Skip to content

Update dependency sobelow to v0.15.0 - #2165

Open
renovate[bot] wants to merge 1 commit into
developfrom
renovate/sobelow-0.x-lockfile
Open

Update dependency sobelow to v0.15.0#2165
renovate[bot] wants to merge 1 commit into
developfrom
renovate/sobelow-0.x-lockfile

Conversation

@renovate

@renovate renovate Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
sobelow (source) dev minor 0.14.10.15.0

Release Notes

sobelow/sobelow (sobelow)

v0.15.0

Compare Source

  • Bug fixes
    • Config.Secrets no longer crashes the scan when a secret is written as
      anything other than a plain double-quoted string. Heredoc values and values
      containing escaped quotes previously raised a MatchError and aborted the
      entire run. These secrets are now reported, using the line of the enclosing
      config call.
    • A corrupt or unreadable version-check cache file no longer aborts the scan.
      Sobelow previously printed "This does not appear to be a Phoenix application"
      and exited 0 — a CI gate could pass having scanned nothing.
    • --strict now reports syntax errors instead of raising. It has been broken
      since Elixir 1.13 changed the error shape returned by
      Code.string_to_quoted/2. Errors are now reported as file:line:column:.
    • A template that cannot be parsed is now skipped (or reported under
      --strict) rather than aborting the scan with an EEx.SyntaxError. The
      error now names the offending template instead of nofile.
    • A malformed .sobelow-conf now produces an actionable message instead of a
      raw MatchError stacktrace. This mattered more since v0.14.1 began reading
      the file automatically.
    • An empty, whitespace-only, or comment-only .sobelow-conf is now read as
      no options rather than aborting the scan. Such a file parses to an empty
      block instead of a keyword list, so it originally crashed with a
      FunctionClauseError and then, once that was fixed, exited 1 with a
      configuration error. Since the file is read automatically, a stray
      touch .sobelow-conf or a truncated write was enough to break every scan
      in a project. Contents that cannot be interpreted are still an error.
    • --save-config now stores ignore_files relative to the project root.
      Absolute paths were previously baked into .sobelow-conf, breaking the
      committed file on every other machine and in CI.
    • Config.Secrets now reports the line of the secret itself when a config
      call spans multiple lines. The line search compared a tuple against an
      integer, so it never worked as intended.
    • An unwritable ~/.sobelow no longer fails a scan.
    • Fixed a string-interpolation typo that rendered dot-access variables as
      conn.${atom_to_string(field)}.
    • .sobelow-conf keys are now genuinely sorted alphabetically.
    • A .sobelow-conf can no longer stop Sobelow from scanning. --save-config
      wrote version into every file it generated, so
      mix sobelow --version --save-config produced a committed file that made
      every later run print the version and exit 0 — a CI gate reading that
      as a clean scan. version, details, all-details, save-config, and
      diff choose what Sobelow does rather than configure a scan, and are now
      accepted on the command line only. One in the file is ignored, with a
      warning when it would have changed anything. version is no longer
      written to the file in the first place.
    • # sobelow_skip comments are no longer thrown away over whitespace. The
      pattern demanded exactly one space after the # and exactly one before
      the list, so # sobelow_skip["XSS.Raw"], # sobelow_skip ["XSS.Raw"],
      and # sobelow_skip [ "XSS.Raw" ] were all ignored — silently, and
      indistinguishably from a skip that had simply not applied. Spacing around
      the marker, inside the list, and around commas is now irrelevant.
    • SQL.Query no longer reports a project's own query/1 as SQL injection.
      An unqualified query/query! call was matched regardless of what it
      referred to, so every call to a local function that happened to carry one
      of those very ordinary names produced a finding. The unqualified form is
      now only considered in a file that has import Ecto.Adapters.SQL or
      use Ecto.Repo — the two ways the bare name can actually reach Ecto.
      Qualified calls, such as Repo.query/1 and Ecto.Adapters.SQL.query/3,
      are unaffected.
    • Enhancements
      • Added --no-router, for scanning a project that has no Phoenix router.
        Sobelow warned that it could not find one and offered no way to silence it,
        which was noise for plain Elixir libraries. It is shorthand for
        --router :none, which can also be set in .sobelow-conf as
        router: :none. The router-dependent checks are skipped either way.
      • .sobelow-skips is now written in sorted order, so regenerating it after
        fixing or adding a finding produces a small diff instead of reshuffling the
        file. Entries sort by type, file, and line number — numerically, so line 10
        follows line 9 rather than line 1. The whole file is sorted, not just the
        newly added entries, so the ordering holds however many times it is
        regenerated. Comments and pre-v0.14 bare-fingerprint lines are preserved.
        Pass --legacy-skips for the previous append-only behaviour, which never
        rewrites lines it did not add.
      • # sobelow_skip comments now work on Phoenix router pipelines, not just
        functions. This makes Config.CSRF, Config.Headers, and Config.CSP
        suppressible per pipeline instead of only via --mark-skip-all, so an API
        pipeline that legitimately has no :protect_from_forgery can be annotated
        in place. Listing the parent Config module skips every Config check on
        that pipeline. As with function-level skips, this only takes effect under
        --skip.
      • A # sobelow_skip comment that cannot be read now warns on stderr, naming
        the file and line, instead of being dropped without a word. Single quotes
        and a list broken across several comment lines are still not accepted, but
        they now say so rather than leaving you to wonder why the finding came
        back.
      • --private now skips the version check entirely rather than still writing
        the cache file. It makes no network requests and touches no files outside
        the scanned project.
      • SOBELOW_HOME is now documented, and is treated as the directory holding
        the version-check cache.
      • Added usage-rules.md, following the usage_rules convention, so projects
        using AI coding assistants can pull Sobelow's guidance into their agent's
        context with mix usage_rules.sync. It is shipped in the Hex package.
      • Added AGENTS.md documenting the checker-module contract for contributors.
      • Added support for Elixir v1.20.x.
    • Testing
      • Added an end-to-end test harness (Sobelow.ScanCase) that runs full scans
        against fixture applications under test/fixtures/apps, plus regression
        coverage for every bug above. Line coverage went from 29% to 67%.
      • Added coverage for CLI option parsing, .sobelow-conf precedence, --exit
        and --threshold mapping, and the json/sarif/quiet/txt renderers.
      • Added end-to-end coverage for pipeline-level # sobelow_skip comments, and
        unit coverage for how skips associate with pipelines in the AST.
      • Sobelow.ScanCase.temp_fixture_file/3 now restores a committed fixture's
        original contents instead of deleting the file, so a test can vary a
        checked-in fixture without destroying it.
    • Misc
      • Replaced the deprecated :preferred_cli_env project key with def cli.
      • Bumped credo to ~> 1.7.19; 1.7.12 crashed on Elixir 1.20.
      • Removed a dead Elixir 1.5 version guard and fixed an always-true conditional
        in the SARIF renderer.
Upgrade notes
  • Config.Secrets line numbers may change for config calls that span
    multiple lines, and for files where the same secret value appears more than
    once. Finding fingerprints include the line number, so any affected
    .sobelow-skips entries will stop matching and those findings will resurface.
    Re-run mix sobelow --mark-skip-all if you rely on a committed skip file.
  • Secrets that previously crashed the scan are now reported. If a heredoc or
    escaped-quote secret exists in your config, you will see new findings where the
    scan previously failed outright.
  • SOBELOW_HOME semantics changed from "path to the cache file" to "directory
    holding the cache file". The previous behaviour raised a MatchError for the
    natural usage, so this is unlikely to affect anyone.

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added dependencies Pull requests that update a dependency file elixir Pull requests that update Elixir code labels Aug 5, 2026
@renovate
renovate Bot requested a review from Flo0807 August 5, 2026 21:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file elixir Pull requests that update Elixir code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants