Skip to content
CAI
Software that uses CAICheck a score

actix/actix-web

74.7

Strong · 27 September 2026

63.8k

lines of production code

Rust

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the Actix Web ecosystem, a modular Rust framework for building high-performance HTTP servers and clients. It provides core capabilities for handling HTTP/1.1 and HTTP/2 protocols, including streaming compression, WebSocket communication, and multipart form parsing. The framework supports declarative route definition, typed request extraction, and comprehensive integration testing utilities for validating application behavior.

How it got here

2017–2019 — Workspace restructuring and protocol modernization

24 changes.

The project reorganized into a multi-crate workspace with standardized tooling and dependency locking, while modernizing core HTTP/1.1, HTTP/2, and WebSocket implementations for better modularity and performance. New features included typed form extraction, streaming compression, and declarative route macros, alongside significant API refinements and security hardening across the ecosystem.

2020–2021 — Testing infrastructure and modular refactoring

17 changes.

This period focused on establishing robust integration testing capabilities through the introduction of the actix-test and actix-http-test crates, alongside comprehensive macro validation. Concurrently, the codebase underwent significant structural refactoring, modularizing HTTP request and response handling in actix-http and restructuring the awc client with a new middleware system and Rustls 23 support.

2022–2026 — API expansion and typed abstractions

19 changes.

This period focused on expanding the framework's API surface with comprehensive typed abstractions for HTTP headers, multipart forms, and request extractors. It introduced significant middleware enhancements, including route introspection and flexible error handling, while establishing robust testing and benchmarking infrastructure to support these new features.

Features

Add TLS-enabled HTTP client example

A new example file demonstrates how to construct and use a TLS-capable HTTP client using the awc library. It shows configuring rustls with platform verification, setting ALPN protocols for HTTP/2 and HTTP/1.1, and making a GET request to https://www.rust-lang.org/.

awc/examples · high confidence

Add streaming content-encoding compression and decompression

The \actix-http/src/encoding\ module now provides built-in support for compressing and decompressing HTTP response and request bodies using gzip, deflate, brotli, and zstd. This change introduces \Encoder\ and \Decoder\ types that handle streaming data, offloading heavy compression tasks to a thread pool when chunks exceed 1024 bytes (encoding) or 2048 bytes (decoding) to prevent blocking the async runtime. The implementation respects feature flags (e.g., \compress-gzip\, \compress-brotli\, \compress-zstd\) to include only the selected algorithms, and automatically skips compression for empty bodies, 204/206 status codes, or when the \Content-Encoding\ header is already present.

actix-http/src/encoding · high confidence

Add typed multipart form field extractors

The \actix-multipart/src/form\ module now provides typed field readers that allow users to extract multipart form fields directly into strongly-typed Rust structs. This includes \Bytes\ for raw binary data, \Json\<T\>\ for deserializing JSON payloads, \Text\<T\>\ for plain text with UTF-8 and serde validation, and \TempFile\ for streaming file uploads to temporary disk storage. These types implement the \FieldReader\ trait and integrate with the \MultipartForm\ derive macro, enabling automatic parsing, content-type validation, and limit enforcement for each field type.

actix-multipart/src/form · high confidence

Added multipart form upload example with configurable size limits

A new example file (form.rs) demonstrates how to handle multipart form uploads in an Actix Web application, including parsing JSON metadata and temporary files. The example configures a 100MB total limit for the multipart form data using MultipartFormConfig to prevent excessive resource consumption during uploads.

actix-multipart/examples · high confidence

Initial release of actix-web-codegen macros

This change introduces the \actix-web-codegen\ crate, providing procedural macros for defining HTTP route handlers and application scopes. Users can now use attributes like \\#\[get\]\, \\#\[post\]\, \\#\[route\]\, and \\#\[routes\]\ to declaratively register handlers with path patterns, HTTP method guards, and middleware. The crate also includes a \\#\[scope\]\ macro to prefix paths within a module and a \\#\[main\]\ macro to bootstrap the Actix async runtime.

actix-web-codegen/src · high confidence

Initial support for route and HTTP method introspection

Actix Web now includes an experimental \experimental-introspection\ feature that allows applications to inspect their configured routes, HTTP methods, and guards at runtime. This feature adds an \IntrospectionCollector\ to the application builder and service configuration, collecting metadata about registered services, scopes, and resources. The collected data is exposed as a serializable report containing route paths, method guards, guard details, and reachability hints, which is useful for debugging routing issues or generating documentation, though it is intended for local or non-production use.

actix-web/src · high confidence

Introduce actix-http-test crate for integration testing

The \actix-http-test\ crate is introduced to provide helpers for writing integration tests for Actix applications. It exposes a \test\_server\ function that starts an HTTP server in a separate thread and returns a \TestServer\ controller. This controller allows users to construct URLs and send HTTP requests (GET, POST, HEAD) via an internal \awc::Client\, supporting both plain HTTP and HTTPS (when the \openssl\ feature is enabled).

actix-http-test/src · high confidence

Introduce typed HTTP header types for charset, content encoding, and quality values

This change adds new typed structs and enums to the \actix-http\ header module to provide safer, more ergonomic handling of common HTTP header components. Users can now work with strongly-typed \Charset\ values (supporting standard encodings like UTF-8, ISO-8859-1, and Big5), \ContentEncoding\ (including support for zstd, brotli, gzip, and deflate), and \Quality\/\QualityItem\ for parsing and formatting q-factor values in headers like Accept-Encoding. It also introduces \HttpDate\ for standardized HTTP date formatting and \ExtendedValue\ for parsing RFC 5987 extended header parameters, replacing previous ad-hoc string parsing with validated, reusable types.

actix-http/src/header/shared · high confidence

Introduce typed multipart form extractor via derive macro

Adds the \MultipartForm\ derive macro in \actix-multipart-derive\, enabling users to define structs that automatically implement \MultipartCollect\ for extracting typed multipart form data in Actix Web. The macro supports field-level configuration via \\#\[multipart\]\ attributes, including renaming fields (\rename\), setting size limits (\limit\ using the \bytesize\ crate), and controlling behavior for duplicate or unknown fields (\duplicate\_field\ and \deny\_unknown\_fields\).

actix-multipart-derive/src · high confidence

New Acceptable guard and Host guard refactoring

Actix Web introduces a new \Acceptable\ guard that allows routes to be matched based on the request's \Accept\ header, enabling content-negotiation at the routing level with optional support for wildcard MIME types. Additionally, the existing \Host\ guard has been refactored into its own module and updated to ignore the \Host\ header for HTTP/2 requests, falling back to the request URI's host instead, which aligns with HTTP/2 specifications where the Host header is not used.

actix-web/src/guard · high confidence

New JSON body parsing and response handling in awc

The \awc\ client now includes a \JsonBody\ type that allows users to consume HTTP response bodies as deserialized JSON objects. This new capability checks the \Content-Type\ header for \application/json\ and parses the payload using \serde\, respecting a configurable size limit (defaulting to 2 MiB) and optional timeouts. The change also introduces a \ResponseBody\ type for reading raw bytes, deprecating the previous \MessageBody\ alias, and restructures the response handling logic into dedicated modules for body reading and JSON parsing.

awc/src/responses · high confidence

New WebSocket builder and HTTP streaming context

The \actix-web-actors\ crate now includes a \WsResponseBuilder\ that allows configuring WebSocket sessions with specific protocols and maximum frame sizes, and introduces an \HttpContext\ struct to support streaming HTTP responses (such as Server-Sent Events) via actors.

actix-web-actors/src · high confidence

New actix-test crate for integration testing

The \actix-test\ crate is introduced to provide integration testing tools for Actix Web applications. It exposes a \TestServer\ that spawns a real HTTP server on an unused port, allowing tests to interact with the application via a real HTTP client rather than in-memory service initialization. The crate re-exports key testing utilities from \actix\_web::test\ (such as \TestRequest\, \call\_service\, and \status\_service\) and \awc\ (such as \Client\ and \Connector\), while also providing configuration options for the test server including TLS support (via OpenSSL and multiple Rustls versions), HTTP version selection (HTTP/1 and HTTP/2), worker count, and client request timeouts.

actix-test/src · high confidence

New client middleware system with redirect handling

The awc client now supports a middleware architecture, allowing users to compose custom request transformations. This release introduces a built-in \Redirect\ middleware that automatically follows HTTP redirects (3xx status codes) up to a configurable limit (default 10), reusing connection state and handling body/method adjustments according to standard redirect rules. The underlying \Transform\ trait and \NestTransform\ helper enable chaining multiple middleware components for advanced client behavior.

awc/src/middleware · high confidence

New examples for from\_fn middleware, route introspection, and connection handling

The examples directory now includes standalone samples demonstrating several capabilities: \from\_fn.rs\ and \middleware\_from\_fn.rs\ show how to create and use the new \from\_fn\ middleware for request processing; \introspection.rs\ and \introspection\_multi\_servers.rs\ showcase the experimental route and HTTP method introspection feature (enabled via the \experimental-introspection\ feature flag), allowing users to inspect and report on registered routes and external resources; \on-connect.rs\ demonstrates using \HttpServer::on\_connect\ to access low-level socket properties like client address and TTL; \basic.rs\ and \macroless.rs\ provide standard and macro-free server setup patterns; \uds.rs\ shows binding to Unix domain sockets; and \worker-cpu-pin.rs\ illustrates pinning workers to specific CPU cores.

actix-web/examples · high confidence

New middleware utilities and expanded documentation

The middleware module now includes a \Compat\ wrapper to allow middleware with incompatible body types to be used on scopes and resources, a \from\_fn\ helper to create middleware from simple async functions, and an \Identity\ no-op middleware. The \Condition\ middleware is now generic over body types, and the \ErrorHandlers\ middleware supports setting default handlers for all client or server errors. Additionally, the \Logger\ middleware now supports configurable log levels and custom request/response replacements, and a comprehensive Middleware Author's Guide has been added.

actix-web/src/middleware · high confidence

New release and CI maintenance scripts

Added four new shell scripts to the \scripts/\ directory: \bump\ automates version updates for Cargo crates by updating \Cargo.toml\, \README.md\, and changelog files (supporting both \CHANGELOG.md\ and \CHANGES.md\), and can optionally update cross-crate dependencies and create GitHub release drafts; \unreleased\ displays pending changelog entries for all crates; \publish\ streamlines the multi-crate publishing process with dry-run checks and handling for cyclic dev-dependencies; and \free-disk-space.sh\ cleans up large packages and directories on CI runners to prevent build failures due to disk space exhaustion.

scripts · high confidence

New response customization and status code builder APIs

Actix-web introduces a \.customize()\ method on the \Responder\ trait, allowing handlers to override the status code and headers (including cookies via \add\_cookie\) of any response type without manually constructing an \HttpResponse\. Additionally, \HttpResponse\ now provides static constructor methods for all standard HTTP status codes (e.g., \HttpResponse::Ok()\, \HttpResponse::NotFound()\), simplifying response creation. The \HttpResponseBuilder\ also gains a \no\_chunking\ method to disable chunked transfer encoding for streaming responses when the content length is known.

actix-web/src/response · high confidence

New typed HTTP header implementations and refactored parsing logic

This change introduces a comprehensive set of new, strongly-typed structs for HTTP headers in the \actix-web/src/http/header\ module, including \Accept\, \AcceptCharset\, \AcceptEncoding\, \AcceptLanguage\, \Allow\, \CacheControl\, \ContentDisposition\, \ContentLanguage\, \ContentLength\, \ContentRange\, and \ContentType\. These types replace or supplement previous string-based handling, providing dedicated parsing, formatting, and convenience methods (such as \Accept::preference()\ for q-factor weighting and \AcceptEncoding::negotiate()\ for content-coding selection). The update also includes a new \AnyOrSome\ wrapper to handle wildcard values in headers like \AcceptLanguage\ and adds a \ContentDisposition::attachment\ constructor. Additionally, the \ContentLength\ header has been modernized to use \derive\_more\ for deref traits, and the \ContentDisposition\ parser now supports a \unicode\ feature flag to switch between \regex\ and \regex-lite\ for improved binary size trade-offs.

actix-web/src/http/header · high confidence

New typed extractors and responders for headers, HTML, and flexible payloads

Actix Web introduces several new request extractors and response responders to simplify common patterns. The new \Header\ extractor allows typed extraction of HTTP headers (e.g., \web::Header\<header::ContentType\>\), while the \Html\ responder provides a semantic way to return HTML content with the correct \text/html\ content type. The \Either\ type enables polymorphic extraction, allowing handlers to accept multiple payload formats (such as JSON or URL-encoded forms) by trying one extractor and falling back to another. Additionally, the \Readlines\ extractor streams request bodies line-by-line, and the \Path\ extractor now supports deserializing path segments into sequences (e.g., \Vec\<String\>\) for multi-component matches like tail routes.

actix-web/src/types · high confidence

actix-multipart v0.7.0: Complete rewrite with typed form extraction and testing utilities

The actix-multipart crate has been rewritten for version 0.7.0, introducing a new \MultipartForm\ extractor and derive macro that allows users to define typed structs (using Serde) to automatically parse multipart/form-data requests into structured data. The core \Multipart\ stream extractor now supports \multipart/related\ and \multipart/mixed\ in addition to \form-data\, while explicitly removing support for nested multipart streams. A new \Field::bytes()\ method enables collecting field data with configurable size limits, and a \test\ module provides utilities like \create\_form\_data\_payload\_and\_headers\ to simplify writing tests for multipart endpoints. The error model has been expanded to include specific variants for missing content types, boundaries, and duplicate/missing fields, and the \MultipartConfig\ no longer implements \Copy\.

actix-multipart/src · high confidence

awc 3.9.0 release: WebSocket camel-case headers and hickory-resolver update

The awc HTTP and WebSocket client library has been updated to version 3.9.0. This release adds camel-case header controls to \WebsocketsRequest\ via the new \camel\_case\_headers()\ and \set\_camel\_case\_headers()\ methods, allowing users to manage header formatting for WebSocket connections. Additionally, the \hickory-resolver\ dependency has been updated to version 0.26.

awc · high confidence

Architecture

HTTP/1.1 protocol implementation refactored into modular components

The HTTP/1.1 protocol handling in \actix-http\ has been restructured from a monolithic dispatcher into a set of specialized, modular components. The new architecture introduces dedicated modules for chunked transfer encoding (\chunked.rs\), message encoding (\encoder.rs\), and message decoding (\decoder.rs\), alongside separate codec implementations for server (\codec.rs\) and client (\client.rs\) roles. The core \dispatcher.rs\ now orchestrates these parts, managing connection state, keep-alive logic, and graceful shutdowns, while \service.rs\ provides the high-level \H1Service\ factory for wiring the dispatcher with application handlers. This change improves code maintainability and separation of concerns without altering the external HTTP/1.1 behavior.

actix-http/src/h1 · high confidence

Repository restructured with new tooling and configuration files

The repository has been reorganized to support a multi-crate workspace structure. A new justfile has been added to standardize build, test, and documentation commands across the workspace, including MSRV checks and feature combination validation. Several configuration files have been introduced: .clippy.toml to enforce coding standards (e.g., disallowing 'e' bindings), .rustfmt.toml for import grouping, .taplo.toml for TOML formatting, .codecov.yml for coverage thresholds, .cspell.yml for spell checking, and zizmor.yml for GitHub Actions security hardening. The root README.md has been converted into a symlink, and a new CODE\_OF\_CONDUCT.md and CHANGES.md (redirecting to crate-specific changelogs) have been added. The license file was renamed to LICENSE-APACHE, and a separate LICENSE-MIT file was created.

(repo-wide) · high confidence

Behavioural changes

Awc HTTP client library restructured with new builder and body abstractions

The awc crate has been reorganized into a new modular structure, introducing a dedicated \ClientBuilder\ for configuring HTTP clients (including timeouts, redirects, and HTTP/2 window sizes) and a \FrozenClientRequest\ type to enable cloning and retrying prepared requests. A new \AnyBody\ enum standardizes how various HTTP message body types are handled internally, while the \connect\ module now explicitly manages combined HTTP and WebSocket connection logic via \ConnectRequest\ and \ConnectResponse\ types. The public API surface has been refined with new error types like \WsClientError\ and \JsonPayloadError\, and the library now exports a \ws\ sub-module for WebSocket-specific types and functionality.

awc/src · high confidence

Awc client rewritten with modular connection handling and Rustls 0.23 support

The awc HTTP client has been restructured into a modular architecture under \awc/src/client\, introducing dedicated modules for configuration, connection management, protocol handling (HTTP/1 and HTTP/2), and connection pooling. This refactor brings native support for Rustls v0.23 (via \rustls-0\_23\ and \rustls-0\_23-native-roots\ features) alongside existing TLS backends, while also refining connection lifecycle management to better handle HTTP/2 GO\_AWAY signals and prevent panics during pool drops. Users benefit from improved stability, clearer error types, and updated TLS capabilities without changing the public API surface.

awc/src/client · high confidence

HTTP service configuration and builder restructured

The \actix-http\ crate introduces a new \HttpServiceBuilder\ and \ServiceConfig\ API for configuring HTTP services, replacing previous patterns. Users can now explicitly set connection keep-alive timeouts, client request and disconnect timeouts, \TCP\_NODELAY\ settings, and HTTP/1 half-close behavior. The builder also exposes configuration for HTTP/2 flow control window sizes (both connection and stream levels) and HTTP/1 write buffer sizes. Additionally, a \Protocol\ enum is added to distinguish between HTTP/1, HTTP/2, and HTTP/3 variants, and the \Extensions\ type gains \get\_or\_insert\ and \get\_or\_insert\_with\ methods for more ergonomic insertion of request-local data.

actix-http/src · high confidence

HTTP/2 implementation refactored with keep-alive and configurable window sizes

The HTTP/2 protocol handling in \actix-http\ has been restructured to support connection keep-alive via ping-pong frames and expose configuration for HTTP/2 flow-control window sizes. The new dispatcher logic manages idle connections by sending periodic pings and resetting timers based on a configurable deadline, ensuring connections remain open when active. Additionally, the handshake process now allows setting initial stream and connection window sizes via \ServiceConfig\, giving users control over backpressure and throughput for HTTP/2 streams.

actix-http/src/h2 · high confidence

New error handling API with response mappers and standardized error types

Actix Web introduces a new \Error\ type that supports adding response mappers, allowing users to modify the HTTP response generated for an error (e.g., adding headers) without discarding the original error details. The \ResponseError\ trait is now the central abstraction for errors that can be converted to HTTP responses, with implementations for standard library errors, \Infallible\, and various payload errors. Helper functions like \ErrorBadRequest\ and \ErrorInternalServerError\ are provided to wrap errors with specific status codes. The module also includes \InternalError\ for wrapping arbitrary errors with custom status codes or responses, and \UrlencodedError\ and \JsonPayloadError\ for handling payload parsing issues with appropriate status codes.

actix-web/src/error · high confidence

New modular body types and streaming utilities

The body module has been restructured into distinct components, introducing \BodyStream\ and \SizedStream\ to wrap asynchronous streams as HTTP bodies, with \SizedStream\ allowing explicit size hints to avoid chunked transfer encoding. A new \EitherBody\ type simplifies middleware composition by allowing conditional return of inner service bodies or error responses. The \BoxBody\ type now provides a unified, boxed representation of message bodies with erased error types, and the \MessageBody\ trait is standardized with an associated \Error\ type. Additionally, \to\_bytes\_limited\ is added to safely collect body bytes with a configurable memory limit, returning a \BodyLimitExceeded\ error if the threshold is breached.

actix-http/src/body · high confidence

Opt-in synchronous file reads for smaller files

The static file serving service now supports an opt-in threshold that allows small files to be read synchronously, bypassing the async blocking thread pool. This change introduces a \read\_mode\_threshold\ configuration option on both the \Files\ service and \NamedFile\; files smaller than this threshold are read directly on the current thread, while larger files continue to use the async \web::block\ approach. This provides a performance optimization for small assets by reducing context-switching overhead.

actix-files/src · high confidence

Refactored HTTP response handling with dedicated builder and head modules

The response subsystem has been restructured into separate modules (\builder.rs\, \head.rs\, \response.rs\) to improve code organization. This change introduces a \ResponseBuilder\ for constructing responses via a fluent API, extracts the \ResponseHead\ structure into its own file with a thread-local object pool for performance, and exposes these components publicly. Users can now build responses using \Response::build()\ and manipulate headers and status codes through the new builder pattern, while the underlying head management is optimized via pooling.

actix-http/src/responses · high confidence

Refreshed actix-http examples with Rustls 0.23 and modern service APIs

The example suite in actix-http has been updated to demonstrate current best practices. TLS examples (tls\_rustls.rs, ws.rs) now use Rustls 0.23 via the rustls\_0\_23 crate, and the WebSocket example supports both TCP and TLS bindings. A new h2c-detect.rs example shows automatic HTTP/2 cleartext upgrade using tcp\_auto\_h2c(). All examples have migrated to the HttpService builder API (e.g., .finish(), .h1(), .h2()) and use tracing for logging, replacing older patterns like direct body construction or manual timeout configuration.

actix-http/examples · high confidence

Restructure HTTP request handling with dedicated head module

The request handling code in actix-http has been reorganized to improve modularity. A new \head.rs\ module now encapsulates the \RequestHead\ struct and its associated logic, including header management, connection type flags, and peer address storage. The main \Request\ struct in \request.rs\ has been updated to use this new head structure, exposing methods to access the request URI, method, version, and headers through the head component. This change separates the request metadata from the payload handling, providing a cleaner internal structure for building HTTP requests.

actix-http/src/requests · high confidence

Reworked header module with new traits and constants

The header module has been restructured to introduce new conversion traits (\TryIntoHeaderValue\, \TryIntoHeaderPair\) and a sealed \AsHeaderName\ trait for more flexible header handling. The internal \HeaderMap\ implementation has been updated to use \foldhash\ instead of \ahash\ for improved performance. Additionally, several new header name constants have been added, including \CACHE\_STATUS\, \CDN\_CACHE\_CONTROL\, \CLEAR\_SITE\_DATA\, and various cross-origin policy headers.

actix-http/src/header · high confidence

WebSocket implementation refactored into modular components

The WebSocket module in \actix-http\ has been restructured into distinct files (\codec.rs\, \dispatcher.rs\, \frame.rs\, \mask.rs\, \proto.rs\) to improve code organization and maintainability. This change introduces a dedicated \Codec\ for encoding/decoding WebSocket frames, a \Dispatcher\ for handling the async I/O loop between the transport and the application service, and a \Parser\ for frame validation. Key behavioral updates include stricter validation of WebSocket frames (e.g., rejecting non-zero reserved bits, validating close frame payloads, and enforcing masking rules), support for continuation frames, and the addition of a \Nop\ message type for low-level services. The public API exposes these components via \mod.rs\, allowing users to interact with WebSocket sessions through the new \Dispatcher\ and \Codec\ abstractions.

actix-http/src/ws · high confidence

actix-files 0.7.0 release notes and license updates

The \actix-files\ crate has reached version 0.7.0, introducing several breaking and new features: the experimental \io-uring\ support (including \NamedFile::open\_async\) has been removed, while new capabilities include passing multiple root directories to \Files::new\ and serving pre-compressed static files via \Files::try\_compressed()\. This release also fixes several behavioral issues, such as panics when handling hidden files with dot segments or pre-epoch modification times, incorrect \Content-Encoding\ headers in range responses, and improper handling of \Range: bytes=0-\. Additionally, license files (Apache-2.0 and MIT) have been added as symlinks, and the README has been updated to reflect the current version and MSRV requirements.

actix-files · high confidence

actix-http 3.18.12 release notes

The actix-http crate has been updated to version 3.18.12. This release includes a fix to flush compressed response bodies when the source is pending, ensuring that data is sent to the client promptly even if the underlying data source is temporarily blocked. The changelog also documents previous fixes in versions 3.18.11 through 3.13.1, covering security improvements for HTTP/1 request smuggling, WebSocket frame validation, and various connection handling and header encoding behaviors.

actix-http · high confidence

actix-multipart 0.8.0 introduces buffering limits and new form extraction features

The actix-multipart crate has been updated to version 0.8.0, introducing a 64KB buffer cap for multipart parsing to prevent unbounded memory growth on malformed bodies (configurable via \MultipartConfig::buffer\_limit\) and fixing user-triggerable panics during boundary parsing. New capabilities include multi-field multipart payload builders in the \test\ module for easier testing, support for \Option\<Vec\<T\>\>\ fields in \MultipartForm\ typed extractors, and a new \Field::bytes()\ method. The minimum supported Rust version (MSRV) has been raised to 1.88, and the \rand\ dependency has been updated to version 0.10.

actix-multipart · high confidence

actix-router 0.5.4 release notes and documentation

This change introduces the changelog, license symlinks, and README for the actix-router crate, documenting the 0.5.4 release. The release notes highlight that the minimum supported Rust version (MSRV) has been raised to 1.88, the PathDeserializer now supports deserialize\_any to enable derived untagged enums in path segments, and a fix prevents out-of-bounds access during extraction by correcting stale path segment indices after path rewrites. The entry also covers the unreleased feature allowing multi-component path parameters to be extracted into sequences.

actix-router · high confidence

actix-router v0.6.0 introduces path deserialization and regex feature flags

This release of the actix-router library introduces a new \PathDeserializer\ (in \de.rs\) that allows routing parameters to be deserialized directly into Rust structs using Serde, supporting maps, tuples, and enums. It also adds a \unicode\ crate feature that lets users choose between the full-featured \regex\ crate and the smaller \regex-lite\ crate to trade off Unicode support for binary size. Additionally, the \Path::path\ method is deprecated in favor of \as\_str()\ and \unprocessed()\, and the \Quoter::requote\ method now returns a \Vec\<u8\>\ instead of an \Option\<Vec\<u8\>\>\ to improve performance.

actix-router/src · high confidence

actix-test 0.1.5 release with TestServer configuration and MSRV update

The actix-test crate has been updated to version 0.1.5, raising the Minimum Supported Rust Version (MSRV) to 1.88. This release introduces the \TestServerConfig::listen\_address()\ method, allowing users to configure the address on which the test server listens. The changelog also documents previous updates including Rustls v0.21, v0.22, and v0.23 support, redirect disabling, and various re-exports from awc and actix\_http.

actix-test · high confidence

actix-web 4.15.0 release and changelog documentation

This change introduces the actix-web 4.15.0 release, adding the \Error::add\_response\_mapper()\ method to allow middleware to modify error-generated responses before they are sent, and removing the experimental \experimental-io-uring\ crate feature. The release also includes a comprehensive changelog (\CHANGES.md\) documenting the history of the library from version 0.7.15 through 4.15.0, alongside updated migration guides for versions 0.x, 1.0, 2.0, 3.0, and 4.0, and a new README highlighting the latest features and MSRV requirements.

actix-web · high confidence

actix-web-actors is deprecated with MSRV bump to 1.88

The actix-web-actors crate is now marked as deprecated, and users are advised to migrate to the actix-ws crate. This release also updates the Minimum Supported Rust Version (MSRV) to 1.88.

actix-web-actors · high confidence

Test coverage

Added HTTP date formatting and response body compression benchmarks; Added benchmark suite for responder, server, and service performance; Added benchmarking suite for router and quoter performance; Added comprehensive integration tests for the AWC HTTP client; Added integration and compile-time tests for route, scope, and trybuild macros; Added integration tests for HTTP/1.1, HTTP/2, TLS, and WebSocket protocols; Added integration tests for WebSocket response builder; Added test coverage for compression, introspection, and server lifecycle; Added tests for file serving edge cases and security; Added tests for multipart boundary handling and derive macro compilation; Added trybuild tests for route, scope, and routes macros; New internal test helpers for HTTP testing; New test utilities module for actix-web.

Dependencies

Initial dependency lock and manifest setup for Actix Web workspace

The project now includes a generated \Cargo.lock\ file and updated \Cargo.toml\ manifests for the Actix Web workspace, establishing a pinned dependency graph for core crates such as \actix-http\ (3.18.12), \actix-files\ (0.7.0), \actix-multipart\ (0.8.5), and \awc\ (3.x). This change ensures reproducible builds by locking all transitive dependencies to specific versions and checksums, replacing any previous state where dependencies might have been resolved dynamically or not fully tracked in the repository.

(dependencies) · high confidence

actix-multipart-derive 0.8.1 release with dependency updates

The actix-multipart-derive crate has been updated to version 0.8.1, which upgrades the \syn\ dependency to version 0.3 and the \darling\ dependency to version 0.24. This release also establishes a new Minimum Supported Rust Version (MSRV) of 1.88, requiring users to update their Rust toolchain to this version or higher to use this crate.

actix-multipart-derive · high confidence

Housekeeping

This change introduces the changelog for actix-http-test version 3.3.0, which removes the unused direct actix-tls dependency and raises the Minimum Supported Rust Version (MSRV) to 1.88. It also adds license symlinks (LICENSE-APACHE and LICENSE-MIT) and a README for the crate.

actix-http-test · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 48 → 75 (+26.3)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 87 (-13.2)
  • Architecture 96 (new)
  • Maturity 50 → 67 (+17.2)
  • Readiness 35 → 89 (+54.2)
  • Security 62 → 74 (+11.9)

Resolved (7)

  • Dimension evaluation failed
  • High: security finding (details withheld)
  • LLM evaluation failed
  • No automated tests
  • No exposed public API
  • No tests found
  • Test reliability not included

New (256)

  • Args::new (cognitive 29) (actix-web-codegen/src/route.rs)
  • ByteRangeSpec::to_satisfiable_range (cognitive 16) (actix-web/src/http/header/range.rs)
  • Change coupling: builder.rs ↔ dispatcher.rs (actix-http/src/builder.rs)
  • Change coupling: decoder.rs ↔ encoder.rs (actix-http/src/encoding/decoder.rs)
  • Codec::decode (cognitive 29) (actix-http/src/ws/codec.rs)
  • Codec::decode (cyclomatic 19) (actix-http/src/ws/codec.rs)
  • Codec::encode (cognitive 19) (actix-http/src/ws/codec.rs)
  • ConnectionPool::call (cognitive 24) (awc/src/client/pool.rs)
  • Connector::finish (cognitive 17) (awc/src/client/connector.rs)
  • ContentDecoder::feed_data (cognitive 25) (actix-http/src/encoding/decoder.rs)
  • ContentDecoder::feed_eof (cognitive 25) (actix-http/src/encoding/decoder.rs)
  • ContentDisposition::from_raw (cognitive 37) (actix-web/src/http/header/content_disposition.rs)
  • Decoder::poll_next (cognitive 32) (actix-http/src/encoding/decoder.rs)
  • Dependency advisory scan runs only on code events
  • Dispatcher::poll (cognitive 20) (actix-http/src/ws/dispatcher.rs)
  • Dispatcher::poll (cognitive 32) (actix-http/src/h2/dispatcher.rs)
  • Dispatcher::poll (cognitive 81) (actix-http/src/h1/dispatcher.rs)
  • Dispatcher::poll (cyclomatic 30) (actix-http/src/h1/dispatcher.rs)
  • Dispatcher::poll_write (cognitive 16) (actix-http/src/ws/dispatcher.rs)
  • Documentation: no contributor guidance (README.md)
  • …and 236 more

Changes since last survey

  • 95 commits — 78 feature/other, 17 fixes

By area

  • (root) — 55 commits
  • actix-http/src — 15 commits
  • .github/workflows — 8 commits
  • actix-multipart/CHANGES.md — 3 commits
  • actix-multipart/src — 3 commits
  • actix-http/CHANGES.md — 2 commits
  • actix-web/CHANGES.md — 2 commits
  • actix-web/src — 2 commits
  • actix-files/src — 1 commit
  • actix-router/Cargo.toml — 1 commit
  • actix-router/src — 1 commit
  • awc/Cargo.toml — 1 commit
  • awc/src — 1 commit

Notable commits

  • fix: chore: revert error display source appending
  • fix: ci: fix lockfile
  • fix: fix(actix-http): return exact size for empty removed headers (#4265)
  • fix: fix(http): correct brotli decompressor buffer capacity to 8 KiB
  • fix: fix(http): flush compressed response bodies when the source is pending (#4256)
  • fix: fix(http): parse chunked trailer section (RFC 9112 §7.1.2) (#4240)
  • fix: fix(http): reject WebSocket frames with reserved bits (#4214)
  • fix: fix(http): reject empty chunk size lines (RFC 9112 §7.1) (#4239)
  • fix: fix(http): terminate ByteString message bodies (#4178)
  • fix: fix(http): validate Host header in HTTP/1.1 requests (RFC 9112 §3.2) (#4273)
  • fix: fix(http): verify chunked is final encoding in HttpMessage::chunked (RFC 9112 §6.1) (#4241)
  • fix: fix(multipart): correctly handle boundary delimiter split across chunks (#4187)
  • fix: fix(multipart): include inner error in Payload and Parse display strings (#4186)
  • fix: fix(multipart): return incomplete error for truncated boundaries at EOF (#4255)
  • fix: fix: reject data frames during WebSocket continuations (#4219)
  • fix: fix: validate WebSocket close frames (#4218)
  • fix: test(multipart): fix tests
  • change: Drain HTTP/1 connections during graceful shutdown (#4169)
  • change: add methods for mapping error responses (#2979)
  • change: awc: use platform verifier in client example (#4264)
  • …and 75 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

actix/actix-web was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit a1d3c932cad97eade59bae5640f9ff10ac6594ed — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-7c1cb6328e11.