Debian Package Tracker
Register | Log in
Subscribe

erlang-hex

Package manager for the Erlang ecosystem

Choose email to subscribe with

general
  • source: erlang-hex (main)
  • version: 2.5.1-2
  • maintainer: Debian Erlang Packagers (archive) (DMD)
  • uploaders: John Lines [DMD]
  • arch: any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • stable: 2.0.6-2
  • testing: 2.5.1-2
  • unstable: 2.5.1-2
versioned links
  • 2.0.6-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.5.1-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • erlang-hex
action needed
Multiarch hinter reports 1 issue(s) low
There are issues with the multiarch metadata for this package.
  • erlang-hex could be converted to Architecture: all and marked Multi-Arch: foreign
Created: 2026-07-20 Last update: 2026-10-06 10:49
2 low-priority security issues in trixie low

There are 2 open security issues in trixie.

2 issues left for the package maintainer to handle:
  • CVE-2026-21619: (needs triaging) Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.erl, src/mix_hex_api.erl, apps/rebar/src/vendored/r3_hex_api.erl and program routines hex_core:request/4, mix_hex_api:request/4, r3_hex_api:request/4. This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0.
  • CVE-2026-32148: (needs triaging) Insufficient Verification of Data Authenticity vulnerability in hexpm hex (Hex.RemoteConverger module) allows dependency integrity bypass via unverified lockfile checksums. Hex stores checksums for dependencies in the mix.lock file to ensure reproducible and integrity-checked builds. However, Hex.RemoteConverger.verify_resolved/2 never executes checksum verification because the lock data returned by Hex.Utils.lock/1 uses string-based dependency names, while the verification logic compares against atom-based names. This type mismatch causes the verification code path to be silently skipped. Checksums are still validated when packages are initially downloaded from the registry, but mismatches between the lockfile and resolved dependencies are not detected. An attacker who can influence cached packages (e.g., via local cache poisoning or a compromised registry) can provide modified dependency contents that will be accepted without detection. The mix.lock file is silently rewritten with the checksum values from the registry, erasing evidence of tampering. This issue affects hex: from 0.16.0 before 2.4.2.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-03-08 Last update: 2026-10-01 22:01
debian/patches: 1 patch to forward upstream low

Among the 1 debian patch available in version 2.5.1-2 of the package, we noticed the following issues:

  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-11-19 Last update: 2026-07-19 18:02
news
[rss feed]
  • [2026-07-24] erlang-hex 2.5.1-2 MIGRATED to testing (Debian testing watch)
  • [2026-07-19] Accepted erlang-hex 2.5.1-2 (source) into unstable (Sergei Golovan)
  • [2026-07-18] Accepted erlang-hex 2.5.1-1 (source) into experimental (Sergei Golovan)
  • [2026-06-19] erlang-hex 2.4.2-2 MIGRATED to testing (Debian testing watch)
  • [2026-06-13] Accepted erlang-hex 2.4.2-2 (source) into unstable (Sergei Golovan)
  • [2026-05-26] Accepted erlang-hex 2.4.2-1 (source) into experimental (Sergei Golovan)
  • [2025-06-09] erlang-hex 2.0.6-2 MIGRATED to testing (Debian testing watch)
  • [2025-05-17] Accepted erlang-hex 2.0.6-2 (source) into unstable (John Lines)
  • [2025-05-15] Accepted erlang-hex 2.0.6-1 (source) into unstable (John Lines)
  • [2024-03-28] erlang-hex 2.0.5-2 MIGRATED to testing (Debian testing watch)
  • [2024-03-09] Accepted erlang-hex 2.0.5-2 (source) into unstable (John Lines)
  • [2023-10-29] erlang-hex 2.0.5-1 MIGRATED to testing (Debian testing watch)
  • [2023-10-24] Accepted erlang-hex 2.0.5-1 (source amd64) into unstable (Debian FTP Masters) (signed by: John Lines)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.5.1-2

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing