Skip to content
CAI
Software that uses CAICheck a score

elixir-mint/mint

72.3

Strong · 23 September 2026

7k

lines of production code

Elixir

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a low-level HTTP client library for Elixir that supports both HTTP/1.1 and HTTP/2 protocols. It provides a unified interface for establishing connections, handling TLS encryption, and managing request/response streams with features like chunked transfer encoding and ALPN protocol negotiation. The codebase includes comprehensive test infrastructure for validating proxy connectivity, certificate verification, and frame parsing across various transport layers.

How it got here

2017–2018 — Initial project scaffolding and test infrastructure

5 changes.

This period established the foundational structure of the Mint HTTP client, including repository configuration, documentation, and initial dependency management. It also focused on building a robust testing environment by implementing property-based tests for HTTP functionality and setting up Docker-based infrastructure for proxy and SSL validation scenarios.

2019–2023 — core HTTP/1 and HTTP/2 implementation

14 changes.

This period focused on building the foundational architecture for the Mint HTTP client, introducing core abstractions for connections, transports, and protocol-specific modules for both HTTP/1.1 and HTTP/2. It established unified interfaces for protocol negotiation, structured error handling, and comprehensive TLS security features, including hostname verification shims for older Erlang versions. Extensive test suites were developed to validate transport behaviors, proxy connectivity, and protocol compliance for both HTTP versions.

Features

Initial implementation of core TCP and SSL transport modules

This change introduces the foundational transport layer for the library, adding \Mint.Core.Transport.TCP\ and \Mint.Core.Transport.SSL\ along with an SSL tunnel callback module. The TCP transport handles raw socket connections with configurable IPv4/IPv6 fallback and timeouts, while the SSL transport implements TLS handling, including a comprehensive list of blocked ciphers for security. These modules implement the \Mint.Core.Transport\ behavior, providing the underlying connectivity primitives for HTTP/1 and HTTP/2 clients.

lib/mint/core/transport · high confidence

Initial project scaffolding and configuration

The repository is initialized with essential configuration files including a \.dialyzer\_ignore\ file to suppress known type-checking warnings, a \.formatter.exs\ file to configure code formatting with \stream\_data\ imports, and a \.gitignore\ file to exclude build artifacts and test storage. A \CHANGELOG.md\ is added to document version history, starting with security fixes for HTTP/1 parsing vulnerabilities ([CVE redacted], [CVE redacted], etc.) and bug fixes. The \README.md\ provides installation and usage instructions, highlighting Mint's process-less architecture and SSL certificate handling. A \LICENSE.txt\ file (Apache 2.0) is included, along with a \Caddyfile\ and \docker-compose.yml\ to support local integration testing with proxy and HTTP server containers.

(repo-wide) · high confidence

Introduce HTTP/1.1 request encoding and chunked transfer support

The HTTP/1.1 client now supports encoding requests with chunked transfer-encoding, allowing users to stream request bodies without pre-calculating the content length. This change adds new modules (\Mint.HTTP1.Parse\, \Mint.HTTP1.Request\, \Mint.HTTP1.Response\) to handle parsing and encoding, including validation of header names and values, case-insensitive header key handling, and support for trailing headers at the end of chunked responses.

lib/mint/http1 · high confidence

Introduce HTTP/2 frame parsing and inspection module

Added the \Mint.HTTP2.Frame\ module to handle the decoding, inspection, and flag manipulation of HTTP/2 protocol frames. This change introduces the core logic for parsing binary frame structures (such as DATA, HEADERS, SETTINGS, and PRIORITY) into Elixir records, enabling the library to correctly interpret incoming HTTP/2 traffic and validate frame sizes and flags according to RFC 7540.

lib/mint/http2 · high confidence

Architecture

Introduce core protocol abstractions and header validation

This change establishes the foundational internal architecture for the Mint HTTP client by introducing new modules: \Mint.Core.Conn\ defines the core connection behavior and API callbacks, \Mint.Core.Headers\ implements header canonicalization and enforces RFC-compliant validation for disallowed trailer headers, \Mint.Core.Transport\ abstracts socket operations, and \Mint.Core.Util\ provides helper functions for hostname resolution and header manipulation.

lib/mint/core · high confidence

Behavioural changes

Add mint\_shims module for hostname verification compatibility

Added the new src/mint\_shims.erl module, which provides shims for the pkix\_verify\_hostname function to enable Mint to operate on older Erlang/OTP releases. This module extracts and adapts certificate hostname validation logic (based on RFC 6125) from the Erlang/OTP public\_key module, ensuring consistent TLS hostname verification behavior across different runtime versions.

src · high confidence

Introduce unified Mint.HTTP module with protocol negotiation and structured error types

The library now provides a single \Mint.HTTP\ module that acts as a unified interface for both HTTP/1.1 and HTTP/2 connections, automatically negotiating the protocol via ALPN when connecting to HTTPS servers. This change introduces dedicated \Mint.HTTPError\ and \Mint.TransportError\ exception structs to replace previous error handling mechanisms, providing structured reasons for failures such as proxy tunnel timeouts, invalid headers, or transport issues. Additionally, the \Mint.Negotiate\ module handles the underlying ALPN negotiation logic, allowing users to connect without specifying a protocol version while maintaining support for explicit HTTP/1 or HTTP/2 connections.

lib/mint · high confidence

Test coverage

Add test infrastructure for Mint; Added Docker test infrastructure for HTTPS and authenticated proxies; Added HTTP/1 test support helpers and server; Added HTTP/2 test helpers and server for connection testing; Added comprehensive test suite for HTTP/2 connection and frame handling; Added empty CA certificates file for test support; Added test coverage for SSL/TLS transport and TCP connection behaviors; Expanded test coverage for HTTP/1 connection handling and parsing; Expanded test coverage for proxy, TLS, and transport error scenarios; Initial test suite for HTTP functionality.

Dependencies

Update to Mint v1.10.1 with Elixir 1.15 requirement and dependency refresh

This release updates the Mint HTTP client to version 1.10.1 and raises the minimum supported Elixir version to 1.15. The dependency list has been refreshed, including an update to the HPAX library (used for HTTP/2 header compression) to version 1.0.3 and the CAStore library to 1.0.19. Development and testing dependencies such as ExDoc, Dialyxir, and StreamData have also been updated to their latest compatible versions.

(dependencies) · high confidence

Housekeeping

Added plts directory placeholder

A new .gitkeep file has been added to the plts directory to ensure the directory is tracked by version control.

plts · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 69 → 72 (+3.8)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 95 → 95 (-0.1)
  • Architecture 94 → 90 (-3.8)
  • Maturity 64 → 64 (-0.1)
  • Readiness 59 → 70 (+11.0)
  • Security 87 → 88 (+1.0)

Resolved (15)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • Duplicated block (7 lines × 2) (lib/mint/http1.ex)
  • Duplicated block (7 lines × 2) (lib/mint/http1.ex)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • Test reliability not included
  • TooManyMethods: HTTP1 (lib/mint/http1.ex)
  • TooManyMethods: HTTP2 (lib/mint/http2.ex)
  • TooManyMethods: SSL (lib/mint/core/transport/ssl.ex)

New (34)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (6 lines × 2) (lib/mint/http1.ex)
  • Duplicated block (8 lines × 2) (lib/mint/http1.ex)
  • Duplicated block (8 lines × 2) (lib/mint/http1.ex)
  • HTTP1.decode_headers (cognitive 20) (lib/mint/http1.ex)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Hotspot: lib/mint/http1.ex (lib/mint/http1.ex)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • No dependency advisory monitoring
  • Off-boarding risk: anonymized user #1
  • Outdated: castore
  • Outdated: dialyxir
  • Outdated: ex_doc
  • Outdated: hpax
  • …and 14 more

Changes since last survey

  • 11 commits — 10 feature/other, 1 fixes

By area

  • lib/mint — 4 commits
  • test/mint — 4 commits
  • (root) — 3 commits

Notable commits

  • fix: Fix tests (ops!)
  • change: Close TCP sockets on errors in HTTP/1 (#502)
  • change: Keep HTTP/1.0 CONNECT tunnel sockets open (#503)
  • change: Merge commit from fork
  • change: Merge commit from fork
  • change: Merge commit from fork
  • change: Release v1.10.0
  • change: Release v1.10.1
  • change: Sort generated functions for deterministic builds (#500)s
  • change: Support processing HTTP/1.1 headers as they arrive (#499)
  • change: Validate HTTP/2 response header fields and pseudo-headers (#504)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

elixir-mint/mint was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 4385c9e2008166844824bb2e086231d6bafcfa6e — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.