Skip to content

chore(deps): bump the production-dependencies group with 4 updates - #448

Merged
zachdaniel merged 1 commit into
mainfrom
dependabot/hex/production-dependencies-e0cb50b342
Aug 2, 2026
Merged

chore(deps): bump the production-dependencies group with 4 updates#448
zachdaniel merged 1 commit into
mainfrom
dependabot/hex/production-dependencies-e0cb50b342

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 4 updates: ash, igniter, phoenix and plug.

Updates ash from 3.29.3 to 3.31.0

Release notes

Sourced from ash's releases.

v3.31.0

Features:

Bug Fixes:

Improvements:

v3.30.1

Bug Fixes:

v3.30.0

Features:

... (truncated)

Changelog

Sourced from ash's changelog.

v3.31.0 (2026-07-28)

Features:

Bug Fixes:

Improvements:

v3.30.1 (2026-07-21)

Bug Fixes:

v3.30.0 (2026-07-21)

Features:

... (truncated)

Commits
  • 6c0357d chore: release version v3.31.0
  • 27af998 fix: order durations semantically instead of by struct field layout (#2809)
  • 1d0b599 improvement: avoid quadratic cost evaluating in-list filters at runtime (#2802)
  • eb7f5ef feat: add units constraint to Ash.Type.Duration (#2811)
  • a3c3c78 fix: compare with Comp in intersects function
  • eed63f2 feat: add mfa constraint to Ash.Type.Function for portable persistence (#2807)
  • 9159464 fix: compare a Decimal to a float instead of raising (#2805)
  • 90baa9f fix: ensure related aggregates set the proper resource
  • 4d27beb improvement: add strict? constraint to Ash.Type.UUIDv7 (#2795)
  • 023c35e feat: add all/1 builtin validation as the complement to any/1 (#2800)
  • Additional commits viewable in compare view

Updates igniter from 0.8.2 to 0.8.3

Release notes

Sourced from igniter's releases.

v0.8.3

Bug Fixes:

  • ensure verbose is passed all the way down by Zach Daniel

  • properly check igniter.rms in --check by Zach Daniel

  • resolve Elixir 1.20 type-check warnings (#387) by Gilbert

Improvements:

  • add Igniter.Libs.Phoenix.web_module_for_router/2 (#393) by James Harton

  • update to Elixir 1.20 (#391) by ESmithByui

  • direct users to format command for unless refactor by Zach Daniel

Changelog

Sourced from igniter's changelog.

v0.8.3 (2026-07-26)

Bug Fixes:

  • ensure verbose is passed all the way down by Zach Daniel

  • properly check igniter.rms in --check by Zach Daniel

  • resolve Elixir 1.20 type-check warnings (#387) by Gilbert

Improvements:

  • add Igniter.Libs.Phoenix.web_module_for_router/2 (#393) by James Harton

  • update to Elixir 1.20 (#391) by ESmithByui

  • direct users to format command for unless refactor by Zach Daniel

Commits
  • 5a167c0 chore: release version v0.8.3
  • 83e46ba fix: ensure verbose is passed all the way down
  • 1357303 fix: properly check igniter.rms in --check
  • e7885c1 chore(deps): Update mint to 1.9.3
  • aceac7a test: cover declined igniter.install dependency prompt (#394)
  • e9d0084 improvement: add Igniter.Libs.Phoenix.web_module_for_router/2 (#393)
  • a4b5364 test: Add regression tests for nested keyword config updates (#392)
  • b29e9d6 chore: warnings
  • 2768e68 improvement: update to Elixir 1.20 (#391)
  • 479c495 improvement: direct users to format command for unless refactor
  • Additional commits viewable in compare view

Updates phoenix from 1.8.8 to 1.8.9

Changelog

Sourced from phoenix's changelog.

1.8.9 (2026-07-07)

Security fixes

  • CVE-2026-56811: Add a max_channels_per_transport option (defaulting to 100) to prevent a single client from spawning an unbounded number of channels (processes), eventually exhausting the server's memory or process limit.
  • CVE-2026-56812: Prevent presence keys from colliding with Object.prototype properties members, crashing the JS Presence client
  • Enforce longpoll batch size introduced in 1.8.6. This is additional hardening against CVE-2026-32689. If your application sends events with a very high frequency and uses long polling, such that a single longpoll request would exceed 100 events, you should update to 1.8.7 first.
Commits
  • 734c8d1 Release v1.8.9
  • beffc4d fix presence keys colliding with object prototype chain
  • 16e295d Limit the number of channels a single transport process can join
  • 211ff62 Allow authToken to be a function (#6751)
  • 6cb2a83 Enforce longpoll batch size
  • 5bf1ce6 Add missing test file
  • 046accc Normalize route verb while grouping
  • 21d1462 Group routes by verb during compilation (#6739)
  • 9d3f1f6 phx.gen.release: Document new Bob Web UI (#6721)
  • afcac09 Bump undici from 7.25.0 to 7.28.0 (#6736)
  • Additional commits viewable in compare view

Updates plug from 1.20.2 to 1.20.3

Changelog

Sourced from plug's changelog.

v1.20.3 (2026-07-09)

Security

  • [Plug.Parsers.MULTIPART] Count files and skipped multipart parts towards the length limit (CVE-2026-56814)
  • [Plug.Conn.Cookies] Raise if ; is present in cookie attributes (CVE-2026-56813)
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the production-dependencies group with 4 updates: [ash](https://github.com/ash-project/ash), [igniter](https://github.com/ash-project/igniter), [phoenix](https://github.com/phoenixframework/phoenix) and [plug](https://github.com/elixir-plug/plug).


Updates `ash` from 3.29.3 to 3.31.0
- [Release notes](https://github.com/ash-project/ash/releases)
- [Changelog](https://github.com/ash-project/ash/blob/main/CHANGELOG.md)
- [Commits](ash-project/ash@v3.29.3...v3.31.0)

Updates `igniter` from 0.8.2 to 0.8.3
- [Release notes](https://github.com/ash-project/igniter/releases)
- [Changelog](https://github.com/ash-project/igniter/blob/main/CHANGELOG.md)
- [Commits](ash-project/igniter@v0.8.2...v0.8.3)

Updates `phoenix` from 1.8.8 to 1.8.9
- [Release notes](https://github.com/phoenixframework/phoenix/releases)
- [Changelog](https://github.com/phoenixframework/phoenix/blob/v1.8.9/CHANGELOG.md)
- [Commits](phoenixframework/phoenix@v1.8.8...v1.8.9)

Updates `plug` from 1.20.2 to 1.20.3
- [Changelog](https://github.com/elixir-plug/plug/blob/main/CHANGELOG.md)
- [Commits](https://github.com/elixir-plug/plug/commits/v1.20.3)

---
updated-dependencies:
- dependency-name: ash
  dependency-version: 3.31.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: igniter
  dependency-version: 0.8.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: phoenix
  dependency-version: 1.8.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: plug
  dependency-version: 1.20.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file elixir Pull requests that update elixir code labels Aug 1, 2026
@zachdaniel

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Aug 1, 2026

Copy link
Copy Markdown
Contributor Author

Looks like this PR is already up-to-date with main! If you'd still like to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

@zachdaniel
zachdaniel merged commit 6537d9d into main Aug 2, 2026
24 of 25 checks passed
@dependabot
dependabot Bot deleted the dependabot/hex/production-dependencies-e0cb50b342 branch August 2, 2026 17:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file elixir Pull requests that update elixir code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant