Skip to content
CAI
Software that uses CAICheck a score

g-andrade/tls_certificate_check

68.9

Weak · 2 October 2026

4.4k

lines of production code

Erlang

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is an Erlang library designed to validate TLS server certificates against a managed CA store. It bundles Mozilla's root certificates and allows for runtime updates and custom authority overrides. The project includes utilities for updating the hardcoded CA data and comprehensive test suites for certificate chain validation and application startup dependencies.

Features

Added TLS certificate authority updater utility

A new Erlang utility module, \tls\_certificate\_check\_hardcoded\_CAs\_updater\, has been added to the \util\ directory. This tool automates the process of reading encoded certificate authority files, parsing them, and generating an Erlang module containing the authoritative certificate values. It includes logic to detect changes in the source data and only writes the output file if the generated code differs from the current version, while also maintaining a changelog of additions and removals.

util · high confidence

Initial release of TLS certificate checking library

Introduces the \tls\_certificate\_check\ application, providing an API to validate server certificates against a managed CA store. The library bundles Mozilla's root certificates (updated as of 2026/09/25) and supports overriding trusted authorities via file paths, encoded binaries, or lists. It includes a shared state manager to handle certificate updates and partial chain verification, with a supervisor tree to manage the application lifecycle.

src · high confidence

Test coverage

Add cross-signing test fixtures and build scripts; Add test fixtures for certificate validation scenarios; Added test fixtures for dependent app startup behavior; Expanded test coverage for TLS certificate validation scenarios.

Housekeeping

Initial project scaffolding and tooling setup

The repository has been initialized with the core build and development infrastructure for the \tls\_certificate\_check\ library. This includes the \rebar.config\ build script (pinning \ssl\_verify\_fun\ and dev plugins like \erlfmt\, \rebar3\_hank\, and \rebar3\_lint\), a \Makefile\ for standard tasks (compile, test, check, format), and configuration files for the Erlang linter (\elvis.config\) and documentation generation (\ex\_doc.config\). Supporting files such as \.gitignore\, \.gitattributes\, \LICENSE\, and agent guides (\AGENTS.md\, \CLAUDE.md\) are also present to establish the project's development environment.

(repo-wide) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 71 → 69 (-2.5)
  • Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 99 → 99 (+0.0)
  • Architecture 100 → 100 (+0.0)
  • Maturity 59 → 59 (+0.0)
  • Readiness 76 → 60 (-16.2)
  • Security 80 → 92 (+12.2)

Resolved (2)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)

New (1)

  • No ADRs found

Changes since last survey

  • 2 commits — 2 feature/other, 0 fixes

By area

  • (repo) — 1 commit
  • (root) — 1 commit

Notable commits

  • change: Merge pull request #74 from g-andrade/automation/hardcoded-CAs-update/2026/09/25
  • change: Update bundled CAs to latest as of 2026/09/25

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

g-andrade/tls_certificate_check was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 2e80f64308b0dfbfe03a630f94c79b964e4ce9ae — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.