Skip to content
CAI
Software that uses CAICheck a score

PSPDFKit-labs/bypass

62.3

Adequate · 23 September 2026

792

lines of production code

Elixir

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a testing utility library for Elixir that allows developers to mock HTTP servers for unit and integration tests. It manages the lifecycle of mock HTTP endpoints, supporting features like temporary server shutdown, concurrent request handling, and compatibility with both ExUnit and ESpec test frameworks. The implementation has been modernized to use GenServer-based instance management and dynamic supervision, replacing older agent and supervisor patterns.

Behavioural changes

Refactor Bypass to use DynamicSupervisor and add up/down controls

The Bypass library has been refactored to use a DynamicSupervisor for managing instances, replacing the previous supervisor strategy. This change introduces Bypass.up/1 and Bypass.down/1 functions, allowing users to temporarily take down and re-open the HTTP server. Additionally, the library now supports ESpec alongside ExUnit for test framework integration, and provides more specific error messages when unexpected HTTP requests occur or expectations are not met.

lib · high confidence

Refactored Bypass architecture to use GenServer-based instance management and dynamic supervision

The Bypass library has been refactored to replace the previous Agent-based state management with a GenServer-driven architecture (Bypass.Instance) that manages HTTP server lifecycle, route expectations, and concurrent request handling. This change introduces support for temporary server shutdown (Bypass.down/up), configurable listen interfaces, and improved error handling for HTTP requests. The application supervisor now uses DynamicSupervisor instead of the deprecated Supervisor.Spec, and the plug implementation has been updated to interact with the new instance model, enabling more robust testing of HTTP endpoints with features like exact request counting and PATCH method support.

lib/bypass · high confidence

Updated Elixir configuration syntax and logging setup

The configuration file was migrated from the deprecated Mix.Config module to the modern Config module, reflecting Elixir 1.16+ standards. Additionally, the default logging configuration was updated to include the process ID in console output, and the Bypass application was explicitly configured to use ExUnit as the test framework.

config · high confidence

Updated documentation and project metadata

The project's README was significantly expanded to include usage examples, configuration options, and integration with ESpec, while also adding a .formatter.exs for code formatting, a CHANGELOG.md for version history, and an updated LICENSE file with the current year.

(repo-wide) · high confidence

Test coverage

Added tests for Bypass lifecycle and concurrency

Added tests for Bypass lifecycle and concurrency, including verifying that Bypass.down waits for the plug to terminate, handling concurrent requests, and testing closing a bypass while a request is in-flight.

test · high confidence

Dependencies

Upgrade to Plug 1.7+ and replace Cowboy with Plug.Cowboy

The project now requires Elixir 1.7+ and upgrades the HTTP server dependency from the direct Cowboy 1.0 to the Plug.Cowboy 2.0 adapter, which bundles the latest compatible versions of Cowboy and Plug. This change also updates the Ranch dependency to 1.7.1 and introduces new dev/test dependencies including ESpec, Dialyxir, and Mint, while removing the older Gun dependency.

(dependencies) · medium confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 57 → 62 (+5.2)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (+0.0)
  • Architecture 69 → 69 (+0.0)
  • Maturity 50 → 50 (+0.0)
  • Readiness 50 → 66 (+16.8)
  • Security 80 → 90 (+9.9)

Resolved (13)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • Test reliability not included
  • The README does not mention the supported Erlang OTP versions or how to set up Elixir 1.10. (README.md)
  • dormant codebase — no living knowledge left to concentrate

New (17)

  • Documentation: no installation or build instructions (README.md)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No dependency advisory monitoring
  • Outdated: dialyxir
  • Outdated: espec
  • Outdated: ex_doc
  • Outdated: mint
  • Outdated: plug
  • Outdated: plug_cowboy

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

PSPDFKit-labs/bypass was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 0a47472667340ed7d3b1250751408c44c6f9a7d7 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.