ericmj

ericmj

Elixir Core Team

Hex v2.5.0 released

Release: Release v2.5.0 · hexpm/hex · GitHub

Announcement: Hex v25 released | Hex

Enhancements

  • Add organization-defined dependency policies that filter the package versions available during dependency resolution. An organization publishes a named policy through its repository, and a project opts into one with the policy config (HEX_POLICY, [org: "ORG", name: "NAME"] in the mix.exs :hex block, or mix hex.config). A policy constrains one or more repositories — typically the organization’s own repo and hexpm — and for each can block releases that:

    • carry a security advisory at or above a minimum severity
    • are retired for one of a given set of reasons
    • are newer than a release-age cooldown window

    Per-package allow/deny overrides take precedence over the restriction (an allow also exempts the release, and the most specific match wins), and versions already in mix.lock are never filtered. Use mix hex.policy show to summarize the active policy and mix hex.policy why PACKAGE to see why specific versions are blocked.

  • Add a configurable release-age cooldown to dependency resolution that withholds freshly published versions until they reach a minimum age, mitigating supply-chain attacks where a compromised release is pulled into projects before it can be detected and retired. Configure it with the cooldown config (HEX_COOLDOWN), accepting durations like 7d, 2w, or 1mo, and exempt specific repositories with cooldown_exclude_repos. Versions already in mix.lock, and locked versions that are retired or carry an advisory, bypass the cooldown so existing projects and security fixes are never held back.

  • Warn about packages with known security advisories during mix deps.get and mix deps.update

  • Add mix hex.search QUERY to search documentation from the terminal, and move package name search to mix hex.package search

  • Add --page and --format md options to mix hex.docs

  • Support JSON output in mix hex.outdated

  • Annotate cooldown-held versions in mix hex.outdated

  • Validate package files in mix hex.build

  • Accept LicenseRef- license identifiers in mix hex.build

  • Use subdomain URLs (PACKAGE.hexdocs.pm) for package docs

  • Escape terminal control sequences in server-provided x-hex-message headers

Bug fixes

  • Fix a crash when a server responds with an x-hex-message header
  • Deduplicate aliased security advisories
  • Warn when the OAuth session cannot be refreshed instead of silently sending unauthenticated requests

Deprecations

  • Deprecate mix hex.organization auth ORGANIZATION without --key; authenticate as a user with mix hex.user auth instead, or pass a pre-generated organization key with --key for CI
  • Deprecate authenticating to organization repositories with a stored key; a future release will require mix hex.user auth or a short-lived organization token
  • Deprecate authenticating to organization repositories with HEX_REPOS_KEY; authenticate per organization with mix hex.organization auth ORGANIZATION --key KEY (HEX_REPOS_KEY continues to authenticate the base hexpm repository and trusted mirrors)

Most Liked

arcanemachine

arcanemachine

The Hex folks have been busy lately! We all appreciate the work you’re doing!

abrookewood

abrookewood

Having those first three items built into the ecosystem is amazing work. Thank you.

Where Next?

Popular in News Top

Elixir
This release includes type inference of patterns to provide warnings for an initial set of constructs (binaries, maps, and atoms). It al...
New
josevalim
Announcement: Elixir v1.8 released - The Elixir programming language Release notes: Release v1.8.0 · elixir-lang/elixir · GitHub Thanks...
New
josevalim
Hi everyone, We have just released Elixir v1.8.0-rc.0. For more information, checkout the CHANGELOG. Please give it a try and give us f...
New
josevalim
ExDoc v0.29 is out with a new amazing feature: cheatsheets! Alongside guides and API reference, cheatsheets are another option for Elixi...
New
Elixir
Official announcement: Elixir v1.15 released - The Elixir programming language This release requires Erlang/OTP 24 and later. Elixir v1...
New
josevalim
Official announcement: Elixir v1.4 released - The Elixir programming language
New
Elixir
This release requires Erlang/OTP 27+ and is compatible with Erlang/OTP 29. 1. Enhancements EEx [EEx] Optimize compiler by flattening ex...
New
Elixir
1. Enhancements Elixir [Duration] Add Duration.to_iso8601/1 and Duration.from_iso8601/1 [Keyword] Add Keyword.intersect/2-3 to mirror th...
New
josevalim
Hello everyone, A vulnerability has been disclosed to Plug. All applications that set cookies based on user input is vulnerable. The vul...
New
josevalim
Announcement: Elixir v1.7 released - The Elixir programming language Release notes: Release v1.7.0 · elixir-lang/elixir · GitHub Thanks...
New

Other popular topics Top

danschultzer
None of the current solutions worked well for me, so I went ahead and built a user management system from scratch. This project took far...
548 29603 241
New
vertexbuffer
Hello, can anybody help here..? I have a list of players and I what to delete an element, but every for loop the list is reverting to ori...
New
lessless
I believe there are people here who are dealing with CSV files import on the daily basis, and since Excel is a really popular tool there ...
New
jononomo
I am trying to figure out how Mix knows whether the environment is test, dev, or prod – where is this set? Thanks.
New
belgoros
I’m not a pro in using Regex and can’t figure out why the following behaviour happens, especially if we take into account the difference ...
New
vonH
When I run the Plug and I recompile I wind up having to use Ctrl C to quit iex and start again. Witht the help of rlwrap I can use the cu...
New
klo
Got a question about when to concat vs. prepending items to list then reversing to achieve appending. So i know lists boil down to [1 | ...
New
AstonJ
We’ve put together this wiki for Phoenix LiveView - please feel free to add any info you feel is worth including. What is Phoenix LiveV...
New
jononomo
For some reason my phoenix channels are working for me in my local dev environment, but as soon as I deploy via Docker, I get a 403 error...
New
vonH
In asking this question I am more interested about the expressiveness of the language itself and less concerned about the availability of...
New

Latest on Elixir Forum

Elixir Forum

We're in Beta

About us Mission Statement