Skip to content

Update Ecto and Absinthe to fix 'decimal' security advisory#39

Open
lewazo wants to merge 2 commits into
masterfrom
update-decimal-dependency
Open

Update Ecto and Absinthe to fix 'decimal' security advisory#39
lewazo wants to merge 2 commits into
masterfrom
update-decimal-dependency

Conversation

@lewazo
Copy link
Copy Markdown
Member

@lewazo lewazo commented May 12, 2026

📖 Description and reason

decimal, which is a transient dependency for ecto and absinthe has release a new major version for fixing this new security advisory.

👷 Work done

Tasks

  • Update Ecto and Absinthe.

Additional notes

It also fixes an issue with the tests where they would sometimes fail, depending of their execution order.

🎉 Result

decimal can now be safely upgraded to v3.0.0.

🦀 Dispatch

#dispatch/elixir

@lewazo lewazo requested review from remi and simonprev May 12, 2026 20:21
@lewazo
Copy link
Copy Markdown
Member Author

lewazo commented May 12, 2026

I just noticed the changes to the tests setup here are the same in https://github.com/mirego/absinthe_error_payload/pull/38/changes

Let's merge #38 first and I'll rebase.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant