Skip to content
CAI
Software that uses CAICheck a score

ericmj/decimal

66.7

Adequate · 3 October 2026

3.4k

lines of production code

Elixir

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a high-performance decimal arithmetic library for Elixir that provides precise numerical operations including parsing, conversion, and IEEE 754 compliant arithmetic. It features configurable contexts for controlling precision and rounding, along with robust security measures to prevent denial-of-service attacks from pathological inputs. The implementation includes extensive property-based testing to ensure algebraic correctness and performance stability.

Security

Mitigation of decimal exponent amplification vulnerability ([CVE redacted])

The library now applies default limits to \parse/1\, \cast/1\, and string conversion functions to reject pathological inputs with extremely large exponents (e.g., \1e1000000\) that could cause excessive memory or CPU usage. By default, these functions enforce a maximum digit count of 34 and a maximum exponent of 6,144, aligning with IEEE 754 decimal128 standards, to prevent denial-of-service scenarios without requiring explicit configuration.

lib · high confidence

Behavioural changes

Decimal library performance optimizations and bug fixes

This release significantly improves the performance of core Decimal operations, including division, addition, subtraction, multiplication, rounding, normalization, comparison, and parsing, with reported speedups ranging from 1.2x to 1.9x and reduced memory allocation. It also optimizes \Decimal.to\_float/1\ for faster conversion, especially for values with extreme exponents. Several bugs are fixed: \Decimal.div/2\ now correctly carries the division remainder into rounding as a sticky bit to prevent incorrect rounding on inexact results; \Decimal.round/3\ now applies only the caller's rounding mode instead of the context's first; and \Decimal.to\_integer/1\ no longer enters an infinite loop for zero coefficients with negative exponents. Additionally, \Decimal.round/3\ no longer signals \:inexact\ or \:rounded\ for digits it discards itself, aligning with expected behavior for explicit rounding calls.

(repo-wide) · high confidence

Introduction of IEEE 754 compliant decimal context and simplified error handling

The library now supports configurable arithmetic contexts (precision, rounding, exponents, traps) stored in the process dictionary, defaulting to IEEE 754 decimal128 settings. This allows users to control how decimal operations behave, such as rounding strategies and overflow/underflow handling. Additionally, the \Decimal.Error\ exception structure has been simplified to only include \:signal\ and \:reason\ fields, removing previous \:message\ and \:result\ fields, which changes how errors are constructed and inspected.

lib/decimal · high confidence

Test coverage

Added comprehensive test coverage for Decimal context and property-based validation; Expanded test suite with property-based testing and performance bounds.

Dependencies

Update to Elixir 1.12+ and modernize project metadata

The project now requires Elixir 1.12 or higher, dropping support for older versions. The \mix.exs\ has been updated to include standard Hex package metadata (name, description, licenses, and source URL) and configures documentation generation via \ex\_doc\. Dependencies have been refreshed, with \ex\_doc\ pinned to the latest version for development and \stream\_data\ added for testing.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 67 → 67 (-0.3)
  • Rubric changed (rubric-2026.09.15 → rubric-2026.10.1) — scores are not directly comparable.

Lenses

  • Code Health 98 → 98 (+0.0)
  • Architecture 100 → 100 (+0.0)
  • Maturity 49 → 47 (-1.8)
  • Readiness 67 → 69 (+2.4)
  • Security 100 → 100 (+0.0)

Resolved (2)

  • Documentation: no usage examples (README.md)
  • Off-boarding risk: anonymized user #1

New (2)

  • Further sole-owners (lower concentration)
  • Off-boarding risk: anonymized user #1

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

ericmj/decimal was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 3 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 92a28e6b9a103f2b52a22b3f772f7a2a34b7b1d5 — the exact code this score is about.
  • Scored under rubric-2026.10.1 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-8fe32cd45d00.