Skip to content

deps: partitioned_buffer dependency update 2026-09-02 - #22

Open
humberaquino wants to merge 4 commits into
mainfrom
deps/2026-09-02
Open

deps: partitioned_buffer dependency update 2026-09-02#22
humberaquino wants to merge 4 commits into
mainfrom
deps/2026-09-02

Conversation

@humberaquino

@humberaquino humberaquino commented Sep 2, 2026

Copy link
Copy Markdown

Scope: routine. Updated 7 dependencies, deferred 10, excluded 4 major-magnitude dependencies as out of this PR's scope (see "Majors excluded by scope" below), closed 9 of 11 open CVEs. Bumped partitioned_buffer 0.4.30.4.4. The two advisories left open are on req, a transitive dev-only dependency whose fixed version (0.6.1) is a pre-1.0 minor bump and therefore out of scope for a routine update.

No dependencies label exists in this repository, so this PR is unlabeled.

Updated

dep from → to tier
benchee 1.5.0 → 1.5.1 patch
credo 1.7.18 → 1.7.19 patch
ex_doc 0.40.1 → 0.40.3 patch
telemetry 1.4.1 → 1.4.2 patch
usage_rules 1.2.6 → 1.2.7 patch
hpax 1.0.3 → 1.0.4 cve
mint 1.7.1 → 1.9.3 cve

Each dependency was unlocked and re-resolved individually (mix deps.unlock <dep> + mix deps.get); no other lock entry moved as a side effect. No mix.exs dependency constraint was changed.

Version bump

partitioned_buffer 0.4.30.4.4 (patch bump). CHANGELOG.md updated.

Deferred

dep available reason detail
deep_merge 1.0.2 transitive-only not a direct dependency; pulled in by benchee
earmark_parser 1.4.46 transitive-only not a direct dependency; pulled in by ex_doc
erlex 0.2.9 transitive-only not a direct dependency; pulled in by dialyxir
glob_ex 0.1.12 transitive-only not a direct dependency; pulled in by igniter / rewrite
jason 1.4.5 transitive-only not a direct dependency; pulled in by credo, excoveralls, igniter, req, usage_rules
makeup 1.2.2 transitive-only not a direct dependency; pulled in by makeup_elixir / makeup_erlang
makeup_erlang 1.1.0 transitive-only not a direct dependency; pulled in by ex_doc
owl 0.13.1 transitive-only not a direct dependency; pulled in by igniter
sourceror 1.12.2 transitive-only not a direct dependency; pulled in by igniter / rewrite
statistex 1.1.1 transitive-only not a direct dependency; pulled in by benchee

Majors excluded by scope

dep tier current latest available CVE (if any)
req cve 0.5.17 0.7.4 GHSA-655f-mp8p-96gv, GHSA-px9f-whj3-246m
finch major 0.21.0 0.23.0
igniter major 0.7.9 0.8.3
spitfire major 0.3.11 0.4.0

All four are pre-1.0 packages where the available update raises the minor component, which this repository's dependency policy treats as a breaking change. All four are transitive (usage_rulesigniterreqfinch; igniterspitfire) and only present in the :dev environment. Each needs a deliberate major upgrade, out of this PR's scope.

CVEs

Severity labels are the ones hex prints during mix deps.get; cvss is the vector recorded by osv.dev. resolved_by comes from re-scanning the updated mix.lock against osv.dev, not from the advisory's own "fixed" field.

id aliases dep severity cvss resolved_by
EEF-CVE-2026-58226 CVE-2026-58226, GHSA-jj2p-32j7-whj2 hpax high CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N hpax@1.0.4
EEF-CVE-2026-56810 CVE-2026-56810, GHSA-c59h-fq4p-r36r mint high CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N mint@1.9.3
EEF-CVE-2026-58229 CVE-2026-58229, GHSA-qrfr-wh4c-3qhw mint high CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N mint@1.9.3
EEF-CVE-2026-59246 CVE-2026-59246, GHSA-8pf6-g464-h6h9 mint medium CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N mint@1.9.3
EEF-CVE-2026-59249 CVE-2026-59249, GHSA-x3x7-96vm-6h2w mint medium CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N mint@1.9.3
GHSA-2p26-p43x-fhp8 CVE-2026-49754, EEF-CVE-2026-49754 mint high CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N mint@1.9.3
GHSA-2pg6-44cx-c49v CVE-2026-48861, EEF-CVE-2026-48861 mint low CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N mint@1.9.3
GHSA-g586-ccqf-7x4r CVE-2026-48862, EEF-CVE-2026-48862 mint high CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N mint@1.9.3
GHSA-mjqx-c6f6-7rc2 CVE-2026-49753, EEF-CVE-2026-49753 mint medium CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N mint@1.9.3
GHSA-655f-mp8p-96gv CVE-2026-49755, EEF-CVE-2026-49755 req high CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N null
GHSA-px9f-whj3-246m CVE-2026-49756, EEF-CVE-2026-49756 req low CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N null

mint 1.9.3 was chosen as the lowest release clearing all eight of its advisories (osv.dev still reports one open advisory at 1.9.2); it stays within the ~> 1.6.2 or ~> 1.7 requirement finch places on it.

Open — blocker: both req advisories are fixed only from req 0.6.1 (0.6.0 still carries GHSA-655f-mp8p-96gv). 0.5.170.6.1 is a pre-1.0 minor bump, i.e. a major-magnitude change, so it is not applied here; see the req row under "Majors excluded by scope". Addressing it needs a deliberate major upgrade of req. req is transitive and :dev-only in this repository (usage_rulesigniterreq); it is not part of the published library or of the test environment.

Breaking changes adopted

None this PR.

Code changes

No code changes required — every updated dependency was a drop-in bump. The only files touched are mix.lock, mix.exs (version attribute) and CHANGELOG.md.

Migrations added

None this PR.

Config changes

None. This repository has no config/ directory and reads no application environment; none of the updated dependencies added or renamed a required configuration key. .credo.exs was not changed and mix credo --strict passes on credo 1.7.19.

Gate results

Gates are the steps of .github/workflows/ci.yml's lint matrix row (Elixir 1.19 / OTP 28, MIX_ENV=test), run locally on Elixir 1.19.5 / OTP 28.5 (matching .tool-versions) at the untouched base commit first (baseline) and again after every commit on this branch. The CI matrix additionally runs the test suite on Elixir 1.18 / OTP 28 and Elixir 1.17 / OTP 25, which were not exercised locally — CI is the evidence for those two rows.

gate venue result detail
mix deps.get local pass baseline and after each commit
mix deps.compile local pass baseline and after each commit
mix deps.unlock --check-unused local pass baseline and after each commit
mix compile --warnings-as-errors local pass baseline and after each commit
mix format --check-formatted local pass baseline and after each commit
mix credo --strict local pass baseline and after each commit; 0 issues
mix coveralls.json local pass baseline and after each commit; 55 tests, 0 failures, 100.0% coverage
mix dialyzer --plt + mix dialyzer --format github local pass baseline and after each commit; 0 errors
CI: PartitionedBuffer Test (Elixir 1.19.x / OTP 28.x) ci pass GitHub Actions
CI: PartitionedBuffer Test (Elixir 1.18.x / OTP 28.x) ci pass GitHub Actions
CI: PartitionedBuffer Test (Elixir 1.17.x / OTP 25.x) ci pass GitHub Actions
CI: CodeRabbit ci pass
CI: WhiteSource Security Check ci skipped reported neutral; recorded, not treated as a pass

Verification

Before being marked ready, this PR was independently re-checked against the rules it is supposed to follow, and all 7/7 checks pass: repo kind and version bump (a package block is present, so this is a published library; 0.4.30.4.4 is a patch bump and CHANGELOG.md gained an entry); CVE claims re-derived by re-scanning both the base and the head mix.lock against osv.dev, matching advisories by the union of their ids and aliases (9 cleared — 1 on hpax, 8 on mint — the 2 req advisories still open exactly as the table above says, and none introduced); major-boundary authorization (none of the seven moved dependencies crosses it); forbidden files (only CHANGELOG.md, mix.exs, mix.lock changed — no CI config, tests, .credo.exs or dialyzer ignore file); PR body completeness; self-contained content; and CI state (every resolvable check passed; the WhiteSource check reported neutral and was recorded as skipped). No CI job on this PR waits on a manual approval, so nothing was ignored for readiness and nothing was actioned.

@coderabbitai

coderabbitai Bot commented Sep 2, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Team

Run ID: 1176cead-17d3-4adc-8a4d-ed3a33d2fe42

📥 Commits

Reviewing files that changed from the base of the PR and between 83ef707 and a0905fc.

⛔ Files ignored due to path filters (1)
  • mix.lock is excluded by !**/*.lock
📒 Files selected for processing (2)
  • CHANGELOG.md
  • mix.exs

Included review availability: 4 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 10 reviews per hour.


📝 Walkthrough

Walkthrough

The project version changed from 0.4.3 to 0.4.4. The changelog now includes a Release 0.4.4 entry with a Maintenance note for routine dependency updates.

Merge Risk: ⚪ Minimal · up to a0905

This PR makes routine dependency and changelog updates without code or configuration changes, and the reported local checks pass. No actionable merge-blocking risk remains beyond normal CI completion and review.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 1 files. (1 skipped: 1 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the main change: a dependency update for partitioned_buffer, with the applicable date. It matches the pull request objectives and changed files.
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 1 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch deps/2026-09-02

Comment @coderabbitai help to get the list of available commands.

@humberaquino
humberaquino marked this pull request as ready for review September 2, 2026 17:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant