Commit d7528c8
Fix checksum verification for dependencies in mix.lock
Checksum verification was not being performed due to a type mismatch
in pattern matching. Comparing atom-based names against string-based
lock data caused the verification to be silently skipped.
Fixes: GHSA-hmv9-4mfr-m92v
Fixes: CVE-2026-32148
Co-authored-by: Jonatan Männchen <jonatan@maennchen.ch>
Co-authored-by: Eric Meadows-Jönsson <eric.meadows.jonsson@gmail.com>1 parent b5a1e94 commit d7528c8
2 files changed
Lines changed: 54 additions & 4 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
569 | 569 | | |
570 | 570 | | |
571 | 571 | | |
572 | | - | |
573 | | - | |
574 | 572 | | |
575 | | - | |
| 573 | + | |
576 | 574 | | |
577 | 575 | | |
578 | 576 | | |
| |||
599 | 597 | | |
600 | 598 | | |
601 | 599 | | |
| 600 | + | |
602 | 601 | | |
| 602 | + | |
603 | 603 | | |
604 | 604 | | |
605 | 605 | | |
606 | 606 | | |
607 | 607 | | |
608 | 608 | | |
609 | | - | |
| 609 | + | |
610 | 610 | | |
611 | 611 | | |
612 | 612 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
198 | 198 | | |
199 | 199 | | |
200 | 200 | | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
| 227 | + | |
| 228 | + | |
| 229 | + | |
| 230 | + | |
| 231 | + | |
| 232 | + | |
| 233 | + | |
| 234 | + | |
| 235 | + | |
| 236 | + | |
| 237 | + | |
| 238 | + | |
| 239 | + | |
| 240 | + | |
| 241 | + | |
| 242 | + | |
| 243 | + | |
| 244 | + | |
| 245 | + | |
| 246 | + | |
| 247 | + | |
| 248 | + | |
| 249 | + | |
| 250 | + | |
201 | 251 | | |
0 commit comments