Skip to content

Bump dependencies with security advisories - #6784

Merged
SteffenDE merged 1 commit into
phoenixframework:mainfrom
praialabs:bump-deps-advisories
Aug 3, 2026
Merged

Bump dependencies with security advisories#6784
SteffenDE merged 1 commit into
phoenixframework:mainfrom
praialabs:bump-deps-advisories

Conversation

@rhcarvalho

@rhcarvalho rhcarvalho commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Declared dependencies in mix.exs remain the same, as to not force downstream users to upgrade despite the advisories.

Versions used in development and CI (mix.lock) updated to the latest versions. Since all versions of Bandit prior to 1.12.1 have a security advisory, mix.exs was updated to reflect that, with no effect on downstream users.

@rhcarvalho
rhcarvalho force-pushed the bump-deps-advisories branch from 49e944d to 3b7d7df Compare August 2, 2026 21:11
Comment thread mix.exs Outdated
@rhcarvalho

Copy link
Copy Markdown
Contributor Author

Forgot to update the integration test project deps in 49e944d, done in 3b7d7df.

Declared dependencies in `mix.exs` remain the same, as to not force
downstream users to upgrade despite the advisories.

Versions used in development and CI (`mix.lock`) updated to the latest
versions. Since all versions of Bandit prior to 1.12.1 have a security
advisory, `mix.exs` was updated to reflect that, with no effect on
downstream users.
@rhcarvalho
rhcarvalho force-pushed the bump-deps-advisories branch from 3b7d7df to 64fa5bb Compare August 2, 2026 21:23
@rhcarvalho

Copy link
Copy Markdown
Contributor Author
  • Reverted changes to mix.exs
  • Bumped more versions in integration_test/mix.lock that had advisories (originally I targeted only mix.lock at the project root)

@SteffenDE
SteffenDE merged commit 4f7d0de into phoenixframework:main Aug 3, 2026
8 checks passed
@SteffenDE

Copy link
Copy Markdown
Member

🙌🏻

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants