#HexPM
People are doing seriously important work for the #ElixirLang ecosystem doesn't get talked about as much as it should. Thanks to @theerlef.bsky.social and folks like @maennchen.dev our security story is getting even better than it already was! Lets show our appreciation 🙏🏻

github.com/hexpm/hexpm/...
Integrate Vulnerability Database by maennchen · Pull Request #1276 · hexpm/hexpm
I spent today procrastinating on the things I should've actually been doing and instead looked at how you could integrate vulnerability databases into hex.pm. This PR does the following: Adds ...
github.com
December 3, 2024 at 1:10 PM
#TIL new hexdocs search is done in... Gleam with Lustre framework! #ElixirLang

github.com/hexpm/hexdoc...
GitHub - hexpm/hexdocs-search
Contribute to hexpm/hexdocs-search development by creating an account on GitHub.
github.com
October 29, 2025 at 12:55 PM
If folks are interested in contributing to an existing lustre project to learn, this might be a great place to start:

github.com/hexpm/hexdoc...
GitHub - hexpm/hexdocs-search
Contribute to hexpm/hexdocs-search development by creating an account on GitHub.
github.com
October 27, 2025 at 4:48 PM
If you've gotten frustrated with Docker Hub crashing when trying to find the latest hexpm Erlang or Elixir image tag, see fhunleth.github.io/latest_elixi.... Updated nightly, so should reflect patch builds for CVEs relatively quickly.
hexpm/elixir Docker Tags
fhunleth.github.io
April 13, 2026 at 1:43 PM
The hexpm package pages are now generated by MDEx and Lumis, thanks to @maennchen.dev !

- Better GitHub Flavored Markdown
- Light/Dark themes
- Syntax highlighting for more languages and sigils - HEEx, Python, Lua, Svelte, React, etc
And more...

#MyElixirStatus
June 16, 2026 at 6:32 PM
hexpm/bob manages docker hub images under hexpm username and Ubuntu builds used by eg GHA. erlef/otp_builds manages macOS builds used by elixir-lang.org/install.sh.

Both are community projects outside of OTP and Elixir core teams, ie no need to wait for their stamp of approval.
May 22, 2025 at 8:20 PM
Quick tip (hex.pm):

You want to check which library is using your library:
type in search bar: "depends:hexpm:PACKAGE_NAME"

ex: depends:hexpm:phoenix

also in url: hex.pm/packages?sea...

#hex.pm #ElixirLang #hexpm
January 2, 2025 at 1:45 AM
🚨 EUVD-2026-84539
📊 2.3/10
🏢 hexpm

📝 Insufficient Session Expiration vulnerability in OAuth token issuance in hexpm hexpm allows a user whose organization membership or session has ended to kee...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-84539

#cybersecurity #infosec #cve #euvd
September 22, 2026 at 5:04 PM
Ah, looks like @maennchen.dev added this two weeks ago. Neat! github.com/hexpm/hex/pu...
Warn on installation of vulnerable packages by maennchen · Pull Request #1150 · hexpm/hex
clean retired vulnerable retired & vulnerable
github.com
May 25, 2026 at 7:35 PM
Erlang Ecosystem Foundation is now a CVE Numbering Authority (CNA) assigning CVE IDs for vulnerabilities in active packages on Hex.pm + projects on GitHub under elixir-lang, erlang, erlef-cna, erlef, gleam-lang, & hexpm, unless covered by the scope of another CNA

cve.org/Media/News/i...
May 13, 2025 at 8:16 PM
... and by doing that learn something from the hexpm code base and get a code review from excellent chaps!
May 6, 2025 at 6:56 PM
Own OSS responsibilities:
* tackle some benchee issues
* evaluate a new feature for benchee to maybe make it into an elixirconf talk
* prepare a keynote about benchee due in less than a month

Thought: "...or I _could_ help the lovely @gleam.run community and my beloved hexpm in one fell swoop..."
May 6, 2025 at 6:56 PM
Any Elixir Phoenix folks up for adding this feature to the Hex API? It would be super useful for the Gleam team!
github.com/hexpm/hexpm/...
API filter by build tool · Issue #1300 · hexpm/hexpm
Hello friends! The Gleam packages website maintains a copy of all the packages with the gleam build tool, which it gets by traversing the Hex API from newest to oldest until it finds new releases w...
github.com
May 5, 2025 at 12:30 PM
Its a write-the-docs kind of morning for me.

#myelixirstatus #elixirlang #elixir #hexpm
June 1, 2025 at 2:51 PM
September 3, 2025 at 7:27 PM
Hex bob failing to build current Elixir docker images?
No amd64 image, only arm64, for latest OTP 27.3.4.1 security fix.

github.com/hexpm/bob/is...
#elixirlang
`debian-bullseye-20250610` images missing `linux/amd64` variants · Issue #217 · hexpm/bob
As per the title, all the newly built debian-bullseye-20250610 images are missing the linux/amd64 variants
github.com
June 17, 2025 at 6:45 AM
Ahh: hub.docker.com/r/hexpm/elix...

The project I was testing uses the official Docker images; I'll switch over to the Hex ones!
hub.docker.com
October 16, 2025 at 6:30 PM
CVE-2026-75542 - OAuth token exchange grants repository scopes for organizations the principal cannot access
CVE ID : CVE-2026-75542

Published : Aug. 24, 2026, 8:14 p.m. | 20 minutes ago

Description : Incorrect Authorization vulnerability in the OAuth token endpoint in h...
CVE-2026-75542 - OAuth token exchange grants repository scopes for organizations the principal cannot access
Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm allows an API key holding the repositories permission to read another organization's private packages. When an API key is exchanged for a token through the OAuth client_credentials grant, validate_scopes_against_key/2 in lib/hexpm_web/controllers/api/oauth_controller.ex admits a requested scope whenever the key carries …
cvefeed.io
August 24, 2026 at 9:01 PM
🟠 Hex PM is reporting a Partial Outage since 18:45 UTC

"Outage"

Affects: Hex.pm Website & API, Private repository (organizations), Private HexDocs (organizations)

Live timeline → https://pingoru.io/providers/hex-pm/incidents/7423548

#HexPM #HexPMDown
July 29, 2026 at 6:51 PM
> biggest challenges

1. Hiring
2. Integrations and missing open-source libraries

I knew and heard about hiring, anyone else knows more about 2? hexpm is maybe not as big as npm but the quality is through the roof. We don't need 10 bad packages for X.
December 14, 2024 at 6:06 AM
Hi 👋 I pinged the Hex.pm team about your issue. They weren’t able to replicate it, but this PR was the result .

If you have more info, feel free to let me know and I’ll relay it!

github.com/hexpm/hexpm/...
Simplify TFA by ericmj · Pull Request #1355 · hexpm/hexpm
Remove intermediate states and the distinction between having TFA enabled and authenticator app added.
github.com
December 11, 2025 at 1:38 PM
CVE-2026-32148 - Lockfile checksums not verified in Hex allows dependency integrity bypass
CVE ID : CVE-2026-32148

Published : April 30, 2026, 7:16 p.m. | 1 hour, 2 minutes ago

Description : Insufficient Verification of Data Authenticity vulnerability in hexpm hex (Hex.R...
CVE-2026-32148 - Lockfile checksums not verified in Hex allows dependency integrity bypass
Insufficient Verification of Data Authenticity vulnerability in hexpm hex (Hex.RemoteConverger module) allows dependency integrity bypass via unverified lockfile checksums. Hex stores checksums for dependencies in the mix.lock file to ensure reproducible and integrity-checked builds. However, Hex.RemoteConverger.verify_resolved/2 never executes checksum verification because the lock data returned by Hex.Utils.lock/1 uses string-based dependency …
cvefeed.io
April 30, 2026 at 9:38 PM
CVE-2026-21622 - Password Reset Tokens Do Not Expire
CVE ID : CVE-2026-21622

Published : March 5, 2026, 9:18 p.m. | 28 minutes ago

Description : Insufficient Session Expiration vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Accounts.PasswordReset' module) allows Accou...
CVE-2026-21622 - Password Reset Tokens Do Not Expire
Insufficient Session Expiration vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Accounts.PasswordReset' module) allows Account Takeover. Password reset tokens generated via the "Reset your password" flow do not expire. When a user requests a password reset, Hex sends an email containing a reset link with a token. This token remains valid indefinitely until used. …
cvefeed.io
March 5, 2026 at 10:23 PM
CVE-2026-21618 - Cross-site scripting (XSS) in OAuth Device Authorization screen
CVE ID : CVE-2026-21618

Published : Jan. 19, 2026, 3:15 p.m. | 2 hours, 17 minutes ago

Description : Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting...
CVE-2026-21618 - Cross-site scripting (XSS) in OAuth Device Authorization screen
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in hexpm hexpm/hexpm ('Elixir.HexpmWeb.SharedAuthorizationView' modules) allows Cross-Site Scripting (XSS). This vulnerability is associated with program files lib/hexpm_web/views/shared_authorization_view.ex and program routines 'Elixir.HexpmWeb.SharedAuthorizationView':render_grouped_scopes/3. This issue affects hexpm: from 617e44c71f1dd9043870205f371d375c5c4d886d before c692438684ead90c3bcbfb9ccf4e63c768c668a8, from pkg:github/hexpm/hexpm@617e44c71f1dd9043870205f371d375c5c4d886d before pkg:github/hexpm/hexpm@c692438684ead90c3bcbfb9ccf4e63c768c668a8; hex.pm: from 2025-10-01 before …
cvefeed.io
January 19, 2026 at 5:42 PM