chore(deps): update hex dependencies (patch) - #428
Merged
Merged
Conversation
renovate
Bot
force-pushed
the
renovate/hex-dependencies-(patch)
branch
from
December 1, 2025 15:06
d509aa9 to
08d77bb
Compare
renovate
Bot
force-pushed
the
renovate/hex-dependencies-(patch)
branch
4 times, most recently
from
December 9, 2025 08:26
821c73e to
75a2462
Compare
renovate
Bot
force-pushed
the
renovate/hex-dependencies-(patch)
branch
2 times, most recently
from
December 18, 2025 00:14
aa6d847 to
a4c1480
Compare
renovate
Bot
force-pushed
the
renovate/hex-dependencies-(patch)
branch
2 times, most recently
from
December 27, 2025 13:26
a4ffecc to
685c319
Compare
renovate
Bot
force-pushed
the
renovate/hex-dependencies-(patch)
branch
3 times, most recently
from
January 15, 2026 19:31
83f3629 to
c0d0f79
Compare
renovate
Bot
force-pushed
the
renovate/hex-dependencies-(patch)
branch
4 times, most recently
from
January 28, 2026 20:46
360b00f to
248cb1c
Compare
renovate
Bot
force-pushed
the
renovate/hex-dependencies-(patch)
branch
from
February 2, 2026 15:10
248cb1c to
bf4c722
Compare
renovate
Bot
force-pushed
the
renovate/hex-dependencies-(patch)
branch
2 times, most recently
from
February 16, 2026 10:02
84516de to
e7dd394
Compare
renovate
Bot
force-pushed
the
renovate/hex-dependencies-(patch)
branch
2 times, most recently
from
February 26, 2026 14:50
c8d7144 to
ba42bd9
Compare
renovate
Bot
force-pushed
the
renovate/hex-dependencies-(patch)
branch
3 times, most recently
from
March 4, 2026 18:40
d0b4041 to
9b29ed1
Compare
renovate
Bot
force-pushed
the
renovate/hex-dependencies-(patch)
branch
2 times, most recently
from
March 13, 2026 12:06
8eb8a5e to
1bc89c1
Compare
renovate
Bot
force-pushed
the
renovate/hex-dependencies-(patch)
branch
from
March 17, 2026 21:42
1bc89c1 to
a36b7b4
Compare
renovate
Bot
force-pushed
the
renovate/hex-dependencies-(patch)
branch
2 times, most recently
from
March 26, 2026 04:45
cb670ea to
0bb7e09
Compare
renovate
Bot
force-pushed
the
renovate/hex-dependencies-(patch)
branch
2 times, most recently
from
May 21, 2026 18:38
a44db3c to
8d70c0d
Compare
renovate
Bot
force-pushed
the
renovate/hex-dependencies-(patch)
branch
2 times, most recently
from
May 29, 2026 15:11
2a2d0a9 to
a9edc81
Compare
renovate
Bot
force-pushed
the
renovate/hex-dependencies-(patch)
branch
from
June 5, 2026 10:50
a9edc81 to
47a1552
Compare
renovate
Bot
force-pushed
the
renovate/hex-dependencies-(patch)
branch
2 times, most recently
from
June 16, 2026 05:10
8bdfe7a to
a47b00e
Compare
renovate
Bot
force-pushed
the
renovate/hex-dependencies-(patch)
branch
from
June 22, 2026 16:58
a47b00e to
df917e7
Compare
renovate
Bot
force-pushed
the
renovate/hex-dependencies-(patch)
branch
3 times, most recently
from
July 9, 2026 11:13
f7613d1 to
da1b652
Compare
renovate
Bot
force-pushed
the
renovate/hex-dependencies-(patch)
branch
3 times, most recently
from
July 20, 2026 18:45
eb14225 to
e6cd397
Compare
renovate
Bot
force-pushed
the
renovate/hex-dependencies-(patch)
branch
8 times, most recently
from
July 29, 2026 15:03
61e043d to
893e9b5
Compare
renovate
Bot
force-pushed
the
renovate/hex-dependencies-(patch)
branch
4 times, most recently
from
August 4, 2026 21:15
211dfd4 to
e17279d
Compare
renovate
Bot
force-pushed
the
renovate/hex-dependencies-(patch)
branch
from
August 4, 2026 21:17
e17279d to
3c186fd
Compare
mathcolo
approved these changes
Aug 4, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.12.0→== 1.12.42.8.0→== 2.8.20.38.0→== 0.38.42.4.0→== 2.4.10.3.4→== 0.3.51.2.7→== 1.2.80.22.2→== 0.22.30.28.1→== 0.28.2Release Notes
mtrudel/bandit (bandit)
v1.12.4Compare Source
Fixes
Enhancements
v1.12.3Compare Source
Enhancements
v1.12.2Compare Source
Enhancements
Fixes
(GHSA-rhh8-5xw9-c3gm,
thanks @lukaszsamson!)
(GHSA-9q5m-g6v3-6772,
thanks @lukaszsamson!)
v1.12.1Compare Source
Fixes
beam-community/ex_machina (ex_machina)
v2.8.2Compare Source
Bug Fixes
v2.8.1Compare Source
Bug Fixes
philss/floki (floki)
v0.38.4Compare Source
Fixed
Fix a regression with
Floki.text/2when a document contains a DOCTYPE tag.It did not appear for most of the users because the "mochiweb" parser (default)
does not produce such tag.
This is similar to the fix from
v0.38.3.Thanks @foxbenjaminfox.
Fixed
v0.38.3Compare Source
Fixed
Floki.text/2when a document contains a "processing instruction" tag.This is the case for a XML tag.
v0.38.2Compare Source
Performance
This is another juicy patch version with performance improvements made by @preciz.
Please check the pull requests to see the improvements.
Fixed
Floki.attribute/3.v0.38.1Compare Source
Performance
This version contains major performance improvements in the following functions:
Floki.filter_out/2.Floki.find/2- with some improvements to specific selectors, like classesand attribute selectors.
Floki.text/2.Those functions are not only faster, but are now using less memory. Please check
the PRs related to this release if you want to better understand the numbers.
do_classes_matches?- #649filter_outfaster - #650HTMLTree.to_tupleconversion usingEnum.reduce- #657Finder.get_descendant_ids/2memory usage and speed - #660Finder.get_siblings/2memory usage and speed - #663FlatText.get/3memory usage and speed - #664Floki.Selector- #665All the improvements in this version were made by Barna Kovacs - @preciz,
so shout out and thanks to him!
Fixed
Remove a warning about an unused
require Loggerthat pops up when using Elixir v1.20.ueberauth/guardian (guardian)
v2.4.1Compare Source
Security
Guardian.revoke/3before invoking the tokenmodule's
revokeand the implementation'son_revokecallbacks. Previouslythe claims were read with
peek/1, which performs no signature verification,allowing a forged token to drive revocation of another session. Claim
validation such as expiry is still skipped so already expired tokens remain
revocable (GHSA-7975-hp3r-5qhv / CVE-2026-55735).
Guardian.Plug.Keys(GHSA-xqch-c77q-rgh5 /CVE-2026-54894). Deriving a Guardian key from attacker-influenced input no
longer creates atoms: namespace lookups resolve through
String.to_existing_atom/1(an unknown value reads back asnil), atoms areonly interned on the write path from developer-controlled keys, and session
and cookie names are derived as strings.
Guardian.Permissions.AtomEncoding.encode_value/3(GHSA-fjr5-7xrc-hmpj / CVE-2026-55733). Permission scopes reaching the
imported
encode/3entry point are now validated against the configuredpermission set before atom conversion instead of being interned unbounded.
Guardian.Permissions.encode_permissions!/1(GHSA-9qx2-v587-q3gg / CVE-2026-55734). Permission-set keys are now
validated, including integer-valued entries which previously bypassed
validation entirely, before being converted to atoms.
dariodf/lcov_ex (lcov_ex)
v0.3.5Compare Source
New Options
--partitions <number>Pass the --partitions option through to mix test to enable OS-level test partitioning. Requires the MIX_TEST_PARTITION environment variable to be set.
--no-compilePass the --no-compile option through to mix test to skip compilation before running tests.
phoenixframework/phoenix_live_view (phoenix_live_view)
v1.2.8Compare Source
Enhancements
You can now listen for the
phx:before-navigateevent and callevent.preventDefault()to cancel the navigation synchronously.This is mostly useful to prevent a "do you really want to leave" scenario when a user has unsaved changes, combined with a
beforeunloadlistener.:localto avoid node names being included in the tokenBug fixes
detail.lock()promise inphx:pushevent never resolving (#4351)elixir-ecto/postgrex (postgrex)
v0.22.3Compare Source
Postgrex.Notifications.listen/3(CVE-2026-58225)mathieuprog/tz (tz)
v0.28.2Compare Source
Configuration
📅 Schedule: (in timezone America/New_York)
* 0-3 * * *)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.