esl/fast_scram
56.5
Adequate · 2 October 2026
1.3k
lines of production code
Erlang
primary language
2
measurements over time
What this system is
This system is an Erlang library implementing the SCRAM authentication mechanism, providing a complete client and server state machine for challenge-response authentication. It supports multiple hash algorithms including SHA-1, SHA-2, and SHA-3, with optional NIF-based performance optimizations for key derivation. The library replaces previous PBKDF2 modules and includes a comprehensive test suite to verify protocol compliance and input validation.
Features
Introduce fast\_scram SCRAM authentication library
The \src\ directory now contains the \fast\_scram\ application, a new Erlang library implementing the Salted Challenge Response Authentication Mechanism (SCRAM). This replaces the previous \erl\_fastpbkdf2\ module, which has been removed. The new library provides a full SCRAM implementation supporting SHA-1, SHA-2 (224, 256, 384, 512), and SHA-3 hash methods, with optional NIF-based performance optimizations for PBKDF2. It exposes a configuration API and state machine (\mech\_new\, \mech\_step\) for both client and server roles, handling channel binding, nonce management, and key derivation as defined in RFC 5802.
src · high confidence
Support for SHA3 hash algorithms in SCRAM authentication
The library now allows the use of SHA3 hash functions for the SCRAM challenge-response algorithm. This is enabled by updating the underlying \fast\_pbkdf2\ dependency to version 2.0.1 (via \rebar.config\ and \rebar.lock\) and updating the Erlang type definitions to include \crypto:sha3()\ alongside existing SHA1 and SHA2 options. Users can now configure their SCRAM states to use SHA3 for improved hashing capabilities.
(repo-wide) · high confidence
Test coverage
Comprehensive test suite for SCRAM authentication
Added a new Common Test suite (\scram\_SUITE.erl\) that covers the full SCRAM authentication flow. The tests verify correct behavior across SHA-1, SHA-2, and SHA-3 hash methods, validate channel binding scenarios, and ensure proper handling of invalid inputs, missing flags, and unsupported extensions.
test · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 55 → 56 (+1.9)
- Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 100 → 100 (+0.0)
- Architecture 69 → 69 (+0.0)
- Maturity 55 → 55 (+0.0)
- Readiness 63 → 65 (+2.7)
- Security 57 → 74 (+17.2)
- Event Sourcing 49 → 49 (+0.0)
Resolved (2)
- Coverage not measured — no coverage collector is wired up
- Off-boarding risk: anonymized user #1
New (1)
- Off-boarding risk: anonymized user #1
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
esl/fast_scram was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 0bc744d7ee88f1a8a84b8aee35fe1d1e71f73abc — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.