Skip to content
CAI
Software that uses CAICheck a score

apache/dubbo-erlang

58.3

Adequate · 2 October 2026

7.4k

lines of production code

Erlang

with Java

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Dubboerl is an Erlang-based implementation of the Apache Dubbo RPC framework, providing a bridge for Erlang services to communicate with Java-based Dubbo ecosystems. The system currently supports core RPC client functionality, including connection management, protocol encoding for Hessian and JSON, and extensible filtering and load balancing. Recent development has focused on solidifying the client-side architecture and addressing security vulnerabilities, indicating a shift toward stabilizing the integration layer for production use.

How it got here

2018 — Initial release and configuration setup

3 changes.

This period marked the initial release of dubboerl, an Erlang-based Dubbo framework, establishing the core project structure and adding an EUnit test suite to verify functionality. The work focused on delivering the first functional version of the framework with basic test coverage. Additionally, default configuration files were moved to an example directory to clarify their role as templates and prevent accidental overwriting.

2019 — Dubbo integration and CI modernization

7 changes.

This period focused on establishing a functional Erlang-Dubbo integration by developing a Java-to-Erlang interface generation tool and creating comprehensive demo services. The team expanded test coverage and defined necessary data structures to ensure reliable interoperability via Zookeeper and Hessian. Concurrently, the continuous integration pipeline was refactored to use a modular, custom shell script approach for improved build management.

2022 — Add Maven build configurations for Dubbo sample service and Erlang analysis tool

1 change.

Introduced Maven project definitions for the \dubbo-sample-service\ and \erlanalysis\ modules. The sample service now depends on Dubbo version 2.7.15 and the Zookeeper metadata report version 2.7.2, while the analysis tool includes dependencies for Hessian, ASM, and Velocity to support its packaging and execution.

2023 — Release 0.4.0: New extension points, JSON serialization, and Apache 2.0 license

1 change.

This release introduces several new extension points for protocol, cluster, registry, loadbalance, and filter configurations, allowing for greater customization of the Dubbo Erlang implementation. It adds support for JSON serialization alongside the existing Hessian serializer and includes a new RpcContext transport. A bug fix ensures the protocol is correctly unexported when a service shuts down. Additionally, the project has migrated from Travis CI to Codecov for coverage reporting, replaced the lager logging library with the standard Erlang logger, and changed the license from MIT to Apache 2.0.

February 2025 — Dubbo RPC client implementation and security remediation

3 changes.

The period focused on introducing the core components for the Dubbo RPC client, including the default client implementation with heartbeat and reconnection logic, protocol codec for Hessian and JSON serialization, and an extension framework for pluggable filters and load balancing. Concurrently, efforts were made to address security vulnerabilities, although this resulted in a regression of five new findings despite no code commits being recorded.

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 57 → 58 (+1.2)
  • Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 94 → 94 (-0.1)
  • Architecture 100 → 100 (+0.0)
  • Maturity 50 → 50 (+0.0)
  • Readiness 39 → 43 (+4.0)
  • Security 100 → 92 (-7.9)

Resolved (6)

  • Coverage not measured — no coverage collector is wired up
  • Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Scanner failed to run — not a clean result
  • Scanner failed to run — not a clean result

New (8)

  • Critical CVE: [GHSA redacted] (tools/erlanalysis/pom.xml)
  • Critical CVE: [GHSA redacted] (tools/erlanalysis/pom.xml)
  • Duplicated block (6 lines × 2) (tools/erlanalysis/src/main/java/org/apache/dubbo/erlang/analysis/generater/ErlProjectGenerater.java)
  • Floating source dependency: dubboerl
  • High CVE: [GHSA redacted] (tools/erlanalysis/pom.xml)
  • High CVE: [GHSA redacted] (tools/erlanalysis/pom.xml)
  • Medium CVE: [GHSA redacted] (tools/erlanalysis/pom.xml)
  • Outdated: jsx

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

apache/dubbo-erlang was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 3e2c2fa0f84a077de07d5363dbbc8daaa0e5c500 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.