Skip to content
CAI
Software that uses CAICheck a score

elixir-tesla/tesla

72.2

Strong · 23 September 2026

8.3k

lines of production code

Elixir

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a flexible HTTP client library for Elixir that abstracts underlying network protocols through a pluggable middleware architecture. It enables developers to construct API clients with dynamic middleware stacks, supporting features like authentication, compression, and streaming across multiple adapters such as Finch and Mint. The library also provides comprehensive tooling for OpenAPI integration, including parameter serialization, path templating, and typed response handling.

How it got here

2015 — v2.0 architecture and middleware overhaul

9 changes.

This period focused on a major architectural refactoring of the Tesla HTTP client library, introducing a structured middleware pipeline and a new \Tesla.client/2\ API. It involved rewriting all HTTP adapters to support streaming and modern Elixir standards, while expanding the middleware suite with new authentication, compression, and URL handling components. Comprehensive test coverage was added to validate the new adapter implementations and middleware behaviors.

2017–2026 — OpenAPI integration and client refactoring

12 changes.

The project introduced comprehensive OpenAPI support through new parameter serialization modules, path templating, and middleware enhancements, alongside a major architectural refactor of the client to support runtime configuration and dynamic middleware manipulation. Extensive test coverage was added to validate these new features, including streaming, multipart handling, and OpenAPI-compliant query and path parameter styles. Documentation and benchmarking were also updated to reflect the new capabilities and performance characteristics.

Features

Initial project scaffolding and documentation

The repository has been initialized with core configuration files including \.editorconfig\, \.formatter.exs\, and \.commitlintrc.yml\ to enforce code style and commit conventions. A comprehensive \README.md\ has been added to document the Tesla HTTP client, its middleware architecture, supported adapters (Mint, Finch, Hackney, etc.), and usage examples. Additionally, standard project files such as \LICENSE\, \CONTRIBUTING.md\, \.gitignore\, and \CHANGELOG.md\ are present to establish the project's legal, contribution, and versioning standards.

(repo-wide) · high confidence

New OpenAPI parameter serialization and path templating modules

This release introduces a comprehensive set of new modules in \lib/tesla/open\_api\ to handle OpenAPI-compliant parameter serialization and path templating. It adds dedicated value objects and collections for query (\QueryParam\, \QueryParams\), header (\HeaderParam\, \HeaderParams\), cookie (\CookieParam\, \CookieParams\), and path (\PathParam\, \PathParams\) parameters, each supporting explicit style, explode, and reserved character settings. A new \PathTemplate\ module provides precompiled path parsing to optimize request URL construction. Additionally, a \QueryString\ module handles whole-URL query string serialization for \in: "querystring"\ parameters, and a \Response\ macro simplifies the creation of typed response wrappers for generated clients.

_lib/tesla/open\api · high confidence

New documentation for HTTP methods, streaming, and OpenAPI integration

Added two new cheat sheets to the guides directory: a general guide covering basic request methods (including the new QUERY method support), request streaming, middleware, and adapter customization, and an OpenAPI guide detailing the mapping of OpenAPI parameters to Tesla APIs, client stack configuration, response wrapper macros, and generated operation metadata.

guides/cheatsheets · high confidence

New middleware collection for authentication, compression, and URL handling

This change introduces a suite of new middleware components to the library. Authentication capabilities are expanded with \BasicAuth\, \BearerAuth\, and \DigestAuth\ middlewares. URL handling is enhanced by \BaseUrl\ (with a strict policy for security) and \FollowRedirects\ (which now handles cross-origin header stripping and 303/307 method preservation). Data handling includes \Compression\ (with safe streaming decompression and size limits), \FormUrlencoded\ (supporting nested maps and bracket notation), \MessagePack\, and \DecodeRels\. Additionally, \KeepRequest\ allows storing original request data for observability, \MethodOverride\ enables POST-based method spoofing, and \Fuse\ provides circuit breaker functionality.

lib/tesla/middleware · high confidence

Behavioural changes

Enhanced OpenTelemetry logging with semantic metadata and URL template support

The OpenTelemetry integration now emits richer semantic metadata for HTTP requests, including the full URL, scheme, server address, and port, while automatically redacting user credentials from the URL string. It also supports the \url.template\ attribute (via OpenTelemetry's incubating attributes) when a preserved request URL is available, and includes the HTTP response status code and error type in the logs. This change introduces a new \SemConv\ module to handle these semantic conventions, ensuring compatibility with the loaded OpenTelemetry SemConv library.

lib/tesla/opentelemetry · high confidence

Introduction of Tesla.client/2 and structured middleware pipeline

The library now provides \Tesla.client/2\ as the primary way to build API clients with a specific set of middlewares and an adapter, replacing the previous \Tesla.build\_client/1\ approach. This change introduces a structured middleware pipeline where requests are processed through pre-middleware, module-defined middleware, post-middleware, and finally the adapter. The \Tesla.Env\ struct has been expanded to include \assigns\ and \private\ fields for storing user and library-specific data respectively, and the default adapter is now explicitly set to \Tesla.Adapter.Httpc\ with support for global configuration overrides.

lib · high confidence

Migrate to Elixir 1.10+ config syntax and update application defaults

The configuration file has been updated to use the modern \import Config\ syntax, replacing the deprecated \use Mix.Config\. This change introduces new default settings for the application: Logger is configured to output at the debug level with a specific format, SASL error logging is suppressed, and the httparrot test helper is configured with specific HTTP/HTTPS ports and SSL enabled. Additionally, the Tesla client is explicitly set to use the Mock adapter for testing, and the deprecated builder warning is disabled.

config · high confidence

Migrated HTTP adapters to a new implementation

The HTTP adapters (Finch, Gun, Hackney, Httpc, Ibrowse, and Mint) have been rewritten from scratch. This migration introduces consistent support for request and response streaming, multipart uploads, and proxy authentication across all adapters. Users will benefit from improved error handling, better connection reuse, and updated compatibility with recent versions of the underlying HTTP libraries.

lib/tesla/adapter · high confidence

Modern path parameter middleware with OpenAPI support and strict validation

The path\_params middleware now includes a new 'modern' mode that supports OpenAPI-style path parameters, allowing for precompiled path templates and distinct definitions from values. This mode enforces stricter validation by raising an error when required path parameter values are missing, and it handles various serialization styles (simple, matrix, label) for primitives, arrays, and objects.

_lib/tesla/middleware/path\params · high confidence

Redesigned client architecture with runtime configuration and new middleware manipulation APIs

The library has been refactored to replace compile-time \use Tesla\ builder macros with runtime client configuration via \Tesla.Client\. This introduces a new \Tesla.Client\ struct and a suite of functions for dynamic middleware management, including \put\_middleware/2\, \update\_middleware/2\, \update\_middleware!/3\, \replace\_middleware!/3\, and \insert\_middleware!/4\. The \Tesla.Env\ struct has been extended with \assigns\ and \private\ fields to support user data and library-reserved metadata. Additionally, the \Tesla.Builder\ module now emits a deprecation warning for the old compile-time approach, guiding users toward the new runtime pattern.

lib/tesla · high confidence

Test coverage

Added OpenAPI parameter collection benchmarks; Added comprehensive test suites for all HTTP adapters; Added test coverage for Builder, Client middleware manipulation, Mocking, Multipart validation, and Test helpers; Added test coverage for OpenAPI parameter serialization and response handling; Added test support infrastructure for HTTP adapters and mocking; Added tests for OpenAPI-style query parameter serialization; Added tests for modern-style OpenAPI path parameter rendering; Added unit tests for Tesla middleware suite; Expanded adapter test suite for streaming, multipart, and query methods; Expanded test coverage for adapter configuration, middleware execution, and dynamic clients.

Dependencies

Tesla v1.21.3 dependency update and project configuration overhaul

This release updates the project's dependency lockfile (mix.lock) and significantly refactors the mix.exs configuration. The lockfile now pins specific versions for core HTTP adapters and utilities, including Finch 0.23.0, Mint 1.10.0, Hackney 4.7.4, Gun 2.6.0, and Castore 1.0.21, alongside dev tools like ExDoc 0.40.4 and Dialyxir 1.4.8. The mix.exs file has been upgraded to require Elixir \~\> 1.14, expanded the OTP application to include :ssl and :inets, and introduced structured package metadata, dialyzer PLT configuration, and comprehensive documentation settings. These changes ensure compatibility with modern Elixir versions and standardize the development and testing environment.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 60 → 72 (+12.0)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 99 (+0.1)
  • Architecture 100 → 89 (-11.1)
  • Maturity 55 → 57 (+1.9)
  • Readiness 73 → 86 (+13.7)
  • Security 49 → 84 (+34.1)

Resolved (24)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • Duplicated block (12 lines × 2) (lib/tesla/open_api/cookie_param.ex)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • No exposed public API
  • …and 4 more

New (17)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (13 lines × 2) (lib/tesla/open_api/cookie_param.ex)
  • Duplicated block (8 lines × 3) (lib/tesla/open_api/path_params.ex)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: [GHSA redacted] (mix.lock)
  • Off-boarding risk: anonymized user #1
  • Outdated: mint
  • TodoComment (lib/tesla/adapter/gun.ex)
  • TodoComment (lib/tesla/adapter/gun.ex)
  • TodoComment (lib/tesla/adapter/mint.ex)
  • TodoComment (lib/tesla/mock.ex)
  • TodoComment (mix.exs)
  • TodoComment (test/tesla/mock_test.exs)
  • Workflow holding a long-lived secret is unscoped

Changes since last survey

  • 36 commits — 28 feature/other, 8 fixes

By area

  • (root) — 12 commits
  • lib/tesla — 9 commits
  • test/tesla — 9 commits
  • .github/workflows — 3 commits
  • test/support — 3 commits

Notable commits

  • fix: fix(adapter): send the final chunk of a request body stream that halts (#923)
  • fix: fix(finch): unwrap error structs introduced by finch 0.22 (#902)
  • fix: fix(finch-adapter): surface the reason a streamed response stopped (#913)
  • fix: fix(form-urlencoded): do not claim a content-type it did not encode (#914)
  • fix: fix(gun-adapter): send socks proxy credentials gun can accept (#934)
  • fix: fix(httpc-adapter): let the multipart content type win over the request one (#935)
  • fix: fix(mint): avoid failing large HTTP/2 uploads (#842)
  • fix: fix(retry): ignore Retry-After values that are not valid delay-seconds (#920)
  • change: chore(adapter): assert request bodies arrive intact (#924)
  • change: chore(ci): activate release-please config and mirror common-config layout (#904)
  • change: chore(ci): let PR checks work on fork pull requests (#911)
  • change: chore(ci): unblock dependency PR checks (#908)
  • change: chore(compression): cover the multi-step inflate path (#929)
  • change: chore(coverage): close every reachable coverage gap in lib (#933)
  • change: chore(deps): bump actions/cache from 6.0.0 to 6.1.0 (#906)
  • change: chore(deps): bump hackney from 4.6.0 to 4.7.2 in the prod group across 1 directory (#907)
  • change: chore(deps): bump mox from 1.2.0 to 1.3.0 in the prod group (#940)
  • change: chore(deps): bump the dev group with 4 updates (#942)
  • change: chore(deps): bump the prod group with 2 updates (#916)
  • change: chore(deps): bump the prod group with 3 updates (#941)
  • …and 16 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

elixir-tesla/tesla was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 467ef748f0acd2afa0c82c39827df9965d3d9637 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.