--- id: ML-9 title: Add mix_audit dependency for CVE scanning status: Done assignee: [] created_date: "2026-04-20 08:49" updated_date: "2026-04-24 07:13" labels: [] dependencies: [] references: - "https://github.com/cloud8421/music_library/issues/174" priority: low --- ## Description _GitHub: created 2026-04-16 · updated 2026-04-16_ ## Summary The project has Sobelow (SAST) and `mix hex.audit` (retirement-only check) but no CVE database scan against the installed dep tree. ## Evidence - `mix.exs` does not list `mix_audit` - `mise run dev:lint` pipeline does not include a CVE step - `.github/workflows/test_and_deploy.yml` lint job does not run any CVE scanner ## Fix Add `{:mix_audit, "~> 2.1", only: :dev, runtime: false}` to `mix.exs` and wire into the lint pipeline: ```toml # in mise.toml, under [tasks."dev:lint"] or as a new task mix deps.audit ``` And add a step in `.github/workflows/test_and_deploy.yml` lint job. ## Acceptance Criteria - `mix deps.audit` runs in CI - CI fails (or warns, TBD) on advisories - [x] #1 `mix deps.audit` runs in CI as a warn-only step (continue-on-error) - [x] #2 `mix deps.audit` runs in `mise run dev:lint` as a warn-only step ## Implementation Notes Decision on fail-vs-warn: **warn-only** on both CI and local lint. Rationale: CVE databases evolve independently of the project, so a newly published advisory should surface quickly (annotation in CI) without blocking unrelated PRs or breaking `dev:lint` for devs who may not be able to remediate immediately (e.g. waiting on upstream fix). Changes: - `mix.exs`: added `{:mix_audit, "~> 2.1", only: :dev, runtime: false}` alongside other dev-only quality tools (ex_slop, quokka, credo). - `scripts/dev/lint`: added `mix deps.audit || true` between credo and gettext steps. - `.github/workflows/test_and_deploy.yml`: added `🛡️ Audit dependencies for CVEs` step in the lint job with `continue-on-error: true`, placed after sobelow. Verification: - `mix deps.get` resolved mix_audit 2.1.x plus yaml_elixir/yamerl transitive deps. - `mix deps.audit` currently reports "No vulnerabilities found." — baseline clean. - `shellcheck` passes on the updated `scripts/dev/lint`.