that need OTP 27. OTP 26 is outside OTP's own support window, and Elixir 1.16 can't run on OTP 27, so the minimum becomes Elixir 1.17 on OTP 27.
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Maintenance release: dependency updates, a Mint security floor, dropping Elixir 1.15, and a docs pass. Each commit stands on its own and can be reviewed separately.
Security
mix hex.auditflagged six published advisories against the locked Mint 1.9.3 (two HIGH). They cover HTTP/1 response smuggling and memory/CPU exhaustion from a malicious upstream, which applies directly to a proxy talking to untrusted servers. Mint 1.11.0 is the lowest release that fixes all six: CVE-2026-82728, CVE-2026-82729, CVE-2026-82672, CVE-2026-94194, CVE-2026-91043, CVE-2026-92103.The lock only protects this repo, so the requirement in
mix.exsgoes from~> 1.9to~> 1.11to stop downstream apps resolving a vulnerable Mint.Two cowlib advisories remain on 2.20.0 (the latest release). cowlib only comes in through
bypass, so it's test-only and doesn't ship with Philter.Changes
Update dependencies: lock-only bump to Mint 1.11.0, hpax, plug_crypto, cowboy/cowlib and dev tooling.
ranchstays on 1.x becauseplug_cowboypins it (test-only).Require Mint 1.11 or later: the floor bump above, with a changelog entry.
Drop Elixir 1.15 and 1.16, and OTP 26: Elixir 1.15 and OTP 26 are outside their security-patch windows. cowlib 2.20 (test-only, via bypass) needs OTP 27, and Elixir 1.16 can't run on OTP 27, so 1.16 goes too.
mix.exsnow needs~> 1.17, and CI covers 1.17–1.20 on OTP 27–29. Elixir 1.20.4 is the current release and CI's'1.20'already picks it up.Refresh CLAUDE.md and README: checked against the code. Fixes a README handler example that didn't compile (missing
require Logger), theallowed_hostsdescription (hosts are still resolved and only skip the block check), and several stale claims in CLAUDE.md about the request flow, whenhandle_response_finished/2runs, and when observations land inconn.private.Fix stale docs left over from the Finch transport:
ProxyPlugnow links toproxy/2for its options rather than keeping a partial copy, and its observations example (which couldn't run afterforward) is replaced with the handler approach. Also fixes the Handler, Config andproxy/2docs, removes a comment about the deleted Dialyzer ignore file, and deletes the unusedPhilter.ConnCase.Keep one log capture handler installed for the whole test run: fixes a flaky race on Elixir 1.17 where
Philter.LogCaptureadding and removing:loggerhandlers per capture crashedLogger.flush/0in other async tests with{:not_found, id}.Not in this PR
Config.finch_name/1and the:finch_nameconfig key are deprecated and ignored but still public. Removing them is a breaking change, so it's left for 0.5.Testing
mix cipasses locally on Elixir 1.20.3 / OTP 29 (237 tests, plus format, credo and dialyzer).mix docsbuilds without warnings. The other Elixir/OTP versions are covered by the CI matrix.