intility/erlang-oci-builder
39.3
Weak · 2 October 2026
12.5k
lines of production code
Erlang
with Elixir
2
measurements over time
What this system is
ocibuild is an Elixir library and CLI tool that builds, signs, and pushes OCI container images directly from Elixir Mix or Erlang rebar3 releases. It provides extensible adapters for build systems, smart dependency layering, and secure image distribution features like SBOM generation and cosign-compatible signing. The system also includes utilities for reproducible builds, HTTP caching, and multi-platform support to streamline CI/CD workflows.
Features
Add Elixir Mix task and release step integration with smart dependency layering
Users can now build OCI images directly from Elixir Mix releases using a new \Ocibuild.MixRelease\ module that integrates as a step in \mix release\, and a new \Ocibuild.Lock\ module that parses \mix.lock\ files to enable smart dependency layering. This allows the build process to classify dependencies (e.g., Hex vs. Git sources) for optimized image layering, configurable via \ocibuild\ options in \mix.exs\ such as \:base\_image\, \:tag\, \:push\, \:annotations\, and \:compression\.
lib/ocibuild · high confidence
Introduce Mix task for building and pushing OCI container images
Adds a new \mix ocibuild\ task that allows users to build OCI container images directly from Elixir Mix releases. This feature supports tagging, outputting to tarballs, pushing to registries, and configuring image metadata such as labels, annotations, and base images. It also includes capabilities for multi-platform builds, chunked uploads, SBOM generation, and image signing.
lib/mix · high confidence
Introduce extensible OCI build adapter architecture with Mix and rebar3 integrations
The \src/adapters\ directory now defines the \ocibuild\_adapter\ behaviour, establishing a standardized interface for build-system integrations to extract configuration, locate release artifacts, and handle logging. This architecture enables the new \ocibuild\_mix\ adapter for Elixir/Mix projects and the \ocibuild\_rebar3\ provider for Erlang/rebar3 projects, both of which implement this behaviour to feed into the shared \ocibuild\_release\ module. Additionally, a \src/vcs\ layer with a \ocibuild\_vcs\ behaviour and a Git adapter (\ocibuild\_vcs\_git\) has been added to automatically detect repositories and populate OCI annotations (source URL, revision) from CI environment variables or git commands.
src/adapters · high confidence
New utility modules for compression, digests, JSON, progress, time, and validation
Added several new utility modules in src/util: ocibuild\_compress provides a unified compression API that automatically selects zstd on OTP 28+ or falls back to gzip on OTP 27; ocibuild\_digest offers SHA256 digest utilities for OCI content addressing; ocibuild\_json wraps OTP 27's json module for encoding and decoding; ocibuild\_progress introduces a multi-line progress bar display for concurrent operations; ocibuild\_time centralizes timestamp utilities supporting SOURCE\_DATE\_EPOCH for reproducible builds; and ocibuild\_validate adds security-focused validation functions for user inputs, including checks for null bytes and path traversal attacks.
src/util · high confidence
OCI image building and signing capabilities added
The \src/oci\ module now provides a complete toolkit for building, managing, and securing OCI images. Users can create multi-platform image indexes, generate layers with automatic zstd compression (falling back to gzip), and export images as directories or tarballs. The build process supports reproducible builds via fixed modification times and allows pushing existing OCI tarballs without rebuilding. Additionally, the module includes SPDX 2.2 SBOM generation and cosign-compatible image signing using ECDSA P-256 keys, enabling secure, verifiable image distribution.
src/oci · high confidence
Behavioural changes
Introduce supervised HTTP client and OCI build layer caching
The HTTP layer in \src/http\ has been refactored to use a proper OTP supervision tree, replacing the previous ad-hoc approach with \ocibuild\_http\_sup\, \ocibuild\_http\_pool\, and \ocibuild\_http\_worker\ modules. This provides isolated \httpc\ profiles per worker, bounded concurrency for parallel downloads/uploads, and cleaner graceful shutdowns to prevent orphaned processes. Additionally, a new \ocibuild\_cache\ module was added to cache OCI image layers locally (defaulting to \\_build/ocibuild\_cache\), supporting environment variable overrides and project root detection to speed up CI/CD builds.
src/http · high confidence
Project rebrand to ocibuild and license change to MIT
The project has been renamed from 'erlang-oci-builder' to 'ocibuild' and the license has been changed from Apache 2.0 to MIT. This includes updating the repository URL to the intility organization, renaming the development guide from DEVELOPMENT.md to AGENTS.md, and updating all documentation (README, CLAUDE.md, CHANGELOG) to reflect the new name and structure.
(repo-wide) · high confidence
Removal of legacy internal modules and API expansion
The internal implementation modules ocibuild\_digest, ocibuild\_json, ocibuild\_layer, ocibuild\_layout, ocibuild\_manifest, ocibuild\_registry, and ocibuild\_tar have been removed from the source tree, likely as part of a refactoring to consolidate logic or switch to external dependencies. Concurrently, the public API in src/ocibuild.erl has been expanded with new functions including from/3, add\_layer/3, push/5, push\_multi/4, push\_multi/5, save/3, and annotation/3, alongside new types for platform and auth. The application version has been bumped to 0.10.5, the license changed to MIT, and the repository link updated to the intility organization.
src · high confidence
Test coverage
Added comprehensive test coverage for adapters, HTTP, and Mix integration
Added new EUnit and ExUnit test suites covering the Mix adapter configuration and release discovery, the rebar3 provider's error formatting and lock-file parsing, shared release handling logic (including symlink security and multi-platform validation), HTTP caching and project root detection, the OCI registry client (including chunked uploads and digest verification), HTTP/SSL shutdown behavior, and Mix task argument parsing and lock-file dependency extraction.
test · high confidence
Dependencies
Initial Elixir project configuration via mix.exs
The project now includes a mix.exs file that defines the Elixir Mix project structure for the :ocibuild application. This configuration sets the Elixir version requirement to \~\> 1.14, specifies source paths (src, lib, include), and configures runtime applications (:crypto, :ssl, :inets). Notably, the version and description are dynamically read from src/ocibuild.app.src to maintain a single source of truth, and the dependencies list is currently empty.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 40 → 39 (-0.5)
- Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 95 → 95 (+0.0)
- Architecture 67 → 60 (-6.3)
- Maturity 60 → 60 (+0.2)
- Readiness 65 → 65 (+0.0)
- Security 83 → 88 (+4.2)
- Event-Driven 10 → 10 (+0.0)
Resolved (4)
- Coverage not measured — no coverage collector is wired up
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Hotspot: src/http/ocibuild_registry.erl (src/http/ocibuild_registry.erl)
New (2)
- Dependency hygiene PARTLY measured — rebar3 pinning read, dependency currency not (no rebar.lock-pinned Hex declaration to grade)
- Projects may be oversized for their cohesion
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
intility/erlang-oci-builder was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 7e7dc22a1c2eb862f4a9b43b6ea79c3716b6e4a4 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.