Skip to content

ci: audit Hex dependencies with mix hex.audit - #76

Merged
rubas-agent[bot] merged 1 commit into
mainfrom
hex-audit
Sep 29, 2026
Merged

rubas-agent[bot] merged 1 commit into
mainfrom
hex-audit

Conversation

@rubas-agent

@rubas-agent rubas-agent Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Before: security.yml runs MIX_ENV=test mix deps.audit from the mix_audit 2.1.5 dependency.

Problem

  • mix_audit reads only a GitHub advisory mirror. It misses the Hex advisory feed (EEF CNA).
  • The repo carries mix_audit and two YAML deps only for this one check.

After: security.yml runs MIX_ENV=test mix hex.audit. mix_audit, yaml_elixir, and yamerl leave mix.exs and mix.lock.

Advisories: none. mix hex.audit reports no advisory and no retired package, so this PR bumps nothing and waives nothing.

Details
  • Hex version: mix hex.audit reports advisories from Hex 2.5.1. The workflow runs mix local.hex --force, which installs the newest Hex (2.5.1 today). Nothing pins an older Hex.
  • CHANGELOG.md has no Unreleased section, so this PR adds no entry.
  • Checks I ran in the branch:
    • ~/.cache/hex-audit/prototype.sh (the audit step that the shared ci workflow will run, on a stub with the hexpm part of the lock): "No retired or security advisory packages found".
    • MIX_ENV=test mix hex.audit with Hex 2.5.1: "No retired or security advisory packages found".
    • mix compile --warnings-as-errors: passes.
  • The reviewer checks that the next Security Audit run passes.

mix_audit reads only a GitHub advisory mirror and misses the Hex advisory feed. mix hex.audit (Hex 2.5.1 or newer) reads it. The security workflow installs the newest Hex with mix local.hex. Removing mix_audit also drops yaml_elixir and yamerl from the lock.
@rubas-agent
rubas-agent Bot merged commit fcc7ebd into main Sep 29, 2026
2 checks passed
@rubas-agent
rubas-agent Bot deleted the hex-audit branch September 29, 2026 07:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant