chore(deps): update elixir minor updates - #202
Open
wttj-bot[bot] wants to merge 1 commit into
Open
Conversation
wttj-bot
Bot
force-pushed
the
renovate/elixir-minor-updates
branch
from
July 5, 2026 11:06
eab1a96 to
86dd88b
Compare
wttj-bot
Bot
force-pushed
the
renovate/elixir-minor-updates
branch
4 times, most recently
from
July 11, 2026 11:07
0759f3a to
cdec4a6
Compare
wttj-bot
Bot
force-pushed
the
renovate/elixir-minor-updates
branch
2 times, most recently
from
July 17, 2026 09:07
b927086 to
d90ccfb
Compare
wttj-bot
Bot
force-pushed
the
renovate/elixir-minor-updates
branch
from
July 24, 2026 11:10
d90ccfb to
021b5d8
Compare
wttj-bot
Bot
force-pushed
the
renovate/elixir-minor-updates
branch
2 times, most recently
from
August 7, 2026 13:07
b9240f1 to
7b2f20f
Compare
wttj-bot
Bot
force-pushed
the
renovate/elixir-minor-updates
branch
2 times, most recently
from
August 14, 2026 17:04
f6ecf66 to
137f1df
Compare
Contributor
Author
|
wttj-bot
Bot
force-pushed
the
renovate/elixir-minor-updates
branch
from
August 19, 2026 09:05
137f1df to
6f380cb
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.13.6→3.14.23.13.5→3.14.0~> 0.12→~> 0.19~> 0.5→~> 0.70.7.3~> 0.13→~> 0.15Release Notes
elixir-ecto/ecto (ecto)
v3.14.2Compare Source
Enhancements
:writableand:on_writable_violationfor the:inserted_atfield generated bytimestamps/1Bug fixes
changed?/3for removed one-to-one relationsbelongs_tokeys inapply_changes/1prepare_changescallbacks inmerge/2:on_castfunction in relation type metadataprepare_changescallbacks@deriveDateTimecasts to UTCv3.14.1Compare Source
Enhancements
embedded_schemato have non-virtual:anyfields:on_writable_violationoption for fields (a default can be specified with@on_writable_violation)Bug fixes
fromsource is a{fragment, schema}tuple:writablein returned structinsert_allwith placeholdersv3.14.0Compare Source
Enhancements
counteroption inprepare_query/3Ecto.Changeset.reorder_assoc/2{fragment, Schema}source:replace_changedon upserts to enable HOT updates in PostgreSQL:query_cacheoption to selectively bypass query cache:on_join_through_conflictoption forEcto.Type.trim/2and allow developers to configure how values are trimmed on cast with the:trim_valuesoptionBug fixes
order_bynow take precedence over:preload_order. The:preload_orderoption is now only applied when no custom query with ordering is provided.elixir-ecto/ecto_sql (ecto_sql)
v3.14.0Compare Source
Enhancements
insert_mode: :ignoremix ecto.createto_sql/4{:unsafe_fragment, ...}support to RETURNING clauseelixirs/faker (faker)
v0.19.0Compare Source
wojtekmach/req (req)
v0.7.2Compare Source
encode_body]: Bring backform_multipart: [{string_name, value}].put_aws_sigv4]: Fix AWS SigV4 compatibility with Supabase Storage S3.v0.7.1Compare Source
cache: true/[cache] step. It will be removed in Req v0.8. I plan a comprehensive cache solution for Req v1.0+.v0.7.0Compare Source
[
Req]: AddReq.new(req, options).[
Req]: Treat URL userinfo as Basic Authentication.[
Req], [Req.Request]: Deprecateadapter: funin favour ofadapter: mod.[
Req.Request]: (BREAKING CHANGE) Removecurrent_request_stepsfield.[
Req.Request]: Fix redacting remaining auth values.(BREAKING CHANGE) Replace
run_finchstep with [Req.Finch] adapter module.(BREAKING CHANGE) Replace
put_plugandrun_plugsteps with [Req.Plug] adapter module.[
Req.Finch]: Supportfinch: options.[
Req.Finch]: Support:request_timeout.[
Req.Finch]: Fix handling duplicate response headers.[
Req.Finch]: Deprecatefinch: namein favour offinch: [name: name].[
Req.Finch]: Deprecatepool_timeout: valuein favour offinch: [pool_timeout: value].[
Req.Finch]: Deprecatepool_max_idle_time: valuein favour offinch: [pool_max_idle_time: value].[
Req.Finch]: Deprecate:finch_request.[
Req.Plug]: Handle individual response body chunks.[
Req.Plug]: Support non-UTF8 request params.[
Req.Plug]: Put original request private data inconn.private.[
Req.Test]: Allow descendant processes.[
Req.Test]: Fix concurrent plug fetches immediately after switching to shared mode.[
compress_body]: Do nothing when request content-encoding is already set.[
compress_body]: Update multipart boundary when re-running the step.[
compressed], [decode_body]: Replace optionalezstddependency with Erlang/OTP 28+built-in
:zstd.[
decode_body]: Deprecate:decode_jsonin favour of setting a custom JSONdecoder via
:decoders:before:
after:
[
encode_body]: (BREAKING CHANGE) Automatically change GET to POST when request body is set.[
put_aws_sigv4]: Excludeaccept-encoding,x-amzn-trace-id, andhop-by-hop headers from the signature.
[
put_aws_sigv4]: Correctly sign duplicate header values.[
put_params]: (BREAKING CHANGE) Overwrite existing query params instead of appending.[
put_path_params]: Preserve the path template when re-running the step.[
redirect]: Strip userinfo from redirect locations and log a warning.Previously, redirecting to a URL with userinfo (e.g.
http://user:pass@host)kept the userinfo in the request URL (without converting it to auth). It is
now dropped so credentials supplied by the redirecting server aren't sent.
[
redirect]: Clear the request body, body options, and content headers whenchanging POST to GET after a 301, 302, or 303 response.
[
retry]: Use jitter by default.[
retry]: Honor configured:retry_delayoverRetry-After.(BREAKING CHANGE) Remove deprecated
follow_redirectsstep.(BREAKING CHANGE) Remove deprecated
outputstep.Require Elixir 1.15 or later.
sobelow/sobelow (sobelow)
v0.15.0Compare Source
Config.Secretsno longer crashes the scan when a secret is written asanything other than a plain double-quoted string. Heredoc values and values
containing escaped quotes previously raised a
MatchErrorand aborted theentire run. These secrets are now reported, using the line of the enclosing
configcall.Sobelow previously printed "This does not appear to be a Phoenix application"
and exited 0 — a CI gate could pass having scanned nothing.
--strictnow reports syntax errors instead of raising. It has been brokensince Elixir 1.13 changed the error shape returned by
Code.string_to_quoted/2. Errors are now reported asfile:line:column:.--strict) rather than aborting the scan with anEEx.SyntaxError. Theerror now names the offending template instead of
nofile..sobelow-confnow produces an actionable message instead of araw
MatchErrorstacktrace. This mattered more since v0.14.1 began readingthe file automatically.
.sobelow-confis now read asno options rather than aborting the scan. Such a file parses to an empty
block instead of a keyword list, so it originally crashed with a
FunctionClauseErrorand then, once that was fixed, exited 1 with aconfiguration error. Since the file is read automatically, a stray
touch .sobelow-confor a truncated write was enough to break every scanin a project. Contents that cannot be interpreted are still an error.
--save-confignow storesignore_filesrelative to the project root.Absolute paths were previously baked into
.sobelow-conf, breaking thecommitted file on every other machine and in CI.
Config.Secretsnow reports the line of the secret itself when aconfigcall spans multiple lines. The line search compared a tuple against an
integer, so it never worked as intended.
~/.sobelowno longer fails a scan.conn.${atom_to_string(field)}..sobelow-confkeys are now genuinely sorted alphabetically..sobelow-confcan no longer stop Sobelow from scanning.--save-configwrote
versioninto every file it generated, somix sobelow --version --save-configproduced a committed file that madeevery later run print the version and exit 0 — a CI gate reading that
as a clean scan.
version,details,all-details,save-config, anddiffchoose what Sobelow does rather than configure a scan, and are nowaccepted on the command line only. One in the file is ignored, with a
warning when it would have changed anything.
versionis no longerwritten to the file in the first place.
# sobelow_skipcomments are no longer thrown away over whitespace. Thepattern demanded exactly one space after the
#and exactly one beforethe list, so
# sobelow_skip["XSS.Raw"],# sobelow_skip ["XSS.Raw"],and
# sobelow_skip [ "XSS.Raw" ]were all ignored — silently, andindistinguishably from a skip that had simply not applied. Spacing around
the marker, inside the list, and around commas is now irrelevant.
SQL.Queryno longer reports a project's ownquery/1as SQL injection.An unqualified
query/query!call was matched regardless of what itreferred to, so every call to a local function that happened to carry one
of those very ordinary names produced a finding. The unqualified form is
now only considered in a file that has
import Ecto.Adapters.SQLoruse Ecto.Repo— the two ways the bare name can actually reach Ecto.Qualified calls, such as
Repo.query/1andEcto.Adapters.SQL.query/3,are unaffected.
--no-router, for scanning a project that has no Phoenix router.Sobelow warned that it could not find one and offered no way to silence it,
which was noise for plain Elixir libraries. It is shorthand for
--router :none, which can also be set in.sobelow-confasrouter: :none. The router-dependent checks are skipped either way..sobelow-skipsis now written in sorted order, so regenerating it afterfixing or adding a finding produces a small diff instead of reshuffling the
file. Entries sort by type, file, and line number — numerically, so line 10
follows line 9 rather than line 1. The whole file is sorted, not just the
newly added entries, so the ordering holds however many times it is
regenerated. Comments and pre-v0.14 bare-fingerprint lines are preserved.
Pass
--legacy-skipsfor the previous append-only behaviour, which neverrewrites lines it did not add.
# sobelow_skipcomments now work on Phoenix router pipelines, not justfunctions. This makes
Config.CSRF,Config.Headers, andConfig.CSPsuppressible per pipeline instead of only via
--mark-skip-all, so an APIpipeline that legitimately has no
:protect_from_forgerycan be annotatedin place. Listing the parent
Configmodule skips every Config check onthat pipeline. As with function-level skips, this only takes effect under
--skip.# sobelow_skipcomment that cannot be read now warns on stderr, namingthe file and line, instead of being dropped without a word. Single quotes
and a list broken across several comment lines are still not accepted, but
they now say so rather than leaving you to wonder why the finding came
back.
--privatenow skips the version check entirely rather than still writingthe cache file. It makes no network requests and touches no files outside
the scanned project.
SOBELOW_HOMEis now documented, and is treated as the directory holdingthe version-check cache.
usage-rules.md, following theusage_rulesconvention, so projectsusing AI coding assistants can pull Sobelow's guidance into their agent's
context with
mix usage_rules.sync. It is shipped in the Hex package.AGENTS.mddocumenting the checker-module contract for contributors.Sobelow.ScanCase) that runs full scansagainst fixture applications under
test/fixtures/apps, plus regressioncoverage for every bug above. Line coverage went from 29% to 67%.
.sobelow-confprecedence,--exitand
--thresholdmapping, and thejson/sarif/quiet/txtrenderers.# sobelow_skipcomments, andunit coverage for how skips associate with pipelines in the AST.
Sobelow.ScanCase.temp_fixture_file/3now restores a committed fixture'soriginal contents instead of deleting the file, so a test can vary a
checked-in fixture without destroying it.
:preferred_cli_envproject key withdef cli.credoto~> 1.7.19; 1.7.12 crashed on Elixir 1.20.in the SARIF renderer.
Upgrade notes
Config.Secretsline numbers may change forconfigcalls that spanmultiple lines, and for files where the same secret value appears more than
once. Finding fingerprints include the line number, so any affected
.sobelow-skipsentries will stop matching and those findings will resurface.Re-run
mix sobelow --mark-skip-allif you rely on a committed skip file.escaped-quote secret exists in your config, you will see new findings where the
scan previously failed outright.
SOBELOW_HOMEsemantics changed from "path to the cache file" to "directoryholding the cache file". The previous behaviour raised a
MatchErrorfor thenatural usage, so this is unlikely to affect anyone.
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.