Repository navigation
fix(deps): upgrade bandit, decimal, mint and lazy_html for security advisories - #81
Merged
Merged
Conversation
Bandit 1.12.4 is affected by two HTTP/2 advisories, both fixed in 1.12.5: - EEF-CVE-2026-74836 (HIGH): connection-window starvation can pin Plug processes indefinitely. - EEF-CVE-2026-75484 (MEDIUM): header field values containing CR, LF or NUL reach the application unvalidated. hpax, Bandit's HPACK implementation, moves from 1.0.4 to 1.1.0 with it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019fnjMN7WpEjQJD2zveakV6
EEF-CVE-2026-97853 (MEDIUM): the places argument to Decimal.round/3 drives an unbounded allocation. Textbin does not call it, but decimal arrives through Ecto, Postgrex and open_api_spex. This takes the 3.1.2 patch release rather than 3.2.0. 3.2.0 shipped a day ago and changes arithmetic results: it adds signals and fixes div/2 rounding. That is a separate upgrade from a security fix. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019fnjMN7WpEjQJD2zveakV6
Mint is the HTTP client under Req and Finch, which talk to S3 storage and other upstream services. 1.9.3 is affected by EEF-CVE-2026-82729 (MEDIUM): a long run of hex digits in a chunk-size line costs quadratic CPU to parse. 1.10.2 fixes that. It also fixes the other Mint advisories published since 1.9.3: unbounded HTTP/1 status and chunk-extension lines, unvalidated chunk extensions, unbounded decoded HTTP/2 header lists and frame buffering, and HTTP/1 transfer-coding framing. Together they are CVE-2026-82728, -82672, -91043, -92103 and -94194. 1.10.2 is the maintainers' backport of the 1.11.0 security fixes. It leaves out 1.11's broader HTTP/1 and HTTP/2 strictness changes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019fnjMN7WpEjQJD2zveakV6
EEF-CVE-2026-92106 (LOW): lazy_html serializes the style and script text of SVG and MathML elements without escaping, which allows mutation XSS. lazy_html is a test-only dependency here, used to query rendered LiveView HTML, so the server never serves its output. This upgrade clears the audit warning. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019fnjMN7WpEjQJD2zveakV6
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
mix deps.getflags four locked dependencies with published advisories. This PR upgrades each one in its own commit, and onlymix.lockchanges.Decimal.round/3Bandit also brings hpax, its HPACK implementation, from 1.0.4 to 1.1.0.
Why not the latest versions
:subnormaland:clampedsignals and fixesdiv/2rounding. 3.1.2 is the patch release that carries the fix.Both upgrades are pinned only through the lock file, and
mix.exsconstraints are unchanged.Verification
mix deps.getreports no vulnerable packages.mix precommitpasses: 582 tests, 0 failures.🤖 Generated with Claude Code
https://claude.ai/code/session_019fnjMN7WpEjQJD2zveakV6
Generated by Claude Code