mirego/mix_audit
60.8
Adequate · 18 September 2026
480
lines of production code
Elixir
primary language
1
measurement over time
What this system is
This system is a command-line security auditing tool for Elixir projects that analyzes Hex dependencies against a dedicated advisory repository. It identifies vulnerable packages by matching dependency versions against known security issues and allows users to suppress specific warnings via ignore lists. The tool provides audit results in either human-readable or JSON formats and integrates with the Mix build system via a dedicated task.
Features
Add human-readable and JSON report formats
Users can now choose between a colorized human-readable report and a JSON output for audit results. The human format displays vulnerability details including package name, version, lockfile path, advisory URL, title, severity, and vulnerable/patched versions, using color coding for labels. The JSON format provides a machine-parseable representation of the report via Jason encoding.
_lib/mix\audit/formatting · high confidence
Removals
Removal of scan functionality and CLI entry point
The main MixAudit module has been stripped of its core scanning logic, including the \scan/1\ function that previously retrieved security advisories, analyzed project dependencies, and halted execution on failures. The module now only exposes a \version/0\ function, effectively removing the ability to perform audits from this library component.
lib · high confidence
Behavioural changes
Audit task delegates to new CLI module
The \mix deps.audit\ command now delegates its execution to the \MixAudit.CLI\ module instead of calling \MixAudit.scan\ directly. This change also adds \--help\ support to the task and exposes a \main\ entry point, indicating a restructure of the CLI handling logic.
lib/mix · high confidence
Improved vulnerability matching and new advisory source
The tool now uses a new advisory repository (mirego/elixir-security-advisories) and supports a more accurate version-matching algorithm that checks if a dependency's version falls within vulnerable ranges, replacing the previous placeholder logic. It also introduces CLI options to ignore specific advisory IDs or package names, supports multiple report formats (human and JSON), and restricts analysis to Hex dependencies only.
_lib/mix\audit · high confidence
New CLI modules for audit, help, and version commands with ignore options
The CLI structure has been refactored into dedicated modules: \MixAudit.CLI.Audit\ handles the core audit logic, while \MixAudit.CLI.Help\ and \MixAudit.CLI.Version\ manage their respective outputs. The audit command now supports \--ignore-advisory-ids\ and \--ignore-package-names\ flags, as well as an \--ignore-file\ option to load ignored items from a file, allowing users to suppress specific security warnings. The audit process exits with code 1 if vulnerabilities are found, and uses \System.halt/0\ for help and version displays to ensure clean termination.
_lib/mix\audit/cli · high confidence
Project initialization and tooling setup
The repository has been initialized with a new Credo configuration for code quality checks, a Makefile for build and lint automation, and an updated Elixir formatter configuration. Documentation has been significantly expanded to include installation instructions for both project dependencies and global escripts, usage options, and explanations of how the tool works, while the default branch has been renamed to main.
(repo-wide) · high confidence
Test coverage
Added test suite for MixAudit core logic and formatters
Added comprehensive tests for the MixAudit application, covering the audit report generation logic (including complex version range matching), the project dependency extraction, the security advisory repository interface, and both human-readable and JSON output formatting.
test · high confidence
Dependencies
Update dependencies and add Credo linting
The project updates several core dependencies, including \yaml\_elixir\ to version 2.12.0, \jason\ to 1.4.4, and \ex\_doc\ to 0.38.4, while also adding \credo\_naming\ for linting. The minimum supported Elixir version is lowered to 1.8, and the project is configured to publish as a Hex package with an escript entry point for the \mix deps.audit\ task.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 61.
Lenses
- Code Health 100
- Architecture 69
- Maturity 49
- Readiness 67
- Security 76
Changes since last survey
- 151 commits — 142 feature/other, 9 fixes
By area
- (root) — 86 commits
- lib/mix_audit — 40 commits
- .github/workflows — 15 commits
- .github/dependabot.yml — 2 commits
- lib/mix — 2 commits
- test/mix_audit — 2 commits
- test/support — 2 commits
- .github/pull_request_template.md — 1 commit
- lib/mix_audit.ex — 1 commit
Notable commits
- fix: Fix credo
- fix: Fix dependabot package ecosystem (hex → mix)
- fix: Fix human format
- fix: Fix setup-beam action
- fix: Fix warnings
- fix: Fix workflow versions
- fix: Minor fixes
- fix: Revert a commit that was temporary to test something locally 🤦♂️
- fix: fix credo error
- change: Add Elixir 1.16 in GitHub Actions workflows
- change: Add --help flag
- change: Add --ignore-advisory-ids and --ignore-package-names options
- change: Add 2.1.0 changelog
- change: Add 2.1.1 changelog
- change: Add Credo
- change: Add Elixir 1.15 in GitHub Actions workflows
- change: Add GHA badge
- change: Add GitHub Actions CI
- change: Add README.md documentation to explain how this works
- change: Add a bit more information on exit statuses
- …and 131 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
mirego/mix_audit was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 18 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 7e90e5f1b071b3ad81ca1d6aa5919e9ea9ece9cd — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-5d04157a340d.