Skip to content

chore(deps-dev): bump sobelow from 0.15.0 to 0.16.0 - #253

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/hex/sobelow-0.16.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/hex/sobelow-0.16.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 10, 2026 •

Copy link
Copy Markdown

Bumps sobelow from 0.15.0 to 0.16.0.

Release notes

Sourced from sobelow's releases.

v0.16.0

What's Changed

New Contributors

Full Changelog: sobelow/sobelow@v0.15.0...v0.16.0

Changelog

Sourced from sobelow's changelog.

v0.16.0

  • Bug fixes
    • XSS.Raw no longer reports calls to a benign local raw helper with the matching arity, including defaults, guards, pipes, captures, and inline HEEx. Local definitions stay within their module; qualified Phoenix calls and implicitly imported template helpers retain detection. Helpers returning dynamic {:safe, value} output or wrapping another raw call retain their caller's original findings, locations, and fingerprints. (#44)
    • XSS.SendResp now recognizes put_resp_header(conn, "content-type", type) on the response connection, including piped, aliased, nested, and assigned calls. HTML, SVG, malformed, and unknown types still report; other XML and PDF document types retain low-confidence findings. Discarded, later, unrelated, locally shadowed, or ambiguously imported setters cannot suppress findings. Known unrelated response headers retain the connection's content type, and MIME parameters do not change its classification. (#45)
    • XSS.Raw now respects explicit imports of unrelated raw helpers. Unknown raw macros and delegates retain detection. Older inline lexical contexts without local-signature metadata remain supported.
    • Invalid project roots, roots with no scannable source files, invalid scan options, and unwritable output files now fail with actionable errors.
    • Repeated scans in the same VM now start with fresh findings, template, and skip state. Malformed sources and templates are skipped with a warning in non-strict mode, and unreadable files are skipped with a warning.
    • Dynamic socket options, literal statements in router pipelines, and access on a literal keyword list no longer abort scans. Unknown socket options produce low-confidence findings.
    • XSS.SendResp now follows the connection passed to each response and its content type before that sink. Later or discarded setters cannot suppress an earlier finding, and rebindings in branches, patterns, callbacks, generators, and call arguments cannot borrow another connection's content type. Unchanged bindings, pins, guards, and explicit setters retain their existing handling.
    • HTTPS and HSTS checks now use effective settings for the scanned application and each endpoint, including ordered overrides and nested keyword merges. One endpoint cannot satisfy another's settings. Dynamic and conditional settings produce low-confidence findings. Empty CSP policies are reported.
    • Enabled sockets now inherit endpoint origin settings from base, production, and runtime configuration, including socket/2 and websocket: true. Explicit socket overrides retain precedence, and disabled WebSockets remain excluded. Defaults are isolated to each endpoint module. Origin allowlists and :conn are recognized; an enabled CSRF check lowers confidence when origin checks are disabled.
    • HEEx comments and script/style text no longer change brace-interpolation scope or introduce findings from literal markup. The phx-no-curly-interpolation directive is recognized as an attribute name; the same text inside another attribute's value cannot suppress findings. Inline columns account for sigil prefixes and heredoc indentation.
    • Module-local use and import declarations now apply only to their own module. Named captures and inline HEEx retain lexical aliases and import

... (truncated)

Commits
  • 80b84f4 version bump - 0.16.0
  • b5ca40d Harden XSS call resolution and response content-type analysis
  • 6cac655 Fix XSS false positives for local raw helpers and response headers
  • 56725cd Add GitHub Actions workflow annotations
  • c3ba4bd Align unreleased changelog with existing release format
  • e0a5bf6 Split parsing and scan orchestration into focused modules
  • ff25101 Fix adversarial scan crashes and missed XSS detections
  • 4539bc1 Fix socket origin inheritance, HEEx directives, and lockfile aliases
  • 468d531 Isolate named processes and configuration in legacy tests
  • 86b922f Respect older Elixir metadata in compatibility tests
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

📌 TL;DR

This PR updates the sobelow security audit dependency from version 0.15.0 to 0.16.0 in the project's lock file. This ensures the application uses the latest security scanning capabilities and vulnerability checks provided by the tool.

🎯 Type of Change

  • 🚀 New feature
  • 🐛 Bugfix
  • 🧹 Refactor
  • ⚡ Performance
  • 📚 Documentation
  • ⚙️ CI / Configuration

🔍 Changes Walkthrough

File Summary of Changes
mix.lock Updated the sobelow dependency entry from version 0.15.0 to 0.16.0, including the new package checksum and hash.

📊 Architectural Flow

(Omitted: This change is a dependency version update in a lock file and does not alter component interactions, APIs, or workflow state.)

Bumps [sobelow](https://github.com/sobelow/sobelow) from 0.15.0 to 0.16.0.
- [Release notes](https://github.com/sobelow/sobelow/releases)
- [Changelog](https://github.com/sobelow/sobelow/blob/main/CHANGELOG.md)
- [Commits](sobelow/sobelow@v0.15.0...v0.16.0)

---
updated-dependencies:
- dependency-name: sobelow
  dependency-version: 0.16.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file elixir Pull requests that update elixir code labels Oct 10, 2026

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Code review skipped — your organization has no extra usage available to pay for this review.

If your organization's extra usage balance is empty, an organization admin can add extra usage credits at claude.ai/admin-settings/usage. If its monthly spend limit was reached, an admin can raise it on the same page. If neither applies, contact Anthropic support.

Once extra usage is available, someone with write access to this repository can comment @claude review on this pull request to trigger a review.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits.
Credits must be used to enable repository wide code reviews.

@coderabbitai

coderabbitai Bot commented Oct 10, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 45cc2dc7-bdd4-4016-8c80-cc5baeda08ea

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

dos[bot]
dos Bot approved these changes Oct 10, 2026

@dos dos Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⏱️ Code Review completed (1 files · 2,454 chars · 1 PR unit(s))

✅ CLEAN_PASS: No candidate issues flagged

NO_ISSUES: The diff only updates a dependency lock file version without introducing functional defects.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file elixir Pull requests that update elixir code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants