Skip to content
CAI
Software that uses CAICheck a score

novaframework/nova

66.4

Adequate · 23 September 2026

5k

lines of production code

Erlang

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Nova is a BEAM-native web framework for Erlang, Elixir, and LFE built on Cowboy that provides a plugin-based architecture for handling HTTP requests. It supports core web functionalities including multipart file uploads, static file serving with range requests, and structured error handling. The system includes built-in security plugins for CORS, CSRF, and request correlation, along with a template engine and JSON logging capabilities.

Features

Custom error pages and static file directory listings

The application now provides custom-styled views for error handling and static file management. A new error template displays status codes, messages, and formatted Erlang stack traces with syntax highlighting, improving the developer experience during debugging. Additionally, a new directory listing view allows users to browse static file contents, showing file names, sizes, and modification dates in a structured table format.

src/views · high confidence

Initial release of Nova web framework with Cowboy 2.18 and modern tooling

Nova is introduced as a BEAM-native web framework supporting Erlang, Elixir, and LFE, built on Cowboy 2.18.0. The release establishes the core project structure, including a new .gitignore, comprehensive README documentation, and a rebar.lock pinning dependencies like Cowboy 2.18.0, ErlyDTL 0.14.0, and Thoas 1.2.1. Configuration in rebar.config sets up source directories, ErlyDTL template compilation, Dialyzer and Xref checks, and ExDoc for Hex.pm documentation. A Renovate configuration is added to automate dependency updates for Hex packages and GitHub Actions.

(repo-wide) · high confidence

Introduces multipart file upload support and a JSON logger

Nova now supports multipart/form-data uploads via a new plugin architecture, including a default file handler that streams parts to disk securely and a memory handler for small attachments. Additionally, a new JSON logger module (nova\_jsonlogger) is provided to format application logs as single-line JSON, and the template system gains a new 'url' tag for generating prefixed application URLs.

src · high confidence

New and updated request-handling plugins for correlation, CORS, CSRF, and multipart uploads

The plugin system now includes dedicated modules for common web tasks. The new correlation plugin automatically injects a correlation ID into request/response headers and logger metadata, configurable via \request\_correlation\_header\ and \logger\_metadata\key\. A new CORS plugin adds \Access-Control-Allow-\\ headers based on an \allow\_origins\ option. CSRF protection is now handled by a synchronizer-token plugin that validates tokens on unsafe methods and injects them on safe ones, with configurable field/header names and path exclusions. The request plugin has been refactored to handle body reading and JSON decoding (using the configurable \json\_lib\, defaulting to \thoas\) and URL-encoded body parsing, returning 400 on JSON decode failures. Additionally, a new multipart plugin streams file uploads to a configurable handler, enforcing limits on parts, sizes, and read timeouts.

src/plugins · high confidence

New error and static file controllers

The application now includes dedicated controllers for handling errors and serving static assets. The error controller (\nova\_error\_controller\) provides structured 404 and 500 responses that respect the client's Accept header (JSON or HTML) and conditionally includes stack traces only in development environments. The static file controller (\nova\_file\_controller\) enables serving files with support for HTTP Range requests (partial content), automatic MIME type detection, directory listing, and index file resolution.

src/controllers · high confidence

Behavioural changes

New header files for deprecation logging, pubsub records, and router definitions

The framework introduces three new header files to standardize internal definitions. nova.hrl adds macros for structured deprecation warnings via the standard logger, notifying users of deprecated functions with version and file context. nova\_pubsub.hrl defines the nova\_pubsub record, updating the channel field to accept both atoms and binaries for greater flexibility. nova\_router.hrl introduces records for handler values (nova\_handler\_value and cowboy\_handler\_value), explicitly defining fields for application, module, function, plugins, and security configurations.

include · high confidence

Test coverage

Added test harness for Nova framework end-to-end validation; Expanded test coverage for Nova core components.

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 53 → 66 (+12.9)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 97 (-2.9)
  • Architecture 100 → 98 (-2.1)
  • Maturity 55 → 60 (+5.4)
  • Readiness 73 → 65 (-8.6)
  • Security 35 → 61 (+26.6)
  • Event Sourcing 100 (new)

Resolved (23)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Further orphaned files (smaller)
  • Further sole-owners (lower concentration)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • …and 3 more

New (34)

  • Coverage not measured — no coverage collector is wired up
  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • FileTooLong: src/nova_router.erl (src/nova_router.erl)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 14 more

Changes since last survey

  • 5 commits — 5 feature/other, 0 fixes

By area

  • src/plugins — 2 commits
  • include/nova_pubsub.hrl — 1 commit
  • src/nova_basic_handler.erl — 1 commit
  • test/nova_test_app — 1 commit

Notable commits

  • change: Be able to return {status, ...}-tuple when upgrading websocket. (#403)
  • change: Replace edoc comments with doc attributes (#414)
  • change: feat(multipart): add nova_multipart_plugin for multipart/form-data uploads (#412)
  • change: feat(pubsub): allow binary channels, not just atoms (#390)
  • change: feat: replace routing_tree with an in-tree routing trie and support multiple listeners (#405)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

novaframework/nova was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 572e121657d582128826d3a8de287ef453d55ab4 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.