devinus/poison
57.8
Adequate · 23 September 2026
1.5k
lines of production code
Elixir
primary language
5
measurements over time
What this system is
Poison is a JSON library for Elixir that provides robust encoding, decoding, and parsing capabilities. It features a modular architecture with distinct modules for encoding, decoding, and parsing, supporting advanced options like HTML-safe escaping and custom type decoding. The system includes comprehensive test coverage and benchmarking tools to ensure correctness and performance.
Features
Added a JSON parsing profiler for benchmarking
A new \Poison.Profiler\ module has been introduced to the profile area, providing a set of functions to run and time the parsing of various JSON files located in the \../bench/data\ directory. This addition supports performance benchmarking and analysis of the JSON parsing logic.
profile · high confidence
Poison 6.0.0 release with performance and feature updates
The library has been updated to version 6.0.0, introducing support for Erlang 27 and Elixir 1.17, and reintroducing \Poison.encode\_to\_iodata!/1\ for Phoenix compatibility. The release also adds \Date.Range\ encoding, allows the \:as\ decode option to be a function, and implements OWASP-recommended HTML escaping for \:html\_safe\. Performance has been significantly improved, and deprecated \HashSet\ encoding has been removed.
(repo-wide) · high confidence
Behavioural changes
Introduce new Decoder, Encoder, and Parser modules with :html\_safe and :as options
The JSON library has been refactored into distinct modules for decoding, encoding, and parsing, introducing new exception types (DecodeError, EncodeError, ParseError) and a protocol-based architecture. Users can now specify the \:as\ option to decode JSON into specific structs or maps, and the \:html\_safe\ escape mode to prevent XSS vulnerabilities by escaping HTML-sensitive characters. The parser now reports precise error positions, and the encoder supports pretty-printing and configurable key types.
lib/poison · high confidence
Refactor Poison's internal architecture with new modules and expanded API
The core \Poison\ module has been refactored to delegate functionality to new dedicated modules: \Decode\, \DecodeError\, \Decoder\, \EncodeError\, \Encoder\, \ParseError\, and \Parser\. This structural change introduces new public API functions \encode\_to\_iodata\ and \encode\_to\_iodata!\ for encoding to IO data, while \encode\ and \decode\ now explicitly return \{:ok, ...}\ or \{:error, ...}\ tuples with specific error types (\EncodeError\, \ParseError\, \DecodeError\). Users interacting with the library will see a more modular codebase and access to the new IO data encoding capabilities.
lib · medium confidence
Updated benchmark data for Poison serialization
The benchmark results for the Poison JSON library have been updated with new performance data, likely reflecting an upgrade to Poison 6 as indicated by the commit messages. This change provides a more accurate or current view of serialization performance for users tracking the library's speed and efficiency.
bench · medium confidence
Test coverage
Add JSONTestSuite as a git submodule; Added property-based tests and JUnit formatter for Poison; Expanded test coverage for JSON decoding, encoding, and parsing.
Dependencies
Updated Elixir version requirement and development dependencies
The project now requires Elixir 1.12 or higher, up from the previous 0.11.0 requirement. Additionally, the development and testing dependencies have been updated to their latest compatible versions, including Credo 1.7.7-rc, Dialyxir 1.4.3, ExDoc 0.34.0, and Jason 1.5.0-alpha.2.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 55 → 58 (+2.9)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 99 → 100 (+0.3)
- Architecture 100 → 100 (+0.0)
- Maturity 49 → 49 (+0.0)
- Readiness 36 → 39 (+2.9)
- Security 89 → 99 (+10.3)
Resolved (12)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — no supported dependency manifest was read
- Duplicated block (11 lines × 2) (bench/run.exs)
- Duplicated block (6 lines × 2) (bench/run.exs)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: EEF-[CVE redacted] (mix.lock)
- Medium IaC: CKV_DOCKER_2 (Dockerfile)
- No exposed public API
- Test reliability not included
- dormant codebase — no living knowledge left to concentrate
New (20)
- Duplicated block (11 lines × 2) (bench/run.exs)
- Duplicated block (6 lines × 2) (bench/run.exs)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: EEF-[CVE redacted] (mix.lock)
- Medium IaC: WD-DOCKER-0003 (Dockerfile)
- No dependency advisory monitoring
- Outdated: benchee
- Outdated: benchee_markdown
- Outdated: castore
- Outdated: credo
- Outdated: dialyxir
- Outdated: ex_doc
- Outdated: excoveralls
- Outdated: jsone
- Outdated: mix_audit
- Outdated: stream_data
- Outdated: tiny
- Workflow token permissions not restricted
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
devinus/poison was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit ffb05bab421b6c29d7e2f0663a0b821bd5fa163a — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.