Update dependencies with security advisories
Bump all Hex deps with OSV advisories to fixed versions: bandit 1.12.5, phoenix 1.8.15, plug 1.20.3, plug_crypto 2.2.0, postgrex 0.22.4, decimal 3.1.1 (via ecto/ecto_sql 3.14), swoosh 1.28.1, mint 1.11.0, hpax 1.1.0, finch 0.24.0, req 0.7.5, lazy_html 0.1.13. Constraint changes: ecto_sql ~> 3.14 (ecto 3.14 requires decimal ~> 3.0), req ~> 0.7. phoenix_live_view stays at 1.1.27 (CVE-2026-64941, LOW): the fix landed in 1.2.9 with no 1.1.x backport, and the microprints git dep pins ~> 1.1.0. Tracked in a follow-up yak.
This commit is contained in:
+2
-2
@@ -44,7 +44,7 @@ defmodule Firehose.MixProject do
|
||||
{:bcrypt_elixir, "~> 3.0"},
|
||||
{:phoenix, "~> 1.8.1"},
|
||||
{:phoenix_ecto, "~> 4.5"},
|
||||
{:ecto_sql, "~> 3.13"},
|
||||
{:ecto_sql, "~> 3.14"},
|
||||
{:postgrex, ">= 0.0.0"},
|
||||
{:phoenix_html, "~> 4.1"},
|
||||
{:phoenix_live_reload, "~> 1.2", only: :dev},
|
||||
@@ -62,7 +62,7 @@ defmodule Firehose.MixProject do
|
||||
depth: 1},
|
||||
{:swoosh, "~> 1.16"},
|
||||
{:gen_smtp, "~> 1.0"},
|
||||
{:req, "~> 0.5"},
|
||||
{:req, "~> 0.7"},
|
||||
{:telemetry_metrics, "~> 1.0"},
|
||||
{:telemetry_poller, "~> 1.0"},
|
||||
{:gettext, "~> 0.26"},
|
||||
|
||||
Reference in New Issue
Block a user