72 lines
2.3 KiB
Markdown
72 lines
2.3 KiB
Markdown
---
|
|
id: ML-9
|
|
title: Add mix_audit dependency for CVE scanning
|
|
status: Done
|
|
assignee: []
|
|
created_date: "2026-04-20 08:49"
|
|
updated_date: "2026-04-24 07:13"
|
|
labels: []
|
|
dependencies: []
|
|
references:
|
|
- "https://github.com/cloud8421/music_library/issues/174"
|
|
priority: low
|
|
---
|
|
|
|
## Description
|
|
|
|
<!-- SECTION:DESCRIPTION:BEGIN -->
|
|
|
|
_GitHub: created 2026-04-16 · updated 2026-04-16_
|
|
|
|
## Summary
|
|
|
|
The project has Sobelow (SAST) and `mix hex.audit` (retirement-only check) but no CVE database scan against the installed dep tree.
|
|
|
|
## Evidence
|
|
|
|
- `mix.exs` does not list `mix_audit`
|
|
- `mise run dev:lint` pipeline does not include a CVE step
|
|
- `.github/workflows/test_and_deploy.yml` lint job does not run any CVE scanner
|
|
|
|
## Fix
|
|
|
|
Add `{:mix_audit, "~> 2.1", only: :dev, runtime: false}` to `mix.exs` and wire into the lint pipeline:
|
|
|
|
```toml
|
|
# in mise.toml, under [tasks."dev:lint"] or as a new task
|
|
mix deps.audit
|
|
```
|
|
|
|
And add a step in `.github/workflows/test_and_deploy.yml` lint job.
|
|
|
|
## Acceptance Criteria
|
|
|
|
<!-- AC:BEGIN -->
|
|
|
|
- `mix deps.audit` runs in CI
|
|
- CI fails (or warns, TBD) on advisories
|
|
<!-- SECTION:DESCRIPTION:END -->
|
|
|
|
- [x] #1 `mix deps.audit` runs in CI as a warn-only step (continue-on-error)
|
|
- [x] #2 `mix deps.audit` runs in `mise run dev:lint` as a warn-only step
|
|
<!-- AC:END -->
|
|
|
|
## Implementation Notes
|
|
|
|
<!-- SECTION:NOTES:BEGIN -->
|
|
|
|
Decision on fail-vs-warn: **warn-only** on both CI and local lint. Rationale: CVE databases evolve independently of the project, so a newly published advisory should surface quickly (annotation in CI) without blocking unrelated PRs or breaking `dev:lint` for devs who may not be able to remediate immediately (e.g. waiting on upstream fix).
|
|
|
|
Changes:
|
|
|
|
- `mix.exs`: added `{:mix_audit, "~> 2.1", only: :dev, runtime: false}` alongside other dev-only quality tools (ex_slop, quokka, credo).
|
|
- `scripts/dev/lint`: added `mix deps.audit || true` between credo and gettext steps.
|
|
- `.github/workflows/test_and_deploy.yml`: added `🛡️ Audit dependencies for CVEs` step in the lint job with `continue-on-error: true`, placed after sobelow.
|
|
|
|
Verification:
|
|
|
|
- `mix deps.get` resolved mix_audit 2.1.x plus yaml_elixir/yamerl transitive deps.
|
|
- `mix deps.audit` currently reports "No vulnerabilities found." — baseline clean.
|
|
- `shellcheck` passes on the updated `scripts/dev/lint`.
|
|
<!-- SECTION:NOTES:END -->
|