Skip to content

Bump sobelow from 0.15.0 to 0.16.0 in the non-security group - #37

Merged
aj-foster merged 1 commit into
mainfrom
dependabot/hex/non-security-c43e7e7917
Oct 5, 2026
Merged

aj-foster merged 1 commit into
mainfrom
dependabot/hex/non-security-c43e7e7917

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the non-security group with 1 update: sobelow.

Updates sobelow from 0.15.0 to 0.16.0

Release notes

Sourced from sobelow's releases.

v0.16.0

What's Changed

New Contributors

Full Changelog: sobelow/sobelow@v0.15.0...v0.16.0

Changelog

Sourced from sobelow's changelog.

v0.16.0

  • Bug fixes
    • XSS.Raw no longer reports calls to a benign local raw helper with the matching arity, including defaults, guards, pipes, captures, and inline HEEx. Local definitions stay within their module; qualified Phoenix calls and implicitly imported template helpers retain detection. Helpers returning dynamic {:safe, value} output or wrapping another raw call retain their caller's original findings, locations, and fingerprints. (#44)
    • XSS.SendResp now recognizes put_resp_header(conn, "content-type", type) on the response connection, including piped, aliased, nested, and assigned calls. HTML, SVG, malformed, and unknown types still report; other XML and PDF document types retain low-confidence findings. Discarded, later, unrelated, locally shadowed, or ambiguously imported setters cannot suppress findings. Known unrelated response headers retain the connection's content type, and MIME parameters do not change its classification. (#45)
    • XSS.Raw now respects explicit imports of unrelated raw helpers. Unknown raw macros and delegates retain detection. Older inline lexical contexts without local-signature metadata remain supported.
    • Invalid project roots, roots with no scannable source files, invalid scan options, and unwritable output files now fail with actionable errors.
    • Repeated scans in the same VM now start with fresh findings, template, and skip state. Malformed sources and templates are skipped with a warning in non-strict mode, and unreadable files are skipped with a warning.
    • Dynamic socket options, literal statements in router pipelines, and access on a literal keyword list no longer abort scans. Unknown socket options produce low-confidence findings.
    • XSS.SendResp now follows the connection passed to each response and its content type before that sink. Later or discarded setters cannot suppress an earlier finding, and rebindings in branches, patterns, callbacks, generators, and call arguments cannot borrow another connection's content type. Unchanged bindings, pins, guards, and explicit setters retain their existing handling.
    • HTTPS and HSTS checks now use effective settings for the scanned application and each endpoint, including ordered overrides and nested keyword merges. One endpoint cannot satisfy another's settings. Dynamic and conditional settings produce low-confidence findings. Empty CSP policies are reported.
    • Enabled sockets now inherit endpoint origin settings from base, production, and runtime configuration, including socket/2 and websocket: true. Explicit socket overrides retain precedence, and disabled WebSockets remain excluded. Defaults are isolated to each endpoint module. Origin allowlists and :conn are recognized; an enabled CSRF check lowers confidence when origin checks are disabled.
    • HEEx comments and script/style text no longer change brace-interpolation scope or introduce findings from literal markup. The phx-no-curly-interpolation directive is recognized as an attribute name; the same text inside another attribute's value cannot suppress findings. Inline columns account for sigil prefixes and heredoc indentation.
    • Module-local use and import declarations now apply only to their own module. Named captures and inline HEEx retain lexical aliases and import

... (truncated)

Commits
  • 80b84f4 version bump - 0.16.0
  • b5ca40d Harden XSS call resolution and response content-type analysis
  • 6cac655 Fix XSS false positives for local raw helpers and response headers
  • 56725cd Add GitHub Actions workflow annotations
  • c3ba4bd Align unreleased changelog with existing release format
  • e0a5bf6 Split parsing and scan orchestration into focused modules
  • ff25101 Fix adversarial scan crashes and missed XSS detections
  • 4539bc1 Fix socket origin inheritance, HEEx directives, and lockfile aliases
  • 468d531 Isolate named processes and configuration in legacy tests
  • 86b922f Respect older Elixir metadata in compatibility tests
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Note

Low Risk
Lockfile-only bump of a dev/test security linter; no runtime code changes, though CI Sobelow findings may differ due to improved rules.

Overview
Updates the locked sobelow dependency from 0.15.0 to 0.16.0 in mix.lock only; mix.exs already permits this via ~> 0.13.

CI and local mix check still run sobelow --config, but they will use the newer scanner. 0.16.0 brings broader XSS and config analysis (fewer false positives on local raw helpers and put_resp_header), GitHub Actions annotation output, and more reliable scan orchestration—so security CI results may shift slightly even though application code is unchanged.

Reviewed by Cursor Bugbot for commit 02bdc86. Bugbot is set up for automated code reviews on this repo. Configure here.

Bumps the non-security group with 1 update: [sobelow](https://github.com/sobelow/sobelow).


Updates `sobelow` from 0.15.0 to 0.16.0
- [Release notes](https://github.com/sobelow/sobelow/releases)
- [Changelog](https://github.com/sobelow/sobelow/blob/main/CHANGELOG.md)
- [Commits](sobelow/sobelow@v0.15.0...v0.16.0)

---
updated-dependencies:
- dependency-name: sobelow
  dependency-version: 0.16.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: non-security
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file elixir Pull requests that update elixir code labels Oct 5, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner October 5, 2026 09:06
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file elixir Pull requests that update elixir code labels Oct 5, 2026
@broly-code-security-scanner

Copy link
Copy Markdown

Broly Security Scan

Note

✅ Clean scan
No vulnerabilities detected in this PR.

Note

Re-scan this PR anytime with /broly scan — useful after /broly undismiss, or to refresh findings without a new push.

Broly — SAST (GLM-5.3-Flash) · Secrets · SCA · IaC · GH Actions · Base Images · Supply Chain Threats · Attack Hypotheses · Adversarial Verification

We're continuously improving Broly's accuracy and finding quality — your feedback is valuable. False positives, missed findings, bugs, and feature requests all welcome.

Ask in #security-engineering   Powered by Together AI

@aj-foster
aj-foster merged commit c7fbdc4 into main Oct 5, 2026
5 checks passed
@aj-foster
aj-foster deleted the dependabot/hex/non-security-c43e7e7917 branch October 5, 2026 16:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file elixir Pull requests that update elixir code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants