erlyaws/yaws
37.2
Weak · 6 August 2026
40.2k
lines of production code
Erlang
primary language
4
measurements over time
What this system is
Yaws is a high-performance, scalable web server for the Erlang/OTP platform, designed to serve dynamic and static content via the HTTP protocol. It provides a comprehensive ecosystem including built-in applications for chat, email, and wikis, alongside a modular handler system for deploying independent web applications. The system supports advanced web standards such as WebSockets, Server-Sent Events, SOAP, and WebDAV, while offering robust security features like SSL/TLS and PAM authentication. Additionally, it includes utilities for monitoring, testing, and cross-platform deployment.
How it got here
2002 — Initial release and feature expansion
14 changes.
This period marks the initial commit and early development of the Yaws web server, establishing the core build system and configuration infrastructure. Significant features were added, including support for SOAP, WebDAV, and WebSockets, alongside security fixes and documentation updates. The release also introduced a wiki application and C-based authentication drivers, expanding the server's capabilities and integration options.
2003–2009 — platform expansion and application examples
13 changes.
This period focused on broadening Yaws' reach by adding native startup scripts for macOS, FreeBSD, and NetBSD, alongside a Windows installer. It also introduced a suite of example applications, including a webmail client, chat room, and shopping cart, while enhancing SSL certificate management and server monitoring capabilities.
2010–2024 — Platform and ecosystem expansion
9 changes.
This period focused on broadening Yaws' deployment and development infrastructure, adding init scripts and packaging for major Linux distributions and OpenBSD. It also expanded the project's capabilities through new contrib modules for session storage, debugging, and benchmarking, alongside modernizing the build system and test suite.
Features
Add C-based drivers for user switching and PAM authentication
The build system (Makefile.am) and source files for the \setuid\_drv\ and \epam\ C drivers are added. The \setuid\_drv\ enables the application to switch to a different user, while \epam\ provides PAM authentication support. The \hashtable\ C library is also included as a dependency for these components.
_c\src · high confidence
Add Gentoo Linux packaging and init scripts for Yaws
Users on Gentoo Linux can now install and manage the Yaws web server using the new ebuild and init scripts. The ebuild handles the package installation, while the init script provides standard service management capabilities including start, stop, reload, and status queries.
scripts/gentoo · high confidence
Add Munin monitoring scripts for Yaws server metrics
Added new Munin plugins to monitor Yaws server performance, specifically tracking hit counts and bytes sent. The update includes the \yaws\hits\\ and \yaws\sent\\ scripts, along with a \README.munin\ file that provides step-by-step instructions for installing the plugins, configuring the Munin node, and enabling graphing for Yaws statistics.
munin · high confidence
Add NetBSD init script for Yaws
A new init script (yaws.sh) has been added for NetBSD, enabling Yaws to be managed as a system service. This script supports starting, stopping, checking status, and reloading the Yaws server, with configuration options for the Yaws ID and additional flags.
scripts/netbsd · high confidence
Add SNI certificate generation for multiple SSL servers on the same IP
The ssl/mkcert\_altname directory now includes a complete example for generating self-signed certificates with multiple subjectAltName entries, enabling Virtual Hosting of several SSL servers on the same IP address. This includes the OpenSSL configuration file (openssl.cnf) and example certificate/key pairs (alice.sni.example.com and yaws.sni.example.com) to demonstrate Server Name Indication (SNI) support.
_ssl/mkcert\altname · high confidence
Add Yaws contrib modules for content negotiation, Mnesia session storage, argument display, and Mnesia table browsing
The contrib directory now includes four new Erlang modules: yaws\_content\_negotiation implements RFC 2296-style content negotiation by parsing Accept, Accept-Charset, and Accept-Language headers to rank and select the best variant; yaws\_mnesia\_session provides a backend for Yaws session storage using the Mnesia distributed database, requiring Erlang/OTP distribution support; yaws\_showarg renders an HTML table displaying all fields of the Yaws ARG record for debugging and inspection; and ymnesia offers a web interface to browse, search, and query Mnesia tables directly from the browser. These additions expand Yaws' ecosystem with new contrib utilities for HTTP header processing, session management, debugging, and database administration.
contrib · high confidence
Add build system and assets for reproducible documentation generation
The documentation build process is now fully supported via a new Makefile (doc/Makefile.am) that integrates the LaTeX source (yaws.tex) and associated assets (EPS images, overview.edoc, README.rss) into the build system. Crucially, the build system supports reproducible builds by utilizing the SOURCE\_DATE\_EPOCH environment variable to stamp generated PostScript and PDF outputs with a deterministic date, ensuring consistent build artifacts.
doc · high confidence
Add example chat application
Added a new example chat application to the Yaws distribution. This includes the Erlang server module (chat.erl) which manages user sessions and chat messages, along with the corresponding Yaws web scripts (chat.yaws, chat\_read.yaws, chat\_write.yaws, index.yaws, login.yaws) and the client-side JavaScript (chat.js) that handles the user interface, message sending, and real-time updates.
applications/chat · high confidence
Add init scripts and systemd unit for Yaws
Added new init scripts for Debian, Red Hat, and SUSE distributions, along with a systemd service unit file, to enable automatic startup and management of the Yaws web server on Linux systems.
(repo-wide) · high confidence
Add macOS startup scripts and documentation for Yaws
Users on macOS (Darwin) can now start, stop, and restart the Yaws HTTP server automatically at boot or via SystemStarter. New files in the darwin scripts directory provide the necessary configuration (Yaws.plist), startup logic (Yaws.StartupItem), and usage instructions (README) to integrate Yaws with the macOS init system.
scripts/darwin · high confidence
Add man pages and build rules for Yaws documentation
The build system now includes explicit rules to install and uninstall man pages for yaws, yaws.conf, yaws\_api, and yaws\_soap\_lib. This ensures that the corresponding .5 and .1 documentation files are properly deployed to the system's man directory during installation.
man · high confidence
Add new documentation and example pages to the Yaws website
The Yaws website has been updated with a new structure and content. A new sidebar navigation (TAB.inc) organizes the documentation into sections for configuration, dynamic content, examples, and more. New pages have been added to explain core concepts such as Appmods, the Arg record, Bindings, CGI, Cookies, Embedded mode, haXe remoting, and Server-Sent Events. The site also includes a contributors list, an articles/resources page, and a contact page. Additionally, supporting files for the haXe sample (haxe\_sample.html, haxe\_sample.yaws) and JavaScript libraries for JSON-RPC and urllib have been added to the www directory.
www · high confidence
Add shopping cart example application
Added a new shopping cart example application, including the Erlang module (shopcart.erl) and associated Yaws page templates (buy.yaws, index.yaws, loginpost.yaws, logout.yaws, shopcart\_form.yaws) for handling user sessions, login, and cart interactions, along with a Makefile for building the example.
www/shoppingcart · high confidence
Add test HTML page with image and link references
A new HTML page (index.html) was added to the test directory, containing a title, meta tags, and several image and anchor tags referencing local assets. This provides a test case for relative URL resolution and character encoding (Swedish characters) in the web server's static file handling.
www/testdir · medium confidence
Added FreeBSD init scripts for Yaws
New startup, shutdown, status, and reload scripts for the Yaws web server on FreeBSD. The \yaws\ script is provided for FreeBSD 9 and newer, while \yaws.sh\ is provided for earlier versions. Both scripts allow users to manage the Yaws daemon via standard service commands.
scripts/freebsd · high confidence
Added M4 macros for version comparison, colored console output, and Erlang environment detection
The build system now includes new M4 macros to support autotools-based configuration. A new \AX\_COMPARE\_VERSION\ macro allows configure scripts to compare software version numbers. A \COLORED\_Echo\ macro provides bold and colored console output for build logs. Additionally, \ERLANG\_CHECK\_ERTS\ and \ERLANG\_CHECK\_RELEASE\ macros are added to detect the Erlang/OTP runtime system (ERTS) version and release, enabling Erlang-related build features.
m4 · high confidence
Added SOAP 1.2 and WSDL schema support
The server now supports SOAP 1.2 and WSDL 1.1/1.2 standards, enabling developers to build and consume SOAP-based web services. This change introduces new XML Schema Definition (XSD) files for SOAP envelopes (\envelope.xsd\, \soap-envelope.xsd\), SOAP bindings (\soap.xsd\), and WSDL definitions (\wsdl.xsd\, \wsdl11soap12.xsd\). These schema files define the structure for SOAP messages, headers, faults, and WSDL bindings, allowing the server to process and validate SOAP 1.2 messages and associated WSDL documents.
priv · high confidence
Added Yaws node templates and obsolete release files
Added a new set of Rebar2 templates for generating a Yaws-based Erlang node, including the node runner script, nodetool, configuration files (sys.config, vm.args, yaws.conf), and build metadata. Additionally, added obsolete release files for the legacy 'yaws' node, including the Windows service script (yaws.cmd), Unix runner (yaws), and associated configuration and tooling files.
rebar2-templates, rel.obsolete · high confidence
Added benchmarking tools for yaws\_server
Added a new set of benchmarking scripts and utilities in the contrib/benchmarks directory to evaluate the performance of yaws\_server functions, including path concatenation and multipart message parsing, allowing users to run and compare different implementation variants.
contrib/benchmarks · high confidence
Added build configuration for Erlang examples
The examples/ebin directory now includes a Makefile.am that configures the build system to install Erlang (.beam) files to the ERTS lib directory. This enables the build process to compile and install example code as part of the standard autotools workflow.
examples/ebin · medium confidence
Added example appmod for reproducible builds
Added a new example application module (myappmod) and its associated Makefile.am to support deterministic, reproducible builds. The example demonstrates how to configure build environments to omit absolute paths and use explicit function exports, ensuring consistent build outputs.
www/code · high confidence
Added self-signed certificate generation script
A new shell script and README have been added to the ssl/mkcert directory. The script generates a self-signed SSL certificate and key, allowing users to create wildcard certificates by specifying a domain pattern like \*.mydomain.com for the common name.
ssl/mkcert · medium confidence
Expanded API and configuration records for WebSocket, SOAP, and DAV support
The \include\ directory now contains new header files (\yaws\_api.hrl\, \yaws\_soap.hrl\, \yaws\_dav.hrl\, \soap.hrl\, \soap-envelope.hrl\, \wsdl11soap12.hrl\) and updated records in \yaws\_api.hrl\. These changes introduce support for SOAP (including WSDL 1.1/1.2 and SOAP 1.2 envelopes), WebDAV, and WebSockets (RFC 6455) by adding corresponding record definitions and expanding the \arg\ and \headers\ records with new fields such as \client\_ip\_port\, \orig\_req\, \opaque\, \appmod\_prepath\, \prepath\, \pathinfo\, \appmod\_name\, \x\_forwarded\_for\, and \other\ headers. The \yaws\_api.hrl\ file is significantly expanded to support these features, including WebSocket frame handling and state management.
include · high confidence
Initial commit of Yaws web server
The repository was initialized with the core build system, including the Makefile.am, configure.ac, and rebar.config, establishing the foundation for building the Yaws web server. This includes the addition of essential configuration files like .gitignore, LICENSE, and various README files, as well as the initial version number 0.2 in vsn.mk.
(repo-wide) · high confidence
Initial import of the Yaws Wiki application
The Yaws Wiki application is introduced, providing a web-based wiki system built on the Yaws HTTP server. This includes the core Erlang modules for page management, formatting, and HTML generation, alongside a plugin architecture supporting backlinks, menus, and dummy plugins. The release adds support for image slideshows, configurable HTML templates, and file uploads, while also including helper scripts for installation and maintenance.
applications/wiki · high confidence
Initial release of the Yaws WebMail application
Adds a complete, stateless web-based email client built on Erlang and Yaws. The application provides a full suite of email functionality including login, viewing, deleting, and sending messages, as well as composing new emails and replying with quoted text. It supports sending email attachments via SMTP and handles multipart MIME messages. The package includes the necessary Erlang modules (mail, smtp, attachment, mail\_html), Yaws templates, and configuration files to deploy the webmail interface.
applications/mail · high confidence
New example modules for WebSockets and Server-Sent Events
Added new Erlang example modules in the examples/src directory to demonstrate advanced WebSocket handling and Server-Sent Events (SSE). The changes include advanced\_echo\_callback.erl for handling fragmented WebSocket messages and binary data, basic\_echo\_callback.erl for simple text/binary echoing with asynchronous replies, basic\_echo\_callback\_extended.erl for stateful WebSocket interactions with message counting and fragmentation, authmod\_gssapi.erl for GSSAPI/SPNEGO authentication, and server\_sent\_events.erl for generating periodic SSE updates. A Makefile.am was also added to build these new example modules.
examples/src · high confidence
OpenBSD init script added for Yaws
A new OpenBSD rc.d init script (yaws.sh) was added to the project, providing a standard mechanism to start, stop, and reload the Yaws web server on OpenBSD systems.
scripts/openbsd · high confidence
Windows installer and startup script added
The win32 directory now includes a complete Windows distribution package. This adds a C-based startup script (yaws.c) that handles command-line arguments and registry lookups, a Makefile.am for building the Windows binary, and a build.xml.in configuration for the BitRock InstallBuilder to generate a Windows installer. The package also includes a default yaws.conf and documentation files (README.txt, README.developer) to support Windows users.
win32 · high confidence
Yapp application handler and admin console
The yapp application is introduced as a handler for deploying Yaws applications (Yapps) independently of each other. It includes a web-based admin console (add/remove/list pages) for managing registered Yapps, with a default Mnesia-based registry and an optional ETS-based registry for non-persistent cases. The application also provides an example Yapp (yapp\_ex\_1) and a local stylesheet for the admin interface.
applications/yapp · high confidence
Removals
Removal of the yaws shell script
The yaws shell script, previously located at bin/yaws, has been removed from the repository. This script previously served as a launcher for the Erlang runtime, handling command-line arguments for interactive, debug, and daemon modes, as well as configuration file paths.
bin · high confidence
Removed obsolete Erlang application and crash dump files
The ebin directory no longer contains the compiled bytecode or metadata for the 'ewww' and 'yaws' applications, nor the 'erl\_crash.dump' file. This removal eliminates legacy server components and debug artifacts from the build output, ensuring the application starts without loading these specific modules.
ebin · high confidence
Security
Security fix for HTTPoxy vulnerability
Fixed a security flaw (HTTPoxy) where the HTTP\_PROXY header was incorrectly passed to CGI scripts as the HTTP\_HOST environment variable. The code now skips the Proxy header when constructing CGI environment variables, preventing potential header injection attacks.
src · high confidence
Behavioural changes
Added Diffie-Hellman parameters and regenerated SSL certificates
The ssl directory now includes a new dhparams.pem file containing 2048-bit Diffie-Hellman parameters, generated via a new mkdhparams script, to support the new dhfile SSL option in yaws.conf. Additionally, the self-signed certificate (yaws-cert.pem) and private key (yaws-key.pem) have been regenerated with an updated signature algorithm, and the private key file no longer contains the public key.
ssl · medium confidence
Yaws server configuration and installation scripts refactored
The build and installation process for Yaws has been restructured. The previous \scripts/Makefile\ and \scripts/mangle\ were replaced with a new \scripts/Makefile.am\ and a suite of new shell scripts (\gen-yaws\, \gen-yaws-conf\, \rebar-pre-script\, \regular-install\, etc.) that generate the \yaws\ executable and configuration files. The default configuration template (\yaws.conf.template\) was significantly expanded to include new settings such as \keepalive\_maxuses\, \process\_options\ for garbage collection tuning, \acceptor\_pool\_size\, and \pick\_first\_virthost\_on\_nomatch\. Additionally, the \regular-install\ script now supports installing init scripts for a wider range of operating systems, including Gentoo, FreeBSD, NetBSD, and Darwin (macOS), alongside the existing Linux and Windows support.
scripts · high confidence
Test coverage
Migrate test suite to Common Test framework
The test suite has been refactored to use the Erlang/OTP Common Test framework instead of a previous in-house testing framework. This change introduces a new \test/Makefile.am\ build system for compiling and running tests, a \test/README.md\ guide for developers on how to run and analyze results, and a \test/analyze\_coverdata.escript.in\ script for code coverage analysis. Existing test suites, such as \auth\_SUITE\ and \cookies\_SUITE\, have been rewritten to conform to Common Test conventions, enabling features like selective test execution, HTML reporting, and debugger integration.
test · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 45 → 37 (-7.6)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.19) — scores are not directly comparable.
Lenses
- Code Health 85 → 35 (-50.6)
- Architecture 99 → 100 (+1.0)
- Maturity 53 → 53 (+0.0)
- Readiness 48 → 32 (-15.6)
- Security 59 → 59 (+0.0)
- Event-Driven 40 → 40 (+0.0)
- Event Sourcing 100 → 100 (+0.0)
- Accessibility 40 → 40 (+0.3)
Resolved (3)
- Change coupling: yaws_jsonrpc.erl ↔ yaws_xmlrpc.erl (src/yaws_jsonrpc.erl)
- Off-boarding risk: anonymized user #1
- Orphaned knowledge (src/yaws_debug.erl)
New (2)
- Off-boarding risk: anonymized user #1
- Orphaned knowledge (src/yaws_websockets.erl)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
erlyaws/yaws was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 6 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit f81d2fc03b325afebe364a26b01cbe3c58c2d1b0 — the exact code this score is about.
- Scored under rubric-2026.08.19 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer latest.