Skip to content
CAI
Software that uses CAICheck a score

AdRoll/erliam

49.4

Weak · 17 September 2026

1k

lines of production code

Erlang

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

Erliam is an Erlang library designed to manage AWS credentials and sign API requests securely. It supports AWS Instance Metadata Service Version 2 (IMDSv2) and Security Token Service (STS) for credential retrieval, with automatic caching and refresh logic. The system also provides AWSv4 signature computation and includes utilities for S3 and KMS operations.

Features

Initial release of AWS IAM credential and signature support

The library now provides AWSv4 signature computation and IAM credential management. It supports fetching credentials from the Instance Metadata Service (IMDS), including support for IMDSv2 tokens, and from AWS Security Token Service (STS) using long-term access keys. Credentials are cached in an ETS table and refreshed automatically before expiration, with an API to force invalidation.

src · high confidence

Initial release of erliam with IMDSv2 support and rebar3 tooling

This entry introduces the erliam library, an Erlang tool for caching AWS credentials and signing API requests. The codebase now supports AWS Instance Metadata Service Version 2 (IMDSv2) by default, enhancing security against SSRF attacks while maintaining fallback to IMDSv1. The project has been fully migrated to rebar3, establishing a modern build environment with OTP 25 as the minimum version, integrated dialyzer and xref static analysis, and spell-checking capabilities. Documentation and usage examples for S3 and KMS operations are included.

(repo-wide) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 49.

Lenses

  • Code Health 99
  • Architecture 69
  • Maturity 29
  • Readiness 52
  • Security 97

Changes since last survey

  • 80 commits — 77 feature/other, 3 fixes

By area

  • (root) — 64 commits
  • .github/workflows — 4 commits
  • src/awsv4.erl — 4 commits
  • src/erliam.app.src — 4 commits
  • src/erliam.erl — 2 commits
  • (repo) — 1 commit
  • src/imds.erl — 1 commit

Notable commits

  • fix: fix kms example in readme
  • fix: fix pairs typespec
  • fix: small fixes
  • change: Add CHANGELOG.md (#38)
  • change: Add Travis integration (#2)
  • change: Add licenses to app.src
  • change: Add more dialyzer checks (#55)
  • change: Add rebar3 formatting (#5)
  • change: Add rebar3_sheldon to spell-check our code (#32)
  • change: Added support for imdsv2 (#70)
  • change: Adjust for OTP23 (#18)
  • change: CI: use otp 25.2.1 (#53)
  • change: Clean up Erlang compile options (#37)
  • change: Get ready for hex publishing (#12)
  • change: Initial commit
  • change: Make sure the code is formatted on CI (#4)
  • change: Merge pull request #1 from AdRoll/RTI-5174-otp21
  • change: Move from Travis to Github Actions (#24)
  • change: Move to rebar3 and OTP21
  • change: Pin rebar3_format to its latest release (#8)
  • …and 60 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

AdRoll/erliam was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 17 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 73fa38bc045aa4956da045ed66ef117c6fca2635 — the exact code this score is about.
  • Scored under rubric-2026.09.13 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d1ef6c0bd534.