Repository navigation
chore(deps): bump the prod group with 3 updates - #948
Conversation
Bumps the prod group with 3 updates: [finch](https://github.com/sneako/finch), [hackney](https://github.com/benoitc/hackney) and [mint](https://github.com/elixir-mint/mint). Updates `finch` from 0.23.0 to 0.24.0 - [Changelog](https://github.com/sneako/finch/blob/main/CHANGELOG.md) - [Commits](sneako/finch@v0.23.0...v0.24.0) Updates `hackney` from 4.8.2 to 4.8.5 - [Release notes](https://github.com/benoitc/hackney/releases) - [Changelog](https://github.com/benoitc/hackney/blob/master/NEWS.md) - [Commits](benoitc/hackney@4.8.2...4.8.5) Updates `mint` from 1.10.1 to 1.11.0 - [Changelog](https://github.com/elixir-mint/mint/blob/main/CHANGELOG.md) - [Commits](elixir-mint/mint@v1.10.1...v1.11.0) --- updated-dependencies: - dependency-name: finch dependency-version: 0.24.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod - dependency-name: hackney dependency-version: 4.8.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod - dependency-name: mint dependency-version: 1.11.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod ... Signed-off-by: dependabot[bot] <support@github.com>
PR SummaryMedium Risk Overview Mint 1.11 is the standout: it patches several HTTP/1 and HTTP/2 client CVEs (header/frame limits and transfer-encoding handling). Finch 0.24 tightens HTTP/1 pool behavior after errors/timeouts and aligns with Mint 1.11. Hackney 4.8.5 fixes GOAWAY/stream draining and related HTTP/2/HTTP/3 pooling issues. No changes to Reviewed by Cursor Bugbot for commit d8edba2. Bugbot is set up for automated code reviews on this repo. Configure here. |
Bumps the prod group with 3 updates: finch, hackney and mint.
Updates
finchfrom 0.23.0 to 0.24.0Changelog
Sourced from finch's changelog.
Commits
3387d4bMerge pull request #399 from sneako/release/v0.24.00bb2f01prepare v0.24.021c4e8aMerge pull request #396 from manuelr-dev/add-http-queryeb9d28fMerge pull request #397 from ogourment/fix-http1-timeout-reuseec2f2e3Close abandoned HTTP1 connections before returning them to the pool660212fAdd support for the QUERY method79885b6Merge pull request #392 from ericmj/async-worker-close1e87c9dClose terminated HTTP/1 connections outside the pool process9978205Merge pull request #387 from britto/fix/http2-pool-cancel-disconnected2d9bf1eMerge pull request #389 from sneako/upgrade-ci-1.20.4Updates
hackneyfrom 4.8.2 to 4.8.5Release notes
Sourced from hackney's releases.
... (truncated)
Changelog
Sourced from hackney's changelog.
... (truncated)
Commits
f915bbaMerge pull request #969 from benoitc/release/4.8.54962e54Release 4.8.5dff0d5fMerge pull request #968 from benoitc/fix/h3-goaway-drainca03c3cDrain an HTTP/3 connection on GOAWAY8957485Merge pull request #967 from benoitc/fix/h3-conn-table-owner978be5eMerge pull request #966 from benoitc/deps/webtransport-0.4.8b3a892aCreate the HTTP/3 connection table in hackney_sup2371345Bump webtransport to 0.4.82cf1c1bMerge pull request #965 from benoitc/fix/h2-goaway-rst-refuseda6e9746Reset the streams a GOAWAY refusesUpdates
mintfrom 1.10.1 to 1.11.0Changelog
Sourced from mint's changelog.
Commits
fb850d3Release v1.11.02ec8b69Merge commit from fork20252caMerge commit from forkc7895cbMerge commit from forkbf2455fAdd fuzz properties for HTTP/1 and HTTP/2 connections (#520)6c531feValidate and track HTTP/2 server push streams (#519)e159932Validate HTTP/2 response semantics (#518)4d163e4Enforce the line size limit on complete status and chunk-size lines (#517)65fe496Validate HTTP/2 DATA, padding, SETTINGS and extension frames (#512)f5fced5Bracket IPv6 literal hostnames in the Host header and :authority (#514)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions