Skip to content

chore(deps): bump the patch-updates group across 1 directory with 19 updates - #1096

Closed
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/hex/patch-updates-f0916f1f21
Closed

chore(deps): bump the patch-updates group across 1 directory with 19 updates#1096
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/hex/patch-updates-f0916f1f21

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the patch-updates group with 9 updates in the / directory:

Package From To
ash_authentication_phoenix 2.17.1 2.17.2
ash_json_api 1.7.0 1.7.1
ash_oban 0.8.10 0.8.13
ash_pagify 1.5.1 1.5.3
ex_machina 2.8.0 2.8.2
live_debugger 1.0.1 1.0.2
oban_web 2.12.5 2.12.6
usage_rules 1.2.6 1.2.7
xml_builder 2.4.0 2.4.1

Updates ash_authentication_phoenix from 2.17.1 to 2.17.2

Release notes

Sourced from ash_authentication_phoenix's releases.

v2.17.2

Breaking Changes:

  • prevent logout CSRF by replacing GET sign-out with confirmation page by @​jimsynz

Bug Fixes:

Improvements:

Changelog

Sourced from ash_authentication_phoenix's changelog.

v2.17.2 (2026-07-20)

Breaking Changes:

  • prevent logout CSRF by replacing GET sign-out with confirmation page by @​jimsynz

Bug Fixes:

Improvements:

Commits

Updates ash_json_api from 1.7.0 to 1.7.1

Release notes

Sourced from ash_json_api's releases.

v1.7.1

Bug Fixes:

  • don't include type-less resources in filter schemas by @​zachdaniel
Changelog

Sourced from ash_json_api's changelog.

v1.7.1 (2026-07-07)

Bug Fixes:

  • don't include type-less resources in filter schemas by @​zachdaniel
Commits
  • c86e559 chore: release version v1.7.1
  • 49c76ea fix: don't include type-less resources in filter schemas
  • 50e6416 chore(deps): bump the production-dependencies group with 3 updates (#446)
  • See full diff in compare view

Updates ash_oban from 0.8.10 to 0.8.13

Release notes

Sourced from ash_oban's releases.

v0.8.13

Improvements:

  • honor special job-specific errors on chunk workers by Zach Daniel

Bug Fixes:

  • typo skip_unknown_input to skip_unknown_inputs by kevinschweikert

v0.8.12

Bug Fixes:

  • don't swap scheduler and worker priority by Zach Daniel

v0.8.11

Improvements:

  • support default_actor on triggers and scheduled actions by Conor Sinclair
Changelog

Sourced from ash_oban's changelog.

v0.8.13 (2026-08-19)

Improvements:

  • honor special job-specific errors on chunk workers by Zach Daniel

Bug Fixes:

  • typo skip_unknown_input to skip_unknown_inputs by kevinschweikert

v0.8.12 (2026-08-11)

Bug Fixes:

  • don't swap scheduler and worker priority by Zach Daniel

v0.8.11 (2026-07-24)

Improvements:

  • support default_actor on triggers and scheduled actions by Conor Sinclair
Commits
  • b609ef8 chore: release version v0.8.13
  • eec4aad fix: typo skip_unknown_input to skip_unknown_inputs
  • 796cb9d improvement: honor special job-specific errors on chunk workers
  • 0fff00d chore: release version v0.8.12
  • bc2a98a fix: don't swap scheduler and worker priority
  • 1445b47 chore: update docs
  • 2507570 chore: release version v0.8.11
  • 899e185 chore: update deps
  • 6596388 improvement: support default_actor on triggers and scheduled actions
  • See full diff in compare view

Updates ash_pagify from 1.5.1 to 1.5.3

Changelog

Sourced from ash_pagify's changelog.

v1.5.3 (2026-08-14)

v1.5.2 (2026-07-08)

Bug Fixes:

  • prevent infinite recursion in order_by validation with replace_invalid_params? by barretcunningham
Commits
  • f234693 chore: release version v1.5.3
  • e5f70f2 chore(deps): upgraded all deps
  • 6956a37 Merge pull request #272 from zebbra/dependabot/hex/patch-updates-1331bdf16f
  • 5b512d8 chore(deps): bump phoenix in the patch-updates group
  • d6f8a81 Merge pull request #271 from zebbra/dependabot/hex/patch-updates-4f713888c2
  • ffb580d chore(deps): bump ash from 3.31.0 to 3.31.2 in the patch-updates group
  • d5c89e7 Merge pull request #269 from zebbra/dependabot/hex/patch-updates-ad52d03bc9
  • e7a66b6 chore(deps-dev): bump ex_machina in the patch-updates group
  • b5403bc Merge pull request #268 from zebbra/dependabot/hex/patch-updates-7ec7dbffcb
  • 5ec5285 chore(deps-dev): bump styler in the patch-updates group
  • Additional commits viewable in compare view

Updates ash_phoenix from 2.3.23 to 2.3.24

Release notes

Sourced from ash_phoenix's releases.

v2.3.24

Bug Fixes:

  • Rename Ash.Resource.record() -> Ash.Resource.Record.t() by @​jimsynz
Changelog

Sourced from ash_phoenix's changelog.

v2.3.24 (2026-07-08)

Bug Fixes:

  • Rename Ash.Resource.record() -> Ash.Resource.Record.t() by @​jimsynz
Commits
  • 0d0421c chore: release version v2.3.24
  • 0d40671 fix: Rename Ash.Resource.record() -> Ash.Resource.Record.t()
  • 54030e4 chore(deps): Update hpax, mint and phoenix because of CVEs
  • 99c6526 chore: Fix reuse on macOS
  • 6d119c3 chore(deps): Unlock libgraph
  • a997152 chore(deps): bump the production-dependencies group across 1 directory with 5...
  • 1eb145a chore(deps-dev): bump credo in the dev-dependencies group (#478)
  • See full diff in compare view

Updates bandit from 1.12.0 to 1.12.5

Changelog

Sourced from bandit's changelog.

1.12.5 (20 Aug 2026)

Changes

  • Bound and cancel HTTP/2 sends blocked on the connection window (GHSA-xj8g-532w-jv94) (#671)
  • Honor Accept-Encoding q-values, the wildcard, and case-insensitive codings (#665)
  • Treat proxy-connection as a connection-specific header in HTTP/2 (#632)
  • Return FRAME_SIZE_ERROR for HEADERS/DATA frames too short for their flags (#652)
  • Treat abortive-close posix reasons as client closures in logging (#663)

Fixes

  • Validate HTTP/2 header field values for CR/LF/NUL (GHSA-x3gh-xhj4-3vq8) (#670)
  • Use PROTOCOL_ERROR for a zero WINDOW_UPDATE increment (#656)
  • Reject send_file ranges past EOF instead of emitting a negative Content-Length (#653)
  • Reject compressed WebSocket control frames regardless of the fin bit (#651)
  • Enforce the RFC9112 chunk-size grammar and reject repeated transfer-encoding (#631)
  • Fix typos (#627)
  • Fix non-deterministic compile-time code (#646)

Enhancements

  • Lazily precompile the invalid-field-value match pattern (#662)
  • Add tests for untested configuration options (#659)
  • Match the weak-etag prefix W/ explicitly (#657)
  • Do not duplicate an existing vary: accept-encoding header (#658)
  • Honor the close/keep-alive token inside a comma-separated Connection header (#655)
  • Initialize the per-stream receive window from the advertised initial_window_size (#654)
  • Keep track of body_length to avoid list iterations (#645)
  • Avoid per-header length/1 and option lookups in do_read_headers! (#614) (#626)

1.12.4 (27 July 2026)

Fixes

  • Properly send Connection: close header when client requests closure (#617)
  • Disallow transfer-encoding on HTTP/1.0 connections (#618)
  • Reject requests with multiple Host headers (#619)
  • Reject malformed header lines (#620)
  • Fix handling of chunk extensions (#621)

Enhancements

  • Tighten up CI against supply chain attacks (#623, thanks @​Totara-thib!)
  • Reorganize and increase coverage of HTTP/1 tests to better match RFC structure (#616)
  • Tolerate a leading newline on HTTP/1 requests (#622)
  • Send "100 Continue" interim response before reading body if client requests it (#624)

1.12.3 (25 July 2026)

... (truncated)

Commits
  • 9571499 Version bump to 1.12.5
  • f6914aa Bound and cancel HTTP/2 sends blocked on the connection window (GHSA-xj8g-532...
  • d38cf04 Validate HTTP/2 header field values for CR/LF/NUL (GHSA-x3gh-xhj4-3vq8) (#670)
  • cce7c5f Honor Accept-Encoding q-values, the wildcard, and case-insensitive codings (#...
  • eca1713 Fixup recent test noise
  • b65c235 Consolidate Plug.Conn.Adapter calling-process tests into adapter_test.exs (#667)
  • 4ccc008 Treat abortive-close posix reasons as client closures in logging (#663)
  • 274eb55 Lazily precompile the invalid-field-value match pattern (#662)
  • 10710de Enforce the chunk-size grammar in a single pass (#661)
  • d69202e Unify case-insensitive comma-separated header token checks (#660)
  • Additional commits viewable in compare view

Updates castore from 1.0.19 to 1.0.21

Commits

Updates ex_machina from 2.8.0 to 2.8.2

Release notes

Sourced from ex_machina's releases.

v2.8.2

2.8.2 (2026-08-02)

Bug Fixes

  • Support schemas with PolymorphicEmbed fields (#521) (8d58431)

v2.8.1

2.8.1 (2026-07-14)

Bug Fixes

  • Unblock common-config sync, pinned actions-sync release had no build output (#560) (029d074)
Changelog

Sourced from ex_machina's changelog.

2.8.2 (2026-08-02)

Bug Fixes

  • Support schemas with PolymorphicEmbed fields (#521) (8d58431)

2.8.1 (2026-07-14)

Bug Fixes

  • Unblock common-config sync, pinned actions-sync release had no build output (#560) (029d074)
Commits
  • 8dc7cf6 chore(main): release 2.8.2 (#567)
  • 8d58431 fix: support schemas with PolymorphicEmbed fields (#521)
  • f3e8e46 chore: sync files with beam-community/common-config (#566)
  • 4d5c649 chore(deps): bump actions/checkout from 7.0.0 to 7.0.1 (#565)
  • bda9e97 chore(deps): bump postgrex from 0.22.2 to 0.22.3 in the dev group (#564)
  • 5f39c8d chore(deps): bump ecto from 3.14.0 to 3.14.1 in the prod group (#563)
  • b72f281 chore(main): release 2.8.1 (#561)
  • 9352ea4 chore: sync files with beam-community/common-config (#562)
  • 029d074 fix: unblock common-config sync, pinned actions-sync release had no build out...
  • 09ac18a chore: sync files with beam-community/common-config (#551)
  • Additional commits viewable in compare view

Updates igniter from 0.8.2 to 0.8.3

Release notes

Sourced from igniter's releases.

v0.8.3

Bug Fixes:

  • ensure verbose is passed all the way down by Zach Daniel

  • properly check igniter.rms in --check by Zach Daniel

  • resolve Elixir 1.20 type-check warnings (#387) by Gilbert

Improvements:

  • add Igniter.Libs.Phoenix.web_module_for_router/2 (#393) by James Harton

  • update to Elixir 1.20 (#391) by ESmithByui

  • direct users to format command for unless refactor by Zach Daniel

Changelog

Sourced from igniter's changelog.

v0.8.3 (2026-07-26)

Bug Fixes:

  • ensure verbose is passed all the way down by Zach Daniel

  • properly check igniter.rms in --check by Zach Daniel

  • resolve Elixir 1.20 type-check warnings (#387) by Gilbert

Improvements:

  • add Igniter.Libs.Phoenix.web_module_for_router/2 (#393) by James Harton

  • update to Elixir 1.20 (#391) by ESmithByui

  • direct users to format command for unless refactor by Zach Daniel

Commits
  • 5a167c0 chore: release version v0.8.3
  • 83e46ba fix: ensure verbose is passed all the way down
  • 1357303 fix: properly check igniter.rms in --check
  • e7885c1 chore(deps): Update mint to 1.9.3
  • aceac7a test: cover declined igniter.install dependency prompt (#394)
  • e9d0084 improvement: add Igniter.Libs.Phoenix.web_module_for_router/2 (#393)
  • a4b5364 test: Add regression tests for nested keyword config updates (#392)
  • b29e9d6 chore: warnings
  • 2768e68 improvement: update to Elixir 1.20 (#391)
  • 479c495 improvement: direct users to format command for unless refactor
  • Additional commits viewable in compare view

Updates lazy_html from 0.1.11 to 0.1.12

Release notes

Sourced from lazy_html's releases.

v0.1.12

Changed

  • Relaxed elixir_make requirement (#35)
Changelog

Sourced from lazy_html's changelog.

Commits

Updates live_debugger from 1.0.1 to 1.0.2

Release notes

Sourced from live_debugger's releases.

v1.0.2

What's Changed

Full Changelog: software-mansion/live-debugger@v1.0.1...v1.0.2

Changelog

Sourced from live_debugger's changelog.

1.0.2 (2026-07-15)

Bug fixes

  • Fix recurring DETS "not properly closed" log in #997

Commits

Updates oban from 2.23.0 to 2.24.0

Release notes

Sourced from oban's releases.

v2.24.0

This release unifies configuration for queues, repos, and services, swaps opaque timing integers for readable durations, and backports per-entry cron timezones and attempt-preserving snoozes from Oban Pro.

⚙️ Unified Service Configuration

Configuration for queues, repos, and all services (formerly "plugins") is now entirely unified. This is a massive syntactic change, but it isn't all sugar. There's purpose behind the unification and the configuration hoisting.

Functionality like pruning jobs and rescuing orphaned jobs is essential to running Oban, and it shouldn't be an optional afterthought that's demoted as a "plugin" and buried in a guide. Now services are top level configuration just like the engine, notifier, and peer:

config :my_app, Oban,
  cron: [crontab: [{"0 2 * * *", MyApp.Nightly}]],
  pruner: [max_age: {7, :days}],
  lifeline: [rescue_after: {30, :minutes}],
  reindexer: Oban.Reindexer,
  ...

This configuration style should look familiar to anybody using oban-py. Building it is where we realized that these services are core functionality (in fact, it doesn't even have plugins).

Service module names are flatter as well. Since they're not considered plugins anymore, the Plugin namespace was a confusing misnomer—so Oban.Plugins.Cron is simply Oban.Cron, Oban.Plugins.Pruner is now Oban.Pruner, and so on.

Along with keyword options, the unified syntax supports bare modules, {module, opts} tuples, and disabling functionality altogether by passing false. The tuple variant makes it especially easy to swap core services out for alternatives (particularly useful for Pro 😉):

config :my_app, Oban,
+ engine: Oban.Pro.Engine,
- cron: {Oban.Cron, crontab: [...]},
+ cron: {Oban.Pro.Cron, crontab: [...]},
- lifeline: Oban.Lifeline,
+ lifeline: Oban.Pro.Lifeline,
- pruner: {Oban.Pruner, ...},
+ pruner: {Oban.Pro.Pruner, ...},
- queues: [...]
+ queues: {Oban.Pro.Queues, queues: [...]}

You'll see more about that in the Pro v1.8 release as well.

Finally, the repo option got the same treatment. Both log and get_dynamic_repo were really repo options, and the stand-alone log option was genuinely confusing. Now you can use the tuple format to pass those options through :repo directly:

repo: {MyApp.Repo, log: false, dynamic_repo: fn -> MyApp.Repo end}

Don't worry, these changes are fully backward compatible. Oban transparently rewrites older configuration formats into the correct format, all of the old plugin modules have backward compatible shims, and you can still provide plugins beyond the standard services.

🎁 Backports from Oban Pro

... (truncated)

Changelog

Sourced from oban's changelog.

v2.24.0 - 2026-08-25

Changes

  • [Oban] Top-level config for maintenance plugins

    Promote the common maintenance plugins to first-class configuration keys: cron, pruner, lifeline, and reindexer. Each desugars into a standard plugin entry and accepts the same forms used elsewhere in Oban:

    config :my_app, Oban,
      cron: [crontab: [{"0 2 * * *", MyApp.Nightly}]],
      pruner: [max_age: 60 * 60 * 24 * 7]
    

    A keyword list configures the default plugin, and a module or {module, opts} tuple can configure an alternative (making it an easy switch for Oban Pro, e.g. lifeline: Oban.Pro.Lifeline).

  • [Oban] Accept repo options through {repo, opts} tuple

    Configure repo-level options like logging and dynamic repo directly on the :repo key instead of at the top level:

    repo: {MyApp.Repo, log: false, dynamic_repo: fn -> MyApp.Repo end}
    

    The top-level log and get_dynamic_repo keys are soft-deprecated. They continue to work for backward compatibility, but the tuple form is now preferred and documented, keeping repo concerns grouped with the repo.

  • [Oban] Accept a module for the top-level :queues option

    The :queues option now accepts a {module, options} tuple in addition to a static keyword list, which hands queue management to an alternative implementation such as Oban Pro's Queues:

    queues: {Oban.Pro.Queues, queues: [default: 10]}
    

    The module is started as a plugin and controls which queues run, while a static keyword list keeps the built-in behavior of starting the listed queues on init. Queues run regardless of the :plugins setting in either form.

    Setting plugins: false now disables plugins configured through top-level servic keys, e.g. :cron or :pruner, rather than crashing during normalization.

  • [Oban] Rename maintenance plugins to top-level modules

    Plugins configured through top-level service keys now live directly in the Oban namespace:

    Oban.Plugins.Cron      -> Oban.Cron
    Oban.Plugins.Lifeline  -> Oban.Lifeline
    Oban.Plugins.Pruner    -> Oban.Pruner
    

... (truncated)

Commits
  • a315b6d Release v2.24
  • 2939e31 Restrict unique warning to insert states only
  • e7b8480 Hoist query imports to module level
  • 82362be Normalize plugin telemetry metadata errors
  • 7d52f9c Add dispatch cooldown tweaking to troubleshooting
  • b48d519 Roll back attempt and count snoozes on snooze
  • 47bb8b2 Support per-entry timezones in the crontab
  • 150c66f Expose stager as a top-level service option
  • 4952572 Return :ok from reindexer without leadership
  • 0ac7cbf Bump the production-dependencies group with 2 updates (#1492)
  • Additional commits viewable in compare view

Updates oban_web from 2.12.5 to 2.12.6

Changelog

Sourced from oban_web's changelog.

v2.12.6 - 2026-07-06

Enhancements

  • [Jobs] Build jobs through worker new/2 when available

    The new job drawer always built changesets with Job.new/2, bypassing worker-level defaults, validation, and Pro stages (recorded, chain, etc). Now we resolve the worker module and use its new/2 when it's loaded on the Web instance, falling back to Job.new/2 when the module isn't available.

Bug Fixes

  • [Dashboard] Resolve Elixir 1.20 compilation warnings

    Fix all of the warnings surfaced by the Elixir v1.20 type checker and upgrade any packages with errors or secutity warnings.

  • [Job Details] Fix clearing tags when editing jobs

    Treat blank tag input as an empty list when editing jobs, while leaving it as nil during job creation.

  • [Job Details] Add clipboard fallback for insecure contexts

    The navigator.clipboard API is only available in secure contexts (HTTPS or localhost), so copying job args, meta, and stacktraces failed with "navigator.clipboard is undefined" when Oban Web was served over plain HTTP. Fall back to execCommand so copy actions work in those environments.

  • [Job Details] Fix new job form ignoring the scheduled at time

    DateTime.from_iso8601/1 returns a three-element tuple, but we only matched on {:ok, datetime}. That clause never matched, so parsing always returned nil and jobs created with a scheduled time ran immediately instead. Match the full tuple so the selected time is applied.

  • [Job Details] Stack timeline labels on narrow screens

    State boxes in the job timeline placed the state label and timestamp in a row that was too narrow until the xl breakpoint, causing the timestamp to wrap awkwardly and the content to bleed. Now the label and timestamp are stacked below xl, switching to side-by-side where there's room to fit them.

  • [Cron] Fix cron and tag history queries for CockroachDB

    The cron history and tag suggestion queries relied on the Postgres-only implicit value column name. CRDB names it after the function instead, which caused an undefined_column error.

    Now the set-returning function is wrapped in a derived table with an explicit column alias for all engines.

Commits
  • 3c2d901 Release v2.12.6
  • 42ee475 Resolve Elixir 1.20 compilation warnings
  • d152fa7 Fix new job form ignoring the scheduled at time
  • 8eaf72d Fix cron and tag history queries for CockroachDB
  • 83e2540 Bump actions/cache from 4 to 6 (#187)
  • 13378ed Bump actions/checkout from 6 to 7 (#186)
  • f47a2d2 Fix clearing tags from edit forms (#184)
  • c992cee Stack timeline labels on narrow screens
  • 711ecea Bump ci matrix with Elixir v1.20 and OTP 29
  • 235ae3b Add clipboard fallback for insecure contexts
  • Additional commits viewable in compare view

Updates phoenix from 1.8.9 to 1.8.13

Release notes

Sourced from phoenix's releases.

v1.8.13

Bug fixes

  • Workaround issue where Mobile Chrome 149+ would not reconnect after tab is resumed (#6804)

v1.8.12

Bug fixes

  • [phx.gen.auth] Fix return_to session key not being cleared after logging in (#6798)
  • [Channels] Fix channel messages being invalidly dropped when receiving messages without a join_ref (introduced in 1.8.3) (#6800)

v1.8.11

Bug fixes

  • Fix Phoenix crashing on boot if Mix is available, but not started (#6789)

v1.8.10

Bug fixes

  • [Phoenix.CodeReloader] Fix "must restart your server" messages from code reloader when compile.lock mtime changes without a content change (#6753)
  • [Phoenix.Endpoint] add missing websocket options (#6758)
  • [phoenix.js] Close and retry the longpoll transport when a batch POST times out (#6769)
  • [phoenix.js] Release the stale reply binding of a buffered push (#6788)

Enhancements

  • [phx.gen.release] Use Bob API to find Docker images in phx.gen.release --docker
  • [Channels] Allow LongPoll transport token to be sent in header (this will change in 1.9)
  • [Phoenix.Router] Support plugs with options in pipe_throught (#6755)
  • [Phoenix.Token] document encode options (see the change in plug_crypto)
  • [phoenix.js] Ensure transport errors are identifiable (#6763)
Changelog

Sourced from phoenix's changelog.

v1.8.13 (2026-08-25)

Bug fixes

  • Workaround issue where Mobile Chrome 149+ would not reconnect after tab is resumed (#6804)

v1.8.12 (2026-08-20)

Bug fixes

  • [phx.gen.auth] Fix return_to session key not being cleared after logging in (#6798)
  • [Channels] Fix channel messages being invalidly dropped when receiving messages without a join_ref (introduced in 1.8.3) (#6800)

v1.8.11 (2026-08-12)

Bug fixes

  • Fix Phoenix crashing on boot if Mix is available, but not started (#6789)

v1.8.10 (2026-08-10)

Bug fixes

  • [Phoenix.CodeReloader] Fix "must restart your server" messages from code reloader when compile.lock mtime changes without a content change (#6753)
  • [Phoenix.Endpoint] add missing websocket options (#6758)
  • [phoenix.js] Close and retry the longpoll transport when a batch POST times out (#6769)
  • [phoenix.js] Release the stale reply binding of a buffered push (#6788)

Enhancements

  • [phx.gen.release] Use Bob API to find Docker images in phx.gen.release --docker
  • [Channels] Allow LongPoll transport token to be sent in header (this will change in 1.9)
  • [Phoenix.Router] Support plugs with options in pipe_throught (#6755)
  • [Phoenix.Token] document encode options (see the change in plug_crypto)
  • [phoenix.js] Ensure transport errors are identifiable (#6763)
Commits

Updates phoenix_live_view from 1.1.32 to 1.1.33

Release notes

Sourced from phoenix_live_view's releases.

v1.1.33

Security fixes

  • CVE-2026-64941: Fix open redirect in redirect/2 via ASCII tab, LF and CR
Changelog

Sourced from phoenix_live_view's changelog.

v1.1.33 (2026-08-10)

Security fixes

  • CVE-2026-64941: Fix open redirect in redirect/2 via ASCII tab, LF and CR
Commits

Updates postgrex from 0.22.2 to 0.22.4

Changelog

Sourced from postgrex's changelog.

v0.22.4 (2026-08-07)

  • Security
    • Escape comments on Postgrex.stream/4 (CVE-2026-66838)

v0.22.3 (2026-07-09)

  • Security
    • Escape dollar signs in channel names in Postgrex.Notifications.listen/3 (CVE-2026-58225)
Commits

Updates req from 0.6.2 to 0.6.3

Changelog

Sourced from req's changelog.

v0.6.3 (2026-07-16)

  • [Req.Test]: Fix __fetch_plug__/1 when called immediately after switching to shared mode.
Commits

Updates usage_rules from 1.2.6 to 1.2.7

Release notes

Sourced from usage_rules's releases.

v1.2.7

What's Changed

New Contributors

…updates

Bumps the patch-updates group with 9 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [ash_authentication_phoenix](https://github.com/team-alembic/ash_authentication_phoenix) | `2.17.1` | `2.17.2` |
| [ash_json_api](https://github.com/ash-project/ash_json_api) | `1.7.0` | `1.7.1` |
| [ash_oban](https://github.com/ash-project/ash_oban) | `0.8.10` | `0.8.13` |
| [ash_pagify](https://github.com/zebbra/ash_pagify) | `1.5.1` | `1.5.3` |
| [ex_machina](https://github.com/beam-community/ex_machina) | `2.8.0` | `2.8.2` |
| [live_debugger](https://github.com/software-mansion/live-debugger) | `1.0.1` | `1.0.2` |
| [oban_web](https://github.com/oban-bg/oban_web) | `2.12.5` | `2.12.6` |
| [usage_rules](https://github.com/ash-project/usage_rules) | `1.2.6` | `1.2.7` |
| [xml_builder](https://github.com/joshnuss/xml_builder) | `2.4.0` | `2.4.1` |



Updates `ash_authentication_phoenix` from 2.17.1 to 2.17.2
- [Release notes](https://github.com/team-alembic/ash_authentication_phoenix/releases)
- [Changelog](https://github.com/team-alembic/ash_authentication_phoenix/blob/v2.17.2/CHANGELOG.md)
- [Commits](team-alembic/ash_authentication_phoenix@v2.17.1...v2.17.2)

Updates `ash_json_api` from 1.7.0 to 1.7.1
- [Release notes](https://github.com/ash-project/ash_json_api/releases)
- [Changelog](https://github.com/ash-project/ash_json_api/blob/main/CHANGELOG.md)
- [Commits](ash-project/ash_json_api@v1.7.0...v1.7.1)

Updates `ash_oban` from 0.8.10 to 0.8.13
- [Release notes](https://github.com/ash-project/ash_oban/releases)
- [Changelog](https://github.com/ash-project/ash_oban/blob/main/CHANGELOG.md)
- [Commits](ash-project/ash_oban@v0.8.10...v0.8.13)

Updates `ash_pagify` from 1.5.1 to 1.5.3
- [Changelog](https://github.com/zebbra/ash_pagify/blob/main/CHANGELOG.md)
- [Commits](zebbra/ash_pagify@v1.5.1...v1.5.3)

Updates `ash_phoenix` from 2.3.23 to 2.3.24
- [Release notes](https://github.com/ash-project/ash_phoenix/releases)
- [Changelog](https://github.com/ash-project/ash_phoenix/blob/main/CHANGELOG.md)
- [Commits](ash-project/ash_phoenix@v2.3.23...v2.3.24)

Updates `bandit` from 1.12.0 to 1.12.5
- [Changelog](https://github.com/mtrudel/bandit/blob/main/CHANGELOG.md)
- [Commits](mtrudel/bandit@1.12.0...1.12.5)

Updates `castore` from 1.0.19 to 1.0.21
- [Commits](elixir-mint/castore@v1.0.19...v1.0.21)

Updates `ex_machina` from 2.8.0 to 2.8.2
- [Release notes](https://github.com/beam-community/ex_machina/releases)
- [Changelog](https://github.com/beam-community/ex_machina/blob/main/CHANGELOG.md)
- [Commits](beam-community/ex_machina@v2.8.0...v2.8.2)

Updates `igniter` from 0.8.2 to 0.8.3
- [Release notes](https://github.com/ash-project/igniter/releases)
- [Changelog](https://github.com/ash-project/igniter/blob/main/CHANGELOG.md)
- [Commits](ash-project/igniter@v0.8.2...v0.8.3)

Updates `lazy_html` from 0.1.11 to 0.1.12
- [Release notes](https://github.com/dashbitco/lazy_html/releases)
- [Changelog](https://github.com/dashbitco/lazy_html/blob/main/CHANGELOG.md)
- [Commits](dashbitco/lazy_html@v0.1.11...v0.1.12)

Updates `live_debugger` from 1.0.1 to 1.0.2
- [Release notes](https://github.com/software-mansion/live-debugger/releases)
- [Changelog](https://github.com/software-mansion/live-debugger/blob/main/CHANGELOG.md)
- [Commits](software-mansion/live-debugger@v1.0.1...v1.0.2)

Updates `oban` from 2.23.0 to 2.24.0
- [Release notes](https://github.com/oban-bg/oban/releases)
- [Changelog](https://github.com/oban-bg/oban/blob/main/CHANGELOG.md)
- [Commits](oban-bg/oban@v2.23.0...v2.24.0)

Updates `oban_web` from 2.12.5 to 2.12.6
- [Release notes](https://github.com/oban-bg/oban_web/releases)
- [Changelog](https://github.com/oban-bg/oban_web/blob/main/CHANGELOG.md)
- [Commits](oban-bg/oban_web@v2.12.5...v2.12.6)

Updates `phoenix` from 1.8.9 to 1.8.13
- [Release notes](https://github.com/phoenixframework/phoenix/releases)
- [Changelog](https://github.com/phoenixframework/phoenix/blob/v1.8.13/CHANGELOG.md)
- [Commits](phoenixframework/phoenix@v1.8.9...v1.8.13)

Updates `phoenix_live_view` from 1.1.32 to 1.1.33
- [Release notes](https://github.com/phoenixframework/phoenix_live_view/releases)
- [Changelog](https://github.com/phoenixframework/phoenix_live_view/blob/v1.1.33/CHANGELOG.md)
- [Commits](phoenixframework/phoenix_live_view@v1.1.32...v1.1.33)

Updates `postgrex` from 0.22.2 to 0.22.4
- [Release notes](https://github.com/elixir-ecto/postgrex/releases)
- [Changelog](https://github.com/elixir-ecto/postgrex/blob/master/CHANGELOG.md)
- [Commits](elixir-ecto/postgrex@v0.22.2...v0.22.4)

Updates `req` from 0.6.2 to 0.6.3
- [Release notes](https://github.com/wojtekmach/req/releases)
- [Changelog](https://github.com/wojtekmach/req/blob/main/CHANGELOG.md)
- [Commits](wojtekmach/req@v0.6.2...v0.6.3)

Updates `usage_rules` from 1.2.6 to 1.2.7
- [Release notes](https://github.com/ash-project/usage_rules/releases)
- [Changelog](https://github.com/ash-project/usage_rules/blob/main/CHANGELOG.md)
- [Commits](ash-project/usage_rules@v1.2.6...v1.2.7)

Updates `xml_builder` from 2.4.0 to 2.4.1
- [Commits](https://github.com/joshnuss/xml_builder/commits)

---
updated-dependencies:
- dependency-name: ash_authentication_phoenix
  dependency-version: 2.17.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-updates
- dependency-name: ash_json_api
  dependency-version: 1.7.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-updates
- dependency-name: ash_oban
  dependency-version: 0.8.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-updates
- dependency-name: ash_pagify
  dependency-version: 1.5.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-updates
- dependency-name: ash_phoenix
  dependency-version: 2.3.24
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-updates
- dependency-name: bandit
  dependency-version: 1.12.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-updates
- dependency-name: castore
  dependency-version: 1.0.21
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-updates
- dependency-name: ex_machina
  dependency-version: 2.8.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patch-updates
- dependency-name: igniter
  dependency-version: 0.8.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patch-updates
- dependency-name: lazy_html
  dependency-version: 0.1.12
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patch-updates
- dependency-name: live_debugger
  dependency-version: 1.0.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patch-updates
- dependency-name: oban
  dependency-version: 2.24.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-updates
- dependency-name: oban_web
  dependency-version: 2.12.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-updates
- dependency-name: phoenix
  dependency-version: 1.8.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-updates
- dependency-name: phoenix_live_view
  dependency-version: 1.1.33
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-updates
- dependency-name: postgrex
  dependency-version: 0.22.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-updates
- dependency-name: req
  dependency-version: 0.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-updates
- dependency-name: usage_rules
  dependency-version: 1.2.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patch-updates
- dependency-name: xml_builder
  dependency-version: 2.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file elixir Pull requests that update Elixir code labels Aug 28, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 31, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Aug 31, 2026
@dependabot
dependabot Bot deleted the dependabot/hex/patch-updates-f0916f1f21 branch August 31, 2026 00:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file elixir Pull requests that update Elixir code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants