Files
music_library/backlog/completed/ml-9 - Add-mix_audit-dependency-for-CVE-scanning.md
T
2026-05-04 21:22:27 +01:00

72 lines
2.3 KiB
Markdown

---
id: ML-9
title: Add mix_audit dependency for CVE scanning
status: Done
assignee: []
created_date: "2026-04-20 08:49"
updated_date: "2026-04-24 07:13"
labels: []
dependencies: []
references:
- "https://github.com/cloud8421/music_library/issues/174"
priority: low
---
## Description
<!-- SECTION:DESCRIPTION:BEGIN -->
_GitHub: created 2026-04-16 · updated 2026-04-16_
## Summary
The project has Sobelow (SAST) and `mix hex.audit` (retirement-only check) but no CVE database scan against the installed dep tree.
## Evidence
- `mix.exs` does not list `mix_audit`
- `mise run dev:lint` pipeline does not include a CVE step
- `.github/workflows/test_and_deploy.yml` lint job does not run any CVE scanner
## Fix
Add `{:mix_audit, "~> 2.1", only: :dev, runtime: false}` to `mix.exs` and wire into the lint pipeline:
```toml
# in mise.toml, under [tasks."dev:lint"] or as a new task
mix deps.audit
```
And add a step in `.github/workflows/test_and_deploy.yml` lint job.
## Acceptance Criteria
<!-- AC:BEGIN -->
- `mix deps.audit` runs in CI
- CI fails (or warns, TBD) on advisories
<!-- SECTION:DESCRIPTION:END -->
- [x] #1 `mix deps.audit` runs in CI as a warn-only step (continue-on-error)
- [x] #2 `mix deps.audit` runs in `mise run dev:lint` as a warn-only step
<!-- AC:END -->
## Implementation Notes
<!-- SECTION:NOTES:BEGIN -->
Decision on fail-vs-warn: **warn-only** on both CI and local lint. Rationale: CVE databases evolve independently of the project, so a newly published advisory should surface quickly (annotation in CI) without blocking unrelated PRs or breaking `dev:lint` for devs who may not be able to remediate immediately (e.g. waiting on upstream fix).
Changes:
- `mix.exs`: added `{:mix_audit, "~> 2.1", only: :dev, runtime: false}` alongside other dev-only quality tools (ex_slop, quokka, credo).
- `scripts/dev/lint`: added `mix deps.audit || true` between credo and gettext steps.
- `.github/workflows/test_and_deploy.yml`: added `🛡️ Audit dependencies for CVEs` step in the lint job with `continue-on-error: true`, placed after sobelow.
Verification:
- `mix deps.get` resolved mix_audit 2.1.x plus yaml_elixir/yamerl transitive deps.
- `mix deps.audit` currently reports "No vulnerabilities found." — baseline clean.
- `shellcheck` passes on the updated `scripts/dev/lint`.
<!-- SECTION:NOTES:END -->