Commit Graph
4 Commits
Author SHA1 Message Date
Firehose Bot 310a5c0afd Bump phoenix_live_view to 1.2.12, closing last security advisory
The microprints git dep now allows phoenix_live_view ~> 1.2, so the
app can take the CVE-2026-64941 fix (open redirect in
validate_local_url!/2, fixed in 1.2.9). No 1.1.x backport existed.

blogex test lock follows to 1.2.12 so the library is tested against
the version the app ships with. mix deps.get now reports zero
security advisories.
2026-10-08 09:50:49 +01:00
Firehose Bot 3eec05b1d3 Update dependencies with security advisories
Bump all Hex deps with OSV advisories to fixed versions:
bandit 1.12.5, phoenix 1.8.15, plug 1.20.3, plug_crypto 2.2.0,
postgrex 0.22.4, decimal 3.1.1 (via ecto/ecto_sql 3.14), swoosh 1.28.1,
mint 1.11.0, hpax 1.1.0, finch 0.24.0, req 0.7.5, lazy_html 0.1.13.

Constraint changes: ecto_sql ~> 3.14 (ecto 3.14 requires decimal ~> 3.0),
req ~> 0.7.

phoenix_live_view stays at 1.1.27 (CVE-2026-64941, LOW): the fix landed
in 1.2.9 with no 1.1.x backport, and the microprints git dep pins
~> 1.1.0. Tracked in a follow-up yak.
2026-10-08 09:49:04 +01:00
Firehose Bot 51ba85d492 upgrade nimble_publisher to 2.0 for mdex_native (replaces deprecated earmark) 2026-07-06 18:18:12 +01:00
mostalive ceeeb994fb Dokku setup script did not work that well, fixed by hand 2026-03-18 14:38:45 +00:00