Skip to content
CAI
Software that uses CAICheck a score

elixir-grpc/grpc

62.0

Adequate · 23 September 2026

11.6k

lines of production code

Elixir

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is an Elixir library that implements the gRPC protocol, providing both client and server capabilities for unary and streaming RPCs. It supports multiple HTTP/2 adapters, handles protocol buffer serialization with security hardening, and includes a benchmarking tool for performance testing. Additionally, it features an interop test suite to validate protocol compliance across different client implementations.

How it got here

2016–2018 — Initial release and tooling expansion

15 changes.

This period established the foundational structure of the gRPC Elixir library with its initial release, Docker support, and Apache 2.0 licensing. It subsequently expanded the project's capabilities by introducing comprehensive interop testing harnesses and a dedicated benchmarking tool with custom NIFs for performance analysis.

2025–2026 — grpc\_server release and security hardening

4 changes.

This period focused on the initial release of the dedicated grpc\_server package, separating it from the client to provide a unified stream-based API. Concurrently, the core library underwent significant security hardening to mitigate decompression vulnerabilities and introduced comprehensive test coverage. The client library also received stability improvements, including better error handling, connection monitoring, and support for supervised connections.

Features

Add benchmarking infrastructure and scripts

Introduces new scripts and configuration files to support gRPC benchmarking. This includes a shell script to generate Elixir code from protobuf definitions, a test script to configure and run client-server benchmark scenarios, and a worker script to manage gRPC server processes. These changes enable users to execute performance tests and collect statistics from the benchmarking suite.

benchmark/bin · high confidence

Add gRPC benchmarking server and protocol buffers

The benchmarking library now includes a gRPC-based worker server implementation and the corresponding protocol buffer definitions. This adds the \BenchmarkService\ and \WorkerService\ definitions, along with message types for client/server configuration, statistics, and payloads, enabling the benchmark tool to control and monitor gRPC server and client processes via RPC calls.

benchmark/lib/grpc · high confidence

Add gRPC interop test server and client

This change introduces a new interop test suite for the gRPC library, providing both a server and a client implementation to validate protocol compliance. The server, defined in \Interop.Server\, implements the standard \TestService\ methods (including unary, client/server streaming, and full-duplex calls) with support for Gzip compression and custom metadata echoing. The accompanying \Interop.Client\ exercises these endpoints to verify behavior, while \Interop.App\ configures the server to listen on port 10000.

interop/lib/interop · high confidence

Added gRPC benchmark protocol definitions

New Protocol Buffer definitions have been added to the \benchmark/proto\ directory to support gRPC performance testing. This includes the \BenchmarkService\ and \WorkerService\ RPCs for orchestrating load tests, along with message schemas for client/server configuration (\control.proto\), payload structures (\messages.proto\, \payloads.proto\), and statistical reporting (\stats.proto\, \core/stats.proto\). These files define the interface for running unary and streaming benchmarks and collecting metrics like latency histograms and CPU usage.

benchmark/proto · high confidence

Added interop test harness for gRPC interoperability testing

A new interop directory has been introduced to support gRPC interoperability testing, including a Makefile for generating Protobuf definitions, configuration files for code formatting and build artifacts, and a script to execute the tests. The core module previously located at lib/grpc.ex has been renamed to interop/lib/interop.ex to reflect this new scope.

interop · high confidence

Initial release of gRPC Elixir with Apache 2.0 license and Docker support

This entry marks the initial commit of the gRPC Elixir project, establishing the foundational structure for the library. It introduces the Apache 2.0 license, a Dockerfile for containerized builds, and a \.formatter.exs\ configuration that organizes the codebase into \grpc\_core\, \grpc\_server\, and \grpc\ subdirectories. The release also includes a \SECURITY.md\ policy defining supported versions (1.0.0-rc.1 and \>= 0.11.0) and a comprehensive README detailing installation, protobuf code generation, and the new stream-based API for server and client implementations.

(repo-wide) · high confidence

Initial release of the grpc\_server package

The gRPC server implementation has been separated from the client into a distinct \grpc\_server\ package (v1.0.0), requiring users to add \{:grpc\_server, "\~\> 1.0"}\ to their dependencies instead of the legacy \:grpc\ package. This release introduces a unified stream-based API for all RPC types, adds support for gRPC-Web trailers encoded in the message body, and surfaces the inbound gRPC deadline on \GRPC.Server.Stream\ for better deadline budget propagation. It also includes several bug fixes such as safer decoding for the erlpack codec, configurable request body size limits, and corrected handling of path parameters in HTTP transcoding.

_grpc\_core, grpc\server · high confidence

New gRPC benchmark tool with Mix tasks and syscall NIF

Adds a new benchmarking tool for gRPC performance testing. Users can now run benchmarks via Mix tasks (\mix benchmark.worker\ to start a server, \mix benchmark.test\ to run tests) which replace legacy scripts. The tool includes a custom NIF (\Benchmark.Syscall\) wrapping the \getrusage\ syscall to capture detailed resource usage statistics during benchmark runs.

benchmark · high confidence

New interop test runner script for GRPC client adapters

A new Elixir script at interop/script/run.exs has been added to execute the gRPC interop test suite. This script launches a local server endpoint and iterates through a defined set of client-side interop tests (such as unary, streaming, and compression scenarios) against both the Gun and Mint client adapters using configurable concurrency and round counts.

interop/script · high confidence

gRPC client library initialization and core stability fixes

This change introduces the \grpc\ Elixir client package, providing a full-featured implementation for unary and streaming RPCs with support for Gun and Mint HTTP/2 adapters, interceptors, and custom codecs. It includes significant stability improvements: the Mint adapter now enforces request deadlines to prevent indefinite blocking and returns raw error tuples instead of formatted strings, while the Gun adapter fixes cross-node connection collisions by scoping named channels to the local node and prevents crashes from dead processes by monitoring the underlying Gun connection. Additionally, the library adds support for supervised client connections with automatic retry logic, IPv6 address parsing, and periodic DNS re-resolution for service discovery.

grpc · high confidence

Security

Introduce hardened erlpack codec and gzip decompression limits

The core library now includes a new \GRPC.Codec.Erlpack\ that mitigates [CVE redacted] by using \:erlang.binary\_to\_term/2\ with the \:safe\ option and rejecting payloads containing functions, pids, ports, or references. Additionally, the \GRPC.Compressor.Gzip\ implementation now enforces a configurable maximum decompressed message size (defaulting to 4 MB) to prevent zip-bomb denial-of-service attacks, raising a \resource\_exhausted\ error if the limit is exceeded.

_grpc\core/lib · high confidence

Behavioural changes

Benchmark logging configuration established

The benchmark environment now includes explicit configuration files that control logging verbosity based on the environment. In development, logging is set to info level, while production and test environments default to warning level, ensuring that benchmark runs do not produce excessive log output during execution or testing.

benchmark/config · high confidence

Default logger level set to warning for interop

The interop component now configures the application logger to default to the :warning level, reducing the volume of informational and debug output for this specific part of the system.

interop/config · high confidence

Refactored benchmark into distinct client and server components with detailed stats collection

The benchmark tool has been restructured to separate client and server logic into dedicated modules (ClientManager, ClientWorker, ServerManager, Server). This change introduces support for both unary and streaming RPC calls, allowing users to benchmark different load patterns. Additionally, the benchmark now collects and returns detailed performance statistics, including CPU time (user and system), elapsed time, and latency histograms, providing more granular insights into benchmark results.

benchmark/lib/benchmark · high confidence

Removal of legacy config/config.exs file

The project has removed the main configuration file (config/config.exs) which previously used the deprecated Mix.Config module. This change indicates a migration to a newer configuration approach, likely using the Config module introduced in Elixir 1.11+, requiring users to update their configuration setup to align with the new standards.

config · high confidence

Updated gRPC interop test definitions to protobuf 0.10

The generated Elixir protobuf files in the interop testing library have been regenerated using protoc-gen-elixir version 0.10.0. This update refreshes the generated modules for the gRPC testing services (including TestService, ReconnectService, LoadBalancerStatsService, and XDS services) and their associated message types, ensuring compatibility with the upgraded protobuf library version.

_interop/lib/grpc\testing · high confidence

Test coverage

Added benchmark test suite; Added test suite for gRPC core components.

Dependencies

Upgrade to gRPC v1.0.5 and update core dependencies

The gRPC client, server, and core libraries are upgraded to version 1.0.5, establishing the new baseline for the release. This update aligns the project with \protobuf\ 0.17, \gun\ 2.4.1, and \cowboy\ 2.16, ensuring compatibility with the latest Elixir 1.15+ requirements and resolving underlying dependency constraints across the client, server, and benchmark components.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 48 → 62 (+13.5)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 98 → 97 (-1.4)
  • Architecture 100 → 86 (-14.1)
  • Maturity 66 → 65 (-0.4)
  • Readiness 27 → 48 (+21.5)
  • Security 55 → 78 (+23.1)

Resolved (33)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (interop/mix.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 13 more

New (71)

  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • HackComment (grpc/test/grpc/adapters/mint/connection_process_test.exs)
  • HackComment (grpc/test/grpc/adapters/mint/connection_process_test.exs)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (interop/mix.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 51 more

Changes since last survey

  • 11 commits — 3 feature/other, 8 fixes

By area

  • grpc/lib — 5 commits
  • grpc/CHANGELOG.md — 1 commit
  • grpc/README.md — 1 commit
  • grpc/mix.exs — 1 commit
  • grpc/test — 1 commit
  • grpc_core/test — 1 commit
  • grpc_server/lib — 1 commit

Notable commits

  • fix: Fix/mint client side timeout (#571)
  • fix: fix(client): harden supervised connection recovery edge cases (#583)
  • fix: fix(core): stop silently shortening gRPC deadlines on the wire (#574)
  • fix: fix(gun): Monitor gun to prevent sending messages to dead processes (#586)
  • fix: fix(gun): scope named connection processes to the local node (#580)
  • fix: fix(mint): return raw connect errors, not strings (#584)
  • fix: fix: recover supervised connections when the transport process dies (#568)
  • fix: fix: remove dangling typespecs and absorb used types into callbacks (#573)
  • change: Release/v1.0.5 (#582)
  • change: [Fi] mint termination (#589)
  • change: update mix deps to 1.0.4

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

elixir-grpc/grpc was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 26bd3ec4ecf5c477e28cf543ebb4419d3c3353a0 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.