Skip to content
CAI
Software that uses CAICheck a score

potatosalad/erlang-jose

67.8

Adequate · 23 September 2026

31.2k

lines of production code

Erlang

with Elixir

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a cryptographic library for the Erlang and Elixir ecosystems, specifically designed to implement the JSON Object Signing and Encryption (JOSE) standards. It provides comprehensive support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Tokens (JWT), enabling users to encrypt, sign, and verify data using a wide array of modern algorithms including Ed25519, ChaCha20-Poly1305, and RSA. The architecture is modular, allowing for flexible JSON backend selection and dynamic configuration of cryptographic backends, while maintaining rigorous correctness through extensive test vectors and property-based testing.

How it got here

2015 — Elixir API and cryptographic refactoring

9 changes.

This period focused on restructuring the library's internal architecture and introducing a high-level Elixir API for JSON Web standards. The work included significant internal refactoring to improve modularity, alongside the addition of comprehensive test suites and property-based tests for cryptographic algorithms.

2016–2023 — Modern cryptographic algorithm support

7 changes.

This period focused on expanding cryptographic capabilities by adding support for modern algorithms like Ed25519, Ed448, and ChaCha20-Poly1305. The codebase was updated to support multiple JSON backends and improved key agreement and wrapping mechanisms, while also refactoring internal code generation tools.

Features

Add Elixir API for JSON Web Encryption, Signature, and Tokens

The library introduces new Elixir modules for working with JSON Web standards: \JOSE.JWE\ for encryption, \JOSE.JWS\ for signatures, and \JOSE.JWT\ for tokens. These modules provide functions to encrypt, decrypt, sign, and verify data using algorithms such as AES-GCM, ChaCha20/Poly1305, Ed25519, and RSA. The \JOSE.JWE\ module supports key derivation algorithms like ECDH-ES and PBES2, while \JOSE.JWS\ supports hashing algorithms like HS256 and EdDSA. The \JOSE.JWT\ module allows for easy creation and verification of JSON Web Tokens. Additionally, the \JOSE.Poison\ module provides a lexical encoder for JSON serialization.

lib/jose · high confidence

Add support for ChaCha20-Poly1305, Ed25519/Ed448, and Curve25519/448 algorithms

The library now supports the ChaCha20-Poly1305 encryption algorithm, as well as Ed25519, Ed25519ctx, Ed25519ph, Ed448, and Ed448ph signature algorithms. Additionally, support has been added for X25519 and X448 key agreement, along with ECDH-ES and ECDH-ES+C20PKW/ECDH-ES+XC20PKW key wrapping modes. The base64 encoding/decoding modules have been refactored to remove external dependencies, and the codebase has been updated for Erlang 24/25 compatibility.

src/jwa · high confidence

Add support for multiple JSON libraries via the jose\_json interface

The library now supports multiple JSON encoding and decoding backends, including jiffy, Jason, jsone, jsx, ojson, OTP's built-in json module, Poison, and Thoas. Each backend is implemented as a separate module (e.g., jose\_json\_jiffy, jose\_json\_poison) that adheres to the jose\_json behavior, allowing users to select their preferred JSON library for serialization and deserialization.

src/json · high confidence

Expanded JWE algorithm and encryption support

Added support for new JWE key agreement and key wrapping algorithms, including C20PKW, XC20PKW, ECDH-ES+C20PKW, ECDH-ES+XC20PKW, ECDH-1PU, and ECDH-SS. The update also introduces PBES2-based key wrapping with AES-GCM, ChaCha20-Poly1305, and XChaCha20-Poly1305, alongside new encryption ciphers C20P and XC20P.

src/jwe · high confidence

Expanded support for EdDSA, X25519, and key format conversions

The library now supports generating, signing, and verifying with Ed25519, Ed25519ph, Ed448, Ed448ph, and X25519 key types, enabling the use of these modern cryptographic algorithms in JWKs. Additionally, the update introduces support for PKCS-8 and DER encoding/decoding for asymmetric keys, allowing users to convert between JWKs and DER/PEM formats. The \box\_encrypt\ and \box\_decrypt\ functions are now deprecated in favor of the new ECDH-1PU and ECDH-ES replacement functions, which provide improved key agreement capabilities.

src/jwk · high confidence

Architecture

Major internal refactoring of the JOSE library architecture

The library's internal structure has been significantly reorganized to improve maintainability and compatibility. The monolithic \jose\_jwa\ module and various key-type specific modules (such as \jose\_jwk\, \jose\_jwk\_kty\, and \jose\_jwe\alg\\*\) have been removed or restructured. New modules like \jose\_crypto\_compat\ and \jose\_server\ have been introduced to handle cryptographic operations, configuration, and fallback logic, providing a more modular and robust foundation for cryptographic algorithms.

src · high confidence

Behavioural changes

Add .dialyzer\_ignore configuration and update build tooling

The project now includes a .dialyzer\_ignore.exs file that suppresses a range of Dialyzer warnings (such as :unknown\_type, :invalid\_contract, and :pattern\_match\_cov) across the codebase, effectively silencing type-checking errors for modules like jose\_jwa, jose\_jwe, jose\_jwk, and jose\_jws. Additionally, the Makefile has been updated to include Travis CI-related commands and a Dockerfile, and the .gitignore file has been expanded to exclude more build artifacts and IDE files.

(repo-wide) · high confidence

Add support for Poison 4.x via new LexicalEncoder

The library now supports Poison 4.x by introducing a new \JOSE.Poison.LexicalEncoder\ module, which handles JSON encoding with options for escaping, pretty-printing, and indentation. This replaces the previous encoding mechanism, ensuring compatibility with newer versions of the Poison library.

lib/jose/poison · high confidence

Added empty file to preserve priv directory

An empty .keep file was added to the priv directory. This ensures the directory is preserved in version control, which is often necessary in certain build systems or deployment processes to maintain directory structure.

priv · low confidence

Centralized configuration API for cryptographic modules

The \lib/jose.ex\ file introduces a centralized API for configuring and inspecting the state of various cryptographic and encoding modules, including ChaCha20/Poly1305, Curve25519, Curve448, SHA3, and JSON encoders/decoders. This allows users to dynamically switch between different backend implementations (e.g., \libsodium\, \crypto\, or fallback modules) and adjust security settings like \crypto\_fallback\ and \unsecured\_signing\ directly from the main \JOSE\ module.

lib · high confidence

Refactor codegen to use a shared base module

The codegen scripts and templates have been restructured to use a shared \jose\_base\ module for common logic, removing the previous dependency on the \parse\_transform\ callback for \jose\_base64\ and \jose\_base64url\. This change introduces \jose\_base.erl\ as a central component for code generation, streamlining the build process and reducing duplication in the codegen tooling.

codegen · medium confidence

Restructure JOSE headers and update JWS record

The library's header files have been reorganized: new include files \jose\_base.hrl\ and \jose\_compat.hrl\ are introduced, while \jose\_jwt.hrl\ is created from the previous \jose\_jwe\_alg.erl\ source file. The \jose.hrl\ header is updated to include the new JWT header. Additionally, the \jose\_jwk.hrl\ record is modified to change the \keys\ field type from a list to a module/any tuple, and the \jose\_jws.hrl\ record is updated to include a \b64\ boolean field.

include · high confidence

Test coverage

Add comprehensive test suite for cryptographic algorithms and test vectors; Added JWE and JWS test data for cryptographic algorithms; Expanded property-based test coverage for JOSE cryptographic algorithms.

Dependencies

Update Elixir and dependency versions for JOSE

The project now requires Elixir 1.13+ and updates its test dependencies to specific versions: Jason 1.4, Jsone 1.9, JSX 3.1, libdecaf 2.1.1, libsodium 2.0.1, ojson 1.0, Thoas 1.2, and Poison 3–6. Development tools ex\_doc, earmark, and dialyxir are also updated to their latest compatible versions.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 57 → 68 (+10.3)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 95 → 91 (-3.7)
  • Architecture 100 → 100 (+0.0)
  • Maturity 49 → 53 (+4.0)
  • Readiness 43 → 65 (+21.3)
  • Security 79 → 98 (+18.2)
  • Event Sourcing 100 → 100 (+0.0)

Resolved (23)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • FileTooLong: jwa/jose_jwa_aes.erl (src/jwa/jose_jwa_aes.erl)
  • Further sole-owners (lower concentration)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Leaked secret: jwt (lib/jose/jwe.ex)
  • Leaked secret: jwt (lib/jose/jwk.ex)
  • Leaked secret: jwt (lib/jose/jwt.ex)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • Test reliability not included
  • TooManyMethods: jose_jwa_pkcs1 (src/jwa/jose_jwa_pkcs1.erl)
  • TooManyMethods: jose_jwk (src/jwk/jose_jwk.erl)
  • …and 3 more

New (135)

  • Coverage not measured — no coverage collector is wired up
  • Duplicated block (10 lines × 2) (codegen/jose_base64.erl)
  • Duplicated block (10 lines × 2) (codegen/jose_base64url.erl)
  • Duplicated block (10 lines × 2) (src/jose_server.erl)
  • Duplicated block (10 lines × 2) (src/jwa/jose_jwa_ed25519.erl)
  • Duplicated block (10 lines × 2) (src/jwe/jose_jwe_alg_c20p_kw.erl)
  • Duplicated block (10 lines × 3) (src/jwa/jose_jwa_concat_kdf.erl)
  • Duplicated block (10 lines × 3) (src/jwa/jose_jwa_curve25519.erl)
  • Duplicated block (10 lines × 3) (src/jws/jose_jws.erl)
  • Duplicated block (10 lines × 4) (codegen/jose_base64.erl)
  • Duplicated block (10–11 lines × 2) (src/jwe/jose_jwe.erl)
  • Duplicated block (11 lines × 2) (src/jwa/chacha20_poly1305/jose_chacha20_poly1305_unsupported.erl)
  • Duplicated block (12 lines × 2) (codegen/jose_base64.erl)
  • Duplicated block (12 lines × 2) (codegen/jose_base64url.erl)
  • Duplicated block (12 lines × 2) (src/jwe/jose_jwe_alg_ecdh_1pu.erl)
  • Duplicated block (12 lines × 2) (src/jwe/jose_jwe_alg_ecdh_1pu.erl)
  • Duplicated block (12 lines × 3) (src/jose_public_key.erl)
  • Duplicated block (13 lines × 2) (src/jose_public_key.erl)
  • Duplicated block (13 lines × 2) (src/jwk/jose_jwk_kty_rsa.erl)
  • Duplicated block (13 lines × 2) (src/jwk/jose_jwk_kty_rsa.erl)
  • …and 115 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

potatosalad/erlang-jose was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit c8b669c86d73300d2af377c7c0f08b4df06fedbe — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.