functional-rewire/dune
74.4
Strong · 18 September 2026
3.1k
lines of production code
Elixir
primary language
1
measurement over time
What this system is
Dune is a sandboxing library for Elixir designed to safely evaluate untrusted code by isolating execution in separate processes with strict resource limits. It prevents security risks such as atom table exhaustion and arbitrary system access through a configurable allowlist, secure AST parsing, and shimmed standard library functions. The system supports both stateless evaluations and persistent sessions, ensuring that dynamic code execution remains deterministic and safe from memory exhaustion attacks.
Features
Added diagnostics formatting and term safety checking helpers
The library now includes two new helper modules in the diagnostics area. Dune.Helpers.Diagnostics provides consistent formatting for code errors and warnings, including a polyfill for Code.with\_diagnostics to support older Elixir versions. Dune.Helpers.TermChecker introduces a recursive check to detect and prevent processing of humongous data structures built via structural sharing, enhancing safety during term inspection.
lib/dune/helpers · high confidence
Initial release of Dune 0.1.1
This change introduces the initial version of Dune, a sandbox for safely evaluating untrusted Elixir code. The release includes the core library implementation, a default allowlist mechanism to restrict execution to safe modules and functions, and configuration files such as \.formatter.exs\ and \LICENSE.md\. It establishes the foundational behavior for isolated code execution, atom safety, and module simulation as described in the accompanying README.
(repo-wide) · high confidence
Initial release of Dune safe code evaluation library
This change introduces the Dune library, providing a secure environment for parsing and evaluating untrusted Elixir code. It includes a customizable allowlist system (Dune.Allowlist) to restrict which modules and functions can be executed, preventing arbitrary code execution and atom leaks. The library supports both one-off evaluations via Dune.eval\_string and stateful sessions via Dune.Session, allowing bindings and modules to persist across multiple code blocks. Key features include configurable resource limits (memory, reductions, timeout), deterministic output options (pretty printing, sorted maps), and detailed error handling with captured standard output.
lib/dune · high confidence
Initial release of Dune sandbox for safe Elixir code evaluation
Introduces the Dune library, a sandbox for safely evaluating untrusted Elixir code from user input. The library provides \Dune.eval\_string/2\ and \Dune.eval\_quoted/2\ to execute code within isolated processes with configurable limits (timeout, memory, reductions) and strict allowlists that restrict access to environment variables, file systems, and network resources. It also includes \Dune.string\_to\_quoted/2\ to parse strings into ASTs without leaking atoms. The implementation ensures safety by preventing atom table exhaustion and simulating module definitions without creating actual modules in the VM.
lib · high confidence
Introduce isolated dynamic code evaluation engine
This change adds the core components for evaluating user-provided code in a sandboxed environment. The new \Dune.Eval.Process\ module executes code in a separate process with configurable limits on heap size, reductions, and execution timeout, capturing standard output and handling various failure modes (timeouts, memory limits, exceptions). It distinguishes between compile errors and runtime exceptions, formatting diagnostics appropriately. Supporting modules like \Dune.Eval.Env\ and \Dune.Eval.FakeModule\ allow for the injection of fake modules and controlled atom mapping, while \Dune.Eval.MacroEnv\ provides a safe macro environment. This enables safe, dynamic code execution within the library.
lib/dune/eval · high confidence
Behavioural changes
Introduce default allowlist with safe shims and strict restrictions
The \lib/dune/allowlist\ location now provides a default allowlist (\Dune.Allowlist.Default\) that strictly controls which functions and macros are permitted during code generation. This change introduces a system where unsafe operations are either restricted or replaced with safe shims (e.g., \to\_string\ is shimmed to \Dune.Shims.Atom.to\_string\), and adds support for version-specific functions like \to\_timeout\ and \is\_non\_struct\_map\ for Elixir 1.17+. It also includes documentation generation capabilities (\Dune.Allowlist.Docs\) and a specification module (\Dune.Allowlist.Spec\) to manage and classify function statuses (allowed, restricted, or shimmed).
lib/dune/allowlist · high confidence
Introduce secure AST parsing with atom encoding and sanitization
The parser now processes Elixir code through a new multi-stage pipeline that encodes atoms to prevent leaks, validates module names, and restricts unsafe syntax. This ensures that parsing untrusted code does not create new atoms in the BEAM VM, handles conflicts between def/defp definitions, and blocks restricted bitstring modifiers and module redefinitions, resulting in safer and more predictable compilation of dynamic code.
lib/dune/parser · high confidence
Introduces safe shim modules for core Elixir functions
Adds new shim implementations in lib/dune/shims for Kernel, IO, Enum, List, Atom, and JSON modules to provide controlled, safe execution environments. These shims handle atom mapping, string conversion, and inspection while enforcing allowlists and restricting dangerous functions like dbg/0 and sigil\_w/2, ensuring that user code runs within defined safety boundaries.
lib/dune/shims · high confidence
Test coverage
Added tests for Dune parser atom encoding and string parsing; Initial test suite for Dune core modules; Initial test suite for Dune sandboxing and evaluation.
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 74.
Lenses
- Code Health 93
- Architecture 100
- Maturity 59
- Readiness 80
- Security 99
Changes since last survey
- 140 commits — 112 feature/other, 28 fixes
By area
- (root) — 82 commits
- lib/dune — 36 commits
- .github/workflows — 8 commits
- test/dune_string_test.exs — 5 commits
- test/dune — 3 commits
- test/dune_oom_safety_test.exs — 3 commits
- test/dune_quoted_test.exs — 2 commits
- test/dune_modules_test.exs — 1 commit
Notable commits
- fix: Bugfix: Handle conflicting def/defp
- fix: Fix CI
- fix: Fix CI due to warning change in LTS
- fix: Fix UndefinedFunctionError on custom allowlist modules (#2)
- fix: Fix atoms prefixed by Elixir
- fix: Fix atoms prefixes by Elixir (again)
- fix: Fix bug for nested function calls
- fix: Fix bug in string_to_quoted/2 with modules
- fix: Fix bug when using single atom in session
- fix: Fix dialyzer improper_lists warning
- fix: Fix doc and typespec
- fix: Fix error message on restricted dbg/0
- fix: Fix error, add dialyzer flags
- fix: Fix flaky test
- fix: Fix flaky test
- fix: Fix heisentest
- fix: Fix incorrect type definitions, delete unused ones
- fix: Fix inspect for quoted atoms
- fix: Fix inspect of quoted atom (elixir 1.13)
- fix: Fix older versions pre-1.18 that don't have JSON
- …and 120 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
functional-rewire/dune was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 18 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 30f03253af4721b68c252a776cf3d80e8e12bc35 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-5d04157a340d.