Skip to content
CAI
Software that uses CAICheck a score

pgourlain/vscode_erlang

37.5

Weak · 2 October 2026

21.2k

lines of production code

Erlang

with TypeScript

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Visual Studio Code extension for the Erlang programming language that provides core development tooling, including a language server, debugger, and test runner. It enables features such as code completion, diagnostics, inline debugging values, and EUnit/Common Test execution with coverage support. The extension also integrates a Model Context Protocol (MCP) inspector to allow AI agents to map OTP topology during debug sessions, while ensuring security through loopback binding and shell escaping.

Features

Automated screenshot generation for documentation

Added a new Playwright-based script (\scripts/screenshots/take-screenshots.mjs\) and a dedicated demo workspace to automatically capture consistent images of the VS Code extension's features (such as semantic tokens, code actions, and test explorer) for the README. The script launches a real VS Code instance with the extension loaded, executes specific user actions, and saves the resulting screenshots to the \images\ directory, ensuring the documentation visuals stay in sync with the extension's current behavior.

scripts, scripts/screenshots/workspace · high confidence

Erlang Language Server ported to Erlang with new VS Code integration features

The Erlang Language Server implementation has been ported from TypeScript to Erlang, introducing a new shell launcher (ErlangShellLSP) that binds distribution and epmd to the loopback interface for security and supports cache management modes. The extension now provides inline values during debugging, a dedicated status bar item to monitor the language server's lifecycle, and a new test controller for discovering and running EUnit and Common Test suites with coverage support.

lib/lsp · high confidence

Introduce opt-in MCP topology inspector for debug sessions

Users can now enable a read-only Model Context Protocol (MCP) server inside the debugged Erlang node to let AI agents map the OTP topology (applications, supervision trees, processes, and approved ETS metadata). This feature is controlled by the new \erlang.mcp.enabled\ setting (defaulting to false) and is restricted to debug sessions only, binding to loopback with per-session authentication. It includes a project-level policy in \rebar.config\ to restrict tools and data exposure, with a developer tier for bounded sampling of process state and mailboxes.

(repo-wide) · high confidence

New LSP infrastructure and documentation support

This change introduces the core Erlang Language Server Protocol (LSP) backend components within the erlangbridge application. It adds a new gen\_server-based configuration server (gen\_lsp\_config\_server) to manage extension settings, a document server (gen\_lsp\_doc\_server) to handle file parsing, caching, and syntax tree management, and a help server (gen\_lsp\_help\_server) to retrieve and render function documentation. Additionally, it includes a generic TCP connection handler (gen\_connection) for debugger communication, a JSON report module for EUnit tests (eunit\_jsonreport), and the necessary license and README files for the embedded erlfmt formatter.

apps/erlangbridge/src · high confidence

Behavioural changes

1 commit (0 fixes) modifying rebar3-erl22, rebar3-latest

A change to existing behaviour in rebar3-erl22, rebar3-latest — 1 commit, 2 files.

rebar3-erl22, rebar3-latest · low confidence · unverified

Redesigned Erlang debugger with shell-escape safety and MCP support

The debugger now uses a dedicated \ErlangConfigurationProvider\ to resolve settings, introducing a new \erlang.useShell\ option (defaulting to 'auto') that controls whether commands are run through a shell. This change adds robust shell-argument escaping via \GenericShell\ to prevent failures in sandboxed environments or with complex arguments, and integrates the MCP inspector for debug sessions. Additionally, the \ErlangAdapterDescriptorFactory\ now supports binding the debug server to 127.0.0.1, and the \RebarRunner\ and \DialyzerStatus\ components provide improved build diagnostics and PLT status tracking.

lib · high confidence

Test coverage

Added Erlang syntax highlighting test suite; Added test coverage for Erlang extension core components; Expanded test coverage for Erlang LSP server components.

Dependencies

Erlang extension updated to version 1.2.6 with dependency upgrades

The Erlang language extension for Visual Studio Code has been updated to version 1.2.6. This release includes several dependency upgrades visible in the package-lock.json, such as bumping qs from 6.12.1 to 6.16.0, tar-fs from 2.1.1 to 2.1.5, lodash from 4.17.15 to 4.17.21, and webpack from 5.76.0 to 5.110.3, among others. The extension now requires Visual Studio Code version 1.136.0 or higher.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 66 → 38 (-28.6)
  • Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 89 → 89 (-0.7)
  • Architecture 93 → 94 (+0.8)
  • Maturity 55 → 73 (+17.8)
  • Readiness 60 → 48 (-11.7)
  • Security 88 → 79 (-8.7)
  • Event-Driven 10 (new)
  • Event Sourcing 100 → 100 (+0.0)
  • Performance 60 (new)

Resolved (10)

  • Coverage not measured — no coverage collector is wired up
  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
  • Duplicated block (11 lines × 2) (apps/erlangbridge/src/hover_doc_layout.erl)
  • Duplicated block (11 lines × 2) (apps/erlangbridge/src/lsp_parse.erl)
  • Further sole-owners (lower concentration)
  • Off-boarding risk: anonymized user #1
  • TodoComment (lib/lsp/lspclientextension.ts)
  • TodoComment (lib/lsp/lspclientextension.ts)
  • TooManyFunctions: gen_lsp_doc_server (apps/erlangbridge/src/gen_lsp_doc_server.erl)
  • TooManyFunctions: lsp_handlers (apps/erlangbridge/src/lsp_handlers.erl)

New (66)

  • Duplicated block (5 lines × 2) (apps/erlangbridge/src/mcp/mcp_runtime.erl)
  • Duplicated block (5 lines × 2) (apps/erlangbridge/src/mcp/mcp_tools.erl)
  • Duplicated block (5 lines × 3) (apps/erlangbridge/src/mcp/mcp_tools.erl)
  • Duplicated block (6 lines × 2) (apps/erlangbridge/src/mcp/mcp_runtime.erl)
  • Duplicated block (7 lines × 2) (apps/erlangbridge/src/lsp_handlers.erl)
  • Duplicated block (8 lines × 2) (apps/erlangbridge/src/hover_doc_layout.erl)
  • Duplicated block (8 lines × 2) (apps/erlangbridge/src/mcp/mcp_runtime.erl)
  • Duplicated block (8 lines × 6) (apps/erlangbridge/src/lsp_codeaction.erl)
  • FileTooLong: lib/erlangDebugSession.ts (lib/erlangDebugSession.ts)
  • FileTooLong: mcp/mcp_runtime.erl (apps/erlangbridge/src/mcp/mcp_runtime.erl)
  • FileTooLong: src/gen_lsp_doc_server.erl (apps/erlangbridge/src/gen_lsp_doc_server.erl)
  • FileTooLong: src/lsp_handlers.erl (apps/erlangbridge/src/lsp_handlers.erl)
  • FixmeComment (apps/erlangbridge/src/lsp_formatting.erl)
  • GenericShell.splitCommandLine (cognitive 24) (lib/GenericShell.ts)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Hotspot: apps/erlangbridge/src/vscode_connection.erl (apps/erlangbridge/src/vscode_connection.erl)
  • …and 46 more

Changes since last survey

  • 14 commits — 10 feature/other, 4 fixes

By area

  • (root) — 8 commits
  • apps/erlangbridge — 5 commits
  • test/test-suite — 1 commit

Notable commits

  • fix: Fix debugger launch when erlang.useShell='auto' (#359)
  • fix: Fix semantic tokens crash on files that include a header (#350)
  • fix: Fix/open issues triage (#348)
  • fix: Users/pgo/fix issues (#354)
  • change: Exclude nested _build directories from the VSIX
  • change: OTP 27/28 compatibility (#349)
  • change: Users/pgo/mcp debugger (#360)
  • change: Users/pgo/next features analysis (#347)
  • change: Users/pgo/push only diagnostics (#357)
  • change: Version 1.2.2
  • change: Version 1.2.5
  • change: add useShell config in order to avoid '/bin/sh ENOENT' in sandbox (#353)
  • change: improve HELP.MD (#355)
  • change: update Visual Studio Marketplace badges

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

pgourlain/vscode_erlang was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 48fd9276e55a70c646c2a044213bd1686c4263a1 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.