Skip to content

Guardrails / elixir

No dependency is fetched from git ​

elixir/no-git-dependencies@v1

No dependency the project declares is fetched from a git repository.

Idelixir/no-git-dependencies
Versionv1
Categoryelixir
Default severitywarning
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectselixir

Collectors ​

This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.

CollectorGathersInputs it is given
elixirThe Mix build in the project directory: the application it declares, the Elixir version it asks for, every application of an umbrella, the dependencies each manifest names with their environments and origins, and the lock file beside them. mix.exs is Elixir rather than a declaration, so what it declares conditionally is not seen and scanned says so.projectDir

The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.

Configuration ​

json
{
  "guardrails": {
      "failOn": "error",
      "checks": [
          {
              "use": "elixir/no-git-dependencies@v1",
              "severity": "warning",
              "with": {
                  "projectDir": "."
              },
              "exemptions": []
          }
      ]
  }
}

Inputs ​

InputDescriptionDefaultEnvironment variable
projectDirDirectory holding the project, relative to the directory the CLI runs in..GUARDRAIL_INPUT_PROJECTDIR

How to fix ​

Take the dependency from Hex instead of from a git repository:

elixir
{:widget_ui, "~> 1.4"}

If the package is yours and unpublished, publish it to a private Hex organisation. A git: or github: tuple tracks a branch its owner can move or force push. It is also compiled from source at fetch time, not taken from a release Hex has published and checksummed, so two builds of the same commit can compile different code.

More in elixir ​

  • elixir/lockfile-committed. The project commits mix.lock, so fetching the same commit resolves the same packages and verifies them.
  • elixir/version-declared. The project declares the Elixir version it compiles against, and that version is no older than the configured floor.

All 3 elixir guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412