edgurgel/httpoison
65.6
Adequate · 23 September 2026
1.2k
lines of production code
Elixir
primary language
5
measurements over time
What this system is
HTTPoison is an HTTP client library for Elixir that simplifies making and handling HTTP requests. It provides a structured way to build and configure requests, supports multipart response parsing, and allows for custom client implementations. The system also includes utilities for debugging via curl command generation and comprehensive test coverage for request handling.
Features
Extracted HTTPoison.Base as a reusable base module
The HTTPoison library has been refactored to extract the core HTTP client functionality into a new \HTTPoison.Base\ module. This change allows developers to easily build custom HTTP clients by using \HTTPoison.Base\ and overriding specific callback functions, such as \process\_request\_url\ or \process\_response\_body\, to tailor request and response handling for specific API endpoints.
lib/httpoison · high confidence
Introduce Request struct and curl generation utility
The library now exposes a dedicated \HTTPoison.Request\ struct to represent HTTP requests, replacing the previous ad-hoc parameter passing. This struct supports methods, URLs, headers, bodies (including form data, files, and streams), and various options like timeouts and proxy settings. A new \to\_curl/1\ function has been added to generate equivalent curl commands from a request, aiding in debugging and integration. The change also includes updated documentation for the request structure and its options.
lib · high confidence
Support for parsing multipart response bodies
HTTPoison now includes a new \HTTPoison.Handlers.Multipart\ module that automatically parses multipart response bodies. When a response header indicates a multipart content type, the library uses \:hackney\_multipart\ to decode the body into a list of parts; otherwise, the raw body is returned unchanged. This allows applications to easily consume multipart HTTP responses without manual parsing.
lib/httpoison/handlers · high confidence
Security
HTTPoison 3.0.0: Upgrade to Hackney 4.0 and Modernize Elixir Support
This release upgrades the underlying HTTP client to Hackney 4.0, which resolves several security vulnerabilities (CVEs) related to URL schemes, header injection, and buffer limits. As a result, the library now requires Erlang/OTP 27+ and Elixir 1.17+. The change also alters SSL option handling (merging with defaults rather than overriding) and removes the \HTTPoison.MaybeRedirect\ struct in favor of following redirects internally. Documentation and examples have been updated to reflect these changes, including new async request examples and cookie handling.
(repo-wide) · high confidence
Behavioural changes
Added test environment configuration for HTTParrot
A new configuration file (config/config.exs) has been added to define settings for the :test environment. Specifically, it configures the HTTParrot application to listen on HTTPS port 8433 and HTTP port 4002, with SSL enabled. This change supports the addition of GitHub CI workflows by providing the necessary environment-specific settings for testing.
config · medium confidence
Test coverage
Expanded test coverage for HTTPoison base and request handling
Added comprehensive tests for the HTTPoison.Base module, including validation of request body processing, header handling, and timeout options. New tests verify that the Request struct correctly captures parameters, headers, and options for various HTTP methods (GET, POST, PUT, PATCH, DELETE, HEAD, OPTIONS). The suite also covers multipart form data handling, nested form data serialization, and error state preservation. Additionally, the test suite was updated to use the Mimic library for mocking HTTPoison's dependencies, replacing previous test infrastructure.
test · high confidence
Dependencies
Upgrade to Elixir 1.17 and major version 3.0.0
The project has been upgraded to require Elixir 1.17 and bumped to version 3.0.0. The \hackney\ dependency has been updated to version 4.0, and test dependencies have been modernized to use \mimic\ (replacing \meck\), \jason\, and \httparrot\. Additionally, the \mix.exs\ configuration now includes explicit package metadata (maintainers, licenses, links) and documentation settings for \ex\_doc\ and \dialyxir\.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 62 → 66 (+3.2)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 95 → 97 (+2.0)
- Architecture 69 → 69 (+0.0)
- Maturity 57 → 59 (+2.0)
- Readiness 58 → 61 (+3.0)
- Security 79 → 96 (+17.9)
Resolved (12)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — no supported dependency manifest was read
- High CVE: [GHSA redacted] (mix.lock)
- High CVE: [GHSA redacted] (mix.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: EEF-[CVE redacted] (mix.lock)
- No exposed public API
- Off-boarding risk: anonymized user #1
- Test reliability not included
New (16)
- Documentation: no installation or build instructions (README.md)
- High CVE: [GHSA redacted] (mix.lock)
- High CVE: [GHSA redacted] (mix.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: EEF-[CVE redacted] (mix.lock)
- No dependency advisory monitoring
- Outdated: cowboy
- Outdated: ex_doc
- Outdated: hackney
- Outdated: httparrot
- Outdated: jason
- Retired release: earmark
- Workflow token permissions not restricted
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
edgurgel/httpoison was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 18be3fe9c75de8f0de4e1d43d11cc98ff04f988c — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.