Skip to content
CAI
Software that uses CAICheck a score

mtrudel/bandit

67.2

Adequate · 23 September 2026

6.3k

lines of production code

Elixir

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is Bandit, a high-performance HTTP server library for Elixir designed as a Plug adapter for Phoenix applications. It implements RFC-compliant handling for HTTP/1.1, HTTP/2, and WebSockets, featuring dedicated process models for connection and stream management. The codebase includes comprehensive type definitions, telemetry integration, and extensive test coverage to ensure protocol correctness and security.

How it got here

2019–2020 — Project stabilization and documentation

5 changes.

This period focused on preparing the Bandit project for public release by establishing robust infrastructure, including Hex packaging, linting, and comprehensive documentation. Significant effort was dedicated to enhancing test coverage for HTTP/2, WebSocket, and TLS protocols through new support helpers and configuration refinements.

2021 — HTTP/1 and HTTP/2 implementation

6 changes.

This period focused on implementing the core HTTP/1 and HTTP/2 protocol handlers for the Bandit server, including dedicated process models, frame parsing, and RFC-compliant validation. Comprehensive test coverage was added to verify adapter functionality, header handling, and protocol conformance.

2022–2026 — WebSocket implementation and optimization

7 changes.

This period focused on introducing a complete, RFC 6455-compliant WebSocket handler, including structured frame parsing, permessage-deflate support, and optimized masking logic. Comprehensive test suites were added to verify protocol compliance, frame handling, and integration with the WebSock behavior, alongside minor asset adjustments and HTTP/1 test coverage.

Features

Add project configuration and documentation files

The repository now includes essential project infrastructure files: a \.credo.exs\ configuration for code linting, a \.dialyzer\_ignore.exs\ file to suppress specific Dialyzer warnings, an \.ackrc\ file to configure search tool exclusions, and a \.gitignore\ update to exclude dialyzer cache directories. Additionally, standard project documentation and legal files have been added, including a \CHANGELOG.md\, \CODE\_OF\_CONDUCT.md\, \LICENSE\, \SECURITY.md\, and a significantly expanded \README.md\ that replaces the placeholder text with comprehensive usage instructions, project goals, and performance benchmarks.

(repo-wide) · high confidence

Comprehensive API documentation and configuration type definitions for Bandit

The main Bandit module now includes extensive @moduledoc, @typedoc, and @type definitions that document all available configuration options for the HTTP server, including top-level server settings (scheme, port, IP, SSL), HTTP/1 and HTTP/2 specific options (such as request limits, process dictionary clearing, and garbage collection frequency), and WebSocket configuration. This provides users with clear, type-safe guidance on how to configure Bandit's behavior, compression, logging, and connection handling directly in the codebase.

lib · high confidence

Introduce Bandit HTTP server with Phoenix adapter and WebSocket support

This change introduces the Bandit HTTP server library, providing a new adapter for Phoenix applications that supports HTTP/1.1, HTTP/2, and WebSockets. The implementation includes a Plug.Conn.Adapter for handling request/response cycles, a delegating handler for protocol selection (ALPN and sniffing), and a Phoenix-specific adapter for seamless integration. Key features include automatic content negotiation for compression (deflate, gzip, zstd), RFC-compliant header validation, and comprehensive telemetry spans for request and WebSocket metrics.

lib/bandit · high confidence

Introduce dedicated HTTP/1 handler and socket implementation

Bandit now includes a dedicated HTTP/1 handler (\Bandit.HTTP1.Handler\) and socket implementation (\Bandit.HTTP1.Socket\) located in \lib/bandit/http1\. This change introduces a specific process model where each HTTP/1 connection is handled by a single process, supporting keep-alive requests, WebSocket upgrades, and configurable limits such as \max\_requests\ and \gc\_every\_n\_keepalive\_requests\. The implementation enforces RFC 9112 compliance, including strict validation of header field values and chunk-size grammar, while providing configuration options to control process dictionary clearing and logging of unknown messages.

lib/bandit/http1 · high confidence

Introduce new HTTP/2 handler implementation

The \lib/bandit/http2\ directory now contains a complete, RFC 9113-compliant HTTP/2 handler implementation. This includes the core \Bandit.HTTP2.Handler\ for managing connection lifecycle and frame parsing, \Bandit.HTTP2.Connection\ for state management, and \Bandit.HTTP2.Stream\ for individual stream processing. The update adds support for all standard HTTP/2 frames (HEADERS, DATA, SETTINGS, PING, GOAWAY, WINDOW\_UPDATE, RST\_STREAM, CONTINUATION), implements HPACK compression via the HPAX library, and enforces flow control and header validation. It also introduces a dedicated process model where each stream runs in its own \Bandit.HTTP2.StreamProcess\ supervised by the connection process.

lib/bandit/http2 · high confidence

Introduce new RFC 6455-compliant WebSocket handler

Bandit now includes a complete WebSocket implementation in \lib/bandit/websocket\ that conforms to RFC 6455. This new handler supports the standard HTTP upgrade mechanism, permessage-deflate compression (RFC 7692), and fragmented message handling. It integrates with the \WebSock\ behavior for application-level message handling and provides detailed telemetry metrics for received and sent frames. The implementation includes strict validation of upgrade requests, UTF-8 enforcement for text frames, and configurable limits for fragmented message sizes.

lib/bandit/websocket · high confidence

Behavioural changes

4 commits (1 fix) modifying assets

A change to existing behaviour in assets — 4 commits (1 fix), 5 files.

assets · medium confidence · unverified

HTTP/2 frame serialization and validation implementation

The HTTP/2 frame handling in \lib/bandit/http2/frame\ has been refactored to include explicit modules for parsing and serializing all standard HTTP/2 frame types (DATA, HEADERS, CONTINUATION, SETTINGS, PUSH\_PROMISE, PRIORITY, RST\_STREAM, WINDOW\_UPDATE, GOAWAY, and PING). This change introduces strict validation of frame structures against RFC 9113, including checks for zero stream IDs, invalid padding, and out-of-bounds settings values. Additionally, large frames are now automatically split to respect the configured maximum frame size during serialization, and unknown frame types are handled gracefully via a generic \Frame.Unknown\ struct.

lib/bandit/http2/frame · high confidence

Introduce structured WebSocket frame parsing and serialization

The WebSocket implementation now uses dedicated modules to parse and serialize individual frame types (binary, text, continuation, ping, pong, and connection close). This change enforces stricter protocol compliance, including rejecting compressed control frames, validating UTF-8 encoding in close frames, and ensuring proper payload sizes for ping/pong messages, which improves reliability and security for WebSocket connections.

lib/bandit/websocket/frame · high confidence

Optimized WebSocket masking implementation

The WebSocket masking logic in Bandit has been replaced with a new implementation that processes data in 32-byte blocks. This change improves performance by unrolling the masking operation, allowing for more efficient bitwise XOR operations on larger chunks of payload data rather than processing byte-by-byte or in smaller segments.

_lib/bandit/primitive\ops · high confidence

Test coverage

Added HTTP/1 test suite for logging, plug handling, protocol compliance, and telemetry; Added HTTP/2 protocol and frame-level test coverage; Added comprehensive test suite for WebSocket frame handling and protocol compliance; Added test coverage for adapter, headers, and server components; Added tests for WebSocket masking logic; New test support infrastructure for HTTP/2, WebSocket, and TLS verification; Refactor test configuration and remove obsolete unit test.

Dependencies

Bandit 1.12.5: Production-ready release with Elixir 1.13+ requirement and Hex packaging

This release bumps the version to 1.12.5 and raises the minimum Elixir requirement to 1.13, ensuring compatibility with modern Elixir features. The project is now fully configured for Hex packaging, including metadata such as maintainers, licenses, and changelog links, along with explicit file inclusions. Key dependencies are updated to stable versions: Thousand Island to \~\> 1.5, Plug to \~\> 1.18, WebSock to \~\> 0.5, and HPAX to \~\> 1.0. Development tooling is also refined, with Finch pinned to \< 0.22.0 to avoid upstream issues, and documentation setup expanded to include implementation notes for HTTP/1, HTTP/2, and WebSocket. Dialyzer configuration is added to improve type checking during development.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 64 → 67 (+3.3)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 99 (-1.3)
  • Architecture 100 → 96 (-3.6)
  • Maturity 55 → 55 (+0.8)
  • Readiness 57 → 67 (+10.6)
  • Security 77 → 80 (+3.5)

Resolved (5)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • Test reliability not included

New (11)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 2) (lib/bandit/http2/frame/goaway.ex)
  • FileTooLong: http2/stream.ex (lib/bandit/http2/stream.ex)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Outdated: dialyxir
  • Outdated: ex_doc
  • TodoComment (test/bandit/http1/protocol_test.exs)
  • TodoComment (test/bandit/http1/protocol_test.exs)
  • TodoComment (test/bandit/http2/protocol_test.exs)
  • Workflow holding a long-lived secret is unscoped

Changes since last survey

  • 45 commits — 41 feature/other, 4 fixes

By area

  • lib/bandit — 29 commits
  • test/bandit — 10 commits
  • (root) — 5 commits
  • .github/workflows — 1 commit

Notable commits

  • fix: Fix chunked read_body(length: 0) falsely completing the body (#691)
  • fix: Fix non-deterministic compile-time code (#646)
  • fix: Fix recent releases changelog headings in docs (#672)
  • fix: RFC Conformance: Fix HTTP/1.0 streaming response framing (#684)
  • change: Add tests for untested configuration options (#659)
  • change: Bound and cancel HTTP/2 sends blocked on the connection window ([GHSA redacted]) (#671)
  • change: Bump req from 0.6.3 to 0.7.2 (#628)
  • change: Bump req from 0.7.2 to 0.7.3 (#676)
  • change: Bump req from 0.7.3 to 0.7.4 (#694)
  • change: Close idle zero byte connections silently instead of answering 408 (#689)
  • change: Consolidate Plug.Conn.Adapter calling-process tests into adapter_test.exs (#667)
  • change: Count each received WebSocket wire frame exactly once in telemetry (#693)
  • change: Do not duplicate an existing vary: accept-encoding header (#658)
  • change: Don't compress 206 Partial Content responses (#677)
  • change: Don't treat max_inflate_ratio as a permessage deflate wire parameter (#678)
  • change: Drain HTTP/2 pending sends without repeated List.delete/2 (#673)
  • change: Enforce the RFC9112 chunk-size grammar and reject repeated transfer-encoding (#631)
  • change: Enforce the chunk-size grammar in a single pass (#661)
  • change: Fixup recent test noise
  • change: Guard against stale conn reuse in Bandit.Adapter (#668)
  • …and 25 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

mtrudel/bandit was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 22dade4353ee7b3635975d0d3670c85ab30b0dd4 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.