<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <atom:link href="https://elixir.sydney/feed.xml" rel="self" type="application/rss+xml" />
  <title>Elixir Sydney</title>
  <link>https://elixir.sydney</link>
  <description>Meetups, news and BEAM jobs from the Elixir Sydney community.</description>
  <language>en-au</language>
  <item>
    <title>News: Kip Cole on Localize: the Livebook and the playground</title>
    <link>https://elixir.sydney/news/localize-talk-and-playgrounds</link>
    <pubDate>Thu, 20 Aug 2026 00:00:00 +1000</pubDate>
    <guid>https://elixir.sydney/news/localize-talk-and-playgrounds</guid>
    <category>news</category>
    <description><![CDATA[ <p><a href="https://elixir.sydney/speakers/kip-cole">Kip Cole</a> returned to the meetup tonight with
<a href="https://github.com/elixir-localize/localize">Localize</a>: locale-aware
formatting, validation and data access for Elixir, built on the Unicode CLDR
repository. It consolidates the whole ex_cldr family into a single package
covering numbers, currencies, dates and times, units, lists, collation and
MessageFormat 2, with CLDR data loaded at runtime and no compile-time code
generation.</p>
<!-- TODO: talk highlights and Q&A gems once the dust settles -->
<!-- TODO: add the video link to this article and to talks[].video in
     _events/2026-08-19-august-meetup.md when it lands on YouTube -->
<p>The best part: you don't need a project, or even Elixir installed, to play
with it.</p>
<ul>
<li>The <a href="https://playground.elixir-localize.com/">Localize playground</a> runs in
your browser, no code required. Pick a locale (there are plenty), then poke
at number, currency, date, time, unit and MessageFormat 2 formatting, with
CLDR pattern references built in.</li>
<li>The <a href="https://localize-inputs-playground.fly.dev/">inputs playground</a> shows
off the new LiveView input components across every CLDR locale: number,
unit and money inputs, plus date pickers that work in Gregorian, Buddhist,
Japanese imperial, Islamic, Persian, Hebrew and ROC calendars.</li>
<li>The <a href="https://github.com/elixir-localize/localize/blob/main/livebooks/elixir_sydney_august_2026.livemd">Livebook Kip built for tonight</a>
walks through the library hands-on. <a href="https://livebook.dev/run?url=https%3A%2F%2Fgithub.com%2Felixir-localize%2Flocalize%2Fblob%2Fmain%2Flivebooks%2Felixir_sydney_august_2026.livemd">Run it in Livebook</a>
and follow along at your own pace.</li>
</ul>
<p>If Kip's name rings a bell beyond the meetup, we've covered his
<a href="https://elixir.sydney/news/optimising-images-with-image">Image library</a> before; Localize is cut
from the same all-of-it-in-one-place cloth. Full recap and the talk video to
come; in the meantime, the <a href="https://elixir.sydney/events/august-2026">event page</a> has the details.</p> ]]></description>
  </item>

  <item>
    <title>News: Conference season: Goatmire, AshConf and the Alembic crew on tour</title>
    <link>https://elixir.sydney/news/conference-season-2026</link>
    <pubDate>Wed, 19 Aug 2026 16:15:00 +1000</pubDate>
    <guid>https://elixir.sydney/news/conference-season-2026</guid>
    <category>news</category>
    <description><![CDATA[ <p>The next two months are the busiest stretch of the BEAM calendar, and there's a
distinctly antipodean flavour to it this year. The season at a glance:</p>
<ul>
<li><a href="https://elixirconf.com/">ElixirConf US</a>, 10 to 11 September, Chicago and
online (a virtual ticket gets you both tracks).</li>
<li><a href="https://goatmire.com/">Goatmire Elixir</a>, 28 September to 3 October, Varberg,
Sweden, with <a href="https://goatmire.com/#ashconf">AshConf</a> capping it off.</li>
<li><a href="https://codebeameurope.com/">Code BEAM Europe</a>, 21 to 22 October, Haarlem,
Netherlands and online.</li>
</ul>
<h2><a href="https://elixir.sydney/news/conference-season-2026#goatmire" aria-hidden="true" class="anchor" id="goatmire"></a>Goatmire</h2>
<p>Goatmire is the one we keep hearing about: a community-first Elixir gathering
in the seaside town of Varberg that optimises for connection over scale. The
week runs free community workshops at Campus Varberg on the 28th and 29th, then
three conference days at Varbergs Teater, with day one doubling as NervesConf
EU. Speakers include Nerves core's Frank Hunleth, Sonic Pi creator Sam Aaron,
and Ash creator Zach Daniel among 35+ others.</p>
<h2><a href="https://elixir.sydney/news/conference-season-2026#ashconf-co-presented-by-alembic" aria-hidden="true" class="anchor" id="ashconf-co-presented-by-alembic"></a>AshConf, co-presented by Alembic</h2>
<p>Saturday 3 October is <a href="https://luma.com/wz4z0iz6">AshConf</a>, a dedicated
one-day Ash Framework conference presented by the Ash project together with
<a href="https://alembic.com.au/">Alembic</a>, with talks from Ash core team members, key
contributors and expert users. It's free for Erlang Ecosystem Foundation
annual supporting members (everyone else is invited to
<a href="https://opencollective.com/ash-framework">donate to the Ash Open Collective</a>),
lunch included. The call for speakers is open on Sessionize, and you can
<a href="https://luma.com/wz4z0iz6">register on Luma</a>.</p>
<p><img src="https://elixir.sydney/images/articles/ashconf-2026-josh-price.webp" alt="AshConf 2026 speaker card: Josh Price, Technical Director at Alembic, on Precision Domain Modeling" /></p>
<p>I'll be there too, talking about precision domain modelling with Ash and
Localize (yes, the library <a href="https://elixir.sydney/events/august-2026">Kip showed us this month</a>),
and what becomes possible when your domain model has better types. Zach's
<a href="https://x.com/ZachSDaniel1/status/2089069229509169632">announcement</a> was far
too kind about it.</p>
<h2><a href="https://elixir.sydney/news/conference-season-2026#familiar-faces-on-the-programme" aria-hidden="true" class="anchor" id="familiar-faces-on-the-programme"></a>Familiar faces on the programme</h2>
<p>The Goatmire week is thick with people who've stood in front of this meetup:</p>
<ul>
<li>Conor Sinclair (tech lead at Alembic) co-leads the free
<a href="https://goatmire.com/talk/ash-demystified">Ash Demystified</a> workshop with
Ash core's Barnabas
Jovanovics: a ground-level introduction to why developers won't shut up
about Ash.</li>
<li><a href="https://elixir.sydney/speakers/james-harton">James Harton</a> (principal engineer at Alembic, Ash
core team, author of Reactor and Ash Authentication) is doing double duty:
the <a href="https://goatmire.com/talk/beam-bots-robotics-on-the-beam">Beam Bots: Robotics on the BEAM</a>
talk with live robot demos, plus the
<a href="https://goatmire.com/talk/achieving-balance-in-the-workshop">Achieving Balance in the Workshop</a>
session where attendees assemble a Nerves-powered balance bot, drive it from
a Phoenix app on their phone, and take the robot home.</li>
<li><a href="https://elixir.sydney/speakers/rebecca-le">Rebecca Le</a> (Alembic, Ash core team, co-author of the
Ash book) presents
<a href="https://goatmire.com/talk/video-game-archaeology-with-elixir">Video Game Archaeology with Elixir</a>:
parsing Morrowind's 24-year-old binary format, modelling the game world with
Ash and Postgres, and browsing it all in LiveView.</li>
</ul>
<p>If Sweden is a stretch, the ElixirConf US virtual ticket is the easy way to get
a conference fix from this timezone, and Code BEAM Europe streams online too.
Closer to home, we'll see you at the
<a href="https://elixir.sydney/events/september-2026">September Hack Night</a>.</p> ]]></description>
  </item>

  <item>
    <title>Event: Hack Night</title>
    <link>https://elixir.sydney/events/september-2026</link>
    <pubDate>Wed, 19 Aug 2026 16:05:27 +1000</pubDate>
    <guid>https://elixir.sydney/events/september-2026</guid>
    <category>event</category>
    <description><![CDATA[ <p>We're switching it up for September: a Hack Night at Decidr in the Sydney CBD on
Wednesday 16th September. No talks this time, just desks, power and a room full of
people who like building things on the BEAM. Bring your ideas, your projects and
your laptop, and be ready to code.</p>
<p>Work on whatever you like: a side project, an open source itch, or the Phoenix app
you keep meaning to start. Plenty of us will be pairing up and sharpening our
AI-assisted coding workflows, so come see how other people drive their agents. It's
also a perfect night for beginners and the Elixir curious: there'll be experienced
folks at every table happy to pair and get you unstuck.</p>
<p>This one is in person only, no livestream.
<a href="https://luma.com/yimyd88z?utm_source=elixir.sydney-event">RSVP on Luma</a> to see the
venue address and entry instructions.</p>
<p>Talks return at the next meetup. Got one in you? Full-length or lightning, and
first-timers are very welcome. <a href="https://elixir.sydney/speak">Pitch us a talk</a>.</p> ]]></description>
  </item>

  <item>
    <title>News: August BEAM security advisories: Livebook, Guardian, Ash and more</title>
    <link>https://elixir.sydney/news/beam-security-advisories-august-2026</link>
    <pubDate>Wed, 19 Aug 2026 16:00:00 +1000</pubDate>
    <guid>https://elixir.sydney/news/beam-security-advisories-august-2026</guid>
    <category>news</category>
    <description><![CDATA[ <p>Three weeks on from the <a href="https://elixir.sydney/news/beam-security-advisories-july-2026">July round-up</a>
and the <a href="https://elixir.sydney/news/otp-cve-batch-july-2026">OTP batch</a>, the
<a href="https://cna.erlef.org/cves/">Erlang Ecosystem Foundation CNA</a> has published
another 25 CVEs. Nothing CRITICAL this time, but plenty of HIGHs, and two
packages where the obvious patch version doesn't cover everything, so read the
Fix lines carefully. As always: grouped by package, ordered by severity (CVSS),
worst first, and if you do one thing, run <code>mix hex.audit</code>.</p>
<p><strong>absinthe_federation</strong></p>
<ul>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-67585.html">CVE-2026-67585</a> <span class="sev sev-high">HIGH 8.7</span>: unauthenticated GraphQL <code>_entities</code> requests with crafted keys hit <code>String.to_atom/1</code>, exhausting the atom table and crashing the VM.</p>
<p><span class="fix-tag">Fix</span> Upgrade <a href="https://hex.pm/packages/absinthe_federation"><code>absinthe_federation</code></a> to <strong>0.9.3</strong>.</p>
</li>
</ul>
<p><strong>Livebook</strong></p>
<ul>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-66298.html">CVE-2026-66298</a> <span class="sev sev-high">HIGH 8.6</span>: untrusted notebook JS can synthesize keyboard events from the sandboxed iframe to trigger session shortcuts, forcing cell evaluation or a runtime restart.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-68746.html">CVE-2026-68746</a> <span class="sev sev-high">HIGH 7.7</span>: Teams identity enforcement fails open when a deployment group can't be resolved, granting unauthenticated access.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-66881.html">CVE-2026-66881</a> <span class="sev sev-high">HIGH 7.0</span>: relative path traversal in file entry imports lets a malicious notebook write files anywhere the Livebook process can.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-66885.html">CVE-2026-66885</a> <span class="sev sev-medium">MEDIUM 6.8</span>: login CSRF, missing OAuth state/nonce validation in Teams sign-in.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-66297.html">CVE-2026-66297</a> <span class="sev sev-medium">MEDIUM 5.0</span>: env var values interpolated unescaped into generated Docker/Fly.io deployment commands, so <code>$(...)</code> substitution runs.</p>
<p><span class="fix-tag">Fix</span> Upgrade <a href="https://livebook.dev/">Livebook</a> to <strong>0.19.9</strong> (or 0.18.7 on the older branch). One upgrade covers all five.</p>
</li>
</ul>
<p><strong>html_sanitize_ex</strong></p>
<ul>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-68749.html">CVE-2026-68749</a> <span class="sev sev-high">HIGH 8.2</span>: CPU-exhaustion DoS via unbounded greedy regex in the CSS scrubber, around 2.4s of CPU per 80KB style body.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-68750.html">CVE-2026-68750</a> <span class="sev sev-high">HIGH 8.2</span>: quadratic sibling traversal, 20k siblings holds a scheduler for about 1.7s.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-66370.html">CVE-2026-66370</a> <span class="sev sev-medium">MEDIUM 4.8</span>: the html5 scrubber keeps <code>form</code>/<code>formaction</code> attributes, so injected inputs can redirect submissions of an existing form.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-68747.html">CVE-2026-68747</a> <span class="sev sev-low">LOW 2.3</span>: CSS allowlist bypass, at-rules like <code>@import url(//attacker/style.css)</code> survive sanitisation.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-66829.html">CVE-2026-66829</a> <span class="sev sev-low">LOW 2.3</span>: <code>&lt;meta http-equiv=&quot;refresh&quot;&gt;</code> is retained, an open redirect.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-66843.html">CVE-2026-66843</a> <span class="sev sev-low">LOW 2.3</span>: <code>&lt;object data=...&gt;</code> URI validation only checks a lowercase <code>javascript:</code> prefix.</p>
<p><span class="fix-tag">Fix</span> Upgrade <a href="https://hex.pm/packages/html_sanitize_ex"><code>html_sanitize_ex</code></a> to <strong>1.5.4</strong>. Gotcha: 1.5.3 fixes five of the six but not the <code>@import</code> bypass, so don't stop there.</p>
</li>
</ul>
<p><strong>guardian</strong></p>
<ul>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-55735.html">CVE-2026-55735</a> <span class="sev sev-high">HIGH 8.2</span>: <code>Guardian.revoke/3</code> decodes tokens without verifying the signature, so an unauthenticated attacker with a forged JWT can revoke victims' sessions.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-55733.html">CVE-2026-55733</a> <span class="sev sev-medium">MEDIUM 6.9</span>: atom exhaustion in <code>Guardian.Permissions.AtomEncoding</code> on untrusted input.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-55734.html">CVE-2026-55734</a> <span class="sev sev-medium">MEDIUM 6.9</span>: atom exhaustion via untrusted permission map keys.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-54894.html">CVE-2026-54894</a> <span class="sev sev-medium">MEDIUM 6.9</span>: atom exhaustion in <code>Guardian.Plug.Keys</code> when key names come from attacker-influenced input like tenant IDs.</p>
<p><span class="fix-tag">Fix</span> Upgrade <a href="https://hex.pm/packages/guardian"><code>guardian</code></a> to <strong>2.4.1</strong>. One bump covers all four.</p>
</li>
</ul>
<p><strong>ash</strong></p>
<ul>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-67579.html">CVE-2026-67579</a> <span class="sev sev-high">HIGH 7.5</span>: filter expression injection via forged keyset pagination cursors. Deserialised <code>%Ash.Query.Call{}</code> structs bypass the safety gates, which means SQL injection on AshPostgres or in-process code execution on the ETS/Simple data layers.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-69659.html">CVE-2026-69659</a> <span class="sev sev-medium">MEDIUM 5.9</span>: keyset cursors accept zlib-compressed <code>binary_to_term</code> payloads with no size cap, kilobytes in, tens of megabytes out.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-70395.html">CVE-2026-70395</a> <span class="sev sev-low">LOW 2.1</span>: predicate injection in <code>manage_relationship</code> belongs_to lookups can leak secret lookup keys.</p>
<p><span class="fix-tag">Fix</span> Upgrade <a href="https://hex.pm/packages/ash"><code>ash</code></a> to <strong>3.31.3</strong>. Gotcha: 3.31.1 fixed the two lower ones but not the HIGH filter injection, which landed three days later. Go straight to 3.31.3.</p>
</li>
</ul>
<p><strong>oidcc_plug</strong></p>
<ul>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-66883.html">CVE-2026-66883</a> <span class="sev sev-medium">MEDIUM 6.3</span>: a case-sensitive <code>&quot;User-Agent&quot;</code> header lookup silently disables session user-agent binding even with <code>check_useragent: true</code>.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-66884.html">CVE-2026-66884</a> <span class="sev sev-low">LOW 2.1</span>: the authorization callback accepts callbacks missing session state, a CSRF enabling forced login.</p>
<p><span class="fix-tag">Fix</span> Upgrade <a href="https://hex.pm/packages/oidcc_plug"><code>oidcc_plug</code></a> to <strong>0.5.0</strong>.</p>
</li>
</ul>
<p><strong>cowlib</strong></p>
<ul>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-43971.html">CVE-2026-43971</a> <span class="sev sev-medium">MEDIUM 6.3</span>: <code>cow_link:link/1</code> interpolates unescaped <code>&gt;</code> in target URIs and <code>&quot;</code>/<code>\</code> in rel values, letting attackers smuggle arbitrary Link header entries.</p>
<p><span class="fix-tag">Fix</span> No tagged release at time of writing; the fix is commit <code>89da27e</code>. If you build Link headers from user input, sanitise it (reject <code>&gt;</code> in targets and quotes/backslashes in rel values) and watch for the next <code>cowlib</code> release.</p>
</li>
</ul>
<p><strong>postgrex</strong></p>
<ul>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-66838.html">CVE-2026-66838</a> <span class="sev sev-medium">MEDIUM 5.9</span>: SQL injection via the <code>:comment</code> option of <code>Postgrex.stream/4</code>, where a <code>*/</code> closes the comment block early. Only <code>stream/4</code> skips the comment validation.</p>
<p><span class="fix-tag">Fix</span> Upgrade <a href="https://hex.pm/packages/postgrex"><code>postgrex</code></a> to <strong>0.22.4</strong>.</p>
</li>
</ul>
<p><strong>oaskit</strong></p>
<ul>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-66296.html">CVE-2026-66296</a> <span class="sev sev-medium">MEDIUM 5.1</span>: reflected XSS, the default HTML error handler interpolates request-controlled values unescaped.</p>
<p><span class="fix-tag">Fix</span> Upgrade <a href="https://hex.pm/packages/oaskit"><code>oaskit</code></a> to <strong>0.14.1</strong>, or set <code>html_errors: false</code>.</p>
</li>
</ul>
<p><strong>phoenix_live_view</strong></p>
<ul>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-64941.html">CVE-2026-64941</a> <span class="sev sev-low">LOW 2.1</span>: open redirect, <code>validate_local_url!/2</code> didn't strip the ASCII tab/newline characters browsers ignore when parsing URLs.</p>
<p><span class="fix-tag">Fix</span> Upgrade <a href="https://hex.pm/packages/phoenix_live_view"><code>phoenix_live_view</code></a> to <strong>1.2.9</strong> (or 1.1.33 / 1.0.19 on older branches). Yes, again; we bumped this site's lockfile too.</p>
</li>
</ul>
<h2><a href="https://elixir.sydney/news/beam-security-advisories-august-2026#what-to-do" aria-hidden="true" class="anchor" id="what-to-do"></a>What to do</h2>
<ol>
<li>Run <code>mix hex.audit</code>, and let Hex 2.5 fail CI on a vulnerable lockfile (see
the <a href="https://elixir.sydney/news/hex-2-5">Hex 2.5 write-up</a>).</li>
<li>Patch worst first: the Guardian <code>revoke/3</code> signature bypass and the Livebook
trio if you run either, then the DoS pile.</li>
<li>Mind the two version gotchas: <code>html_sanitize_ex</code> needs <strong>1.5.4</strong> (not 1.5.3)
and <code>ash</code> needs <strong>3.31.3</strong> (not 3.31.1).</li>
<li>Watch the <a href="https://cna.erlef.org/cves/">EEF CNA advisory list</a>.</li>
</ol>
<p>The theme this month is untrusted input reaching places that assume trust:
atoms, filters, cursors, sanitisers. Nothing here is a remote takeover of a
patched stack, but the Guardian and Ash ones are genuinely nasty in the wrong
app shape, so run the audit today rather than at the next meetup.</p> ]]></description>
  </item>

  <item>
    <title>News: September is Hack Night at Decidr</title>
    <link>https://elixir.sydney/news/hack-night-september-2026</link>
    <pubDate>Wed, 19 Aug 2026 15:45:00 +1000</pubDate>
    <guid>https://elixir.sydney/news/hack-night-september-2026</guid>
    <category>news</category>
    <description><![CDATA[ <p>Our September meetup is a <a href="https://elixir.sydney/events/september-2026">Hack Night</a>: Wednesday
16 September, 5:30 PM at Decidr in the Sydney CBD. No talks, no schedule, just a
room full of BEAM people, their laptops and their pet projects. Bring your ideas,
your projects and your laptop, and be ready to code.</p>
<p>It's a great excuse to finally start that thing, and an even better one to watch
how other people work: plenty of us will be pairing on Elixir and comparing
AI-assisted coding workflows on real code. If you're new to Elixir or just
curious, this is honestly the best possible first meetup. There's no pressure to
know anything yet, and you'll have experienced folks at the table to pair with
and get you unstuck.</p>
<p>One thing to note: unlike our usual meetups, this one is in person only, with no
livestream. <a href="https://luma.com/yimyd88z">RSVP on Luma</a>
to see the venue address and entry instructions, and we'll see you on the 16th.</p> ]]></description>
  </item>

  <item>
    <title>Event: Kip Cole on Localize</title>
    <link>https://elixir.sydney/events/august-2026</link>
    <pubDate>Wed, 19 Aug 2026 00:00:00 +1000</pubDate>
    <guid>https://elixir.sydney/events/august-2026</guid>
    <category>event</category>
    <description><![CDATA[ <p>We're back at Decidr in the Sydney CBD on 19th August, and we've got one of our favourite
speakers and most prolific open source contributors: Kip Cole, talking about his shiniest
new library, <a href="https://github.com/elixir-localize/localize">Localize</a>.
<a href="https://luma.com/ujcqkbju?utm_source=elixir.sydney-event">RSVP on Luma</a>.</p>
<p>Got a talk in you? We're after speakers, full-length or lightning, and first-timers are
very welcome. <a href="https://elixir.sydney/speak">Pitch us a talk</a>.</p> ]]></description>
  </item>

  <item>
    <title>News: Ecosystem roundup: Macro Mayhem Podcast</title>
    <link>https://elixir.sydney/news/elixir-ecosystem-roundup-august-2026</link>
    <pubDate>Tue, 18 Aug 2026 00:00:00 +1000</pubDate>
    <guid>https://elixir.sydney/news/elixir-ecosystem-roundup-august-2026</guid>
    <category>news</category>
    <description><![CDATA[ <p><a href="https://macromayhem.fm/">Macro Mayhem</a>, the podcast that
<a href="https://elixir.sydney/news/macro-mayhem-podcast">picked up where Thinking Elixir left off</a>, is three
episodes in and showing no signs of slowing down.
<a href="https://macromayhem.fm/3">Episode 003</a> landed this week, and it surfaced enough
good ecosystem news that it deserves a written round-up of its own.</p>
<h2><a href="https://elixir.sydney/news/elixir-ecosystem-roundup-august-2026#phoenix-and-bandit-by-the-numbers" aria-hidden="true" class="anchor" id="phoenix-and-bandit-by-the-numbers"></a>Phoenix and Bandit, by the numbers</h2>
<p>Praia Labs published two posts putting actual numbers on things we usually only
have vibes for. Their
<a href="https://www.praialabs.com/phoenix-version-adoption">Phoenix version adoption</a>
analysis of Hex download data has Phoenix 1.8.x at roughly 64% of monthly
downloads by mid-2026 (it crossed the 50% line back in March), with 1.7.x still
above 28%. The companion
<a href="https://www.praialabs.com/bandit-adoption">Bandit adoption</a> post is the fun
one: Bandit reached download parity with Cowboy in July, up from about 2% in
late 2023, with the big jump coming when it became the Phoenix default. Bandit
users also patch faster: 38% were on a new security release within three days,
versus 28% for Cowboy. The usual caveat applies, downloads are a proxy rather
than a census, but the trend lines are hard to argue with.</p>
<h2><a href="https://elixir.sydney/news/elixir-ecosystem-roundup-august-2026#sobelow-015" aria-hidden="true" class="anchor" id="sobelow-015"></a>Sobelow 0.15</h2>
<p>The Phoenix security scanner <a href="https://hex.pm/packages/sobelow">Sobelow</a> shipped
<a href="https://github.com/sobelow/sobelow/releases/tag/v0.15.0">0.15.0</a>, its first
release since October 2025, from its new home at <code>sobelow/sobelow</code>. The
headline: a <code>--no-router</code> flag so plain Elixir projects can be scanned, not
just Phoenix apps. It also gains Elixir 1.20 support, a <code>usage-rules.md</code> so AI
coding assistants use it properly, and an end-to-end test harness that lifted
coverage from 29% to 67%. Given <a href="https://elixir.sydney/news/beam-security-advisories-august-2026">last month's CVE volume</a>,
having the scanner actively maintained again is very welcome.</p>
<h2><a href="https://elixir.sydney/news/elixir-ecosystem-roundup-august-2026#de-slopping-ai-generated-code" aria-hidden="true" class="anchor" id="de-slopping-ai-generated-code"></a>De-slopping AI-generated code</h2>
<p>A whole cottage industry of Credo plugins has sprung up to catch the smells
LLMs leave behind. <a href="https://github.com/elixir-vibe/ex_slop">ExSlop</a> is the most
developed: 40 checks for things like blanket rescues, narrator comments and
anti-idiomatic <code>Enum</code> usage. <a href="https://github.com/dmitriid/llamex">Llamex</a>
targets LLM-refactor smells and cheerfully admits to being largely vibe-coded
itself, and Jump's <a href="https://github.com/Jump-App/credo_checks">credo_checks</a>
includes checks aimed squarely at vacuous LLM-generated tests.</p>
<p>Related, and worth sitting with: the Syntax podcast's
<a href="https://ai-health.syntax.fm/">Vibe Health survey</a> of 1,252 developers found
59% feel their coding skills are diminishing with heavy AI use, 54% report less
enjoyment or flow, and 65% feel pressure to produce more. Tools that keep the
slop out of your codebase are good; keeping your own skills sharp is better.
Come practise both at our <a href="https://elixir.sydney/events/september-2026">September Hack Night</a>.</p>
<h2><a href="https://elixir.sydney/news/elixir-ecosystem-roundup-august-2026#elixir-for-finance" aria-hidden="true" class="anchor" id="elixir-for-finance"></a>Elixir for Finance</h2>
<p><a href="https://www.financialelixir.dev/">Elixir for Finance</a> is a new book from
Dr. Dimitrios Koutmos and Alexander Koutmos, edited by Hugo Baraúna: market
analysis with Livebook, Explorer, Scholar and Nx, from pulling FRED and Yahoo
Finance data through portfolio risk and backtesting. It's in beta with five
chapters so far, and every chapter ships as runnable Livebook notebooks.</p>
<h2><a href="https://elixir.sydney/news/elixir-ecosystem-roundup-august-2026#quick-hits" aria-hidden="true" class="anchor" id="quick-hits"></a>Quick hits</h2>
<p><a href="https://tidewave.ai/blog/tidewave-connect">Tidewave Connect</a> lets the coding
agent you already run in a terminal or editor (Claude Code, Cursor and friends)
plug into your running Phoenix app: click an element in the browser and your
prompt is enriched with framework traces, while the agent can query the
database, read logs and run code in the live app.
<a href="https://github.com/Dokploy/dokploy/releases/tag/v0.30.0">Dokploy v0.30.0</a> is
out for the self-hosters deploying Phoenix with it, adding external secrets
managers and Cloudflare/Route53 DNS automation. And if you want the wider AI
security context, the Black Hat USA debrief on the
<a href="https://www.youtube.com/watch?v=87DyyMV0kCY">OpenAI and Hugging Face incident</a>
is worth an hour, with a good written
<a href="https://simonwillison.net/2026/Aug/7/openai-timeline/">timeline from Simon Willison</a>.</p> ]]></description>
  </item>

  <item>
    <title>News: GenStage demand, finally visualised</title>
    <link>https://elixir.sydney/news/genstage-demand-visualised</link>
    <pubDate>Sat, 08 Aug 2026 00:00:00 +1000</pubDate>
    <guid>https://elixir.sydney/news/genstage-demand-visualised</guid>
    <category>news</category>
    <description><![CDATA[ <p>If you've ever configured a GenStage or Broadway pipeline by copying <code>max_demand</code>
and <code>min_demand</code> numbers from a blog post and hoping for the best, Elixir core
team member Andrea Leopardi has written the piece for you:
<a href="https://andrealeopardi.com/posts/genstage-demand-visualized/">Elixir's GenStage Demand (a Visual Explainer)</a>.</p>
<p>The framing that makes it click: concurrency gives us more workers; demand tells
us when to stop sending them work. Back-pressure is the whole point of GenStage,
and the post walks through it visually. <code>max_demand</code> caps how many events can be
in flight for a subscription at once, while <code>min_demand</code> is the threshold that
triggers the consumer to ask the producer for more. Seeing the numbers flow
between stages makes it obvious why the defaults behave the way they do, and
what actually changes when you tune them.</p>
<p>Andrea co-wrote <a href="https://pragprog.com/titles/lmelixir/testing-elixir/">Testing Elixir</a>
and his posts are reliably worth your time. This one deserves a bookmark for the
next time someone on your team asks why their pipeline sits idle in batches, a
question <code>min_demand</code> usually answers.</p> ]]></description>
  </item>

  <item>
    <title>News: elixir-lang.org has a new look</title>
    <link>https://elixir.sydney/news/elixir-lang-org-redesign</link>
    <pubDate>Wed, 29 Jul 2026 00:00:00 +1000</pubDate>
    <guid>https://elixir.sydney/news/elixir-lang-org-redesign</guid>
    <category>news</category>
    <description><![CDATA[ <p><a href="https://elixir-lang.org/">elixir-lang.org</a> has had its first major redesign in
years: a cleaner, more modern homepage that leads with what people build on the
BEAM, real companies and use cases up front, plus refreshed branding and
easier paths into the docs.</p>
<p>There's no blog post announcing it (the site itself is the announcement), but
José Valim filled in the story in the
<a href="https://news.ycombinator.com/item?id=48959042">Hacker News thread</a>, which
racked up 250+ points: the design is by the
<a href="https://swmansion.com/">Software Mansion</a> folks, iterated on together in
Figma, and José rewrote all of the copy himself with feedback from the core
maintainers. The thread's reception says a lot about where Elixir sits in 2026:
less &quot;what is this language?&quot; and more appreciation for a mature ecosystem
that keeps investing in its front door.</p>
<p>If you want the community hot takes, the first episode of the new
<a href="https://elixir.sydney/news/macro-mayhem-podcast">Macro Mayhem podcast</a> spends a chunk of its
news segment on the redesign.</p> ]]></description>
  </item>

  <item>
    <title>News: Macro Mayhem picks up where Thinking Elixir left off</title>
    <link>https://elixir.sydney/news/macro-mayhem-podcast</link>
    <pubDate>Wed, 29 Jul 2026 00:00:00 +1000</pubDate>
    <guid>https://elixir.sydney/news/macro-mayhem-podcast</guid>
    <category>news</category>
    <description><![CDATA[ <p>When the <a href="https://podcast.thinkingelixir.com/">Thinking Elixir podcast</a> wrapped
up in June after six years of weekly episodes, it left a real hole: it was
<em>the</em> way a lot of us kept up with Elixir news on the commute.</p>
<p>Enter <a href="https://macromayhem.fm/">Macro Mayhem</a>, a new podcast from Peter Ullrich
and Gus Workman covering the latest Elixir news and broader software industry
topics. Episode 001, &quot;Redesigns, Conferences, and Rogue Agents&quot;, landed on
27 July and sets the template: Hex 2.5.0's new
<a href="https://elixir.sydney/news/hex-2-5">vulnerability warnings</a>, the
<a href="https://elixir.sydney/news/elixir-lang-org-redesign">elixir-lang.org redesign</a>, the conference
season ahead (Goatmire with AshConf, ElixirConf US, Code BEAM EU), and a
discussion segment on AI news of the week.</p>
<p>Subscribe on <a href="https://podcasts.apple.com/podcast/macro-mayhem/id6795165234">Apple Podcasts</a>
or <a href="https://open.spotify.com/show/033WMuMkwo9bblXhIwiiJZ">Spotify</a>, or grab the
feed from <a href="https://macromayhem.fm/subscribe">macromayhem.fm</a>. And thanks to the
Thinking Elixir crew for six great years.</p> ]]></description>
  </item>

  <item>
    <title>News: New OTP CVE batch: patch to 29.0.4, 28.5.0.4 or 27.3.4.15</title>
    <link>https://elixir.sydney/news/otp-cve-batch-july-2026</link>
    <pubDate>Wed, 29 Jul 2026 00:00:00 +1000</pubDate>
    <guid>https://elixir.sydney/news/otp-cve-batch-july-2026</guid>
    <category>news</category>
    <description><![CDATA[ <p>Two weeks after <a href="https://elixir.sydney/news/beam-security-advisories-july-2026">July's big round-up</a>,
the <a href="https://cna.erlef.org/cves/">Erlang Ecosystem Foundation CNA</a> has published
another batch: eight Erlang/OTP CVEs on 27 July and two for Cowboy/Cowlib on the
28th. The headline is a <strong>critical TLS client authentication bypass in <code>ssl</code></strong>.
If your app makes TLS connections (and it does), update OTP.</p>
<p><strong>Erlang/OTP</strong></p>
<ul>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-55953.html">CVE-2026-55953</a> <span class="sev sev-critical">CRITICAL 9.1</span>: the TLS 1.2 (and earlier) and DTLS client accepts a cipher suite the server selected even if the client never offered it, enabling an algorithm downgrade and adversary-in-the-middle against <code>ssl</code> clients.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-58227.html">CVE-2026-58227</a> <span class="sev sev-high">HIGH 8.7</span>: TLS/DTLS denial of service via unbounded recursion on a cross-signed peer certificate chain.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-59251.html">CVE-2026-59251</a> <span class="sev sev-high">HIGH 8.7</span>: <code>public_key</code> DoS via exponential certificate-policy-tree growth during path validation.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-59250.html">CVE-2026-59250</a> <span class="sev sev-high">HIGH 8.3</span>: Megaco flex scanner buffer overflow via an oversized property parm name.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-54890.html">CVE-2026-54890</a> <span class="sev sev-high">HIGH 8.2</span>: BEAM VM crash via an integer underflow in <code>binary_to_term</code> <code>BIT_BINARY_EXT</code> decoding, a DoS anywhere you decode untrusted external term format.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-42792.html">CVE-2026-42792</a> <span class="sev sev-medium">MEDIUM 6.3</span>: <code>epmd</code> permanent DoS via file-descriptor exhaustion (<code>EMFILE</code>) on <code>accept(2)</code>.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-55737.html">CVE-2026-55737</a> <span class="sev sev-medium">MEDIUM 5.1</span>: heap pointer corruption via a signed/unsigned mismatch in <code>LARGE_TUPLE_EXT</code> decoding.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-47078.html">CVE-2026-47078</a> <span class="sev sev-medium">MEDIUM 4.8</span>: relative path traversal in <code>zip:unzip/1</code> and <code>zip:extract/1</code> via a depth-counter bypass in <code>check_dir_level</code>.</p>
<p><span class="fix-tag">Fix</span> Upgrade <a href="https://www.erlang.org/downloads">Erlang/OTP</a> to <strong>29.0.4</strong>, <strong>28.5.0.4</strong>, or <strong>27.3.4.15</strong>. Same drill as two weeks ago: an OTP upgrade, not a Hex bump.</p>
</li>
</ul>
<p><strong>cowlib</strong></p>
<ul>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-59248.html">CVE-2026-59248</a> <span class="sev sev-high">HIGH 8.7</span>: unbounded HPACK/QPACK prefixed-integer decoding, a memory-exhaustion DoS reachable through HTTP/2 and HTTP/3.</p>
<p><span class="fix-tag">Fix</span> Upgrade <a href="https://hex.pm/packages/cowlib"><code>cowlib</code></a> to <strong>2.19.0</strong>.</p>
</li>
</ul>
<p><strong>cowboy</strong></p>
<ul>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-65624.html">CVE-2026-65624</a> <span class="sev sev-medium">MEDIUM 6.9</span>: duplicate header names bypass the HTTP/1.1 <code>max_headers</code> limit, enabling memory exhaustion.</p>
<p><span class="fix-tag">Fix</span> Upgrade <a href="https://hex.pm/packages/cowboy"><code>cowboy</code></a> to <strong>2.18.0</strong>. Newer Phoenix apps default to Bandit, but plenty of deployed apps still serve on Cowboy, so check your lockfile.</p>
</li>
</ul>
<h2><a href="https://elixir.sydney/news/otp-cve-batch-july-2026#what-to-do" aria-hidden="true" class="anchor" id="what-to-do"></a>What to do</h2>
<ol>
<li>Update OTP first: the critical <code>ssl</code> cipher-suite bypass undermines TLS
server authentication for every outbound connection your node makes.</li>
<li>Run <code>mix hex.audit</code> for the Cowboy/Cowlib pair, and remember Hex 2.5 flags
advisories during <code>mix deps.get</code> (see the <a href="https://elixir.sydney/news/hex-2-5">Hex 2.5 write-up</a>).</li>
<li>Watch the <a href="https://cna.erlef.org/cves/">EEF CNA advisory list</a>. At this
cadence it's worth a bookmark.</li>
</ol>
<p>The pattern from the last batch holds: mostly DoS via unbounded resource use,
but the one that isn't (the TLS downgrade) is the one to lose sleep over.
Patch that today.</p> ]]></description>
  </item>

  <item>
    <title>Event: Plugging CVEs and Temporal Postgres</title>
    <link>https://elixir.sydney/events/july-2026</link>
    <pubDate>Wed, 15 Jul 2026 00:00:00 +1000</pubDate>
    <guid>https://elixir.sydney/events/july-2026</guid>
    <category>event</category>
    <description><![CDATA[ <p>We're back at Decidr in the Sydney CBD on 15th July, with two talks locked in: Mike Buhot on
PostgreSQL 19's new temporal data features, and Braidon Whatley and Julian Doherty on the
quadratic-time Plug CVE they found and what it means. <a href="https://luma.com/8nrbdf9o?utm_source=elixir.sydney-event">RSVP on Luma</a>.</p>
<p>Got a talk in you? We're after speakers, full-length or lightning, and first-timers are
very welcome. <a href="https://elixir.sydney/speak">Pitch us a talk</a>.</p> ]]></description>
  </item>

  <item>
    <title>News: A busy month for BEAM security advisories</title>
    <link>https://elixir.sydney/news/beam-security-advisories-july-2026</link>
    <pubDate>Wed, 15 Jul 2026 00:00:00 +1000</pubDate>
    <guid>https://elixir.sydney/news/beam-security-advisories-july-2026</guid>
    <category>news</category>
    <description><![CDATA[ <p>Since our <a href="https://elixir.sydney/news/securing-the-beam-cna-and-cves">last CNA write-up</a> the
<a href="https://cna.erlef.org/cves/">Erlang Ecosystem Foundation CNA</a> has been busy:
roughly two dozen CVEs in the last month, several in packages almost every
Elixir web app depends on. Below they're grouped by package and ordered by
severity (CVSS), worst first, with the version to upgrade to. If you do one
thing, run <code>mix hex.audit</code>.</p>
<p><strong>ueberauth_apple</strong></p>
<ul>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-55954.html">CVE-2026-55954</a> <span class="sev sev-critical">CRITICAL 9.1</span>: the JWT signature is checked but ID-token claims aren't, so any Apple-signed token bearing a victim's identifier can be replayed for account takeover.</p>
<p><span class="fix-tag">Fix</span> Upgrade <a href="https://hex.pm/packages/ueberauth_apple"><code>ueberauth_apple</code></a> to <strong>0.6.2</strong>. Patch this today if you offer Sign in with Apple.</p>
</li>
</ul>
<p><strong>phoenix</strong></p>
<ul>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-56811.html">CVE-2026-56811</a> <span class="sev sev-high">HIGH 8.7</span>: no per-connection channel-join limit, process-exhaustion DoS from a single unauthenticated connection.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-56812.html">CVE-2026-56812</a> <span class="sev sev-medium">MEDIUM 6.3</span>: Presence client crashes on prototype-key collisions in <code>syncState</code>/<code>syncDiff</code>.</p>
<p><span class="fix-tag">Fix</span> Upgrade <a href="https://hex.pm/packages/phoenix"><code>phoenix</code></a> to <strong>1.8.9</strong> (or 1.7.24 / 1.6.17 / 1.5.15 on older branches).</p>
</li>
</ul>
<p><strong>mint</strong></p>
<ul>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-56810.html">CVE-2026-56810</a> <span class="sev sev-high">HIGH 8.7</span>: buffers an entire chunked response chunk in memory.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-58229.html">CVE-2026-58229</a> <span class="sev sev-high">HIGH 8.2</span>: unbounded HTTP/1 response-header accumulation, memory-exhaustion DoS.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-59246.html">CVE-2026-59246</a> <span class="sev sev-medium">MEDIUM 6.3</span>: zero-length HTTP/2 CONTINUATION frames slip past the header byte-size cap.</p>
<p><span class="fix-tag">Fix</span> Upgrade <a href="https://hex.pm/packages/mint"><code>mint</code></a> to <strong>1.9.2</strong>. Mint sits under Finch, Req and friends, so you may pull it in transitively.</p>
</li>
</ul>
<p><strong>hpax</strong></p>
<ul>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-58226.html">CVE-2026-58226</a> <span class="sev sev-high">HIGH 8.7</span>: unbounded HPACK integer decoding, unauthenticated DoS.</p>
<p><span class="fix-tag">Fix</span> Upgrade <a href="https://hex.pm/packages/hpax"><code>hpax</code></a> to <strong>1.0.4</strong>. Transitive via Bandit and Mint.</p>
</li>
</ul>
<p><strong>ssl (Erlang/OTP)</strong></p>
<ul>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-55950.html">CVE-2026-55950</a> <span class="sev sev-high">HIGH 8.7</span>: DTLS listener crash via a race in <code>dtls_packet_demux</code>.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-55952.html">CVE-2026-55952</a> <span class="sev sev-high">HIGH 8.2</span>: TLS 1.3 server DoS via a malformed ClientHello pre-shared-key extension.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-54891.html">CVE-2026-54891</a> <span class="sev sev-medium">MEDIUM 6.3</span>: plaintext <code>APPLICATION_DATA</code> injected during the TLS handshake, delivered post-handshake.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-54887.html">CVE-2026-54887</a> <span class="sev sev-medium">MEDIUM 6.3</span>: DTLS cookie bypass during the startup window.</p>
<p><span class="fix-tag">Fix</span> Upgrade <a href="https://www.erlang.org/downloads">Erlang/OTP</a> to <strong>29.0.3</strong>, <strong>28.5.0.3</strong>, or <strong>27.3.4.14</strong> (whichever matches your branch). An OTP upgrade, not a Hex bump.</p>
</li>
</ul>
<p><strong>mdex</strong></p>
<ul>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-53426.html">CVE-2026-53426</a> <span class="sev sev-high">HIGH</span>: atom-table exhaustion DoS via JSON <code>parse_document</code>.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-54889.html">CVE-2026-54889</a> <span class="sev sev-medium">MEDIUM</span>: <code>javascript:</code> injection (XSS) in Quill Delta output.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-54888.html">CVE-2026-54888</a> <span class="sev sev-medium">MEDIUM</span>: uncontrolled recursion over deeply nested Markdown crashes the BEAM.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-53429.html">CVE-2026-53429</a> <span class="sev sev-medium">MEDIUM</span>: native memory leak in escaped-tag rendering.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-53428.html">CVE-2026-53428</a> <span class="sev sev-medium">MEDIUM</span>: unbounded allocation in <code>highlight_lines</code> range expansion.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-53427.html">CVE-2026-53427</a> <span class="sev sev-low">LOW</span>: XSS via an unescaped <code>highlight_lines_class</code> code-fence attribute.</p>
<p><span class="fix-tag">Fix</span> Upgrade <a href="https://hex.pm/packages/mdex"><code>mdex</code></a> to <strong>0.13.x</strong> (we run 0.13.3). We hit these on this very site, see the <a href="https://elixir.sydney/news/hex-2-5">Hex 2.5 write-up</a>.</p>
</li>
</ul>
<p><strong>plug</strong></p>
<ul>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-56814.html">CVE-2026-56814</a> <span class="sev sev-medium">MEDIUM 6.9</span>: multipart part headers aren't charged to the <code>:length</code> limit, so uploads can create unbounded temp files.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-56813.html">CVE-2026-56813</a> <span class="sev sev-low">LOW 2.1</span>: cookie attribute injection in <code>Plug.Conn.Cookies.encode/2</code>.</p>
<p><span class="fix-tag">Fix</span> Upgrade <a href="https://hex.pm/packages/plug"><code>plug</code></a> to <strong>1.20.3</strong> (or 1.19.5 / 1.18.5 / 1.17.4 / 1.16.6 on older branches).</p>
</li>
</ul>
<p><strong>ssh (Erlang/OTP)</strong></p>
<ul>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-54886.html">CVE-2026-54886</a> <span class="sev sev-medium">MEDIUM 5.3</span>: SFTP server DoS via an extended channel-data infinite loop.</p>
</li>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-53422.html">CVE-2026-53422</a> <span class="sev sev-low">LOW 2.3</span>: SFTP <code>REALPATH</code> path-existence oracle allows enumeration outside the configured root.</p>
<p><span class="fix-tag">Fix</span> The same OTP releases as above: <strong>29.0.3</strong> / <strong>28.5.0.3</strong> / <strong>27.3.4.14</strong>.</p>
</li>
</ul>
<p><strong>phoenix_live_view</strong></p>
<ul>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-58228.html">CVE-2026-58228</a> <span class="sev sev-medium">MEDIUM 5.1</span>: scheme-validation bypass in <code>Phoenix.LiveView.Utils</code>, XSS via <code>&lt;.link&gt;</code>.</p>
<p><span class="fix-tag">Fix</span> Upgrade <a href="https://hex.pm/packages/phoenix_live_view"><code>phoenix_live_view</code></a> to <strong>1.2.7</strong>.</p>
</li>
</ul>
<p><strong>postgrex</strong></p>
<ul>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-58225.html">CVE-2026-58225</a> <span class="sev sev-low">LOW 2.1</span>: SQL injection via an unescaped dollar-quote in notification reconnect replay, causing DoS.</p>
<p><span class="fix-tag">Fix</span> Upgrade <a href="https://hex.pm/packages/postgrex"><code>postgrex</code></a> to <strong>0.22.3</strong>.</p>
</li>
</ul>
<p><strong>swoosh</strong></p>
<ul>
<li>
<p><a href="https://cna.erlef.org/cves/CVE-2026-54893.html">CVE-2026-54893</a> <span class="sev sev-low">LOW 2.1</span>: email-derived URL path injection in the Microsoft Graph adapter, only if you derive the sender address from untrusted input.</p>
<p><span class="fix-tag">Fix</span> Upgrade <a href="https://hex.pm/packages/swoosh"><code>swoosh</code></a> to <strong>1.26.3</strong>.</p>
</li>
</ul>
<h2><a href="https://elixir.sydney/news/beam-security-advisories-july-2026#what-to-do" aria-hidden="true" class="anchor" id="what-to-do"></a>What to do</h2>
<ol>
<li>Run <code>mix hex.audit</code>. On Hex 2.5 it also flags advisories inline during <code>mix deps.get</code> and fails CI on a vulnerable lockfile (see the <a href="https://elixir.sydney/news/hex-2-5">Hex 2.5 write-up</a>).</li>
<li>Patch worst first: the CRITICAL <code>ueberauth_apple</code> account-takeover, then the HIGH memory-exhaustion DoS in Phoenix, Mint, hpax and OTP <code>ssl</code>. Update <strong>Erlang/OTP</strong> for the <code>ssl</code> and <code>ssh</code> ones.</li>
<li>Watch the <a href="https://cna.erlef.org/cves/">EEF CNA advisory list</a>.</li>
</ol>
<p>Most of these are denial-of-service via unbounded memory, but the Apple auth
bypass is a real account takeover and the LiveView issue is an XSS, so don't sit
on those. The reassuring part: the ecosystem catalogues this properly now and
the tooling surfaces it, so staying current is mostly a matter of running the
audit and not ignoring it.</p> ]]></description>
  </item>

  <item>
    <title>News: Optimising every image with Kip Cole&#39;s Image library</title>
    <link>https://elixir.sydney/news/optimising-images-with-image</link>
    <pubDate>Wed, 15 Jul 2026 00:00:00 +1000</pubDate>
    <guid>https://elixir.sydney/news/optimising-images-with-image</guid>
    <category>news</category>
    <description><![CDATA[ <p>Small confession: this site was shipping about 5 MB of avatars and event photos,
mostly full-size JPEGs shown at thumbnail size. Now every image is a right-sized
WebP, generated at build time by <a href="https://hex.pm/packages/image">Image</a>, the
libvips-backed library from <a href="https://elixir.sydney/speakers/kip-cole">Kip Cole</a>.</p>
<p>There's a nice symmetry to it: Kip gave a talk at Elixir Sydney in May 2024,
<a href="https://youtu.be/H-Psxgqoa-M">Fast and efficient image processing in Elixir</a>,
on exactly this topic, using libvips, Vix and Image to scale, transform and
compose images fast. We're now running his library to build the very page you're
reading.</p>
<h2><a href="https://elixir.sydney/news/optimising-images-with-image#what-it-does-for-us" aria-hidden="true" class="anchor" id="what-it-does-for-us"></a>What it does for us</h2>
<ul>
<li>A <code>mix images</code> build step walks the image folder and writes a right-sized
<code>.webp</code> next to each source (avatars capped at 160px, event photos at 800px).
On-page images dropped from roughly 5 MB to about 900 KB.</li>
<li>The OpenGraph share cards are re-encoded to lossless WebP through the same
library (libvips' <code>webpsave</code>), taking the card set from around 26 MB to 9 MB
with no loss of crispness on the text.</li>
<li>It's self-contained: Vix ships a precompiled libvips, so there's nothing to
install in CI.</li>
</ul>
<p>Image is a lovely piece of the ecosystem: a clean Elixir API over a very fast C
library, precompiled so it just works. If you push images around in an Elixir
app, watch <a href="https://youtu.be/H-Psxgqoa-M">Kip's talk</a> and reach for
<a href="https://hex.pm/packages/image">Image</a>.</p> ]]></description>
  </item>

  <item>
    <title>News: Who&#39;s building on Elixir in Australia?</title>
    <link>https://elixir.sydney/news/elixir-companies-in-australia</link>
    <pubDate>Tue, 14 Jul 2026 00:00:00 +1000</pubDate>
    <guid>https://elixir.sydney/news/elixir-companies-in-australia</guid>
    <category>news</category>
    <description><![CDATA[ <p>We've added a list of Australian companies building on Elixir and the BEAM to
the <a href="https://elixir.sydney/">home page</a>. It's a small thing, but a visible one: proof that there are
real jobs and real production systems on the BEAM here, not just a hobby.</p>
<p>If your company runs Elixir, Erlang, Gleam or anything else on the BEAM, we'd
love to include you. There are two other places worth getting listed, both a
quick way to show your support for the ecosystem:</p>
<ul>
<li>
<p>The <a href="https://registry.erlef.org">EEF company registry</a>, where companies
formally register their use of the ecosystem so the Erlang Ecosystem
Foundation can point to who depends on it.</p>
</li>
<li>
<p><a href="https://elixir-companies.com">elixir-companies.com</a>, the community directory.
Adding yourself is a pull request on
<a href="https://github.com/elixir-companies/elixir-companies">the repo</a>.</p>
</li>
</ul>
<p>Getting on these lists helps people find BEAM work locally and makes the
community a little more visible. Tell us at a meetup or drop us a line and we'll
add you to the Sydney list too.</p> ]]></description>
  </item>

  <item>
    <title>News: Hex 2.5 hardens the supply chain</title>
    <link>https://elixir.sydney/news/hex-2-5</link>
    <pubDate>Mon, 29 Jun 2026 00:00:00 +1000</pubDate>
    <guid>https://elixir.sydney/news/hex-2-5</guid>
    <category>news</category>
    <description><![CDATA[ <p><a href="https://hex.pm/blog/hex-v25-released">Hex 2.5</a> landed on 29 June 2026 with one
theme: making it harder for a compromised release to reach your build. Supply
chain attacks on package registries have become routine. The usual pattern is
that someone compromises a maintainer account or a build pipeline, publishes a
tampered release, and automated tooling pulls it into thousands of projects
within hours, long before anyone notices. Hex 2.5 ships three layers of defence,
most of which need no configuration.</p>
<h2><a href="https://elixir.sydney/news/hex-2-5#advisories-in-the-terminal" aria-hidden="true" class="anchor" id="advisories-in-the-terminal"></a>Advisories in the terminal</h2>
<p><code>mix deps.get</code> and <code>mix deps.update</code> now flag known-vulnerable packages inline,
tagging them &quot;VULNERABLE&quot; with a short summary and deduplicating advisories
across databases. It is exactly how we recently caught and cleared a handful of
advisories on this very site. Resolving deps looks like this now:</p>
<pre class="lumis" style="color: #e0def4; background-color: #232136;"><code class="language-bash" translate="no" tabindex="0"><div class="l-line" data-line="1"><span style="color: #ea9a97;">Resolving</span> <span style="color: #c4a7e7;">Hex</span> <span style="color: #c4a7e7;">dependencies...</span>
</div><div class="l-line" data-line="2"><span style="color: #ea9a97;">Resolution</span> <span style="color: #c4a7e7;">completed</span> <span style="color: #c4a7e7;">in</span> <span style="color: #c4a7e7;">0.42s</span>
</div><div class="l-line" data-line="3">  <span style="color: #ea9a97;">mdex</span> <span style="color: #c4a7e7;">0.11.7</span> <span style="color: #c4a7e7;">VULNERABLE!</span>
</div><div class="l-line" data-line="4">    <span style="color: #ea9a97;">EEF-CVE-2026-54889</span> <span style="color: #908caa;">(</span><span style="color: #ea9a97;">MEDIUM</span><span style="color: #908caa;">)</span>
</div><div class="l-line" data-line="5">    <span style="color: #ea9a97;">aka:</span> <span style="color: #c4a7e7;">CVE-2026-54889,</span> <span style="color: #c4a7e7;">GHSA-4383-7xfp-gpph</span>
</div><div class="l-line" data-line="6">    <span style="color: #ea9a97;">Unsanitized</span> <span style="color: #c4a7e7;">URL</span> <span style="color: #c4a7e7;">schemes</span> <span style="color: #c4a7e7;">in</span> <span style="color: #c4a7e7;">MDEx</span> <span style="color: #c4a7e7;">Quill</span> <span style="color: #c4a7e7;">Delta</span> <span style="color: #c4a7e7;">output</span> <span style="color: #c4a7e7;">allow</span> <span style="color: #c4a7e7;">javascript:</span> <span style="color: #c4a7e7;">injection</span> <span style="color: #908caa;">(</span><span style="color: #ea9a97;">XSS</span><span style="color: #908caa;">)</span>
</div><div class="l-line" data-line="7">    <span style="color: #ea9a97;">https://osv.dev/vulnerability/EEF-CVE-2026-54889</span>
</div><div class="l-line" data-line="8">    <span style="color: #ea9a97;">EEF-CVE-2026-53426</span> <span style="color: #908caa;">(</span><span style="color: #ea9a97;">HIGH</span><span style="color: #908caa;">)</span>
</div><div class="l-line" data-line="9">    <span style="color: #ea9a97;">aka:</span> <span style="color: #c4a7e7;">CVE-2026-53426,</span> <span style="color: #c4a7e7;">GHSA-923r-7vf4-5vw8</span>
</div><div class="l-line" data-line="10">    <span style="color: #ea9a97;">Atom-table</span> <span style="color: #c4a7e7;">exhaustion</span> <span style="color: #c4a7e7;">denial-of-service</span> <span style="color: #c4a7e7;">via</span> <span style="color: #c4a7e7;">JSON</span> <span style="color: #c4a7e7;">parse_document</span> <span style="color: #c4a7e7;">in</span> <span style="color: #c4a7e7;">MDEx</span>
</div><div class="l-line" data-line="11">    <span style="color: #ea9a97;">https://osv.dev/vulnerability/EEF-CVE-2026-53426</span>
</div><div class="l-line" data-line="12"><span style="color: #ea9a97;">Found</span> <span style="color: #c4a7e7;">packages</span> <span style="color: #c4a7e7;">with</span> <span style="color: #c4a7e7;">security</span> <span style="color: #c4a7e7;">advisories</span>
</div></code></pre>
<p>For CI, <code>mix hex.audit</code> inspects your lockfile and exits non-zero if any
dependency carries an advisory or has been retired, so a vulnerable release
fails the build instead of slipping through:</p>
<pre class="lumis" style="color: #e0def4; background-color: #232136;"><code class="language-bash" translate="no" tabindex="0"><div class="l-line" data-line="1"><span style="color: #908caa;">$</span> <span style="color: #e0def4;">mix</span> <span style="color: #c4a7e7;">hex.audit</span>
</div><div class="l-line" data-line="2"><span style="color: #ea9a97;">Advisories:</span>
</div><div class="l-line" data-line="3">  <span style="color: #ea9a97;">phoenix_live_view</span> <span style="color: #c4a7e7;">1.2.6</span> <span style="color: #c4a7e7;">-</span> <span style="color: #c4a7e7;">EEF-CVE-2026-58228</span> <span style="color: #908caa;">(</span><span style="color: #ea9a97;">MEDIUM</span><span style="color: #908caa;">)</span>
</div><div class="l-line" data-line="4">    <span style="color: #ea9a97;">aka:</span> <span style="color: #c4a7e7;">CVE-2026-58228,</span> <span style="color: #c4a7e7;">GHSA-5cgh-g58j-m9cq</span>
</div><div class="l-line" data-line="5">    <span style="color: #ea9a97;">Scheme</span> <span style="color: #c4a7e7;">validation</span> <span style="color: #c4a7e7;">bypass</span> <span style="color: #c4a7e7;">in</span> <span style="color: #c4a7e7;">Phoenix.LiveView.Utils</span> <span style="color: #c4a7e7;">leads</span> <span style="color: #c4a7e7;">to</span> <span style="color: #c4a7e7;">XSS</span> <span style="color: #c4a7e7;">via</span> <span style="color: #908caa;">&lt;</span><span style="color: #f6c177;">.link</span><span style="color: #908caa;">&gt;</span>
</div><div class="l-line" data-line="6">    <span style="color: #f6c177;">https://osv.dev/vulnerability/EEF-CVE-2026-58228</span>
</div><div class="l-line" data-line="7">
</div><div class="l-line" data-line="8"><span style="color: #ea9a97;">Found</span> <span style="color: #c4a7e7;">packages</span> <span style="color: #c4a7e7;">with</span> <span style="color: #c4a7e7;">security</span> <span style="color: #c4a7e7;">advisories</span>
</div></code></pre>
<p>Bumping <code>phoenix_live_view</code> to a patched release and re-running it prints
&quot;No retired or security advisory packages found&quot;, and the build is green again.
This is all on for every project with nothing to configure.</p>
<h2><a href="https://elixir.sydney/news/hex-2-5#release-age-cooldown" aria-hidden="true" class="anchor" id="release-age-cooldown"></a>Release-age cooldown</h2>
<p>The cooldown withholds very recently published versions from resolution, giving
the community time to catch a bad release before it lands in your deps:</p>
<pre class="lumis" style="color: #e0def4; background-color: #232136;"><code class="language-elixir" translate="no" tabindex="0"><div class="l-line" data-line="1"><span style="color: #908caa;"># mix.exs</span>
</div><div class="l-line" data-line="2"><span style="color: #e0def4;">hex</span>: <span style="color: #908caa;">[</span><span style="color: #ea9a97;">cooldown</span>: <span style="color: #f6c177;">&quot;7d&quot;</span><span style="color: #908caa;">]</span>
</div></code></pre>
<p>Durations look like <code>7d</code>, <code>2w</code> or <code>1mo</code>. It never touches already-locked
dependencies, and there is an escape hatch when a current version turns out to
be unsafe. <code>mix hex.outdated</code> shows which updates are being held and when they
become eligible.</p>
<h2><a href="https://elixir.sydney/news/hex-2-5#dependency-policies" aria-hidden="true" class="anchor" id="dependency-policies"></a>Dependency policies</h2>
<p>Organisations can publish a signed policy and enforce it across every project
that opts in, restricting releases by advisory severity, retirement reason, or
release age. <code>mix hex.policy show</code> summarises the active policy, and
<code>mix hex.policy why &lt;package&gt;</code> explains, version by version, why something is
blocked.</p>
<p>Package authors need do nothing for any of this. Consumers get the advisories
and the cooldown for free, which is a rare thing in security: a genuine
improvement you pick up just by upgrading.</p>
<p>The advisories Hex surfaces are published by the
<a href="https://cna.erlef.org/cves/">Erlang Ecosystem Foundation CNA</a>, which has been
busy lately. Watch it, run <code>mix hex.audit</code>, and keep your dependencies current:
most of these fixes are one <code>mix deps.update</code> away. We rounded up the last
month's advisories <a href="https://elixir.sydney/news/beam-security-advisories-july-2026">here</a>.</p> ]]></description>
  </item>

  <item>
    <title>Event: Elixir Sydney: The Mythos/Fable Edition</title>
    <link>https://elixir.sydney/events/mythos-fable-edition</link>
    <pubDate>Wed, 17 Jun 2026 00:00:00 +1000</pubDate>
    <guid>https://elixir.sydney/events/mythos-fable-edition</guid>
    <category>event</category>
    <description><![CDATA[ <p>It's been a hot minute and we've not done an Elixir Sydney meetup in a while.</p>
<p>We'll kick off with an ecosystem update covering the Mythos class Fable 5 launch and what's been happening in the community in 2026, including security updates and new releases, followed by two Ash framework talks.</p>
<p>Thanks to Decidr for hosting us in the CBD. <a href="https://luma.com/6k7hotj8">RSVP on Luma</a> to see the venue address.</p>
<p>Got an idea for a talk? <a href="https://github.com/elixirsydney/elixirsydney/issues">Submit a talk proposal</a> or come along and say hi, everyone is welcome, no matter your skill level.</p> ]]></description>
  </item>

  <item>
    <title>News: A new home for Elixir Sydney</title>
    <link>https://elixir.sydney/news/a-new-home-for-elixir-sydney</link>
    <pubDate>Mon, 15 Jun 2026 00:00:00 +1000</pubDate>
    <guid>https://elixir.sydney/news/a-new-home-for-elixir-sydney</guid>
    <category>news</category>
    <description><![CDATA[ <p>We've given <a href="https://elixir.sydney/">elixir.sydney</a> a complete rebuild, and along the way we dug up our
entire history.</p>
<p>The new site is a small, fast static site built, fittingly, in Elixir with
<a href="https://github.com/elixir-tools/tableau">Tableau</a>, the elixir-tools static site
generator. The whole thing compiles to plain HTML and is pushed to <strong>S3</strong> and served
through <strong>CloudFront</strong>, so it's cheap, fast and has nothing to keep running. Content
lives as Markdown and YAML in the <a href="https://github.com/elixirsydney">repo</a>, and every
push to <code>main</code> deploys automatically.</p>
<p>More importantly, it now documents <strong>every Elixir Sydney meetup since 2015</strong>: more than
eighty events and the talks, speakers and recordings that went with them. A lot of that
had been scattered across an old site, our Meetup group, GitHub and the Internet
Archive, and we've pulled it back together for good.</p>
<p>We've also <strong>finally shut down our Meetup.com group</strong> (yay!). It served us well for a
decade, but it's done, everything now lives here, with RSVPs on Luma.</p>
<p>A few things to explore:</p>
<ul>
<li><strong><a href="https://elixir.sydney/events">Events</a></strong>, the full archive, newest first, with talk videos and slides
where we have them.</li>
<li><strong><a href="https://elixir.sydney/speakers">Speakers</a></strong>, everyone who has ever given a talk, with links to their
work. If you spot something wrong, let us know.</li>
<li><strong><a href="https://elixir.sydney/speak">Give a talk</a></strong>, first-time speakers are very welcome, and we're happy to
help you shape an idea.</li>
</ul>
<p>RSVPs now run through <a href="https://luma.com/elixir-sydney">Luma</a>, and we hang out in the
Elixir community channels linked in the footer.</p>
<p>See you at the next one.</p> ]]></description>
  </item>

  <item>
    <title>News: Fable 5 launched, then vanished three days later</title>
    <link>https://elixir.sydney/news/fable-5-released-then-pulled</link>
    <pubDate>Sat, 13 Jun 2026 00:00:00 +1000</pubDate>
    <guid>https://elixir.sydney/news/fable-5-released-then-pulled</guid>
    <category>news</category>
    <description><![CDATA[ <p>We named tonight's meetup &quot;The Mythos/Fable Edition&quot; after Anthropic's big launch. By the
time we actually meet, the models are already gone. The whole thing lasted three days.</p>
<p>On 9 June, Anthropic
<a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">released Claude Fable 5 and Mythos 5</a>,
pitching Fable 5 as its most capable widely-released model and aiming it squarely at
long-horizon agentic work. It went out the same day across the Claude API, AWS Bedrock,
Microsoft Foundry and the rest.</p>
<p>Then on Friday 12 June, the US Commerce Department
<a href="https://www.infoq.com/news/2026/06/claude-5-release/">directed Anthropic</a> to block foreign
nationals from using both models. Rather than carve the world in two, Anthropic
<a href="https://techcrunch.com/2026/06/09/anthropic-released-claude-fable-5-its-most-powerful-model-publicly-days-after-warning-ai-is-getting-too-dangerous/">disabled Fable 5 and Mythos 5 globally for everyone</a>
the same day. As best anyone can tell, the government believes a way to jailbreak Fable 5
surfaced, and the standoff traces back to Anthropic refusing to hand over full access to
Claude.</p>
<p>Worth noting from down here: &quot;foreign nationals&quot; includes us. So even setting the jailbreak
drama aside, a Sydney developer poking at Fable 5 over the weekend would have watched it
blink out regardless.</p>
<p>It's a strange one to sit with. The most capable model anyone had shipped, public on a
Tuesday and pulled by Friday, on government order. If you're building agentic tooling on the
BEAM, it's a sharp reminder that the model under your abstraction can disappear out from
under you. Plan for the provider, and the politics, not just the API.</p> ]]></description>
  </item>

  <item>
    <title>News: Phoenix LiveView 1.2 is out</title>
    <link>https://elixir.sydney/news/phoenix-liveview-1-2</link>
    <pubDate>Wed, 10 Jun 2026 00:00:00 +1000</pubDate>
    <guid>https://elixir.sydney/news/phoenix-liveview-1-2</guid>
    <category>news</category>
    <description><![CDATA[ <p><a href="https://phoenixframework.org/blog/phoenix-liveview-1-2-released">Phoenix LiveView 1.2</a>
shipped on 10 June 2026, and it rounds out the colocation work that started in 1.1.</p>
<p>The headline is <strong>colocated CSS</strong>. Where 1.1 let you keep a component's hooks and JS
next to its markup, 1.2 lets you do the same with styles, using the CSS <code>@scope</code> rule to
stop them leaking into the rest of the page. To make that work the team had to
<strong>split HEEx compilation into separate tokenization and parsing steps</strong>, which is the
kind of unglamorous internal change that quietly makes a lot of other things possible.</p>
<p>A few other things worth knowing:</p>
<ul>
<li><code>Phoenix.LiveView.JS</code> commands are now <strong>automatically encoded</strong> when you send them with
<code>push_event</code>, whether you're on <code>Jason</code> or the built-in <code>JSON</code> module.</li>
<li><strong>Test warnings can be configured by category</strong>, so you can tune the checks that run
in <code>LiveViewTest</code>.</li>
<li>Custom formatting for <code>&lt;script&gt;</code> and <code>&lt;style&gt;</code> tags, and module-level HEEx debug
annotations.</li>
</ul>
<p>Worth a look if you're building anything with LiveView. We'll likely touch on it at an
upcoming meetup, <a href="https://luma.com/elixir-sydney">RSVP on Luma</a>.</p> ]]></description>
  </item>

  <item>
    <title>News: Securing the BEAM: the EEF is now a CNA</title>
    <link>https://elixir.sydney/news/securing-the-beam-cna-and-cves</link>
    <pubDate>Fri, 05 Jun 2026 00:00:00 +1000</pubDate>
    <guid>https://elixir.sydney/news/securing-the-beam-cna-and-cves</guid>
    <category>news</category>
    <description><![CDATA[ <p>Security has been front of mind in the BEAM world this year, and there's good news on
how the ecosystem is responding.</p>
<h2><a href="https://elixir.sydney/news/securing-the-beam-cna-and-cves#the-wake-up-call-cve-2025-32433" aria-hidden="true" class="anchor" id="the-wake-up-call-cve-2025-32433"></a>The wake-up call: CVE-2025-32433</h2>
<p>In April 2025, <a href="https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2">CVE-2025-32433</a>
landed, an <strong>unauthenticated, pre-auth remote code execution</strong> flaw in Erlang/OTP's
SSH server, scored a maximum <strong>CVSS 10.0</strong>. A remote attacker could run code before
authenticating. It was fixed in <strong>OTP-27.3.3, 26.2.5.11 and 25.3.2.20</strong>, and it was a
clear reminder to keep the runtime patched.</p>
<h2><a href="https://elixir.sydney/news/securing-the-beam-cna-and-cves#otp-29-responds" aria-hidden="true" class="anchor" id="otp-29-responds"></a>OTP 29 responds</h2>
<p>That focus shows up directly in <a href="https://www.erlang.org/blog/highlights-otp-29/">OTP 29</a>:
SSH is now <strong>secure-by-default</strong> (shell and exec disabled unless you enable them),
TLS defaults to a post-quantum key exchange, and the compiler warns about unsafe
functions, alongside a new set of secure coding guidelines.</p>
<h2><a href="https://elixir.sydney/news/securing-the-beam-cna-and-cves#the-eef-is-now-a-cve-numbering-authority" aria-hidden="true" class="anchor" id="the-eef-is-now-a-cve-numbering-authority"></a>The EEF is now a CVE Numbering Authority</h2>
<p>The bigger structural change: the
<a href="https://erlef.org/blog/security/eef-cna-announcement">Erlang Ecosystem Foundation is now a CNA</a>
(a CVE Numbering Authority). It assigns CVE IDs and publishes advisories for active
<a href="https://hex.pm">Hex.pm</a> packages and the <code>elixir-lang</code>, <code>erlang</code>, <code>erlef</code> and
<code>gleam-lang</code> GitHub orgs, with records published at
<a href="https://cna.erlef.org/">cna.erlef.org</a>. It's already coordinating real disclosures, recent 2026 advisories cover <code>Tesla</code> middleware, <code>public_key</code> certificate validation,
and the <code>Mint</code> HTTP/2 client, which means coordinated, properly-tracked vulnerability
handling for the whole ecosystem.</p>
<h2><a href="https://elixir.sydney/news/securing-the-beam-cna-and-cves#what-to-do" aria-hidden="true" class="anchor" id="what-to-do"></a>What to do</h2>
<ul>
<li>Keep Elixir and OTP patched, most BEAM CVEs are fixed quickly across supported
release lines.</li>
<li>Watch <a href="https://cna.erlef.org/">cna.erlef.org</a> and the EEF security advisories.</li>
<li>Run <code>mix hex.audit</code> for retired packages, and consider
<a href="https://hex.pm/packages/mix_audit"><code>mix_audit</code></a> (<code>mix deps.audit</code>) to scan deps
against known advisories in CI.</li>
</ul> ]]></description>
  </item>

  <item>
    <title>News: Elixir 1.20 and OTP 29 have landed</title>
    <link>https://elixir.sydney/news/elixir-1-20-and-otp-29</link>
    <pubDate>Thu, 04 Jun 2026 00:00:00 +1000</pubDate>
    <guid>https://elixir.sydney/news/elixir-1-20-and-otp-29</guid>
    <category>news</category>
    <description><![CDATA[ <p>It's been a big few weeks for the BEAM. Both <strong>Erlang/OTP 29</strong> and <strong>Elixir 1.20</strong>
have shipped.</p>
<h2><a href="https://elixir.sydney/news/elixir-1-20-and-otp-29#elixir-120" aria-hidden="true" class="anchor" id="elixir-120"></a>Elixir 1.20</h2>
<p>Released on 3 June 2026, <a href="https://elixir-lang.org/blog/2026/06/03/elixir-v1-20-0-released/">Elixir 1.20</a>
is a landmark for the type system. The compiler now performs <strong>type inference and
gradual type checking of every Elixir program, with no type annotations required</strong>.
In practice that means Elixir increasingly flags dead code and guaranteed-to-fail
typing violations, with a very low false-positive rate.</p>
<p>Highlights:</p>
<ul>
<li>Type <strong>narrowing</strong> across guards, <code>case</code>/<code>cond</code>/<code>with</code> clauses, and conditionals
(occurrence typing), so types are more precise inside each branch.</li>
<li>Much of the standard library is now typed, including most of the <code>Map</code> module and
tuples.</li>
<li>Faster compilation, especially on many-core machines, the benchmarks now put
Mix among the fastest build tools on the BEAM.</li>
</ul>
<h2><a href="https://elixir.sydney/news/elixir-1-20-and-otp-29#erlangotp-29" aria-hidden="true" class="anchor" id="erlangotp-29"></a>Erlang/OTP 29</h2>
<p><a href="https://www.erlang.org/blog/highlights-otp-29/">OTP 29</a> (13 May 2026) leans hard into
security and developer ergonomics:</p>
<ul>
<li><strong>Secure-by-default SSH</strong> (shell/exec disabled unless you opt in) and a
post-quantum <code>x25519mlkem768</code> default key exchange for TLS.</li>
<li>New warnings for unsafe and potentially-unsafe functions, plus secure coding
guidelines.</li>
<li>Experimental <strong>native records</strong> (EEP-79), multi-valued comprehensions, an
<code>is_integer/3</code> guard, and JIT improvements for binary matching.</li>
</ul>
<p>If you want to play with both, point your version manager at <strong>Elixir 1.20.1</strong> on
<strong>OTP 29.0.2</strong>, that's what runs this very site's build pipeline.</p>
<p>We'll cover the ecosystem updates at the next meetup, <a href="https://luma.com/elixir-sydney">RSVP on Luma</a>.</p> ]]></description>
  </item>

  <item>
    <title>News: HexDocs moves to per-package subdomains</title>
    <link>https://elixir.sydney/news/hexdocs-per-package-subdomains</link>
    <pubDate>Mon, 01 Jun 2026 00:00:00 +1000</pubDate>
    <guid>https://elixir.sydney/news/hexdocs-per-package-subdomains</guid>
    <category>news</category>
    <description><![CDATA[ <p><a href="https://hexdocs.pm">HexDocs</a> has changed how it serves documentation: every package now
lives on its own subdomain.</p>
<p>So <code>hexdocs.pm/ecto</code> becomes <code>ecto.hexdocs.pm</code>, and <code>hexdocs.pm/ecto_sql</code> becomes
<code>ecto-sql.hexdocs.pm</code> (underscores turn into hyphens). Organisation docs move from
<code>org.hexdocs.pm/package</code> to <code>org.hexorgs.pm/package</code>.</p>
<p>The reason is security. Until now every public package was served from the same origin, so
a malicious or compromised package could, in principle, reach into another package's docs
in the browser. Giving each package its own subdomain hands that isolation to the browser's
same-origin policy for free. It's a small, sensible piece of the same
<a href="https://elixir.sydney/news/securing-the-beam-cna-and-cves">security push we wrote about</a> across the ecosystem.</p>
<p>Nothing breaks today, old URLs redirect to the new ones. But if you've got HexDocs links in
a README, a blog post, or your socials, it's worth updating them to the subdomain form
while you're thinking about it.</p>
<p>Read the <a href="https://hex.pm/blog/hexdocs-per-package-subdomains">announcement on hex.pm</a>.</p> ]]></description>
  </item>

  <item>
    <title>News: Put your company on the EEF registry</title>
    <link>https://elixir.sydney/news/erlef-company-registry</link>
    <pubDate>Fri, 29 May 2026 00:00:00 +1000</pubDate>
    <guid>https://elixir.sydney/news/erlef-company-registry</guid>
    <category>news</category>
    <description><![CDATA[ <p>The Erlang Ecosystem Foundation has launched
<a href="https://registry.erlef.org">registry.erlef.org</a>, a free, central registry of companies
that use Erlang, Elixir and the wider BEAM. It exists to answer the question every one of
us has been asked: <strong>&quot;who actually uses this?&quot;</strong></p>
<p>The pitch is simple. The registry shows the real scope of the ecosystem across more than
sixteen languages, helps people find companies working with the tech they know, and gives
the Foundation something concrete to point funders at. Signing up is quick: one person
nominates themselves as the contact, verifies by email, and the company is listed. There's
no further commitment, and registered contacts get a quarterly update on what's happening
across the ecosystem.</p>
<p>If your company works with Elixir or the BEAM, <strong><a href="https://registry.erlef.org">add it to the registry</a></strong>.
It takes a few minutes and it makes the community look as big as it actually is. We'd
especially love to see more Sydney and Australian names on the list.</p>
<p>And if you can do more than a free listing: the EEF runs on membership and sponsorship.
The security work we <a href="https://elixir.sydney/news/securing-the-beam-cna-and-cves">wrote about recently</a>, the
working groups, the infrastructure, all of it is funded by companies that rely on the
BEAM. If that's you, <a href="https://erlef.org/sponsorship">supporting the EEF</a> is a direct way
to give back to the runtime your business is built on.</p> ]]></description>
  </item>

  <item>
    <title>Event: GEM: Elixir Sydney</title>
    <link>https://elixir.sydney/events/gem-elixir-sydney</link>
    <pubDate>Tue, 23 Sep 2025 00:00:00 +1000</pubDate>
    <guid>https://elixir.sydney/events/gem-elixir-sydney</guid>
    <category>event</category>
    <description><![CDATA[ <p>As part of the Global Elixir Meetup week we ran a long awaited in person and online Elixir Sydney meetup in Leichhardt.</p>
<p><strong>Agenda</strong></p>
<ul>
<li>5:30pm, Welcome, housekeeping &amp; introduction</li>
<li>6:00pm, Talks (with a break in between)</li>
</ul> ]]></description>
  </item>

  <item>
    <title>Event: SPA-like UX with MVC-like DX, and Writing the book on Ash</title>
    <link>https://elixir.sydney/events/ashframeworkbook</link>
    <pubDate>Tue, 18 Mar 2025 00:00:00 +1100</pubDate>
    <guid>https://elixir.sydney/events/ashframeworkbook</guid>
    <category>event</category>
    <description><![CDATA[ <p>Hey Elixir community! Welcome to the first Elixir Sydney meetup for 2025 - this is online, so come and join us from wherever you are.</p>
<p>Got an idea for an Elixir talk? We’d love to hear it! Whether you’re an experienced developer with deep insights or just starting out and excited to share what you’ve learned, our meetups are a great place to connect, learn, and grow.</p>
<p>Not ready to give a talk? No worries! Come along to meet fellow Elixir enthusiasts, ask questions, and get guidance from more experienced developers. Everyone is welcome, no matter your skill level!</p>
<p>If you’d like to submit a talk idea, just drop us a message, we’re happy to help you shape it into a great presentation!</p>
<p>Josh and Mike</p> ]]></description>
  </item>

  <item>
    <title>Event: Xmas Bash: GenAI UI with Golden Orb</title>
    <link>https://elixir.sydney/events/xmas-bash-golden-orb</link>
    <pubDate>Wed, 11 Dec 2024 00:00:00 +1100</pubDate>
    <guid>https://elixir.sydney/events/xmas-bash-golden-orb</guid>
    <category>event</category>
    <description><![CDATA[ <p>Our end-of-year Xmas bash! An evening of Elixir, WebAssembly and generative AI to close out 2024.</p> ]]></description>
  </item>

  <item>
    <title>Event: Elixir Sydney October Edition</title>
    <link>https://elixir.sydney/events/october-2024</link>
    <pubDate>Wed, 16 Oct 2024 00:00:00 +1100</pubDate>
    <guid>https://elixir.sydney/events/october-2024</guid>
    <category>event</category>
    <description><![CDATA[ <p>Get ready to dive into Elixir Sydney Meetup! Connect with Elixir enthusiasts and share your passion for this incredible programming language.</p>
<p>Whether you're a seasoned developer or just curious about Elixir, come along for an evening filled with engaging discussions, insightful talks, and maybe even a few surprises.</p> ]]></description>
  </item>

  <item>
    <title>Event: BulmaComponents and The new Set-Theoretic Type System for Elixir</title>
    <link>https://elixir.sydney/events/bulmacomponents</link>
    <pubDate>Wed, 24 Jul 2024 00:00:00 +1000</pubDate>
    <guid>https://elixir.sydney/events/bulmacomponents</guid>
    <category>event</category>
    <description><![CDATA[  ]]></description>
  </item>

  <item>
    <title>Event: Practical AI In Elixir</title>
    <link>https://elixir.sydney/events/practical-ai-in-elixir</link>
    <pubDate>Mon, 24 Jun 2024 00:00:00 +1000</pubDate>
    <guid>https://elixir.sydney/events/practical-ai-in-elixir</guid>
    <category>event</category>
    <description><![CDATA[ <p>Elixir Sydney is back for the June 2024 meetup with an AI themed event! We're in-person and online, so come and join us from wherever you are.</p>
<p>Josh and Mike</p> ]]></description>
  </item>

</channel>
</rss>
