Skip to content

Add SARIF output format to mix hex.audit#1203

Merged
ericmj merged 1 commit into
mainfrom
jm/audit-sarif
Jul 18, 2026
Merged

Add SARIF output format to mix hex.audit#1203
ericmj merged 1 commit into
mainfrom
jm/audit-sarif

Conversation

@maennchen

Copy link
Copy Markdown
Member

Add a --format sarif option that renders the audit result as a SARIF v2.1.0 document, plus an --output PATH option to write it to a file instead of stdout. This allows uploading audit findings to GitHub code scanning and other SARIF consumers; themoduledoc documents a complete GitHub Actions workflow using github/codeql-action/upload-sarif.

Retirements map to one rule per retirement reason (HEX0001 to HEX0005, with security retirements defaulting to level error) and advisories map to one rule per advisory identifier so each alert carries its own severity score, title and help link. Results are anchored to the dependency entry in mix.lock, relative to the git repository root when available, with region and context region snippets. The run includes git-derived version control provenance (with credentials stripped from
the repository URL), stable partial fingerprints, and messages that carry both resolved text and template arguments. Ignored findings are included with a suppression so they show up as closed alerts.

The exit code behaves the same as with the human format. SARIF output requires the OTP 27 json module, matching mix hex.outdated --json.

Needs #1202

Add a --format sarif option that renders the audit result as a SARIF
v2.1.0 document, plus an --output PATH option to write it to a file
instead of stdout. This allows uploading audit findings to GitHub code
scanning and other SARIF consumers; the moduledoc documents a complete
GitHub Actions workflow using github/codeql-action/upload-sarif.

Retirements map to one rule per retirement reason (HEX0001 to HEX0005,
with security retirements defaulting to level error) and advisories map
to one rule per advisory identifier so each alert carries its own
severity score, title and help link. Results are anchored to the
dependency entry in mix.lock, relative to the git repository root when
available, with region and context region snippets. The run includes
git-derived version control provenance (with credentials stripped from
the repository URL), stable partial fingerprints, and messages that
carry both resolved text and template arguments. Ignored findings are
included with a suppression so they show up as closed alerts.

The exit code behaves the same as with the human format. SARIF output
requires the OTP 27 :json module, matching mix hex.outdated --json.
@ericmj
ericmj merged commit 22bb0af into main Jul 18, 2026
22 checks passed
@ericmj
ericmj deleted the jm/audit-sarif branch July 18, 2026 20:27
@ericmj

ericmj commented Jul 18, 2026

Copy link
Copy Markdown
Member

Thank you! 💜

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants