Skip to content
CAI
Software that uses CAICheck a score

elixir-protobuf/protobuf

64.9

Adequate · 23 September 2026

9.4k

lines of production code

Elixir

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a pure Elixir library for Google Protocol Buffers that provides a protoc plugin to generate Elixir modules from .proto files. It implements the core Protobuf wire format for encoding and decoding, along with support for JSON and Text serialization formats. The library also includes utilities for handling Google's well-known types, message extensions, and gRPC service generation.

How it got here

2017 — Initial release and core implementation

15 changes.

This period marks the initial public release of protobuf-elixir v0.17.0, establishing the library's baseline with a pure Elixir implementation of Google Protobuf. The work focused on delivering core features including the protoc code generator, support for Protobuf.Any, and new serialization formats like JSON and Text. Comprehensive test suites and property-based tests were added to validate encoding, decoding, and code generation correctness.

2018–2020 — Protobuf feature expansion and benchmarking

10 changes.

This period focused on expanding the library's capabilities by adding support for Google's well-known types, Protobuf extensions, and comprehensive JSON encoding/decoding. Concurrently, a robust benchmarking infrastructure was established, including dataset generation, automated download scripts, and performance measurement tools to validate the library's efficiency.

2021–2026 — conformance testing and internal refactoring

9 changes.

This period focused on establishing Protocol Buffers conformance testing infrastructure and implementing a dedicated test runner to verify specification compliance. Concurrently, the codebase underwent significant internal refactoring, splitting Protobuf wire format and DSL logic into dedicated modules to improve performance and maintainability. The work also included adding utility functions for Google Protobuf type conversions and introducing CI scripts to ensure output parity with the Go implementation.

Features

Add JSON encoding and decoding support for Protobuf messages

This change introduces a complete JSON mapping implementation for Protobuf messages, allowing users to serialize and deserialize Protobuf structs to and from JSON. The new \Protobuf.JSON\ module handles standard field types as well as special Google Protobuf types like \Duration\, \Timestamp\, \FieldMask\, and \Any\, including RFC3339 parsing for timestamps and specific validation rules for durations. It supports both encoding and decoding, with options to ignore unknown fields and a configurable recursion limit for nested structures. The implementation uses the \JSON\ library (Elixir 1.18+) or \Jason\ as a fallback for the underlying JSON parsing and serialization.

lib/protobuf/json · high confidence

Add ProtoBench utility for loading benchmark datasets

Introduces a new benchmarking utility that allows loading and decoding Protobuf benchmark datasets. The change adds a generated Protobuf module (Benchmarks.BenchmarkDataset) defining the schema for benchmark data (name, message name, and payload) and a ProtoBench module providing functions to read these files and decode them into Elixir structs, along with a helper to convert message names to module names.

bench/lib · high confidence

Add Protobuf conformance test runner

Introduces a new conformance test runner (\Conformance.Protobuf.Runner\) that reads encoded requests from standard input and writes responses to standard output. The runner supports decoding and encoding messages in Protobuf, JSON, and Text Format, and includes specific handling for JSON decoding options such as ignoring unknown fields during specific test categories. It also manages logging to stderr to avoid interfering with the stdin/stdout interface and enforces a timeout for reading input.

conformance/protobuf · high confidence

Add generated Google Protobuf well-known types

The library now includes generated Elixir modules for Google's standard protobuf well-known types, including Any, Timestamp, Duration, Empty, FieldMask, Struct, Value, NullValue, and various wrapper types (Int32Value, UInt32Value, Int64Value, UInt64Value, FloatValue, DoubleValue). These modules allow users to work with standard protocol buffer definitions directly in Elixir, supporting features like arbitrary message packing via Any and precise time handling via Timestamp and Duration.

lib/google/protobuf · high confidence

Add protoc templates for enums, extensions, messages, and services

The code generator now includes EEx templates for producing Elixir modules corresponding to Protocol Buffer enums, extensions, messages, and gRPC services. Generated enum and message modules include support for module documentation, descriptors, and field definitions, while service templates generate both the service definition and the client stub using the GRPC library.

priv · high confidence

Add support for Protobuf extensions and file-level module prefix options

Users can now define and use Protobuf extensions, with new Elixir data structures in \lib/protobuf/extension/props.ex\ to represent extension metadata. Additionally, the \src/elixirpb.proto\ file introduces a new \module\_prefix\ option for file-level configuration, allowing users to override the default package-based module naming for generated messages.

lib/protobuf/extension, src · high confidence

Add utility functions for Google Protobuf conversions

The \lib/google/protobuf.ex\ module now provides helper functions to convert between Elixir native types and Google Protobuf structs. Users can convert maps to and from \Google.Protobuf.Struct\ via \to\_map\ and \from\_map\, and convert Elixir \DateTime\ structs to and from \Google.Protobuf.Timestamp\ using \to\_datetime\ and \from\_datetime\. Additionally, if the \Duration\ module is available (Elixir 1.17+), the module supports bidirectional conversion between Elixir \Duration\ structs and \Google.Protobuf.Duration\ via \to\_duration\ and \from\_duration\.

lib/google · high confidence

Added Google Protocol Buffers v2 benchmark dataset

A new benchmark dataset module has been added to generate Elixir structs from Google's Protocol Buffers v2 (proto2) schema. This file defines the \Benchmarks.Proto2.GoogleMessage2\ message structure, including its nested \Group1\ and \GoogleMessage2GroupedMessage\ types, providing a standardized set of fields and types for performance testing against the protobuf library.

_bench/lib/datasets/google\message2 · high confidence

Added automated dataset download script

A new shell script (download.sh) has been added to the bench/data directory to automate the retrieval of benchmark datasets. Running this script downloads a compressed archive from Google Cloud Storage and extracts it, ensuring the necessary data files are present for benchmarking.

bench/data · high confidence

Added benchmarking scripts for Protobuf encode/decode performance

New scripts have been added to the bench/script directory to measure and compare the performance of Protobuf encoding and decoding operations. The bench.exs script utilizes the Benchee library to run benchmarks on payload data, saving results as JSON and displaying console output. The standard\_bench.exs script provides a throughput measurement (MB/s) for parsing and serializing messages, designed to be compatible with standard protobuf benchmarks from other language implementations. Additionally, load.exs allows for loading and comparing previously saved benchmark results, outputting both console summaries and HTML reports.

bench/script · high confidence

Initial conformance test infrastructure and baseline exemptions

Added the initial infrastructure for running Protocol Buffers conformance tests, including a README with usage instructions, a shell script to invoke the test runner, and exemption files listing known failures for both standard and text format outputs. This establishes a baseline for verifying compliance with the Protobuf specification, with specific tests for features like MessageSet encoding and JSON extension field names currently marked as exempt.

conformance · high confidence

Initial protoc code generator for Elixir

Adds the \protoc\ plugin (\protoc-gen-elixir\) that generates Elixir modules from \.proto\ files. The generator supports proto2 and proto3 syntax, including proto3 optional fields, and produces Elixir structs with typespecs. It offers CLI options to customize output, such as \one\_file\_per\_module\ for directory structure, \package\_prefix\ and \module\_prefix\ for namespace control, \include\_docs\ to embed comments, and \transform\_module\ for value transformation. The plugin also handles service generation (when \plugins=grpc\ is specified), package-level extensions, and resolves types from transitive \import public\ dependencies.

lib/protobuf/protoc · high confidence

Initial release of protobuf-elixir v0.17.0

This entry marks the first public release of the protobuf-elixir library, establishing the baseline for version 0.17.0. The package provides a pure Elixir implementation of Google Protobuf, featuring a \protoc\ plugin for code generation, support for structs, typespecs, maps, and oneof fields, and native JSON encoding/decoding. The release includes the \textproto\ encoding support, \Protobuf.Any.unpack/2\, and the \gen\_proto\_source\ CLI option for traceability, while also addressing security concerns regarding unbounded recursion in message decoding.

(repo-wide) · high confidence

Introduce Protobuf.Any support and new serialization formats

This release adds support for the \google.protobuf.Any\ type, allowing you to pack and unpack arbitrary Protobuf messages using a custom type provider via \Protobuf.Any\. It also introduces new serialization capabilities: \Protobuf.JSON\ for encoding and decoding messages to/from JSON strings, and \Protobuf.Text\ for human-readable text format encoding. Under the hood, the library has been refactored with new modules for the encoder, decoder, and DSL, and now enforces stricter validation, such as raising errors for invalid UTF-8 data and handling float special values like infinity and NaN.

lib/protobuf · high confidence

Behavioural changes

Introduces Protobuf message generation and core library documentation

This change adds the initial implementation of Protobuf message structures for the \elixirpb\ namespace, including \Elixirpb.FileOptions\ and \Elixirpb.PbExtension\, generated via \protoc\_gen\_elixir\ version 0.15.0. It also significantly expands the \Protobuf\ module with comprehensive documentation, new type definitions for wire types and unknown fields, and the \is\_protobuf\_message/1\ guard for identifying Protobuf structs. The core API is updated to support \full\_name/0\ and \proto\_source/0\ callbacks, and the \decode/3\ function now includes a \:max\_nesting\_depth\ option to prevent unbounded recursion during decoding.

lib · high confidence

Refactor DSL into dedicated Enum and Typespecs modules

The DSL logic has been split into two new modules: \Protobuf.DSL.Enum\ and \Protobuf.DSL.Typespecs\. The enum module now explicitly generates callbacks for converting between atom, string, and integer enum tags, including support for string-based lookups. The typespecs module centralizes the generation of Elixir typespecs, ensuring that oneof fields correctly include \nil\ in their union types and that message structs include fields for unknown fields and protobuf markers. This refactoring improves code organization and clarifies the generated types and behaviors for enum and message structures.

lib/protobuf/dsl · high confidence

Refactored Protobuf wire format encoder and decoder

The Protobuf wire encoding and decoding logic has been refactored into dedicated modules (Protobuf.Wire.Types, Protobuf.Wire.Varint, and Protobuf.Wire.Zigzag) to improve performance and maintainability. Varint decoding now utilizes a macro-generated \defdecoderp\ mechanism to reuse binary match contexts, reducing memory allocation overhead. Additionally, the public API has been cleaned up by removing \Protobuf.Wire.Varint\ from public exports and moving \wire\_type/2\ to \Protobuf.Wire\, while fixing compilation warnings for older Elixir versions and resolving a bug in varint decoding.

lib/protobuf/wire · high confidence

Refactored protoc generator into modular components with improved code safety

The protoc generator has been restructured into distinct modules (Comment, Enum, Extension, Message, Service, Util) to improve maintainability and separation of concerns. This change introduces strict validation for protobuf identifiers to prevent code injection from untrusted descriptors, ensures generated files always end with a newline, and embeds the protoc-gen-elixir plugin version into all generated output. The refactoring also standardizes how comments are parsed and included, and how module names are constructed, providing a more robust foundation for future feature additions.

lib/protobuf/protoc/generator · high confidence

Regenerated Google Message 3 benchmark dataset

The generated Elixir source files for the Google Message 3 benchmark dataset have been updated. This regeneration aligns the code with the protobuf 3.12.3 specification and incorporates fixes for explicit packed options and enum defaults, ensuring the benchmark data structures accurately reflect the protocol buffer definitions.

_bench/lib/datasets/google\message3 · medium confidence

Regenerated benchmark protobuf datasets with updated syntax and defaults

The benchmark datasets for GoogleMessage1 (both proto2 and proto3) and GoogleMessage4 have been regenerated using protoc-gen-elixir version 0.10.1-dev. This update refreshes the generated Elixir structs to align with the current protobuf compiler output, including the application of type-aware struct defaults in proto2 messages and the removal of unnecessary whitespace in generated code. Users running benchmarks will see these updated message definitions, which may affect serialization/deserialization performance characteristics or memory layout slightly due to the updated code generation.

_bench/lib/datasets/google\_message1, bench/lib/datasets/google\message4 · high confidence

Removal of legacy config/config.exs file

The legacy config/config.exs file has been removed from the project. This file previously contained boilerplate comments and instructions for using Mix.Config to configure the application and its dependencies, but it is no longer part of the configuration structure.

config · high confidence

Test coverage

Added comprehensive test coverage for Protobuf JSON encoding and decoding; Added comprehensive test coverage for Protobuf core components; Added comprehensive test suite for protoc CLI and code generation; Added property-based tests for scalar encoding, varints, and unknown fields; Added script to verify protoc-gen-elixir output parity with Go implementation; Added test coverage for the protoc generator components; Added test fixtures for Protobuf protoc code generation; Added test support modules for Protobuf testing; Added tests for Google Protobuf conversion helpers; Added tests for Protobuf DSL typespec generation; Added tests for Protobuf.Wire.Varint encoding and decoding; Enhanced test infrastructure with helper utilities and configuration.

Dependencies

Add benchmarking project and modernize main project dependencies

This change introduces a new \bench\ directory containing a dedicated Mix project (\proto\_bench\) for performance testing, utilizing \benchee\ and \benchee\_html\ for benchmarking. In the main library, the Elixir requirement is raised to \\~\> 1.16\, and development dependencies are updated to include \dialyxir\, \credo\, \ex\_doc\, \stream\_data\, and \excoveralls\. The \mix.lock\ files are regenerated to reflect these dependency changes, including the addition of \google\_protobuf\ as a git dependency for conformance testing.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 62 → 65 (+3.0)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 99 (+0.2)
  • Architecture 99 → 99 (+0.4)
  • Maturity 63 → 42 (-21.1)
  • Readiness 50 → 79 (+29.7)
  • Security 69 → 85 (+16.6)

Resolved (21)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • Duplicated block (15 lines × 2) (lib/google/protobuf/duration.pb.ex)
  • Duplicated block (15 lines × 3) (lib/google/protobuf/any.pb.ex)
  • Duplicated block (16 lines × 2) (lib/google/protobuf/struct.pb.ex)
  • High CVE: [GHSA redacted] (mix.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • …and 1 more

New (43)

  • Documentation: no usage examples (README.md)
  • Duplicated block (18 lines × 2) (lib/google/protobuf/duration.pb.ex)
  • Duplicated block (18 lines × 3) (lib/google/protobuf/any.pb.ex)
  • Duplicated block (41 lines × 2) (lib/google/protobuf/struct.pb.ex)
  • High CVE: [GHSA redacted] (mix.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 23 more

Changes since last survey

  • 4 commits — 4 feature/other, 0 fixes

By area

  • .github/workflows — 2 commits
  • conformance/exemptions.txt — 1 commit
  • scripts/compare_go_plugin — 1 commit

Notable commits

  • change: Add more exempted conformance tests
  • change: Harden latest-conformance CI test (#446)
  • change: Use generated Protobuf commit for conformance (#447)
  • change: ci: guard codegen parity with the Go protoc-gen-elixir (#444)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

elixir-protobuf/protobuf was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit dc149f87d046ce6731cd95c1563c1311fb5d2700 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.