Skip to content

chore(deps-dev): bump sobelow from 0.15.0 to 0.16.0 in /design - #187

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/hex/design/sobelow-0.16.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/hex/design/sobelow-0.16.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Bumps sobelow from 0.15.0 to 0.16.0.

Release notes

Sourced from sobelow's releases.

v0.16.0

What's Changed

New Contributors

Full Changelog: sobelow/sobelow@v0.15.0...v0.16.0

Changelog

Sourced from sobelow's changelog.

v0.16.0

  • Bug fixes
    • XSS.Raw no longer reports calls to a benign local raw helper with the matching arity, including defaults, guards, pipes, captures, and inline HEEx. Local definitions stay within their module; qualified Phoenix calls and implicitly imported template helpers retain detection. Helpers returning dynamic {:safe, value} output or wrapping another raw call retain their caller's original findings, locations, and fingerprints. (#44)
    • XSS.SendResp now recognizes put_resp_header(conn, "content-type", type) on the response connection, including piped, aliased, nested, and assigned calls. HTML, SVG, malformed, and unknown types still report; other XML and PDF document types retain low-confidence findings. Discarded, later, unrelated, locally shadowed, or ambiguously imported setters cannot suppress findings. Known unrelated response headers retain the connection's content type, and MIME parameters do not change its classification. (#45)
    • XSS.Raw now respects explicit imports of unrelated raw helpers. Unknown raw macros and delegates retain detection. Older inline lexical contexts without local-signature metadata remain supported.
    • Invalid project roots, roots with no scannable source files, invalid scan options, and unwritable output files now fail with actionable errors.
    • Repeated scans in the same VM now start with fresh findings, template, and skip state. Malformed sources and templates are skipped with a warning in non-strict mode, and unreadable files are skipped with a warning.
    • Dynamic socket options, literal statements in router pipelines, and access on a literal keyword list no longer abort scans. Unknown socket options produce low-confidence findings.
    • XSS.SendResp now follows the connection passed to each response and its content type before that sink. Later or discarded setters cannot suppress an earlier finding, and rebindings in branches, patterns, callbacks, generators, and call arguments cannot borrow another connection's content type. Unchanged bindings, pins, guards, and explicit setters retain their existing handling.
    • HTTPS and HSTS checks now use effective settings for the scanned application and each endpoint, including ordered overrides and nested keyword merges. One endpoint cannot satisfy another's settings. Dynamic and conditional settings produce low-confidence findings. Empty CSP policies are reported.
    • Enabled sockets now inherit endpoint origin settings from base, production, and runtime configuration, including socket/2 and websocket: true. Explicit socket overrides retain precedence, and disabled WebSockets remain excluded. Defaults are isolated to each endpoint module. Origin allowlists and :conn are recognized; an enabled CSRF check lowers confidence when origin checks are disabled.
    • HEEx comments and script/style text no longer change brace-interpolation scope or introduce findings from literal markup. The phx-no-curly-interpolation directive is recognized as an attribute name; the same text inside another attribute's value cannot suppress findings. Inline columns account for sigil prefixes and heredoc indentation.
    • Module-local use and import declarations now apply only to their own module. Named captures and inline HEEx retain lexical aliases and import

... (truncated)

Commits
  • 80b84f4 version bump - 0.16.0
  • b5ca40d Harden XSS call resolution and response content-type analysis
  • 6cac655 Fix XSS false positives for local raw helpers and response headers
  • 56725cd Add GitHub Actions workflow annotations
  • c3ba4bd Align unreleased changelog with existing release format
  • e0a5bf6 Split parsing and scan orchestration into focused modules
  • ff25101 Fix adversarial scan crashes and missed XSS detections
  • 4539bc1 Fix socket origin inheritance, HEEx directives, and lockfile aliases
  • 468d531 Isolate named processes and configuration in legacy tests
  • 86b922f Respect older Elixir metadata in compatibility tests
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [sobelow](https://github.com/sobelow/sobelow) from 0.15.0 to 0.16.0.
- [Release notes](https://github.com/sobelow/sobelow/releases)
- [Changelog](https://github.com/sobelow/sobelow/blob/main/CHANGELOG.md)
- [Commits](sobelow/sobelow@v0.15.0...v0.16.0)

---
updated-dependencies:
- dependency-name: sobelow
  dependency-version: 0.16.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file elixir Pull requests that update elixir code labels Oct 6, 2026
@cursor

cursor Bot commented Oct 7, 2026

Copy link
Copy Markdown

Superseded by #185 (merged). Closing this Dependabot PR; the branch is left in place.

@dependabot @github

dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/hex/design/sobelow-0.16.0 branch October 7, 2026 11:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file elixir Pull requests that update elixir code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant