Files
music_library/backlog/tasks/ml-9 - Add-mix_audit-dependency-for-CVE-scanning.md
T
2026-04-20 10:02:25 +01:00

1.2 KiB

id, title, status, assignee, created_date, labels, dependencies, references, priority
id title status assignee created_date labels dependencies references priority
ML-9 Add mix_audit dependency for CVE scanning To Do
2026-04-20 08:49
https://github.com/cloud8421/music_library/issues/174
low

Description

GitHub: created 2026-04-16 · updated 2026-04-16

Summary

The project has Sobelow (SAST) and mix hex.audit (retirement-only check) but no CVE database scan against the installed dep tree.

Evidence

  • mix.exs does not list mix_audit
  • mise run dev:lint pipeline does not include a CVE step
  • .github/workflows/test_and_deploy.yml lint job does not run any CVE scanner

Fix

Add {:mix_audit, "~> 2.1", only: :dev, runtime: false} to mix.exs and wire into the lint pipeline:

# in mise.toml, under [tasks."dev:lint"] or as a new task
mix deps.audit

And add a step in .github/workflows/test_and_deploy.yml lint job.

Acceptance Criteria

  • mix deps.audit runs in CI
  • CI fails (or warns, TBD) on advisories
  • #1 mix deps.audit runs in CI
  • #2 CI fails (or warns, TBD) on advisories