tanguilp/wax
60.2
Adequate · 18 September 2026
3.1k
lines of production code
Elixir
primary language
1
measurement over time
What this system is
Wax is an Elixir library that implements the FIDO2 and WebAuthn protocols for server-side authentication. It provides core functionality for handling registration and authentication flows, including challenge generation, authenticator data parsing, and cryptographic verification of COSE keys. The system supports multiple attestation statement formats such as Packed, TPM, Android Key, and Apple Anonymous, while integrating with FIDO Alliance metadata services to validate authenticator trust roots.
Features
Added ASN.1 schema definitions for Android Key Attestation versions 1, 2, and 3
The \asn1\ directory now includes the ASN.1 source files for Android Key Attestation V1, V2, and V3. These definitions formalize the structure of attestation certificates, including the \AndroidKeyAttestation\ sequence, \SecurityLevel\ (adding \strongBox\ in V3), \AuthorizationList\ (expanding with device identity fields like IMEI and model in V2/V3, and vendor/boot patch levels in V3), and \RootOfTrust\ (adding \verifiedBootHash\ in V3). These files serve as the schema source for generating the corresponding code.
asn1 · high confidence
Initial configuration structure for the Wax\_ application
The application now includes a standard Elixir configuration setup with a main config file that loads environment-specific settings. New configuration files for development and test environments define the Wax\_ application's origin, RP ID, and metadata handling settings, such as allowed attestation types and update intervals.
config · high confidence
Initial release of Wax FIDO2 library
This entry introduces the Wax library, providing functions for FIDO2 registration and authentication. It supports configurable options for attestation types, origin verification, user verification, and trust root validation, along with metadata loading capabilities from the FIDO Alliance MDSv3 or local directories.
lib · high confidence
Initial release of Wax WebAuthn library
This change introduces the Wax library, an Elixir implementation of the WebAuthn protocol. It provides core data structures for parsing and verifying WebAuthn messages, including \Wax.Challenge\, \Wax.AuthenticatorData\, and \Wax.ClientData\. The library supports multiple attestation statement formats (packed, TPM, Android Key, Apple, FIDO-U2F, and none) and integrates with FIDO Alliance metadata services to validate authenticator status and trust roots. It also includes a supervision tree for managing metadata updates and handles cryptographic operations for COSE keys.
lib/wax · high confidence
Initial release of Wax WebAuthn library for Elixir
This entry introduces the Wax library, a server-side FIDO2 (WebAuthn) implementation for Elixir. The diff establishes the project's foundational configuration, including \.formatter.exs\ for code formatting, \.gitignore\ for build artifacts, and \.tool-versions\ specifying Erlang 28.3.1 and Elixir 1.19.5. It also includes \.dialyzer\_ignore.exs\ to suppress warnings related to ASN.1 and public key types, and a \CHANGELOG.md\ documenting version 0.7.0 features such as custom challenge bytes, origin list support, and the removal of deprecated SafeNet attestation. The \README.md\ provides installation instructions, usage examples for registration and authentication, and a comprehensive list of configuration options like \attestation\, \origin\, \rp\_id\, and \user\_verification\.
(repo-wide) · high confidence
New cryptographic and utility modules for FIDO2/WebAuthn validation
Added new utility modules in lib/wax/utils to support FIDO2 attestation and metadata validation. Wax.Utils.CBOR provides CBOR decoding with binary reduction, Wax.Utils.Certificate extracts certificate attributes using X509, Wax.Utils.JWS handles JWS verification with x5c chains, Wax.Utils.PKIX implements PKIX path validation logic, and Wax.Utils.Timestamp introduces a swappable timestamp adapter (including a test-time-travel mock). These changes enable support for various attestation statement formats (e.g., packed, Android SafetyNet) and metadata TOC verification as part of the v0.5.0 release.
lib/wax/utils · high confidence
Support for Android Key, Apple Anonymous, FIDO U2F, Packed, TPM, and None attestation formats
The library now implements verification logic for six additional FIDO2/WebAuthn attestation statement formats: Android Key, Apple Anonymous, FIDO U2F, Packed, TPM, and None. This allows Wax to validate authenticators using these specific attestation types, including handling Android Key ASN.1 structures, Apple certificate path validation, TPM cert info parsing, and FIDO U2F signature verification.
_lib/wax/attestation\_statement\format · high confidence
Test coverage
Added test coverage for Wax core modules; Initial test suite for WebAuthn attestation verification.
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 60.
Lenses
- Code Health 100
- Architecture 100
- Maturity 54
- Readiness 42
- Security 98
Changes since last survey
- 143 commits — 131 feature/other, 12 fixes
By area
- lib/wax — 76 commits
- (root) — 57 commits
- lib/wax.ex — 3 commits
- (repo) — 2 commits
- test/wax_test.exs — 2 commits
- .github/FUNDING.yml — 1 commit
- config/test.exs — 1 commit
- priv/android_key — 1 commit
Notable commits
- fix: Android Safetynet + bugfix
- fix: Bugfix #13 incorrect padding crashing Wax on app start
- fix: Bugfix packed attestation stmt format
- fix: Dialyzer warning suppressed or fixed
- fix: Fix erroneously deleted date in CHANGELOG
- fix: Fix some dialyzer errors
- fix: Fix warnings with Elixir 1.17 & OTP 27 (#45)
- fix: Fixed most tests
- fix: Fixed potential race cond w/ metadata update
- fix: Fixed wrong attestation size calculation
- fix: Minor bugfix
- fix: Various bugfix
- change: Add backup flags to AuthenticatorData (#30)
- change: Add new TPM manufacturers' IDs
- change: Add support for custom bytes in Wax.Challenge struct (#47)
- change: Added :android_key_allow_software_enforcement option
- change: Added PS* and EdDSA signature support
- change: Added capability to load metadata from dir
- change: Added credential id type definition
- change: Added invalid sig test cases
- …and 123 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
tanguilp/wax was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 18 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit fdcfdd8d5c638d5825c486af045ec28c6ea94d92 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-5d04157a340d.