Skip to content

chore(deps): bump the prod group with 3 updates - #948

Merged
yordis merged 1 commit into
masterfrom
dependabot/hex/prod-d24bf53722
Oct 11, 2026
Merged

yordis merged 1 commit into
masterfrom
dependabot/hex/prod-d24bf53722

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 11, 2026

Copy link
Copy Markdown
Contributor

Bumps the prod group with 3 updates: finch, hackney and mint.

Updates finch from 0.23.0 to 0.24.0

Changelog

Sourced from finch's changelog.

v0.24.0 (2026-09-29)

Added

  • Support the HTTP QUERY method via the :query atom in Finch.build/5 #396
  • Add t:Finch.pool_opt/0 and t:Finch.pool_opts/0 types and a typespec for Finch.start_link/1 #382

Fixed

  • Close HTTP/1 connections after request or response errors before returning them to the pool, preventing stale response references from reaching subsequent requests after receive timeouts with Mint 1.11 #397
  • Close discarded HTTP/1 connections asynchronously so slow TLS shutdowns do not block pool checkouts #392
  • Wait for dynamically started HTTP/2 pools to become ready within :pool_timeout, avoiding :pool_not_available errors on initial requests #388
  • Return :ok when cancelling an async request while its HTTP/2 pool is disconnected, avoiding a MatchError #387
  • Unregister HTTP/1 and HTTP/2 pool workers before shutdown completes so resizing pools does not leave stale registry entries #391
  • Treat empty or whitespace-only SSLKEYLOGFILE and :ssl_key_log_file values as unset #381

Other

  • Update locked dependencies to Mint 1.11 and HPAX 1.1 #397
  • CI: update to Elixir 1.20.4 and Erlang/OTP 29.0.6 #389
  • Fix documentation warnings from references to the removed six-argument Finch.request function #389
  • Remove timing races from HTTP/1 pool idle-timeout tests #391
Commits
  • 3387d4b Merge pull request #399 from sneako/release/v0.24.0
  • 0bb2f01 prepare v0.24.0
  • 21c4e8a Merge pull request #396 from manuelr-dev/add-http-query
  • eb9d28f Merge pull request #397 from ogourment/fix-http1-timeout-reuse
  • ec2f2e3 Close abandoned HTTP1 connections before returning them to the pool
  • 660212f Add support for the QUERY method
  • 79885b6 Merge pull request #392 from ericmj/async-worker-close
  • 1e87c9d Close terminated HTTP/1 connections outside the pool process
  • 9978205 Merge pull request #387 from britto/fix/http2-pool-cancel-disconnected
  • 2d9bf1e Merge pull request #389 from sneako/upgrade-ci-1.20.4
  • Additional commits viewable in compare view

Updates hackney from 4.8.2 to 4.8.5

Release notes

Sourced from hackney's releases.

hackney 4.8.5

Fixed

  • A GOAWAY fails only the requests the server refused. HTTP/2 failed every in-flight request with {error, {goaway, _}}, including ones the server went on to complete, and HTTP/3 ignored the GOAWAY and kept sending new requests on the connection. Accepted streams now finish, streamed uploads and responses included, refused ones fail and are reset, and the connection leaves the pool and closes once drained (#961, #962, #964, #965, #968).
  • A failed HTTP/2 request body send fails the other streams on the connection instead of leaving them waiting (#964).
  • Closing an HTTP/3 connection no longer makes the other live HTTP/3 connections unreachable. The connection table was owned by the first connection and went away with it (#967).

Changed

  • Update h2 to 0.12.4, quic to 2.1.1 and webtransport to 0.4.8.

hackney 4.8.4

Fixed

  • hackney:close/1 on a shared pooled HTTP/2 connection resets only the caller's own streams. It stopped the connection, failing every other caller's streams on it. The connection still closes itself once idle with no stream open.
  • A connection opened without a pool honours connect_timeout above 8 seconds, and a dial that outlives it returns {error, connect_timeout}. The wait was capped at 8 seconds and ended as an exit in the caller. A dial stuck in the transport no longer holds the caller past its deadline either (#945).

hackney 4.8.3

Fixed

  • hackney_conn:set_owner/2 works while a streamed request body is being sent. It returned {error, invalid_state}.
  • A response body cut short by the server closing the connection is an error. For a chunked or Content-Length body, body/1 returns {error, {closed, Partial}} with the bytes that arrived, and stream_body/1 and async responses end with {error, closed}. They reported a short body as complete. A body with neither still ends when the connection closes.
  • An HTTPS request through a CONNECT proxy reached over TLS ({proxy_transport, ssl}) works. The target TLS handshake ran over the proxy TLS socket as if it were plain TCP and failed.
  • A pooled connection from hackney:connect/* stays with its caller between requests, and hackney:close/1 checks it back into the pool. It went back to the pool after every response while the caller still used it, so the

... (truncated)

Changelog

Sourced from hackney's changelog.

4.8.5 - 2026-10-04

Fixed

  • A GOAWAY fails only the requests the server refused. HTTP/2 failed every in-flight request with {error, {goaway, _}}, including ones the server went on to complete, and HTTP/3 ignored the GOAWAY and kept sending new requests on the connection. Accepted streams now finish, streamed uploads and responses included, refused ones fail and are reset, and the connection leaves the pool and closes once drained (#961, #962, #964, #965, #968).
  • A failed HTTP/2 request body send fails the other streams on the connection instead of leaving them waiting (#964).
  • Closing an HTTP/3 connection no longer makes the other live HTTP/3 connections unreachable. The connection table was owned by the first connection and went away with it (#967).

Changed

  • Update h2 to 0.12.4, quic to 2.1.1 and webtransport to 0.4.8.

4.8.4 - 2026-09-27

Fixed

  • hackney:close/1 on a shared pooled HTTP/2 connection resets only the caller's own streams. It stopped the connection, failing every other caller's streams on it. The connection still closes itself once idle with no stream open.
  • A connection opened without a pool honours connect_timeout above 8 seconds, and a dial that outlives it returns {error, connect_timeout}. The wait was capped at 8 seconds and ended as an exit in the caller. A dial stuck in the transport no longer holds the caller past its deadline either (#945).

4.8.3 - 2026-09-27

Fixed

  • hackney_conn:set_owner/2 works while a streamed request body is being sent. It returned {error, invalid_state}.
  • A response body cut short by the server closing the connection is an error. For a chunked or Content-Length body, body/1 returns {error, {closed, Partial}} with the bytes that arrived, and stream_body/1 and async responses end with {error, closed}. They reported a short body as complete. A body with neither still ends when the connection closes.

... (truncated)

Commits
  • f915bba Merge pull request #969 from benoitc/release/4.8.5
  • 4962e54 Release 4.8.5
  • dff0d5f Merge pull request #968 from benoitc/fix/h3-goaway-drain
  • ca03c3c Drain an HTTP/3 connection on GOAWAY
  • 8957485 Merge pull request #967 from benoitc/fix/h3-conn-table-owner
  • 978be5e Merge pull request #966 from benoitc/deps/webtransport-0.4.8
  • b3a892a Create the HTTP/3 connection table in hackney_sup
  • 2371345 Bump webtransport to 0.4.8
  • 2cf1c1b Merge pull request #965 from benoitc/fix/h2-goaway-rst-refused
  • a6e9746 Reset the streams a GOAWAY refuses
  • Additional commits viewable in compare view

Updates mint from 1.10.1 to 1.11.0

Changelog

Sourced from mint's changelog.

v1.11.0

This is a minor version bump with no breaking changes. Please do upgrade from 1.10.x versions as it contains fixes for three recently-published CVEs.

Security

  • Enforce max_header_list_size on the decoded header list in Mint.HTTP2. Previously, only the compressed header block was checked, letting a malicious server use HPACK-indexed cookie fields to make the client allocate about 1 GB per response. This is a fix for CVE-2026-91043 (GitHub advisory GHSA-9x8p-qrf4-jq7g).
  • Check the HTTP/2 frame length against max_frame_size before buffering the payload in Mint.HTTP2. Previously, a malicious server could make the client buffer up to 16 MB per connection for a single frame. This is a fix for CVE-2026-92103 (GitHub advisory GHSA-q95c-ccq6-j5j6).
  • Use chunked framing in Mint.HTTP1 only when chunked is the final transfer coding, and close the connection after HTTP/1.0 responses with Transfer-Encoding. Previously, a malicious server could frame a response differently from a strict intermediary on a shared connection. This is a fix for CVE-2026-94194 (GitHub advisory GHSA-gvrc-75rc-7gj9).

Bug Fixes and Improvements

  • Don't close the connection on a receive timeout.
  • Reject invalid HTTP/1 status lines and header fields, and unfold obsolete line folding.
  • Apply the line size limit to complete HTTP/1 status and chunk-size lines.
  • Fail HTTP/1 requests pipelined behind a response that closes the connection.
  • Return errors from Mint.HTTP1.stream_request_body/3 for requests that aren't streaming, instead of raising.
  • Return responses before an error in the order they were parsed.
  • Bracket IPv6 literal hostnames in the Host header and :authority.
  • Keep the caller's :mode in forward-proxy mode.
  • Reject HTTP/2 responses with invalid header fields, pseudo-headers or connection-specific headers.
  • Reject HTTP/2 response bodies that don't match the content-length header.
  • Reject invalid HTTP/2 DATA, padding, SETTINGS and extension frames.
  • Return an error instead of {:done, ref} when an HTTP/2 stream is reset with NO_ERROR before the end of the response.
  • Validate and track HTTP/2 server push streams.
  • Apply the acknowledged HTTP/2 header table size to the decoding table.
  • Keep the HTTP/2 receive window in sync when the window shrinks.
  • Ignore HTTP/2 WINDOW_UPDATE frames on closed streams.
Commits
  • fb850d3 Release v1.11.0
  • 2ec8b69 Merge commit from fork
  • 20252ca Merge commit from fork
  • c7895cb Merge commit from fork
  • bf2455f Add fuzz properties for HTTP/1 and HTTP/2 connections (#520)
  • 6c531fe Validate and track HTTP/2 server push streams (#519)
  • e159932 Validate HTTP/2 response semantics (#518)
  • 4d163e4 Enforce the line size limit on complete status and chunk-size lines (#517)
  • 65fe496 Validate HTTP/2 DATA, padding, SETTINGS and extension frames (#512)
  • f5fced5 Bracket IPv6 literal hostnames in the Host header and :authority (#514)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the prod group with 3 updates: [finch](https://github.com/sneako/finch), [hackney](https://github.com/benoitc/hackney) and [mint](https://github.com/elixir-mint/mint).


Updates `finch` from 0.23.0 to 0.24.0
- [Changelog](https://github.com/sneako/finch/blob/main/CHANGELOG.md)
- [Commits](sneako/finch@v0.23.0...v0.24.0)

Updates `hackney` from 4.8.2 to 4.8.5
- [Release notes](https://github.com/benoitc/hackney/releases)
- [Changelog](https://github.com/benoitc/hackney/blob/master/NEWS.md)
- [Commits](benoitc/hackney@4.8.2...4.8.5)

Updates `mint` from 1.10.1 to 1.11.0
- [Changelog](https://github.com/elixir-mint/mint/blob/main/CHANGELOG.md)
- [Commits](elixir-mint/mint@v1.10.1...v1.11.0)

---
updated-dependencies:
- dependency-name: finch
  dependency-version: 0.24.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod
- dependency-name: hackney
  dependency-version: 4.8.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod
- dependency-name: mint
  dependency-version: 1.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from a team as a code owner October 11, 2026 01:23
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file elixir Pull requests that update Elixir code labels Oct 11, 2026
@cursor

cursor Bot commented Oct 11, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
Touches the optional HTTP client stack (including Mint security fixes) with pooling and protocol error-handling changes that can affect adapter behavior without any Tesla code changes.

Overview
Updates mix.lock only for the prod dependency group: Finch 0.23.0 → 0.24.0, Hackney 4.8.2 → 4.8.5, and Mint 1.10.1 → 1.11.0. Hackney’s bump also refreshes locked transitives (h2, quic, webtransport).

Mint 1.11 is the standout: it patches several HTTP/1 and HTTP/2 client CVEs (header/frame limits and transfer-encoding handling). Finch 0.24 tightens HTTP/1 pool behavior after errors/timeouts and aligns with Mint 1.11. Hackney 4.8.5 fixes GOAWAY/stream draining and related HTTP/2/HTTP/3 pooling issues.

No changes to mix.exs or Tesla adapter code—version ranges already allow these releases. Worth running the Finch/Hackney/Mint adapter tests to catch any edge-case behavior shifts.

Reviewed by Cursor Bugbot for commit d8edba2. Bugbot is set up for automated code reviews on this repo. Configure here.

@github-actions github-actions Bot added the chore label Oct 11, 2026
@github-actions
github-actions Bot enabled auto-merge (squash) October 11, 2026 01:23
@yordis
yordis disabled auto-merge October 11, 2026 01:35
@yordis
yordis merged commit c004b27 into master Oct 11, 2026
12 checks passed
@yordis
yordis deleted the dependabot/hex/prod-d24bf53722 branch October 11, 2026 01:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

chore dependencies Pull requests that update a dependency file elixir Pull requests that update Elixir code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant