Update dependencies with security advisories

Bump all Hex deps with OSV advisories to fixed versions:
bandit 1.12.5, phoenix 1.8.15, plug 1.20.3, plug_crypto 2.2.0,
postgrex 0.22.4, decimal 3.1.1 (via ecto/ecto_sql 3.14), swoosh 1.28.1,
mint 1.11.0, hpax 1.1.0, finch 0.24.0, req 0.7.5, lazy_html 0.1.13.

Constraint changes: ecto_sql ~> 3.14 (ecto 3.14 requires decimal ~> 3.0),
req ~> 0.7.

phoenix_live_view stays at 1.1.27 (CVE-2026-64941, LOW): the fix landed
in 1.2.9 with no 1.1.x backport, and the microprints git dep pins
~> 1.1.0. Tracked in a follow-up yak.
This commit is contained in:
Firehose Bot
2026-10-08 09:49:04 +01:00
parent 4ed6aee47f
commit 3eec05b1d3
3 changed files with 35 additions and 35 deletions
+2 -2
View File
@@ -44,7 +44,7 @@ defmodule Firehose.MixProject do
{:bcrypt_elixir, "~> 3.0"},
{:phoenix, "~> 1.8.1"},
{:phoenix_ecto, "~> 4.5"},
{:ecto_sql, "~> 3.13"},
{:ecto_sql, "~> 3.14"},
{:postgrex, ">= 0.0.0"},
{:phoenix_html, "~> 4.1"},
{:phoenix_live_reload, "~> 1.2", only: :dev},
@@ -62,7 +62,7 @@ defmodule Firehose.MixProject do
depth: 1},
{:swoosh, "~> 1.16"},
{:gen_smtp, "~> 1.0"},
{:req, "~> 0.5"},
{:req, "~> 0.7"},
{:telemetry_metrics, "~> 1.0"},
{:telemetry_poller, "~> 1.0"},
{:gettext, "~> 0.26"},