Skip to content
CAI
Software that uses CAICheck a score

erlyaws/yaws

37.2

Weak · 6 August 2026

40.2k

lines of production code

Erlang

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Yaws is a high-performance, scalable web server for the Erlang/OTP platform, designed to serve dynamic and static content via the HTTP protocol. It provides a comprehensive ecosystem including built-in applications for chat, email, and wikis, alongside a modular handler system for deploying independent web applications. The system supports advanced web standards such as WebSockets, Server-Sent Events, SOAP, and WebDAV, while offering robust security features like SSL/TLS and PAM authentication. Additionally, it includes utilities for monitoring, testing, and cross-platform deployment.

How it got here

2002 — Initial release and feature expansion

14 changes.

This period marks the initial commit and early development of the Yaws web server, establishing the core build system and configuration infrastructure. Significant features were added, including support for SOAP, WebDAV, and WebSockets, alongside security fixes and documentation updates. The release also introduced a wiki application and C-based authentication drivers, expanding the server's capabilities and integration options.

2003–2009 — platform expansion and application examples

13 changes.

This period focused on broadening Yaws' reach by adding native startup scripts for macOS, FreeBSD, and NetBSD, alongside a Windows installer. It also introduced a suite of example applications, including a webmail client, chat room, and shopping cart, while enhancing SSL certificate management and server monitoring capabilities.

2010–2024 — Platform and ecosystem expansion

9 changes.

This period focused on broadening Yaws' deployment and development infrastructure, adding init scripts and packaging for major Linux distributions and OpenBSD. It also expanded the project's capabilities through new contrib modules for session storage, debugging, and benchmarking, alongside modernizing the build system and test suite.

Features

Add C-based drivers for user switching and PAM authentication

The build system (Makefile.am) and source files for the \setuid\_drv\ and \epam\ C drivers are added. The \setuid\_drv\ enables the application to switch to a different user, while \epam\ provides PAM authentication support. The \hashtable\ C library is also included as a dependency for these components.

_c\src · high confidence

Add Gentoo Linux packaging and init scripts for Yaws

Users on Gentoo Linux can now install and manage the Yaws web server using the new ebuild and init scripts. The ebuild handles the package installation, while the init script provides standard service management capabilities including start, stop, reload, and status queries.

scripts/gentoo · high confidence

Add Munin monitoring scripts for Yaws server metrics

Added new Munin plugins to monitor Yaws server performance, specifically tracking hit counts and bytes sent. The update includes the \yaws\hits\\ and \yaws\sent\\ scripts, along with a \README.munin\ file that provides step-by-step instructions for installing the plugins, configuring the Munin node, and enabling graphing for Yaws statistics.

munin · high confidence

Add NetBSD init script for Yaws

A new init script (yaws.sh) has been added for NetBSD, enabling Yaws to be managed as a system service. This script supports starting, stopping, checking status, and reloading the Yaws server, with configuration options for the Yaws ID and additional flags.

scripts/netbsd · high confidence

Add SNI certificate generation for multiple SSL servers on the same IP

The ssl/mkcert\_altname directory now includes a complete example for generating self-signed certificates with multiple subjectAltName entries, enabling Virtual Hosting of several SSL servers on the same IP address. This includes the OpenSSL configuration file (openssl.cnf) and example certificate/key pairs (alice.sni.example.com and yaws.sni.example.com) to demonstrate Server Name Indication (SNI) support.

_ssl/mkcert\altname · high confidence

Add Yaws contrib modules for content negotiation, Mnesia session storage, argument display, and Mnesia table browsing

The contrib directory now includes four new Erlang modules: yaws\_content\_negotiation implements RFC 2296-style content negotiation by parsing Accept, Accept-Charset, and Accept-Language headers to rank and select the best variant; yaws\_mnesia\_session provides a backend for Yaws session storage using the Mnesia distributed database, requiring Erlang/OTP distribution support; yaws\_showarg renders an HTML table displaying all fields of the Yaws ARG record for debugging and inspection; and ymnesia offers a web interface to browse, search, and query Mnesia tables directly from the browser. These additions expand Yaws' ecosystem with new contrib utilities for HTTP header processing, session management, debugging, and database administration.

contrib · high confidence

Add build system and assets for reproducible documentation generation

The documentation build process is now fully supported via a new Makefile (doc/Makefile.am) that integrates the LaTeX source (yaws.tex) and associated assets (EPS images, overview.edoc, README.rss) into the build system. Crucially, the build system supports reproducible builds by utilizing the SOURCE\_DATE\_EPOCH environment variable to stamp generated PostScript and PDF outputs with a deterministic date, ensuring consistent build artifacts.

doc · high confidence

Add example chat application

Added a new example chat application to the Yaws distribution. This includes the Erlang server module (chat.erl) which manages user sessions and chat messages, along with the corresponding Yaws web scripts (chat.yaws, chat\_read.yaws, chat\_write.yaws, index.yaws, login.yaws) and the client-side JavaScript (chat.js) that handles the user interface, message sending, and real-time updates.

applications/chat · high confidence

Add init scripts and systemd unit for Yaws

Added new init scripts for Debian, Red Hat, and SUSE distributions, along with a systemd service unit file, to enable automatic startup and management of the Yaws web server on Linux systems.

(repo-wide) · high confidence

Add macOS startup scripts and documentation for Yaws

Users on macOS (Darwin) can now start, stop, and restart the Yaws HTTP server automatically at boot or via SystemStarter. New files in the darwin scripts directory provide the necessary configuration (Yaws.plist), startup logic (Yaws.StartupItem), and usage instructions (README) to integrate Yaws with the macOS init system.

scripts/darwin · high confidence

Add man pages and build rules for Yaws documentation

The build system now includes explicit rules to install and uninstall man pages for yaws, yaws.conf, yaws\_api, and yaws\_soap\_lib. This ensures that the corresponding .5 and .1 documentation files are properly deployed to the system's man directory during installation.

man · high confidence

Add new documentation and example pages to the Yaws website

The Yaws website has been updated with a new structure and content. A new sidebar navigation (TAB.inc) organizes the documentation into sections for configuration, dynamic content, examples, and more. New pages have been added to explain core concepts such as Appmods, the Arg record, Bindings, CGI, Cookies, Embedded mode, haXe remoting, and Server-Sent Events. The site also includes a contributors list, an articles/resources page, and a contact page. Additionally, supporting files for the haXe sample (haxe\_sample.html, haxe\_sample.yaws) and JavaScript libraries for JSON-RPC and urllib have been added to the www directory.

www · high confidence

Add shopping cart example application

Added a new shopping cart example application, including the Erlang module (shopcart.erl) and associated Yaws page templates (buy.yaws, index.yaws, loginpost.yaws, logout.yaws, shopcart\_form.yaws) for handling user sessions, login, and cart interactions, along with a Makefile for building the example.

www/shoppingcart · high confidence

A new HTML page (index.html) was added to the test directory, containing a title, meta tags, and several image and anchor tags referencing local assets. This provides a test case for relative URL resolution and character encoding (Swedish characters) in the web server's static file handling.

www/testdir · medium confidence

Added FreeBSD init scripts for Yaws

New startup, shutdown, status, and reload scripts for the Yaws web server on FreeBSD. The \yaws\ script is provided for FreeBSD 9 and newer, while \yaws.sh\ is provided for earlier versions. Both scripts allow users to manage the Yaws daemon via standard service commands.

scripts/freebsd · high confidence

Added M4 macros for version comparison, colored console output, and Erlang environment detection

The build system now includes new M4 macros to support autotools-based configuration. A new \AX\_COMPARE\_VERSION\ macro allows configure scripts to compare software version numbers. A \COLORED\_Echo\ macro provides bold and colored console output for build logs. Additionally, \ERLANG\_CHECK\_ERTS\ and \ERLANG\_CHECK\_RELEASE\ macros are added to detect the Erlang/OTP runtime system (ERTS) version and release, enabling Erlang-related build features.

m4 · high confidence

Added SOAP 1.2 and WSDL schema support

The server now supports SOAP 1.2 and WSDL 1.1/1.2 standards, enabling developers to build and consume SOAP-based web services. This change introduces new XML Schema Definition (XSD) files for SOAP envelopes (\envelope.xsd\, \soap-envelope.xsd\), SOAP bindings (\soap.xsd\), and WSDL definitions (\wsdl.xsd\, \wsdl11soap12.xsd\). These schema files define the structure for SOAP messages, headers, faults, and WSDL bindings, allowing the server to process and validate SOAP 1.2 messages and associated WSDL documents.

priv · high confidence

Added Yaws node templates and obsolete release files

Added a new set of Rebar2 templates for generating a Yaws-based Erlang node, including the node runner script, nodetool, configuration files (sys.config, vm.args, yaws.conf), and build metadata. Additionally, added obsolete release files for the legacy 'yaws' node, including the Windows service script (yaws.cmd), Unix runner (yaws), and associated configuration and tooling files.

rebar2-templates, rel.obsolete · high confidence

Added benchmarking tools for yaws\_server

Added a new set of benchmarking scripts and utilities in the contrib/benchmarks directory to evaluate the performance of yaws\_server functions, including path concatenation and multipart message parsing, allowing users to run and compare different implementation variants.

contrib/benchmarks · high confidence

Added build configuration for Erlang examples

The examples/ebin directory now includes a Makefile.am that configures the build system to install Erlang (.beam) files to the ERTS lib directory. This enables the build process to compile and install example code as part of the standard autotools workflow.

examples/ebin · medium confidence

Added example appmod for reproducible builds

Added a new example application module (myappmod) and its associated Makefile.am to support deterministic, reproducible builds. The example demonstrates how to configure build environments to omit absolute paths and use explicit function exports, ensuring consistent build outputs.

www/code · high confidence

Added self-signed certificate generation script

A new shell script and README have been added to the ssl/mkcert directory. The script generates a self-signed SSL certificate and key, allowing users to create wildcard certificates by specifying a domain pattern like \*.mydomain.com for the common name.

ssl/mkcert · medium confidence

Expanded API and configuration records for WebSocket, SOAP, and DAV support

The \include\ directory now contains new header files (\yaws\_api.hrl\, \yaws\_soap.hrl\, \yaws\_dav.hrl\, \soap.hrl\, \soap-envelope.hrl\, \wsdl11soap12.hrl\) and updated records in \yaws\_api.hrl\. These changes introduce support for SOAP (including WSDL 1.1/1.2 and SOAP 1.2 envelopes), WebDAV, and WebSockets (RFC 6455) by adding corresponding record definitions and expanding the \arg\ and \headers\ records with new fields such as \client\_ip\_port\, \orig\_req\, \opaque\, \appmod\_prepath\, \prepath\, \pathinfo\, \appmod\_name\, \x\_forwarded\_for\, and \other\ headers. The \yaws\_api.hrl\ file is significantly expanded to support these features, including WebSocket frame handling and state management.

include · high confidence

Initial commit of Yaws web server

The repository was initialized with the core build system, including the Makefile.am, configure.ac, and rebar.config, establishing the foundation for building the Yaws web server. This includes the addition of essential configuration files like .gitignore, LICENSE, and various README files, as well as the initial version number 0.2 in vsn.mk.

(repo-wide) · high confidence

Initial import of the Yaws Wiki application

The Yaws Wiki application is introduced, providing a web-based wiki system built on the Yaws HTTP server. This includes the core Erlang modules for page management, formatting, and HTML generation, alongside a plugin architecture supporting backlinks, menus, and dummy plugins. The release adds support for image slideshows, configurable HTML templates, and file uploads, while also including helper scripts for installation and maintenance.

applications/wiki · high confidence

Initial release of the Yaws WebMail application

Adds a complete, stateless web-based email client built on Erlang and Yaws. The application provides a full suite of email functionality including login, viewing, deleting, and sending messages, as well as composing new emails and replying with quoted text. It supports sending email attachments via SMTP and handles multipart MIME messages. The package includes the necessary Erlang modules (mail, smtp, attachment, mail\_html), Yaws templates, and configuration files to deploy the webmail interface.

applications/mail · high confidence

New example modules for WebSockets and Server-Sent Events

Added new Erlang example modules in the examples/src directory to demonstrate advanced WebSocket handling and Server-Sent Events (SSE). The changes include advanced\_echo\_callback.erl for handling fragmented WebSocket messages and binary data, basic\_echo\_callback.erl for simple text/binary echoing with asynchronous replies, basic\_echo\_callback\_extended.erl for stateful WebSocket interactions with message counting and fragmentation, authmod\_gssapi.erl for GSSAPI/SPNEGO authentication, and server\_sent\_events.erl for generating periodic SSE updates. A Makefile.am was also added to build these new example modules.

examples/src · high confidence

OpenBSD init script added for Yaws

A new OpenBSD rc.d init script (yaws.sh) was added to the project, providing a standard mechanism to start, stop, and reload the Yaws web server on OpenBSD systems.

scripts/openbsd · high confidence

Windows installer and startup script added

The win32 directory now includes a complete Windows distribution package. This adds a C-based startup script (yaws.c) that handles command-line arguments and registry lookups, a Makefile.am for building the Windows binary, and a build.xml.in configuration for the BitRock InstallBuilder to generate a Windows installer. The package also includes a default yaws.conf and documentation files (README.txt, README.developer) to support Windows users.

win32 · high confidence

Yapp application handler and admin console

The yapp application is introduced as a handler for deploying Yaws applications (Yapps) independently of each other. It includes a web-based admin console (add/remove/list pages) for managing registered Yapps, with a default Mnesia-based registry and an optional ETS-based registry for non-persistent cases. The application also provides an example Yapp (yapp\_ex\_1) and a local stylesheet for the admin interface.

applications/yapp · high confidence

Removals

Removal of the yaws shell script

The yaws shell script, previously located at bin/yaws, has been removed from the repository. This script previously served as a launcher for the Erlang runtime, handling command-line arguments for interactive, debug, and daemon modes, as well as configuration file paths.

bin · high confidence

Removed obsolete Erlang application and crash dump files

The ebin directory no longer contains the compiled bytecode or metadata for the 'ewww' and 'yaws' applications, nor the 'erl\_crash.dump' file. This removal eliminates legacy server components and debug artifacts from the build output, ensuring the application starts without loading these specific modules.

ebin · high confidence

Security

Security fix for HTTPoxy vulnerability

Fixed a security flaw (HTTPoxy) where the HTTP\_PROXY header was incorrectly passed to CGI scripts as the HTTP\_HOST environment variable. The code now skips the Proxy header when constructing CGI environment variables, preventing potential header injection attacks.

src · high confidence

Behavioural changes

Added Diffie-Hellman parameters and regenerated SSL certificates

The ssl directory now includes a new dhparams.pem file containing 2048-bit Diffie-Hellman parameters, generated via a new mkdhparams script, to support the new dhfile SSL option in yaws.conf. Additionally, the self-signed certificate (yaws-cert.pem) and private key (yaws-key.pem) have been regenerated with an updated signature algorithm, and the private key file no longer contains the public key.

ssl · medium confidence

Yaws server configuration and installation scripts refactored

The build and installation process for Yaws has been restructured. The previous \scripts/Makefile\ and \scripts/mangle\ were replaced with a new \scripts/Makefile.am\ and a suite of new shell scripts (\gen-yaws\, \gen-yaws-conf\, \rebar-pre-script\, \regular-install\, etc.) that generate the \yaws\ executable and configuration files. The default configuration template (\yaws.conf.template\) was significantly expanded to include new settings such as \keepalive\_maxuses\, \process\_options\ for garbage collection tuning, \acceptor\_pool\_size\, and \pick\_first\_virthost\_on\_nomatch\. Additionally, the \regular-install\ script now supports installing init scripts for a wider range of operating systems, including Gentoo, FreeBSD, NetBSD, and Darwin (macOS), alongside the existing Linux and Windows support.

scripts · high confidence

Test coverage

Migrate test suite to Common Test framework

The test suite has been refactored to use the Erlang/OTP Common Test framework instead of a previous in-house testing framework. This change introduces a new \test/Makefile.am\ build system for compiling and running tests, a \test/README.md\ guide for developers on how to run and analyze results, and a \test/analyze\_coverdata.escript.in\ script for code coverage analysis. Existing test suites, such as \auth\_SUITE\ and \cookies\_SUITE\, have been rewritten to conform to Common Test conventions, enabling features like selective test execution, HTML reporting, and debugger integration.

test · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 45 → 37 (-7.6)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.08.19) — scores are not directly comparable.

Lenses

  • Code Health 85 → 35 (-50.6)
  • Architecture 99 → 100 (+1.0)
  • Maturity 53 → 53 (+0.0)
  • Readiness 48 → 32 (-15.6)
  • Security 59 → 59 (+0.0)
  • Event-Driven 40 → 40 (+0.0)
  • Event Sourcing 100 → 100 (+0.0)
  • Accessibility 40 → 40 (+0.3)

Resolved (3)

  • Change coupling: yaws_jsonrpc.erl ↔ yaws_xmlrpc.erl (src/yaws_jsonrpc.erl)
  • Off-boarding risk: anonymized user #1
  • Orphaned knowledge (src/yaws_debug.erl)

New (2)

  • Off-boarding risk: anonymized user #1
  • Orphaned knowledge (src/yaws_websockets.erl)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

erlyaws/yaws was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 6 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit f81d2fc03b325afebe364a26b01cbe3c58c2d1b0 — the exact code this score is about.
  • Scored under rubric-2026.08.19 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer latest.