aws-beam/aws_signature
53.0
Adequate · 17 September 2026
1.8k
lines of production code
Erlang
primary language
1
measurement over time
What this system is
This system is an Elixir library that implements AWS Signature Version 4 and the asymmetric Signature Version 4a for signing API requests. It provides core functionality to generate cryptographic signatures for standard HTTP requests and event stream messages, supporting both HMAC-SHA256 and ECDSA-based signing across multiple regions. The codebase includes comprehensive test coverage for canonical request construction and credential derivation, ensuring correctness for various authentication scenarios.
Features
Initial implementation of AWS Signature Version 4 and SigV4a
This release introduces the core library for signing AWS API requests, adding support for both Signature Version 4 (SigV4) and the asymmetric Signature Version 4a (SigV4a). Users can now sign standard HTTP requests via \sign\_v4/9\ and \sign\_v4/10\, which support options for URI path encoding and body digests, as well as event stream messages via \sign\_v4\_event/7\. The new \sign\_v4a/10\ function enables signing for services requiring ECDSA-based signatures across multiple regions. The implementation includes internal utilities for HMAC-SHA256, URI encoding, and credential derivation, with compatibility for OTP versions below 21.
src · high confidence
Test coverage
Added tests for AWS SigV4a signature calculation and canonical request building
Added new EUnit test suites (\aws\_sigv4\_internal\_tests\ and \aws\_sigv4a\_tests\) to verify the correctness of the AWS SigV4a implementation. The tests cover canonical request construction, including handling of URL paths, query parameter sorting, and header normalization, as well as the full signing process for various credential scenarios (with and without session tokens, seekable vs. non-seekable payloads) and ECDSA key derivation.
test · high confidence
Housekeeping
Library documentation and build configuration updated
The project's documentation has been significantly improved with a new README that provides installation instructions for Hex and Rebar3, and a comprehensive CHANGELOG documenting version history from v0.1.0 to v0.3.2. The build configuration (rebar.config) has been updated to include plugins for Hex publishing (rebar3\_hex) and ExDoc documentation generation (rebar3\_ex\_doc), and the .gitignore file now excludes the generated doc/ directory.
(repo-wide) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 53.
Lenses
- Code Health 98
- Architecture 100
- Maturity 39
- Readiness 68
- Security 48
Changes since last survey
- 79 commits — 68 feature/other, 11 fixes
By area
- src/aws_signature.erl — 31 commits
- (repo) — 19 commits
- (root) — 12 commits
- .github/workflows — 8 commits
- src/aws_sigv4_internal.erl — 6 commits
- src/aws_signature.app.src — 1 commit
- src/aws_signature_utils.erl — 1 commit
- src/aws_sigv4a.erl — 1 commit
Notable commits
- fix: Fix SigV4a double hashing in signature calculation
- fix: Fix dialyzer error in the sign_v4_event/7 spec
- fix: Fix hex-encode CanonicalRequest hash in StringToSign
- fix: Fix release pipeline
- fix: Merge pull request #30 from mikpe/fix-sign_v4_event-spec
- fix: Merge pull request #37 from k-asm/fix/sigv4a-double-hashing
- fix: Merge pull request #38 from aws-beam/fix-release-pipeline
- fix: Merge pull request #39 from colman-hartinger/fix-session-token-query-encoding
- fix: Revert "Add support for signing event stream messages"
- fix: Revert "Require encoded headers, provide flat hash of signature"
- fix: fix: add ttl option on typespec to fix dialyzer (#9)
- change: Add Dialyzer step to pipeline
- change: Add OTP28 and drop OTP 24, 25 from the test pipeline
- change: Add body_digest option to sign_v4/10
- change: Add an option controlling URI-escaping of the canonical URI
- change: Add docs
- change: Add function specs (#3)
- change: Add reference tests
- change: Add release automation upon tagging
- change: Add release train to hex.pm
- …and 59 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
aws-beam/aws_signature was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 17 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 3ab64e601c6fcbfa8091d5dcc3177a717a7501a6 — the exact code this score is about.
- Scored under rubric-2026.09.12 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-f94092f054c1.