Commit 70abe4d
Add SARIF output format to mix hex.audit
Add a --format sarif option that renders the audit result as a SARIF
v2.1.0 document, plus an --output PATH option to write it to a file
instead of stdout. This allows uploading audit findings to GitHub code
scanning and other SARIF consumers; the moduledoc documents a complete
GitHub Actions workflow using github/codeql-action/upload-sarif.
Retirements map to one rule per retirement reason (HEX0001 to HEX0005,
with security retirements defaulting to level error) and advisories map
to one rule per advisory identifier so each alert carries its own
severity score, title and help link. Results are anchored to the
dependency entry in mix.lock, relative to the git repository root when
available, with region and context region snippets. The run includes
git-derived version control provenance (with credentials stripped from
the repository URL), stable partial fingerprints, and messages that
carry both resolved text and template arguments. Ignored findings are
included with a suppression so they show up as closed alerts.
The exit code behaves the same as with the human format. SARIF output
requires the OTP 27 :json module, matching mix hex.outdated --json.1 parent 29b5731 commit 70abe4d
4 files changed
Lines changed: 930 additions & 14 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
| 8 | + | |
8 | 9 | | |
9 | 10 | | |
10 | 11 | | |
| |||
0 commit comments