Skip to content

chore(deps): update hex dependencies (patch) - #428

Merged
mathcolo merged 2 commits into
mainfrom
renovate/hex-dependencies-(patch)
Aug 4, 2026
Merged

mathcolo merged 2 commits into
mainfrom
renovate/hex-dependencies-(patch)

Conversation

@renovate

@renovate renovate Bot commented Nov 26, 2025 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
bandit (source) prod patch 1.12.0 → == 1.12.4
ex_machina (source) dev patch 2.8.0 → == 2.8.2
floki (source) dev patch 0.38.0 → == 0.38.4
guardian (source) prod patch 2.4.0 → == 2.4.1
lcov_ex (source) dev patch 0.3.4 → == 0.3.5
phoenix_live_view (source) prod patch 1.2.7 → == 1.2.8
postgrex (source) prod patch 0.22.2 → == 0.22.3
tz (source) prod patch 0.28.1 → == 0.28.2

Release Notes

mtrudel/bandit (bandit)

v1.12.4

Compare Source

Fixes
  • Properly send Connection: close header when client requests closure (#​617)
  • Disallow transfer-encoding on HTTP/1.0 connections (#​618)
  • Reject requests with multiple Host headers (#​619)
  • Reject malformed header lines (#​620)
  • Fix handling of chunk extensions (#​621)
Enhancements
  • Tighten up CI against supply chain attacks (#​623, thanks @​Totara-thib!)
  • Reorganize and increase coverage of HTTP/1 tests to better match RFC structure (#​616)
  • Tolerate a leading newline on HTTP/1 requests (#​622)
  • Send "100 Continue" interim response before reading body if client requests it (#​624)

v1.12.3

Compare Source

Enhancements
  • Cache connection-level data between HTTP/1 keepalives (#​603, thanks @​preciz!)

v1.12.2

Compare Source

Enhancements
  • Improve internal HTTP/2 error handling to be better about closing stream/connection
  • Coalesce header and body in to single transport send (#​606, thanks @​NelsonVides!)
  • Improve compression behaviour when streaming an explicitly length delimited body (#​605, thanks @​elibosley!)
  • Quiet WebSocket deserialization errors, add verbosity config lever (#​610, thanks @​ericmj!)
  • Send connection: close when we're at max_requests (#​613, thanks @​joshdchang!)
Fixes

v1.12.1

Compare Source

Fixes
  • Fix DoS issue with fragmented WebSocket frames (CVE-2026-65623, thanks @​PJUllrich!)
beam-community/ex_machina (ex_machina)

v2.8.2

Compare Source

Bug Fixes

v2.8.1

Compare Source

Bug Fixes
  • Unblock common-config sync, pinned actions-sync release had no build output (#​560) (029d074)
philss/floki (floki)

v0.38.4

Compare Source

Fixed
  • Fix a regression with Floki.text/2 when a document contains a DOCTYPE tag.
    It did not appear for most of the users because the "mochiweb" parser (default)
    does not produce such tag.

    This is similar to the fix from v0.38.3.

    Thanks @​foxbenjaminfox.

Fixed

v0.38.3

Compare Source

Fixed
  • Fix a regression with Floki.text/2 when a document contains a "processing instruction" tag.
    This is the case for a XML tag.

v0.38.2

Compare Source

Performance

This is another juicy patch version with performance improvements made by @​preciz.

Please check the pull requests to see the improvements.

Fixed
  • Fix compiler warnings for the upcoming Elixir v1.20.
  • Fix typespecs of Floki.attribute/3.
  • Fix documentation for some functions.

v0.38.1

Compare Source

Performance

This version contains major performance improvements in the following functions:

  • Floki.filter_out/2.
  • Floki.find/2 - with some improvements to specific selectors, like classes
    and attribute selectors.
  • Floki.text/2.

Those functions are not only faster, but are now using less memory. Please check
the PRs related to this release if you want to better understand the numbers.

All the improvements in this version were made by Barna Kovacs - @​preciz,
so shout out and thanks to him!

Fixed

Remove a warning about an unused require Logger that pops up when using Elixir v1.20.

ueberauth/guardian (guardian)

v2.4.1

Compare Source

Security
  • Verify a token's signature in Guardian.revoke/3 before invoking the token
    module's revoke and the implementation's on_revoke callbacks. Previously
    the claims were read with peek/1, which performs no signature verification,
    allowing a forged token to drive revocation of another session. Claim
    validation such as expiry is still skipped so already expired tokens remain
    revocable (GHSA-7975-hp3r-5qhv / CVE-2026-55735).
  • Fix unbounded atom creation in Guardian.Plug.Keys (GHSA-xqch-c77q-rgh5 /
    CVE-2026-54894). Deriving a Guardian key from attacker-influenced input no
    longer creates atoms: namespace lookups resolve through
    String.to_existing_atom/1 (an unknown value reads back as nil), atoms are
    only interned on the write path from developer-controlled keys, and session
    and cookie names are derived as strings.
  • Fix unbounded atom creation in Guardian.Permissions.AtomEncoding.encode_value/3
    (GHSA-fjr5-7xrc-hmpj / CVE-2026-55733). Permission scopes reaching the
    imported encode/3 entry point are now validated against the configured
    permission set before atom conversion instead of being interned unbounded.
  • Fix unbounded atom creation in Guardian.Permissions.encode_permissions!/1
    (GHSA-9qx2-v587-q3gg / CVE-2026-55734). Permission-set keys are now
    validated, including integer-valued entries which previously bypassed
    validation entirely, before being converted to atoms.
dariodf/lcov_ex (lcov_ex)

v0.3.5

Compare Source

New Options

--partitions <number>

Pass the --partitions option through to mix test to enable OS-level test partitioning. Requires the MIX_TEST_PARTITION environment variable to be set.

MIX_TEST_PARTITION=1 mix lcov --partitions 2
--no-compile

Pass the --no-compile option through to mix test to skip compilation before running tests.

mix lcov --no-compile
phoenixframework/phoenix_live_view (phoenix_live_view)

v1.2.8

Compare Source

Enhancements
  • Allow cancelling client-side navigation (#​4332)
    You can now listen for the phx:before-navigate event and call event.preventDefault() to cancel the navigation synchronously.
    This is mostly useful to prevent a "do you really want to leave" scenario when a user has unsaved changes, combined with a beforeunload listener.
  • Sign LiveView upload tokens as :local to avoid node names being included in the token
  • Ensure async tasks exit gracefully in LiveView tests (#​4348)
  • Allow opting focused form elements into DOM patching (#​4339)
Bug fixes
  • Fix server close handler not being reattached after a manual disconnect + connect (#​4341)
  • Fix detail.lock() promise in phx:push event never resolving (#​4351)
  • Fix live components not being correctly patched when changing their DOM ID (#​4338)
  • Gracefully handle missing upload refs (#​4354)
elixir-ecto/postgrex (postgrex)

v0.22.3

Compare Source

  • Security
    • Escape dollar signs in channel names in Postgrex.Notifications.listen/3 (CVE-2026-58225)
mathieuprog/tz (tz)

v0.28.2

Compare Source


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • Between 12:00 AM and 03:59 AM (* 0-3 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/hex-dependencies-(patch) branch from d509aa9 to 08d77bb Compare December 1, 2025 15:06
@renovate renovate Bot changed the title chore(deps): update dependency phoenix_live_view to == 1.1.18 chore(deps): update hex dependencies (patch) Dec 1, 2025
@renovate
renovate Bot force-pushed the renovate/hex-dependencies-(patch) branch 4 times, most recently from 821c73e to 75a2462 Compare December 9, 2025 08:26
@renovate
renovate Bot force-pushed the renovate/hex-dependencies-(patch) branch 2 times, most recently from aa6d847 to a4c1480 Compare December 18, 2025 00:14
@renovate
renovate Bot force-pushed the renovate/hex-dependencies-(patch) branch 2 times, most recently from a4ffecc to 685c319 Compare December 27, 2025 13:26
@renovate
renovate Bot force-pushed the renovate/hex-dependencies-(patch) branch 3 times, most recently from 83f3629 to c0d0f79 Compare January 15, 2026 19:31
@renovate
renovate Bot force-pushed the renovate/hex-dependencies-(patch) branch 4 times, most recently from 360b00f to 248cb1c Compare January 28, 2026 20:46
@renovate
renovate Bot force-pushed the renovate/hex-dependencies-(patch) branch from 248cb1c to bf4c722 Compare February 2, 2026 15:10
@renovate
renovate Bot force-pushed the renovate/hex-dependencies-(patch) branch 2 times, most recently from 84516de to e7dd394 Compare February 16, 2026 10:02
@renovate
renovate Bot force-pushed the renovate/hex-dependencies-(patch) branch 2 times, most recently from c8d7144 to ba42bd9 Compare February 26, 2026 14:50
@renovate
renovate Bot force-pushed the renovate/hex-dependencies-(patch) branch 3 times, most recently from d0b4041 to 9b29ed1 Compare March 4, 2026 18:40
@renovate
renovate Bot force-pushed the renovate/hex-dependencies-(patch) branch 2 times, most recently from 8eb8a5e to 1bc89c1 Compare March 13, 2026 12:06
@renovate
renovate Bot force-pushed the renovate/hex-dependencies-(patch) branch from 1bc89c1 to a36b7b4 Compare March 17, 2026 21:42
@renovate
renovate Bot force-pushed the renovate/hex-dependencies-(patch) branch 2 times, most recently from cb670ea to 0bb7e09 Compare March 26, 2026 04:45
@renovate
renovate Bot force-pushed the renovate/hex-dependencies-(patch) branch 2 times, most recently from a44db3c to 8d70c0d Compare May 21, 2026 18:38
@renovate
renovate Bot force-pushed the renovate/hex-dependencies-(patch) branch 2 times, most recently from 2a2d0a9 to a9edc81 Compare May 29, 2026 15:11
@renovate
renovate Bot force-pushed the renovate/hex-dependencies-(patch) branch from a9edc81 to 47a1552 Compare June 5, 2026 10:50
@renovate
renovate Bot force-pushed the renovate/hex-dependencies-(patch) branch 2 times, most recently from 8bdfe7a to a47b00e Compare June 16, 2026 05:10
@renovate
renovate Bot force-pushed the renovate/hex-dependencies-(patch) branch from a47b00e to df917e7 Compare June 22, 2026 16:58
@renovate
renovate Bot force-pushed the renovate/hex-dependencies-(patch) branch 3 times, most recently from f7613d1 to da1b652 Compare July 9, 2026 11:13
@renovate
renovate Bot force-pushed the renovate/hex-dependencies-(patch) branch 3 times, most recently from eb14225 to e6cd397 Compare July 20, 2026 18:45
@renovate
renovate Bot force-pushed the renovate/hex-dependencies-(patch) branch 8 times, most recently from 61e043d to 893e9b5 Compare July 29, 2026 15:03
@renovate
renovate Bot force-pushed the renovate/hex-dependencies-(patch) branch 4 times, most recently from 211dfd4 to e17279d Compare August 4, 2026 21:15
@renovate
renovate Bot force-pushed the renovate/hex-dependencies-(patch) branch from e17279d to 3c186fd Compare August 4, 2026 21:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant