Commit Graph
10 Commits
Author SHA1 Message Date
Firehose Bot 310a5c0afd Bump phoenix_live_view to 1.2.12, closing last security advisory
The microprints git dep now allows phoenix_live_view ~> 1.2, so the
app can take the CVE-2026-64941 fix (open redirect in
validate_local_url!/2, fixed in 1.2.9). No 1.1.x backport existed.

blogex test lock follows to 1.2.12 so the library is tested against
the version the app ships with. mix deps.get now reports zero
security advisories.
2026-10-08 09:50:49 +01:00
Firehose Bot 3eec05b1d3 Update dependencies with security advisories
Bump all Hex deps with OSV advisories to fixed versions:
bandit 1.12.5, phoenix 1.8.15, plug 1.20.3, plug_crypto 2.2.0,
postgrex 0.22.4, decimal 3.1.1 (via ecto/ecto_sql 3.14), swoosh 1.28.1,
mint 1.11.0, hpax 1.1.0, finch 0.24.0, req 0.7.5, lazy_html 0.1.13.

Constraint changes: ecto_sql ~> 3.14 (ecto 3.14 requires decimal ~> 3.0),
req ~> 0.7.

phoenix_live_view stays at 1.1.27 (CVE-2026-64941, LOW): the fix landed
in 1.2.9 with no 1.1.x backport, and the microprints git dep pins
~> 1.1.0. Tracked in a follow-up yak.
2026-10-08 09:49:04 +01:00
mostalive 990af18ef8 v0.2.0 — RSS subscribe links
- Add release note for v0.2.0
- Bump version from 0.1.0 to 0.2.0
2026-07-08 17:00:11 +01:00
Firehose Bot fc583f19be microprints as https dep 2026-05-15 11:53:36 +01:00
mostalive 7a50f2d4e7 WIP microprints source now showing
also added go to install showboat and rodney for the next steps.

microprints work in qwan tracker, but not in firehose. some of the
rendering is in the project, maybe the library should provide sample
webpages.
2026-05-14 11:15:37 +01:00
mostalive 77b1972204 add mimemail dep 2026-05-07 17:05:52 +01:00
Willem van den Ende a380d0cb69 Add phx.gen.auth authentication scaffolding
- LiveView-based email/password auth via mix phx.gen.auth
- Auth links removed from public navigation (direct URL access only)
- Accounts context with User schema and token management
2026-04-01 20:31:13 +00:00
Firehose Bot cf7df3111f Linting rule only for dev and test
Production build broke because our custom lint rule was compiled. The
credo linter is not available and not necessary in production.

Solution: create separate directory for dev tools.
2026-03-24 14:41:58 +00:00
mostalive 3837a72059 update blog post, and run credo with 'pi' 2026-03-18 15:03:24 +00:00
Your Name bc14696f57 Static blog with front page summary
Goal: have a personal blog, and try out another point in the 'modular
app design with elixir' space.

Designing OTP systems with elixir had some interesting ideas.
2026-03-17 11:17:21 +00:00