Skip to content

Bump sobelow from 0.11.1 to 0.16.0 - #439

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/hex/sobelow-0.16.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/hex/sobelow-0.16.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps sobelow from 0.11.1 to 0.16.0.

Release notes

Sourced from sobelow's releases.

v0.16.0

What's Changed

New Contributors

Full Changelog: sobelow/sobelow@v0.15.0...v0.16.0

v0.15.0

What's Changed

New Contributors

Full Changelog: sobelow/sobelow@v0.14.1...v0.15.0

v0.14.1

  • Enhancements
    • Implicitly use .sobelow-conf if detected in the root directory rather than require --config switch. The --no-config switch is still supported to prevent any settings from being read in from the file if needed.
    • Added guidance for warn_if_outdated option in mix deps
    • Added support for Elixir v1.19.x
  • Bug fixes
    • Handled extra config options for app releases in mix.exs
    • Properly handle the use of CLI switches and config file settings in the same run. These would previously clobber each other in unapparent ways leading to confusing behavior. CLI switch take precedence.
    • .sobelow-conf now sorted alphabetically
    • Fix edwarning from zero argument functions
    • Fixed broken skip funcationality
    • Fixed broken GitHub Actions CI

... (truncated)

Changelog

Sourced from sobelow's changelog.

v0.16.0

  • Bug fixes
    • XSS.Raw no longer reports calls to a benign local raw helper with the matching arity, including defaults, guards, pipes, captures, and inline HEEx. Local definitions stay within their module; qualified Phoenix calls and implicitly imported template helpers retain detection. Helpers returning dynamic {:safe, value} output or wrapping another raw call retain their caller's original findings, locations, and fingerprints. (#44)
    • XSS.SendResp now recognizes put_resp_header(conn, "content-type", type) on the response connection, including piped, aliased, nested, and assigned calls. HTML, SVG, malformed, and unknown types still report; other XML and PDF document types retain low-confidence findings. Discarded, later, unrelated, locally shadowed, or ambiguously imported setters cannot suppress findings. Known unrelated response headers retain the connection's content type, and MIME parameters do not change its classification. (#45)
    • XSS.Raw now respects explicit imports of unrelated raw helpers. Unknown raw macros and delegates retain detection. Older inline lexical contexts without local-signature metadata remain supported.
    • Invalid project roots, roots with no scannable source files, invalid scan options, and unwritable output files now fail with actionable errors.
    • Repeated scans in the same VM now start with fresh findings, template, and skip state. Malformed sources and templates are skipped with a warning in non-strict mode, and unreadable files are skipped with a warning.
    • Dynamic socket options, literal statements in router pipelines, and access on a literal keyword list no longer abort scans. Unknown socket options produce low-confidence findings.
    • XSS.SendResp now follows the connection passed to each response and its content type before that sink. Later or discarded setters cannot suppress an earlier finding, and rebindings in branches, patterns, callbacks, generators, and call arguments cannot borrow another connection's content type. Unchanged bindings, pins, guards, and explicit setters retain their existing handling.
    • HTTPS and HSTS checks now use effective settings for the scanned application and each endpoint, including ordered overrides and nested keyword merges. One endpoint cannot satisfy another's settings. Dynamic and conditional settings produce low-confidence findings. Empty CSP policies are reported.
    • Enabled sockets now inherit endpoint origin settings from base, production, and runtime configuration, including socket/2 and websocket: true. Explicit socket overrides retain precedence, and disabled WebSockets remain excluded. Defaults are isolated to each endpoint module. Origin allowlists and :conn are recognized; an enabled CSRF check lowers confidence when origin checks are disabled.
    • HEEx comments and script/style text no longer change brace-interpolation scope or introduce findings from literal markup. The phx-no-curly-interpolation directive is recognized as an attribute name; the same text inside another attribute's value cannot suppress findings. Inline columns account for sigil prefixes and heredoc indentation.
    • Module-local use and import declarations now apply only to their own module. Named captures and inline HEEx retain lexical aliases and import

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [sobelow](https://github.com/sobelow/sobelow) from 0.11.1 to 0.16.0.
- [Release notes](https://github.com/sobelow/sobelow/releases)
- [Changelog](https://github.com/sobelow/sobelow/blob/main/CHANGELOG.md)
- [Commits](https://github.com/sobelow/sobelow/commits/v0.16.0)

---
updated-dependencies:
- dependency-name: sobelow
  dependency-version: 0.16.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file elixir Pull requests that update Elixir code labels Oct 5, 2026

@nelsonic nelsonic left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Superseded by #231

@nelsonic nelsonic closed this Oct 5, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/hex/sobelow-0.16.0 branch October 5, 2026 16:37

This branch had an error being deployed

1 failed deployment
dwylauth — d38da19e Deployed Oct 5, 2026 by dependabot[bot] via Build and test #363
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file elixir Pull requests that update Elixir code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant