Skip to content

Audit Hex dependencies with mix hex.audit - #90

Merged
rubas-agent[bot] merged 1 commit into
mainfrom
hex-audit
Sep 29, 2026
Merged

rubas-agent[bot] merged 1 commit into
mainfrom
hex-audit

Conversation

@rubas-agent

@rubas-agent rubas-agent Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

The daily security audit now runs mix hex.audit instead of mix deps.audit.

Before: security.yml ran MIX_ENV=test mix deps.audit from the mix_audit 2.1.5 dependency.

Problem:

  • mix_audit reads only a GitHub advisory mirror. It misses the Hex advisory feed (EEF CNA).
  • The repo carried mix_audit and two YAML deps only for this one check.

After: security.yml runs MIX_ENV=test mix hex.audit. It fails on a security advisory and on a retired package. mix_audit, yaml_elixir, and yamerl are gone from mix.exs and mix.lock.

Advisories: none. No bumps and no waivers.

Details and checks
  • Hex reports advisories in mix hex.audit from 2.5.1 on. The workflow runs mix local.hex --force, which installs the latest Hex, so CI gets 2.5.1 or newer.
  • mix deps.unlock --unused removed mix_audit, yaml_elixir, and yamerl. jason stays, because credo needs it.
  • Checks I ran with Hex 2.5.1, Elixir 1.20.4, OTP 29.1.1:
    • mix hex.audit in the branch: "No retired or security advisory packages found".
    • The audit prototype of the shared workflow on this branch: the same result.
    • MIX_ENV=test mix compile --warnings-as-errors: passes.
  • The reviewer checks that the Security Audit workflow still passes on main after the merge.

mix_audit reads only a GitHub advisory mirror and misses the Hex advisory feed. Hex 2.5.1 and newer report advisories in mix hex.audit; the workflow installs the latest Hex with mix local.hex.
@rubas-agent
rubas-agent Bot merged commit 87956c3 into main Sep 29, 2026
1 check passed
@rubas-agent
rubas-agent Bot deleted the hex-audit branch September 29, 2026 09:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant