mudasobwa

mudasobwa

Creator of Cure

I want to share some concerns about storing mix.lock file in VCS for libraries. The current version of Library Guidelines page has zero mentions of mix.lock and the established community practice is to indeed version control mix.lock.

Which is meaningless and might be even harmful in some scenarios.

Consider the library A that depends on another library B. B occasionally introduces a breaking change in the minor updates. Even if A library has nightly builds turned on, it continues to be green because in mix.lock there is a previous version of B. All the projects, depending on A get broken, because they ignore A’s mix.lock.

Without mix.lock in the VCS, A library author would have been informed a night after B upgrade. With mix.lock file in VCS, they will be informed by a tornado of issues from A users days after.

A less exotic case might be also taken into account: A depends on B and C, then B and C start conflicting on D at some point, but A nightly builds are still all green, because there is mix.lock in VCS and A is never tried to compile against modern versions of B, C, and D.

This is all not expected in our great self-organized ecosystem, but things happen. Currently, I personally switch nightly build on and remove mix.lock from VCS. It makes me think I will, at least, be notified about issues with the latest dependencies consistency the very next night.

I think removing mix.lock from VCS for libraries is a good practice in any case and I think we might enforce/suggest it via Guidelines I linked above.

Thoughts? /cc @josevalim

Showing Posts 1 to 10

josevalim

josevalim

Creator of Elixir

The benefit of mix.lock is making builds reproducible. You don’t want contributors to jump into a library and then become unable to write a patch because they can’t get their tests to pass anyway.

If the goal is to catch bugs, then I recommend having additional builds on CI that remove the lock file before running. Then you get the best of both words.

mudasobwa

mudasobwa OP

Creator of Cure

Eh. Does not that mean that projects using that library cannot use that library because of, well, above?

Or, even worse, they can get it to compile, but tests were red in this env, if they were ever attempted?

benwilson512

benwilson512

Author of Craft GraphQL APIs in Elixir with Absinthe

If a new version of library A’s dependency B breaks A, and I’m some contributor trying to fix some other, unrelated bug in A, how does it benefit me or the owner or the owner of A that I’m stuck and can’t move forward?

If that were the only way to know about breaking updates to B then sure, but as Jose noted, this is solved with a CI setup that simply unlocks everything before running tests. Perhaps that suggestion is what is missing from the guides?

mudasobwa

mudasobwa OP

Creator of Cure

Seems like a best solution, yes. I would strongly appreciate putting it there to alarm future library owners, yes. Shall I provide a PR?

josevalim

josevalim

Creator of Elixir

A PR that recommends checking it under version control and running a separate build without it would be welcome, yes. :slight_smile:

mudasobwa

mudasobwa OP

Creator of Cure

On it.

dbern

dbern

FWIW, I’ve found the same issue, and in CI I’ve started deleting the mix.lock before getting deps and running tests. :+1: to removing it for libraries; regardless, I’m hopeful that this isn’t a common problem.

fmcgeough

fmcgeough

mix deps.get has a command line option --check-locked. This was added in mix version 15.0.0. The doc says “raises if there are pending changes to the lockfile”. CI should use this so that if a change occurs where mix needs to modify the mix.lock file it can raise an exception. I recommend 1) check in the mix.lock file; 2) add that option to your CI builds. This ensures that what is built in CI is what was built on dev boxes and you’d be notified of discrepancies.
mix deps.get options

lud

lud

If I understand correctly this makes your CI fail if there are possible updates to the dependencies, even if your CI ran otherwise fine with the latest updates (by deleting mix.lock in CI)?

Or do you not delete mix.lock and call mix deps.update --all in CI.

Because if you check in the mix.lock and just run mix deps.get --check-locked in CI then how can it fail?

Edit:

Well actually I don’t uderstant what raises if there are pending changes to the lockfile means. I though it was checking on git status but it seems that it’s supposed to do something else.

benwilson512

benwilson512

Author of Craft GraphQL APIs in Elixir with Absinthe

Let’s say someone makes a change to mix.exs to switch from version 1 to version 2 for a dependency. The lock file is now “out of date” as the version in the lock file is now incompatible with what’s in mix.exs.

In development that’s fine, and you just get deps to write a new lock file. but what if you developer forgets, and commits the new mix.exs version without pulling deps and writing a new lock file? This is the value of the option. In the CI you want this to raise instead of silently writing a lock file.

Where Next? Top

Trending in Discussions Top

budgie
A little off-topic, but I feel like people here have a good head on their shoulders. I used to be quite good at making software. Was luc...
New
axelson
Hi there! :wave: @frigidcode and I (but mostly him) have been running an Elixir Book club, we’re almost done with Designing Elixir Syste...
New
juhalehtonen
There has been a thread to discuss the Stack Overflow Developer Survey on this forum every year since 2018, so here’s yet another one for...
New
achempion
I’ve been using Emacs as my main code editor for more than a two years. It’s a custom build version although I’ve tried doom emacs and sp...
New
budgie
I love Elixir. It’s one of 2 programming languages I’ve ever fallen in love with. But I don’t use it anymore. Serverless was the promis...
New
jtormey
Lately I’ve been thinking about how to organize components as a LiveView application grows. One of the pain points I’ve found (for myself...
New
Null-logic-0
What IDE or editor are you using for Elixir development? Personally, I use Zed, and I really like it, but sometimes I wish there were a ...
New

Other Trending Topics Top

GenericJam
Edit: 2026 May 15 - This post is archived. Mob is alive!! Main docs: mob v0.7.11 — Documentation A bit of explanation for the slightly c...
New
garrison
Hobbes is a low-level distributed database for the Elixir programming language. Hobbes provides a simple, safe, and scalable storage lay...
New
KristerV
Hey. Is there anyone here who creates agents in their apps? Not talking about using agents, but creating them. I’m finding it pretty diff...
New
mudasobwa
I fully migrated to my own harness from Anthropic/Gemini and I think it’s time to share it. Welcome DSH, the DeepSeek Harness, fully writ...
New
mcass19
ExRatatui lets you cook up rich terminal UIs in Elixir, powered by Rust’s ratatui via Rustler NIFs. Build interactive terminal applicatio...
New
ausimian
Emily is an Elixir library that runs Nx computations on Apple’s MLX. Install it as the default Nx backend and Nx, defn, Axon, Nx.Serving,...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews