Vulnerability report system

· by Lois Soto Lopez and Eric Meadows-Jönsson

Today we announce the vulnerability report system, which will allow users to report and keep track of security vulnerabilies on Hex packages.

Read more...

Updates to Terms of Service and Code of Conduct

· by Eric Meadows-Jönsson

Today we are publishing updates to our Terms of Service and Code of Conduct.

Read more...

Announcing Two-factor Auth

· by Todd Resudek

Today we launched the option for two-factor authentication on hex.pm. Starting today, you can activate 2FA via the hex.pm dashboard. Many thanks to community contributors Bryan Paxton and Jeffrey Liao for their work on this project.

Read more...

Announcing Hex Diff

· by Johanna Larsson

I’m incredibly excited to announce the new web-based Hex package differ: diff.hex.pm, maintained by the Hex team! This is the result of the issue on the hex.pm Github repo and the discussion it started.

Read more...

Hex v0.20 released

· by Eric Meadows-Jönsson

A bit more than year ago we released private packages with organizations. With it you can add members to your organization and publish private packages only accessible by the members of the organization. The private packages are published to a separate repository (hosted by hex.pm) making sure they are separate from public packages.

Read more...

Hex v0.19 released

· by Eric Meadows-Jönsson

The v0.19 release includes an important security fix to anyone accessing Hex repositories through a mirror. A bug has been found that would allow a malicious mirror to serve modified versions of Hex packages. hex versions 0.14.0 to 0.18.2 and rebar3 versions 3.7.0 to 3.7.5 are vulnerable. Make sure to update to hex 0.19.0 and rebar3 3.8.0.

Read more...

Database migration

· by Eric Meadows-Jönsson

We are changing hosting provider from Heroku to Google Cloud. All applications have already been moved to Google Kubernetes Engine, but we sill have to move the database for hex.pm itself.

Read more...

Private Hexdocs

· by Eric Meadows-Jönsson

Today we are happy to announce the release of Hexdocs for private packages. All the private packages you have uploaded documentation for (the default when running mix hex.publish) are now available and browsable on Hexdocs.

Read more...

Announcing hex_core

· by Wojtek Mach

Today we are releasing the first version of hex_core, an Erlang library to interact with Hex.pm and other servers implementing Hex specifications.

Read more...

Hex v0.18 released

· by Eric Meadows-Jönsson

The v0.18 release includes improvements to API key handling and workflows when using continuous integration.

Read more...

Organizations going live

· by Eric Meadows-Jönsson

A few months ago we introduced the beta of private packages and organizations. In the meantime we have been building the billing system and iterating on organizations. We’d like to thank beta users for their valuable feedback.

Read more...

Private packages and organizations

· by Eric Meadows-Jönsson

We are announcing the addition of private packages on Hex.pm. With private packages you can publish packages to Hex.pm that only your organization members can access and download. With your organization you get a repository namespace on Hex.pm so that your private packages will not conflict with packages in the global, public repository. Go check out the private package documentation to learn exactly how it works.

Read more...