Bump phoenix_live_view to 1.2.12, closing last security advisory
The microprints git dep now allows phoenix_live_view ~> 1.2, so the app can take the CVE-2026-64941 fix (open redirect in validate_local_url!/2, fixed in 1.2.9). No 1.1.x backport existed. blogex test lock follows to 1.2.12 so the library is tested against the version the app ships with. mix deps.get now reports zero security advisories.
This commit is contained in:
+1
-1
@@ -48,7 +48,7 @@ defmodule Firehose.MixProject do
|
||||
{:postgrex, ">= 0.0.0"},
|
||||
{:phoenix_html, "~> 4.1"},
|
||||
{:phoenix_live_reload, "~> 1.2", only: :dev},
|
||||
{:phoenix_live_view, "~> 1.1.0"},
|
||||
{:phoenix_live_view, "~> 1.2"},
|
||||
{:lazy_html, ">= 0.1.0", only: :test},
|
||||
{:phoenix_live_dashboard, "~> 0.8.3"},
|
||||
{:esbuild, "~> 0.10", runtime: Mix.env() == :dev},
|
||||
|
||||
Reference in New Issue
Block a user