No dependency is fetched from git
elixir/no-git-dependencies@v1
No dependency the project declares is fetched from a git repository.
| Id | elixir/no-git-dependencies |
| Version | v1 |
| Category | elixir |
| Default severity | warning |
| Interpreter | python3 |
| Timeout | 30 seconds |
| Violations tolerated | 0 |
| Collects | elixir |
Collectors
This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.
| Collector | Gathers | Inputs it is given |
|---|---|---|
elixir | The Mix build in the project directory: the application it declares, the Elixir version it asks for, every application of an umbrella, the dependencies each manifest names with their environments and origins, and the lock file beside them. mix.exs is Elixir rather than a declaration, so what it declares conditionally is not seen and scanned says so. | projectDir |
The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.
Configuration
{
"guardrails": {
"failOn": "error",
"checks": [
{
"use": "elixir/no-git-dependencies@v1",
"severity": "warning",
"with": {
"projectDir": "."
},
"exemptions": []
}
]
}
}Inputs
| Input | Description | Default | Environment variable |
|---|---|---|---|
projectDir | Directory holding the project, relative to the directory the CLI runs in. | . | GUARDRAIL_INPUT_PROJECTDIR |
How to fix
Take the dependency from Hex instead of from a git repository:
{:widget_ui, "~> 1.4"}If the package is yours and unpublished, publish it to a private Hex organisation. A git: or github: tuple tracks a branch its owner can move or force push. It is also compiled from source at fetch time, not taken from a release Hex has published and checksummed, so two builds of the same commit can compile different code.
More in elixir
elixir/lockfile-committed. The project commitsmix.lock, so fetching the same commit resolves the same packages and verifies them.elixir/version-declared. The project declares the Elixir version it compiles against, and that version is no older than the configured floor.