ericmj

ericmj

Elixir Core Team

Hex v2.5.0 released

Release: Release v2.5.0 · hexpm/hex · GitHub

Announcement: Hex v25 released | Hex

Enhancements

  • Add organization-defined dependency policies that filter the package versions available during dependency resolution. An organization publishes a named policy through its repository, and a project opts into one with the policy config (HEX_POLICY, [org: "ORG", name: "NAME"] in the mix.exs :hex block, or mix hex.config). A policy constrains one or more repositories — typically the organization’s own repo and hexpm — and for each can block releases that:

    • carry a security advisory at or above a minimum severity
    • are retired for one of a given set of reasons
    • are newer than a release-age cooldown window

    Per-package allow/deny overrides take precedence over the restriction (an allow also exempts the release, and the most specific match wins), and versions already in mix.lock are never filtered. Use mix hex.policy show to summarize the active policy and mix hex.policy why PACKAGE to see why specific versions are blocked.

  • Add a configurable release-age cooldown to dependency resolution that withholds freshly published versions until they reach a minimum age, mitigating supply-chain attacks where a compromised release is pulled into projects before it can be detected and retired. Configure it with the cooldown config (HEX_COOLDOWN), accepting durations like 7d, 2w, or 1mo, and exempt specific repositories with cooldown_exclude_repos. Versions already in mix.lock, and locked versions that are retired or carry an advisory, bypass the cooldown so existing projects and security fixes are never held back.

  • Warn about packages with known security advisories during mix deps.get and mix deps.update

  • Add mix hex.search QUERY to search documentation from the terminal, and move package name search to mix hex.package search

  • Add --page and --format md options to mix hex.docs

  • Support JSON output in mix hex.outdated

  • Annotate cooldown-held versions in mix hex.outdated

  • Validate package files in mix hex.build

  • Accept LicenseRef- license identifiers in mix hex.build

  • Use subdomain URLs (PACKAGE.hexdocs.pm) for package docs

  • Escape terminal control sequences in server-provided x-hex-message headers

Bug fixes

  • Fix a crash when a server responds with an x-hex-message header
  • Deduplicate aliased security advisories
  • Warn when the OAuth session cannot be refreshed instead of silently sending unauthenticated requests

Deprecations

  • Deprecate mix hex.organization auth ORGANIZATION without --key; authenticate as a user with mix hex.user auth instead, or pass a pre-generated organization key with --key for CI
  • Deprecate authenticating to organization repositories with a stored key; a future release will require mix hex.user auth or a short-lived organization token
  • Deprecate authenticating to organization repositories with HEX_REPOS_KEY; authenticate per organization with mix hex.organization auth ORGANIZATION --key KEY (HEX_REPOS_KEY continues to authenticate the base hexpm repository and trusted mirrors)

Most Liked

arcanemachine

arcanemachine

The Hex folks have been busy lately! We all appreciate the work you’re doing!

abrookewood

abrookewood

Having those first three items built into the ecosystem is amazing work. Thank you.

Where Next?

Popular in News Top

josevalim
In Elixir we are continuously trying to improve the experience for developers learning the language. However, there are still common road...
New
josevalim
Hi everyone, We have just released the second release candidate for the next Elixir version: v1.7.0-rc.1. The CHANGELOG and precompiled...
New
jola
Hey everyone! It’s my enormous pleasure to present Hex Diff, an official hex.pm service for generating web-based diffs between package ve...
New
josevalim
Hi! :wave: I hope everyone is well! The Elixir team releases new versions every 6 months, typically every January and July. However, si...
New
josevalim
Elixir v1.14 brings many improvements to the debugging experience in Elixir and data-type inspection. It also includes a new abstraction...
New
Elixir
This release adds basic support for Erlang/OTP 26. When migrating to Erlang/OTP 26, keep it mind it changes how maps are stored interna...
New
Elixir
Overall, the compiler finds more bugs, for free, and it has never been faster: Infers types across clauses, finding more bugs and dead...
New

Other popular topics Top

minhajuddin
I have seen a lot of code which picks the first element from a list using Enum.at(0) instead of List.first. Is there a reason why people ...
New
grych
Hi folks, Few months ago I have announced the proof-of-concept of the library to manipulate the browsers DOM objects directly from Elixi...
639 54260 488
New
aadeshere1
I have a another noob question about loop. Since elixir is immutable, while loop is not directly possible. total = 10 while total != 0 ...
New
alice
Hey, Just curious what are the main benefits of Elixir compared to Clojure? When is Elixir more useful than Clojure and vice versa? Th...
New
romenigld
I am trying to run a deploy with docker and I successfully runned with this command: docker build -t romenigld/blog-prod . but when I t...
New
TunkShif
This post is an instruction guide to help you setup your Neovim for Elixir development from scratch. It includes general information on h...
274 42716 114
New

We're in Beta

About us Mission Statement