1.2 KiB
1.2 KiB
id, title, status, assignee, created_date, labels, dependencies, references, priority
| id | title | status | assignee | created_date | labels | dependencies | references | priority | |
|---|---|---|---|---|---|---|---|---|---|
| ML-9 | Add mix_audit dependency for CVE scanning | To Do | 2026-04-20 08:49 |
|
low |
Description
GitHub: created 2026-04-16 · updated 2026-04-16
Summary
The project has Sobelow (SAST) and mix hex.audit (retirement-only check) but no CVE database scan against the installed dep tree.
Evidence
mix.exsdoes not listmix_auditmise run dev:lintpipeline does not include a CVE step.github/workflows/test_and_deploy.ymllint job does not run any CVE scanner
Fix
Add {:mix_audit, "~> 2.1", only: :dev, runtime: false} to mix.exs and wire into the lint pipeline:
# in mise.toml, under [tasks."dev:lint"] or as a new task
mix deps.audit
And add a step in .github/workflows/test_and_deploy.yml lint job.
Acceptance Criteria
mix deps.auditruns in CI- CI fails (or warns, TBD) on advisories
- #1
mix deps.auditruns in CI - #2 CI fails (or warns, TBD) on advisories