Elixir dependencies are locked
elixir/lockfile-committed@v1
The project commits mix.lock, so fetching the same commit resolves the same packages and verifies them.
| Id | elixir/lockfile-committed |
| Version | v1 |
| Category | elixir |
| Default severity | warning |
| Interpreter | python3 |
| Timeout | 30 seconds |
| Violations tolerated | 0 |
| Collects | elixir |
Collectors
This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.
| Collector | Gathers | Inputs it is given |
|---|---|---|
elixir | The Mix build in the project directory: the application it declares, the Elixir version it asks for, every application of an umbrella, the dependencies each manifest names with their environments and origins, and the lock file beside them. mix.exs is Elixir rather than a declaration, so what it declares conditionally is not seen and scanned says so. | projectDir |
The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.
Configuration
{
"guardrails": {
"failOn": "error",
"checks": [
{
"use": "elixir/lockfile-committed@v1",
"severity": "warning",
"with": {
"projectDir": "."
},
"exemptions": []
}
]
}
}Inputs
| Input | Description | Default | Environment variable |
|---|---|---|---|
projectDir | Directory holding the project, relative to the directory the CLI runs in. | . | GUARDRAIL_INPUT_PROJECTDIR |
How to fix
Resolve your dependencies once and commit the lock file Mix writes:
mix deps.get
git add mix.lockmix.lock pins every package to one version along with its checksum. Without it, an application resolves whatever Hex serves that day and checks nothing against what was reviewed.
More in elixir
elixir/no-git-dependencies. No dependency the project declares is fetched from a git repository.elixir/version-declared. The project declares the Elixir version it compiles against, and that version is no older than the configured floor.