hexpm/hex_core
84.5
Strong · 2 October 2026
8.6k
lines of production code
Erlang
primary language
2
measurements over time
What this system is
This system is a comprehensive Erlang library for interacting with the Hex package manager, providing both client-side API access and foundational data contracts. It enables build tools to authenticate via OAuth or API keys, manage packages and organizations, and handle secure tarball operations. The library also includes logic to aggregate and deduplicate security advisories from multiple sources, ensuring consistent vulnerability reporting.
Features
Introduce structured protocol buffers for package metadata, policies, and security advisories
This change adds a new set of Protocol Buffers definitions (proto2) to the \proto/\ directory, establishing the data contracts for the registry. The schema introduces \hex\_pb\_package.proto\ to define package and release structures, including fields for checksums, dependencies, retirement status, and security advisories. It adds \hex\_pb\_policy.proto\ to model repository-level policies, visibility settings, and granular restrictions/overrides (allow, deny, advisory, retirement, cooldown). Security information is formalized in \hex\_pb\_signed.proto\ for payload verification and \hex\_pb\_versions.proto\ for version indexing, including retired and advisory flags. These definitions provide the foundational serialization format for package data, policy enforcement, and security advisory integration.
proto · high confidence
New Hex API client modules and security advisory grouping
This release introduces a comprehensive set of new modules for interacting with the Hex API, including \hex\_api\ (core HTTP request handling), \hex\_api\_auth\ (key testing), \hex\_api\_key\ (key management), \hex\_api\_oauth\ (OAuth device and client credentials flows), \hex\_api\_organization\ and \hex\_api\_organization\_member\ (organization and member management), \hex\_api\_package\ and \hex\_api\_package\_owner\ (package and owner operations), \hex\_api\_release\ (publishing, retiring, and deleting releases), \hex\_api\_short\_url\ (short URL creation), and \hex\_api\_user\ (user account operations). Additionally, \hex\_advisory\ is added to group and deduplicate security advisories from multiple sources (EEF, GHSA, NVD) by identifying primary identifiers and merging aliases, ensuring users see one entry per vulnerability. \hex\_cli\_auth\ provides the CLI authentication layer with support for API keys, OAuth tokens, OTP, and device auth flows, integrating with the new API modules.
src · high confidence
New Hex API example application
Added a new example application (myapp\_hex) that demonstrates how to interact with the Hex package manager API. The example provides functions to retrieve package details, repository versions, and tarballs, utilizing a naive process-dictionary-based HTTP cache for repeated requests and supporting API key authentication via the HEX\_API\_KEY environment variable.
examples · high confidence
Rename to hex\_core and introduce new build tool authentication
The library has been renamed from hex\_erl to hex\_core, with updated documentation and configuration to reflect this identity. A major new capability is added in v0.19.0: the \hex\_cli\_auth\ module provides callback-based authentication for build tools, handling OAuth token exchange, automatic refresh, and OTP prompts via \with\_api/3,4\ and \with\_repo/2,3\ wrappers. This is accompanied by the \hex\_api\_oauth:device\_auth\_flow/4,5\ function for complete OAuth device authorization. The project also updates its build configuration to use rebar3 profiles for development and testing dependencies.
(repo-wide) · high confidence
Test coverage
Add HTTP test fixtures and test helpers; Expanded Common Test suite for security, authentication, and tarball handling.
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 87 → 85 (-2.6)
- Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 95 → 94 (-0.3)
- Architecture 100 → 83 (-16.5)
- Maturity 80 → 80 (+0.1)
- Readiness 89 → 89 (+0.0)
- Security 100 → 100 (+0.0)
- Event Sourcing 100 → 100 (+0.0)
Resolved (4)
- Coverage not measured — no coverage collector is wired up
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Off-boarding risk: anonymized user #1
New (5)
- Dependency hygiene PARTLY measured — rebar3 pinning read, dependency currency not (no rebar.lock-pinned Hex declaration to grade)
- Duplicated block (5 lines × 2) (src/hex_deflate.erl)
- FileTooLong: src/hex_deflate.erl (src/hex_deflate.erl)
- Off-boarding risk: anonymized user #1
- Projects may be oversized for their cohesion
Changes since last survey
- 7 commits — 7 feature/other, 0 fixes
By area
- src/hex_erl_tar.erl — 3 commits
- .github/workflows — 2 commits
- src/hex_deflate.erl — 1 commit
- src/hex_tarball.erl — 1 commit
Notable commits
- change: Bump the codeql group with 2 updates (#224)
- change: Bump zizmorcore/zizmor-action from 0.6.3 to 0.6.4 (#225)
- change: Compress tarballs with a deterministic deflate encoder (#230)
- change: Create identical package tarballs from identical inputs (#228)
- change: Decode metadata strings that end in a backslash (#227)
- change: Update vendored erl_tar to OTP 29.1.1 (#229)
- change: Write UTF-8 file names when unpacking with latin1 native encoding (#226)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
hexpm/hex_core was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 6f7aa49e41e9df1f2b451ac236e1d2f1f7400c8d — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.