elixir-tesla/tesla
72.2
Strong · 23 September 2026
8.3k
lines of production code
Elixir
primary language
5
measurements over time
What this system is
This system is a flexible HTTP client library for Elixir that abstracts underlying network protocols through a pluggable middleware architecture. It enables developers to construct API clients with dynamic middleware stacks, supporting features like authentication, compression, and streaming across multiple adapters such as Finch and Mint. The library also provides comprehensive tooling for OpenAPI integration, including parameter serialization, path templating, and typed response handling.
How it got here
2015 — v2.0 architecture and middleware overhaul
9 changes.
This period focused on a major architectural refactoring of the Tesla HTTP client library, introducing a structured middleware pipeline and a new \Tesla.client/2\ API. It involved rewriting all HTTP adapters to support streaming and modern Elixir standards, while expanding the middleware suite with new authentication, compression, and URL handling components. Comprehensive test coverage was added to validate the new adapter implementations and middleware behaviors.
2017–2026 — OpenAPI integration and client refactoring
12 changes.
The project introduced comprehensive OpenAPI support through new parameter serialization modules, path templating, and middleware enhancements, alongside a major architectural refactor of the client to support runtime configuration and dynamic middleware manipulation. Extensive test coverage was added to validate these new features, including streaming, multipart handling, and OpenAPI-compliant query and path parameter styles. Documentation and benchmarking were also updated to reflect the new capabilities and performance characteristics.
Features
Initial project scaffolding and documentation
The repository has been initialized with core configuration files including \.editorconfig\, \.formatter.exs\, and \.commitlintrc.yml\ to enforce code style and commit conventions. A comprehensive \README.md\ has been added to document the Tesla HTTP client, its middleware architecture, supported adapters (Mint, Finch, Hackney, etc.), and usage examples. Additionally, standard project files such as \LICENSE\, \CONTRIBUTING.md\, \.gitignore\, and \CHANGELOG.md\ are present to establish the project's legal, contribution, and versioning standards.
(repo-wide) · high confidence
New OpenAPI parameter serialization and path templating modules
This release introduces a comprehensive set of new modules in \lib/tesla/open\_api\ to handle OpenAPI-compliant parameter serialization and path templating. It adds dedicated value objects and collections for query (\QueryParam\, \QueryParams\), header (\HeaderParam\, \HeaderParams\), cookie (\CookieParam\, \CookieParams\), and path (\PathParam\, \PathParams\) parameters, each supporting explicit style, explode, and reserved character settings. A new \PathTemplate\ module provides precompiled path parsing to optimize request URL construction. Additionally, a \QueryString\ module handles whole-URL query string serialization for \in: "querystring"\ parameters, and a \Response\ macro simplifies the creation of typed response wrappers for generated clients.
_lib/tesla/open\api · high confidence
New documentation for HTTP methods, streaming, and OpenAPI integration
Added two new cheat sheets to the guides directory: a general guide covering basic request methods (including the new QUERY method support), request streaming, middleware, and adapter customization, and an OpenAPI guide detailing the mapping of OpenAPI parameters to Tesla APIs, client stack configuration, response wrapper macros, and generated operation metadata.
guides/cheatsheets · high confidence
New middleware collection for authentication, compression, and URL handling
This change introduces a suite of new middleware components to the library. Authentication capabilities are expanded with \BasicAuth\, \BearerAuth\, and \DigestAuth\ middlewares. URL handling is enhanced by \BaseUrl\ (with a strict policy for security) and \FollowRedirects\ (which now handles cross-origin header stripping and 303/307 method preservation). Data handling includes \Compression\ (with safe streaming decompression and size limits), \FormUrlencoded\ (supporting nested maps and bracket notation), \MessagePack\, and \DecodeRels\. Additionally, \KeepRequest\ allows storing original request data for observability, \MethodOverride\ enables POST-based method spoofing, and \Fuse\ provides circuit breaker functionality.
lib/tesla/middleware · high confidence
Behavioural changes
Enhanced OpenTelemetry logging with semantic metadata and URL template support
The OpenTelemetry integration now emits richer semantic metadata for HTTP requests, including the full URL, scheme, server address, and port, while automatically redacting user credentials from the URL string. It also supports the \url.template\ attribute (via OpenTelemetry's incubating attributes) when a preserved request URL is available, and includes the HTTP response status code and error type in the logs. This change introduces a new \SemConv\ module to handle these semantic conventions, ensuring compatibility with the loaded OpenTelemetry SemConv library.
lib/tesla/opentelemetry · high confidence
Introduction of Tesla.client/2 and structured middleware pipeline
The library now provides \Tesla.client/2\ as the primary way to build API clients with a specific set of middlewares and an adapter, replacing the previous \Tesla.build\_client/1\ approach. This change introduces a structured middleware pipeline where requests are processed through pre-middleware, module-defined middleware, post-middleware, and finally the adapter. The \Tesla.Env\ struct has been expanded to include \assigns\ and \private\ fields for storing user and library-specific data respectively, and the default adapter is now explicitly set to \Tesla.Adapter.Httpc\ with support for global configuration overrides.
lib · high confidence
Migrate to Elixir 1.10+ config syntax and update application defaults
The configuration file has been updated to use the modern \import Config\ syntax, replacing the deprecated \use Mix.Config\. This change introduces new default settings for the application: Logger is configured to output at the debug level with a specific format, SASL error logging is suppressed, and the httparrot test helper is configured with specific HTTP/HTTPS ports and SSL enabled. Additionally, the Tesla client is explicitly set to use the Mock adapter for testing, and the deprecated builder warning is disabled.
config · high confidence
Migrated HTTP adapters to a new implementation
The HTTP adapters (Finch, Gun, Hackney, Httpc, Ibrowse, and Mint) have been rewritten from scratch. This migration introduces consistent support for request and response streaming, multipart uploads, and proxy authentication across all adapters. Users will benefit from improved error handling, better connection reuse, and updated compatibility with recent versions of the underlying HTTP libraries.
lib/tesla/adapter · high confidence
Modern path parameter middleware with OpenAPI support and strict validation
The path\_params middleware now includes a new 'modern' mode that supports OpenAPI-style path parameters, allowing for precompiled path templates and distinct definitions from values. This mode enforces stricter validation by raising an error when required path parameter values are missing, and it handles various serialization styles (simple, matrix, label) for primitives, arrays, and objects.
_lib/tesla/middleware/path\params · high confidence
Redesigned client architecture with runtime configuration and new middleware manipulation APIs
The library has been refactored to replace compile-time \use Tesla\ builder macros with runtime client configuration via \Tesla.Client\. This introduces a new \Tesla.Client\ struct and a suite of functions for dynamic middleware management, including \put\_middleware/2\, \update\_middleware/2\, \update\_middleware!/3\, \replace\_middleware!/3\, and \insert\_middleware!/4\. The \Tesla.Env\ struct has been extended with \assigns\ and \private\ fields to support user data and library-reserved metadata. Additionally, the \Tesla.Builder\ module now emits a deprecation warning for the old compile-time approach, guiding users toward the new runtime pattern.
lib/tesla · high confidence
Test coverage
Added OpenAPI parameter collection benchmarks; Added comprehensive test suites for all HTTP adapters; Added test coverage for Builder, Client middleware manipulation, Mocking, Multipart validation, and Test helpers; Added test coverage for OpenAPI parameter serialization and response handling; Added test support infrastructure for HTTP adapters and mocking; Added tests for OpenAPI-style query parameter serialization; Added tests for modern-style OpenAPI path parameter rendering; Added unit tests for Tesla middleware suite; Expanded adapter test suite for streaming, multipart, and query methods; Expanded test coverage for adapter configuration, middleware execution, and dynamic clients.
Dependencies
Tesla v1.21.3 dependency update and project configuration overhaul
This release updates the project's dependency lockfile (mix.lock) and significantly refactors the mix.exs configuration. The lockfile now pins specific versions for core HTTP adapters and utilities, including Finch 0.23.0, Mint 1.10.0, Hackney 4.7.4, Gun 2.6.0, and Castore 1.0.21, alongside dev tools like ExDoc 0.40.4 and Dialyxir 1.4.8. The mix.exs file has been upgraded to require Elixir \~\> 1.14, expanded the OTP application to include :ssl and :inets, and introduced structured package metadata, dialyzer PLT configuration, and comprehensive documentation settings. These changes ensure compatibility with modern Elixir versions and standardize the development and testing environment.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 60 → 72 (+12.0)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 99 → 99 (+0.1)
- Architecture 100 → 89 (-11.1)
- Maturity 55 → 57 (+1.9)
- Readiness 73 → 86 (+13.7)
- Security 49 → 84 (+34.1)
Resolved (24)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — no supported dependency manifest was read
- Duplicated block (12 lines × 2) (lib/tesla/open_api/cookie_param.ex)
- High CVE: [GHSA redacted] (mix.lock)
- High CVE: [GHSA redacted] (mix.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: EEF-[CVE redacted] (mix.lock)
- Medium CVE: EEF-[CVE redacted] (mix.lock)
- Medium CVE: EEF-[CVE redacted] (mix.lock)
- Medium CVE: EEF-[CVE redacted] (mix.lock)
- No exposed public API
- …and 4 more
New (17)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (13 lines × 2) (lib/tesla/open_api/cookie_param.ex)
- Duplicated block (8 lines × 3) (lib/tesla/open_api/path_params.ex)
- Medium CVE: EEF-[CVE redacted] (mix.lock)
- Medium CVE: EEF-[CVE redacted] (mix.lock)
- Medium CVE: EEF-[CVE redacted] (mix.lock)
- Medium CVE: [GHSA redacted] (mix.lock)
- Off-boarding risk: anonymized user #1
- Outdated: mint
- TodoComment (lib/tesla/adapter/gun.ex)
- TodoComment (lib/tesla/adapter/gun.ex)
- TodoComment (lib/tesla/adapter/mint.ex)
- TodoComment (lib/tesla/mock.ex)
- TodoComment (mix.exs)
- TodoComment (test/tesla/mock_test.exs)
- Workflow holding a long-lived secret is unscoped
Changes since last survey
- 36 commits — 28 feature/other, 8 fixes
By area
- (root) — 12 commits
- lib/tesla — 9 commits
- test/tesla — 9 commits
- .github/workflows — 3 commits
- test/support — 3 commits
Notable commits
- fix: fix(adapter): send the final chunk of a request body stream that halts (#923)
- fix: fix(finch): unwrap error structs introduced by finch 0.22 (#902)
- fix: fix(finch-adapter): surface the reason a streamed response stopped (#913)
- fix: fix(form-urlencoded): do not claim a content-type it did not encode (#914)
- fix: fix(gun-adapter): send socks proxy credentials gun can accept (#934)
- fix: fix(httpc-adapter): let the multipart content type win over the request one (#935)
- fix: fix(mint): avoid failing large HTTP/2 uploads (#842)
- fix: fix(retry): ignore Retry-After values that are not valid delay-seconds (#920)
- change: chore(adapter): assert request bodies arrive intact (#924)
- change: chore(ci): activate release-please config and mirror common-config layout (#904)
- change: chore(ci): let PR checks work on fork pull requests (#911)
- change: chore(ci): unblock dependency PR checks (#908)
- change: chore(compression): cover the multi-step inflate path (#929)
- change: chore(coverage): close every reachable coverage gap in lib (#933)
- change: chore(deps): bump actions/cache from 6.0.0 to 6.1.0 (#906)
- change: chore(deps): bump hackney from 4.6.0 to 4.7.2 in the prod group across 1 directory (#907)
- change: chore(deps): bump mox from 1.2.0 to 1.3.0 in the prod group (#940)
- change: chore(deps): bump the dev group with 4 updates (#942)
- change: chore(deps): bump the prod group with 2 updates (#916)
- change: chore(deps): bump the prod group with 3 updates (#941)
- …and 16 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
elixir-tesla/tesla was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 467ef748f0acd2afa0c82c39827df9965d3d9637 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.