ericmj

ericmj

Elixir Core Team

Hex v2.5.0 released

Release: Release v2.5.0 · hexpm/hex · GitHub

Announcement: Hex v25 released | Hex

Enhancements

  • Add organization-defined dependency policies that filter the package versions available during dependency resolution. An organization publishes a named policy through its repository, and a project opts into one with the policy config (HEX_POLICY, [org: "ORG", name: "NAME"] in the mix.exs :hex block, or mix hex.config). A policy constrains one or more repositories — typically the organization’s own repo and hexpm — and for each can block releases that:

    • carry a security advisory at or above a minimum severity
    • are retired for one of a given set of reasons
    • are newer than a release-age cooldown window

    Per-package allow/deny overrides take precedence over the restriction (an allow also exempts the release, and the most specific match wins), and versions already in mix.lock are never filtered. Use mix hex.policy show to summarize the active policy and mix hex.policy why PACKAGE to see why specific versions are blocked.

  • Add a configurable release-age cooldown to dependency resolution that withholds freshly published versions until they reach a minimum age, mitigating supply-chain attacks where a compromised release is pulled into projects before it can be detected and retired. Configure it with the cooldown config (HEX_COOLDOWN), accepting durations like 7d, 2w, or 1mo, and exempt specific repositories with cooldown_exclude_repos. Versions already in mix.lock, and locked versions that are retired or carry an advisory, bypass the cooldown so existing projects and security fixes are never held back.

  • Warn about packages with known security advisories during mix deps.get and mix deps.update

  • Add mix hex.search QUERY to search documentation from the terminal, and move package name search to mix hex.package search

  • Add --page and --format md options to mix hex.docs

  • Support JSON output in mix hex.outdated

  • Annotate cooldown-held versions in mix hex.outdated

  • Validate package files in mix hex.build

  • Accept LicenseRef- license identifiers in mix hex.build

  • Use subdomain URLs (PACKAGE.hexdocs.pm) for package docs

  • Escape terminal control sequences in server-provided x-hex-message headers

Bug fixes

  • Fix a crash when a server responds with an x-hex-message header
  • Deduplicate aliased security advisories
  • Warn when the OAuth session cannot be refreshed instead of silently sending unauthenticated requests

Deprecations

  • Deprecate mix hex.organization auth ORGANIZATION without --key; authenticate as a user with mix hex.user auth instead, or pass a pre-generated organization key with --key for CI
  • Deprecate authenticating to organization repositories with a stored key; a future release will require mix hex.user auth or a short-lived organization token
  • Deprecate authenticating to organization repositories with HEX_REPOS_KEY; authenticate per organization with mix hex.organization auth ORGANIZATION --key KEY (HEX_REPOS_KEY continues to authenticate the base hexpm repository and trusted mirrors)

Most Liked

arcanemachine

arcanemachine

The Hex folks have been busy lately! We all appreciate the work you’re doing!

abrookewood

abrookewood

Having those first three items built into the ecosystem is amazing work. Thank you.

Where Next?

Popular in News Top

josevalim
In Elixir we are continuously trying to improve the experience for developers learning the language. However, there are still common road...
New
josevalim
NOTE: this is a focused thread, so we appreciate if everybody stayed on topic. Feel free to comment anything in regards to calendar forma...
New
Elixir
Release: Release v1.9.0 · elixir-lang/elixir · GitHub Releases The main feature in Elixir v1.9 is the addition of releases. A release is...
New
Elixir
Release: Release v1.9.2 · elixir-lang/elixir · GitHub 1. Enhancements Mix [mix release] Allow {:from_app, app_name} as a version for re...
New
Elixir
Release: Release v1.11.0 · elixir-lang/elixir · GitHub Over the last releases, the Elixir team has been focusing on the compiler, both i...
New
josevalim
Elixir v1.14 brings many improvements to the debugging experience in Elixir and data-type inspection. It also includes a new abstraction...
New
Elixir
Full announcement: Elixir v1.18 released: type checking of calls, LSP listeners, built-in JSON, and more - The Elixir programming languag...
New

Other popular topics Top

nobody
Hi! In PHP: $_SERVER[‘SERVER_ADDR’] - in Elixir? Searched the docs for ip address and the web, no good results. Thanks!
New
vertexbuffer
Hello, can anybody help here..? I have a list of players and I what to delete an element, but every for loop the list is reverting to ori...
New
openscript
Hello! Sorry for this astonishing simple question, but I’m really stuck. I try to set up the intellij-elixir plugin, but I don’t know ho...
New
alice
Hey, Just curious what are the main benefits of Elixir compared to Clojure? When is Elixir more useful than Clojure and vice versa? Th...
New
SoCreat
i’m a new one to elixir which editor can i use vs code? or atom? Thanks! :smiley:
New
AstonJ
Posting this to see if we can make things easier for people to get into Neovim. If you use Neovim and have a favourite distro please let ...
New

We're in Beta

About us Mission Statement