Skip to content
CAI
Software that uses CAICheck a score

mirego/mix_audit

60.8

Adequate · 18 September 2026

480

lines of production code

Elixir

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a command-line security auditing tool for Elixir projects that analyzes Hex dependencies against a dedicated advisory repository. It identifies vulnerable packages by matching dependency versions against known security issues and allows users to suppress specific warnings via ignore lists. The tool provides audit results in either human-readable or JSON formats and integrates with the Mix build system via a dedicated task.

Features

Add human-readable and JSON report formats

Users can now choose between a colorized human-readable report and a JSON output for audit results. The human format displays vulnerability details including package name, version, lockfile path, advisory URL, title, severity, and vulnerable/patched versions, using color coding for labels. The JSON format provides a machine-parseable representation of the report via Jason encoding.

_lib/mix\audit/formatting · high confidence

Removals

Removal of scan functionality and CLI entry point

The main MixAudit module has been stripped of its core scanning logic, including the \scan/1\ function that previously retrieved security advisories, analyzed project dependencies, and halted execution on failures. The module now only exposes a \version/0\ function, effectively removing the ability to perform audits from this library component.

lib · high confidence

Behavioural changes

Audit task delegates to new CLI module

The \mix deps.audit\ command now delegates its execution to the \MixAudit.CLI\ module instead of calling \MixAudit.scan\ directly. This change also adds \--help\ support to the task and exposes a \main\ entry point, indicating a restructure of the CLI handling logic.

lib/mix · high confidence

Improved vulnerability matching and new advisory source

The tool now uses a new advisory repository (mirego/elixir-security-advisories) and supports a more accurate version-matching algorithm that checks if a dependency's version falls within vulnerable ranges, replacing the previous placeholder logic. It also introduces CLI options to ignore specific advisory IDs or package names, supports multiple report formats (human and JSON), and restricts analysis to Hex dependencies only.

_lib/mix\audit · high confidence

New CLI modules for audit, help, and version commands with ignore options

The CLI structure has been refactored into dedicated modules: \MixAudit.CLI.Audit\ handles the core audit logic, while \MixAudit.CLI.Help\ and \MixAudit.CLI.Version\ manage their respective outputs. The audit command now supports \--ignore-advisory-ids\ and \--ignore-package-names\ flags, as well as an \--ignore-file\ option to load ignored items from a file, allowing users to suppress specific security warnings. The audit process exits with code 1 if vulnerabilities are found, and uses \System.halt/0\ for help and version displays to ensure clean termination.

_lib/mix\audit/cli · high confidence

Project initialization and tooling setup

The repository has been initialized with a new Credo configuration for code quality checks, a Makefile for build and lint automation, and an updated Elixir formatter configuration. Documentation has been significantly expanded to include installation instructions for both project dependencies and global escripts, usage options, and explanations of how the tool works, while the default branch has been renamed to main.

(repo-wide) · high confidence

Test coverage

Added test suite for MixAudit core logic and formatters

Added comprehensive tests for the MixAudit application, covering the audit report generation logic (including complex version range matching), the project dependency extraction, the security advisory repository interface, and both human-readable and JSON output formatting.

test · high confidence

Dependencies

Update dependencies and add Credo linting

The project updates several core dependencies, including \yaml\_elixir\ to version 2.12.0, \jason\ to 1.4.4, and \ex\_doc\ to 0.38.4, while also adding \credo\_naming\ for linting. The minimum supported Elixir version is lowered to 1.8, and the project is configured to publish as a Hex package with an escript entry point for the \mix deps.audit\ task.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 61.

Lenses

  • Code Health 100
  • Architecture 69
  • Maturity 49
  • Readiness 67
  • Security 76

Changes since last survey

  • 151 commits — 142 feature/other, 9 fixes

By area

  • (root) — 86 commits
  • lib/mix_audit — 40 commits
  • .github/workflows — 15 commits
  • .github/dependabot.yml — 2 commits
  • lib/mix — 2 commits
  • test/mix_audit — 2 commits
  • test/support — 2 commits
  • .github/pull_request_template.md — 1 commit
  • lib/mix_audit.ex — 1 commit

Notable commits

  • fix: Fix credo
  • fix: Fix dependabot package ecosystem (hex → mix)
  • fix: Fix human format
  • fix: Fix setup-beam action
  • fix: Fix warnings
  • fix: Fix workflow versions
  • fix: Minor fixes
  • fix: Revert a commit that was temporary to test something locally 🤦‍♂️
  • fix: fix credo error
  • change: Add Elixir 1.16 in GitHub Actions workflows
  • change: Add --help flag
  • change: Add --ignore-advisory-ids and --ignore-package-names options
  • change: Add 2.1.0 changelog
  • change: Add 2.1.1 changelog
  • change: Add Credo
  • change: Add Elixir 1.15 in GitHub Actions workflows
  • change: Add GHA badge
  • change: Add GitHub Actions CI
  • change: Add README.md documentation to explain how this works
  • change: Add a bit more information on exit statuses
  • …and 131 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

mirego/mix_audit was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 18 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 7e90e5f1b071b3ad81ca1d6aa5919e9ea9ece9cd — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-5d04157a340d.