• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

elixir-mint / mint
89%
main: 91%

Build:
Build:
LAST BUILD BRANCH: v1.10
DEFAULT BRANCH: main
Repo Added 11 Jun 2022 07:10AM UTC
Token xUOJjt5H7KcTvx6ikZQ7qWuMslrGKsjIE regen
Build 390 Last
Files 21
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

LAST BUILD ON BRANCH validate-http2-response-headers
branch: validate-http2-response-headers
CHANGE BRANCH
x
Reset
Sync Branches
  • validate-http2-response-headers
  • al/1.18
  • al/bump-ci
  • al/ci
  • al/client-settings
  • al/deps
  • al/elixir-1.10
  • al/elixir-1.11+
  • al/fix-leak
  • al/fix-tests
  • al/http2-logs
  • al/improve-defguard
  • al/modernize-ci
  • al/stream-docs
  • al/update-ci-versions
  • al/updates
  • allow-not-validating-target
  • allow_302_for_twitter_integration_test
  • andrea/code-coverage
  • andrea/dialyzer
  • andrea/fix-guard
  • andrea/new-ci-versions
  • apply-http2-client-settings
  • check-http2-content-length
  • chore/replace-deprecated-xref-exclude
  • clamp-tunnel-timeout
  • close_sockets_on_error
  • comp-time-optimization
  • configurable-test-ports
  • connect-tunnel-fixes
  • connection-docs-ref
  • contributing-and-testing-housekeeping
  • dialyzer-without-ignore-file
  • docs-for-open
  • dont-close-socket-on-recv-timeout
  • ericmj/deprecate-read-write
  • ericmj/fix-1xx-informational-response
  • ericmj/http2-connection-window-size
  • ericmj/http2-larger-default-windows
  • ericmj/inet4-option
  • ericmj/local-h2c-integration-tests
  • ericmj/support-elixir-1.12
  • ericmj/update-ubuntu
  • fix-cannot-build-docker-image-using-podman-compose
  • fix-dialyzer
  • fix-http1-tests-not-tagged-correctly
  • fix-incorrect-ci-badge
  • fix-warnings
  • fix/446-proxy-host-header
  • fix/http10-connect-tunnel
  • fix/humize_error_code_custom_error
  • forward-proxy-mode
  • http-fuzz-properties
  • http1-followups
  • http1-header-parsing
  • http1-line-size-limit
  • http1-pipelining
  • http1-reason-phrase
  • http2-connect-target
  • http2-followups
  • http2-frame-validation
  • http2-response-semantics
  • http2-server-push
  • https-tunnel-proxies
  • ignore-http2-window-update-on-closed-streams
  • ip-address-match-fun
  • ipv6-host-header
  • jv-default-store
  • jv-elixir-1-19
  • keep-http1-state-after-pipelined-responses
  • main
  • next_body_chunk
  • np/export-error-types
  • optimize-http/2-request-creation
  • patch-3
  • preserve_header_case
  • pvthuyen/add-support-for-cacerts-get
  • refs/heads/main
  • refs/pull/399/merge
  • refs/pull/407/merge
  • refs/pull/500/merge
  • return-responses-in-parse-order
  • rewrite-contributing-and-testing-doc
  • run-ci-against-erlang-27.1
  • stream-http1-headers
  • test-followups
  • tunnel-target-identity
  • unnecessary-rst-stream-2
  • unsafe-proxy-opts
  • update-deps
  • use-hpax-protocol-resize
  • use_local_http_bin_in_all_tests
  • v1.10
  • whatyouhide/issue311
  • wm-decompression
  • wm-docker-compose
  • wm-recv-response
  • wrap-tunnel-errors

19 Sep 2026 10:08PM UTC coverage: 88.627% (+0.2%) from 88.455%
388d5336422434bc759954d4c828f85d9ab1f511-PR-504

Pull #504

github

ericmj
Validate HTTP/2 response header fields and pseudo-headers

A :status value that isn't an integer, such as "abc" or "200 ", raised
ArgumentError from String.to_integer/1 inside stream/2, so a server could
crash the process streaming the response. Uppercase or otherwise invalid
field names, values containing NUL, CR or LF, undefined pseudo-headers,
duplicate :status fields, pseudo-headers after regular fields and
pseudo-headers in trailers were all delivered to the caller as if they
were regular headers.

Response header blocks are now checked against RFC 9113 8.2.1 and 8.3
before they're interpreted. A malformed block is a stream error: the
stream is reset with PROTOCOL_ERROR and the caller gets
{:invalid_status_header, value}, {:invalid_header_name, name},
{:invalid_header_value, name, value} or {:protocol_error, debug_data}.

A 1xx block after the final response is now reported as a pseudo-header
in trailers, which made the dedicated check for it unreachable.
Pull Request #504: Validate HTTP/2 response header fields and pseudo-headers

33 of 33 new or added lines in 1 file covered. (100.0%)

1543 of 1741 relevant lines covered (88.63%)

552.25 hits per line

Relevant lines Covered
Build:
Build:
1741 RELEVANT LINES 1543 COVERED LINES
552.25 HITS PER LINE
Source Files on validate-http2-response-headers
  • Tree
  • List 21
  • Changed 1
  • Source Changed 0
  • Coverage Changed 1
Coverage ∆ File Lines Relevant Covered Missed Hits/Line

Recent builds

Builds Branch Commit Type Ran Committer Via Coverage
388d5336... validate-http2-response-headers Validate HTTP/2 response header fields and pseudo-headers A :status value that isn't an integer, such as "abc" or "200 ", raised ArgumentError from String.to_integer/1 inside stream/2, so a server could crash the process streaming the response. U... Pull #504 19 Sep 2026 10:10PM UTC ericmj github
88.63
See All Builds (322)

Badge your Repo: mint

We detected this repo isn’t badged! Grab the embed code to the right, add it to your repo to show off your code coverage, and when the badge is live hit the refresh button to remove this message.

Could not find badge in README.

Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

Refresh
  • Settings
  • Repo on GitHub
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc