Skip to content
CAI
Software that uses CAICheck a score

mtrudel/thousand_island

69.9

Adequate · 23 September 2026

3.1k

lines of production code

Elixir

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Thousand Island is a pure Elixir socket server library designed as a modern alternative to Ranch, providing a robust architecture for managing TCP and SSL connections. It features a configurable supervision tree, a Handler behavior for application-level logic, and comprehensive telemetry for monitoring server and connection events. The system supports advanced transport options, including TLS with SNI and efficient file transfers, while ensuring stability through graceful error handling and process labeling.

Features

Add SSL transport and expand TCP transport capabilities

Users can now serve HTTPS traffic via a new SSL transport implementation that supports TLS configuration options including keyfile, certfile, sni\_hosts, and sni\_fun, with a custom chunked sendfile implementation for large file transfers. The existing TCP transport has been significantly expanded to include handshake and upgrade stubs, support for inet\_backend configuration, and new methods for retrieving connection statistics, negotiated protocols, and detailed connection information, while also ensuring file descriptors are properly closed during sendfile operations.

_lib/thousand\island/transports · high confidence

Added sample handler implementations for common protocols

The examples directory now includes four new sample handler implementations: Daytime, Echo, HTTPHelloWorld, and Messenger. These files demonstrate how to implement the ThousandIsland.Handler behavior for basic TCP protocols, including handling connections, echoing data, serving simple HTTP responses, and managing bidirectional messaging via GenServer casts.

examples · high confidence

Initial release of Thousand Island socket server

Introduces Thousand Island, a pure Elixir socket server library designed as a modern alternative to Ranch. The module provides a supervision tree for managing server processes, a \Handler\ behaviour for application-level connection logic, and comprehensive configuration options including timeouts, connection limits, and transport settings. It also includes built-in telemetry support for monitoring server, acceptor, and connection events.

lib · high confidence

Project initialization and documentation overhaul

The repository has been initialized with core project files including a CHANGELOG, LICENSE, SECURITY policy, and Code of Conduct. The README has been significantly expanded to provide comprehensive usage instructions, architecture diagrams (rewritten in MermaidJS), and detailed explanations of the supervision tree, handler behavior, and telemetry events. Additionally, developer tooling configurations for Credo, Dialyzer, and ack have been added to support code quality and static analysis.

(repo-wide) · high confidence

Behavioural changes

3 commits (0 fixes) modifying assets

A change to existing behaviour in assets — 3 commits, 5 files.

assets · medium confidence · unverified

Thousand Island server architecture and API overhaul

The server's internal architecture has been restructured to improve stability and observability. The acceptor loop now runs in transient tasks that gracefully handle transient network errors (such as \:emfile\, \:econnaborted\, and \:einval\) by backing off or retrying instead of crashing the server. A new \AcceptorPoolSupervisor\ manages multiple acceptor supervisors, and connection handling has been moved to a dedicated \Connection\ module that manages socket ownership transfer and handler lifecycle. The public API has been updated to use \ThousandIsland.Socket\ for all connection interactions, replacing the previous raw socket approach. Additionally, the library now supports \Process.set\_label/1\ for better process identification on Elixir 1.17+ and exposes comprehensive telemetry events for listeners, acceptors, and connections via the \ThousandIsland.Logger\ and \ThousandIsland.Telemetry\ modules.

_lib/thousand\island · high confidence

Test coverage

Added test support infrastructure for TLS and telemetry verification; Expanded test coverage for server lifecycle and error handling.

Dependencies

Thousand Island 1.5.0 release with Elixir 1.13+ requirement and dev tooling updates

This release bumps the project version to 1.5.0 and raises the minimum supported Elixir version to 1.13. It adds telemetry as a runtime dependency (accepting \~\> 0.4 or \~\> 1.0) and includes the :ssl application in the OTP application list. Development tooling is updated with new versions of ex\_doc (0.40.3), credo (1.7.19), dialyxir (1.4.7), and machete (0.3.12), alongside configuration for Dialyzer and HexDocs packaging.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 70 → 70 (+0.3)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (+0.3)
  • Architecture 85 → 96 (+10.6)
  • Maturity 69 → 68 (-0.2)
  • Readiness 65 → 61 (-3.6)
  • Security 70 → 78 (+8.5)

Resolved (8)

  • Change coupling: acceptor.ex ↔ socket.ex (lib/thousand_island/acceptor.ex)
  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • Duplicated block (16 lines × 2) (lib/thousand_island/transports/ssl.ex)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • Test reliability not included

New (10)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Outdated: dialyxir
  • Outdated: ex_doc
  • PR-triggered workflow without a permissions block
  • Workflow holding a long-lived secret is unscoped

Changes since last survey

  • 18 commits — 12 feature/other, 6 fixes

By area

  • lib/thousand_island — 15 commits
  • test/thousand_island — 2 commits
  • lib/thousand_island.ex — 1 commit

Notable commits

  • fix: Fix port 0 with num_listen_sockets: bind every listener to the advertised port (#214)
  • fix: Fix: Add system time to telemetry span start measurements (#223)
  • fix: Fix: Emit connection readiness only after handshake success (#221)
  • fix: Fix: Emit telemetry exception events for handler callback exceptions (#222)
  • fix: Fix: Handle socket ownership-transfer errors during connection start (#220)
  • fix: Fix: Omit the TCP_NODELAY default for Unix domain listeners (#225)
  • change: Back off on :emfile / :enfile in the accept loop instead of crashing the server (#206)
  • change: Handler performance: reset the read timer lazily instead of on every message (#213)
  • change: Reduce the TLS sendfile chunk size from 8 MiB to 1 MiB (#215)
  • change: Refactor: Consolidate supervisor lifecycle helpers (#217)
  • change: Refactor: Separate connection start retries from socket handoff (#216)
  • change: Refactor: Share listener option resolution across transports (#218)
  • change: Refactor: Simplify shutdown listener state (#219)
  • change: Retry the transient network errors accept(2) documents instead of crashing the acceptor (#208)
  • change: Stop emitting a duplicate connection stop event on handshake and upgr… (#210)
  • change: Survive handler start failure: close the socket and keep accepting (#209)
  • change: add a handshake_timeout server option (#211)
  • change: add status/1 and info/1 runtime introspection (#212)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

mtrudel/thousand_island was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 6146e1bfdd1a85c5c16c3c92ad98ff5f11066820 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.