Skip to content
CAI
Software that uses CAICheck a score

esl/fast_scram

56.5

Adequate · 2 October 2026

1.3k

lines of production code

Erlang

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is an Erlang library implementing the SCRAM authentication mechanism, providing a complete client and server state machine for challenge-response authentication. It supports multiple hash algorithms including SHA-1, SHA-2, and SHA-3, with optional NIF-based performance optimizations for key derivation. The library replaces previous PBKDF2 modules and includes a comprehensive test suite to verify protocol compliance and input validation.

Features

Introduce fast\_scram SCRAM authentication library

The \src\ directory now contains the \fast\_scram\ application, a new Erlang library implementing the Salted Challenge Response Authentication Mechanism (SCRAM). This replaces the previous \erl\_fastpbkdf2\ module, which has been removed. The new library provides a full SCRAM implementation supporting SHA-1, SHA-2 (224, 256, 384, 512), and SHA-3 hash methods, with optional NIF-based performance optimizations for PBKDF2. It exposes a configuration API and state machine (\mech\_new\, \mech\_step\) for both client and server roles, handling channel binding, nonce management, and key derivation as defined in RFC 5802.

src · high confidence

Support for SHA3 hash algorithms in SCRAM authentication

The library now allows the use of SHA3 hash functions for the SCRAM challenge-response algorithm. This is enabled by updating the underlying \fast\_pbkdf2\ dependency to version 2.0.1 (via \rebar.config\ and \rebar.lock\) and updating the Erlang type definitions to include \crypto:sha3()\ alongside existing SHA1 and SHA2 options. Users can now configure their SCRAM states to use SHA3 for improved hashing capabilities.

(repo-wide) · high confidence

Test coverage

Comprehensive test suite for SCRAM authentication

Added a new Common Test suite (\scram\_SUITE.erl\) that covers the full SCRAM authentication flow. The tests verify correct behavior across SHA-1, SHA-2, and SHA-3 hash methods, validate channel binding scenarios, and ensure proper handling of invalid inputs, missing flags, and unsupported extensions.

test · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 55 → 56 (+1.9)
  • Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (+0.0)
  • Architecture 69 → 69 (+0.0)
  • Maturity 55 → 55 (+0.0)
  • Readiness 63 → 65 (+2.7)
  • Security 57 → 74 (+17.2)
  • Event Sourcing 49 → 49 (+0.0)

Resolved (2)

  • Coverage not measured — no coverage collector is wired up
  • Off-boarding risk: anonymized user #1

New (1)

  • Off-boarding risk: anonymized user #1

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

esl/fast_scram was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 0bc744d7ee88f1a8a84b8aee35fe1d1e71f73abc — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.