brettwooldridge/HikariCP
62.6
Adequate · 24 September 2026
8.5k
lines of production code
Java
with JavaScript
5
measurements over time
What this system is
HikariCP is a high-performance JDBC connection pool library for Java. It manages database connections and provides extensive monitoring capabilities through integrations with Dropwizard, Micrometer, and Prometheus. The system also supports Hibernate integration and dynamic credential management.
How it got here
2013–2014 — HikariCP 5.0 refactoring and metrics
10 changes.
This period was dominated by the HikariCP 5.0 release, which introduced a redesigned configuration API, a new metrics tracking system, and a comprehensive refactoring of the core pool implementation. The work also included adding mock JDBC classes and OSGi integration tests to improve test coverage and reliability.
2015–2016 — metrics integration and test coverage
7 changes.
This period focused on expanding HikariCP's observability by adding support for Dropwizard 5 and Prometheus metrics systems. The work included implementing new metrics trackers and health checks, alongside comprehensive unit testing to verify the correct behavior of pool states, utility classes, and monitoring integrations.
2017–2023 — Java 11+ module support and metrics integration
5 changes.
This period focused on modernizing the project's build and runtime environment by adding Java 11+ module descriptor support and configuring Eclipse IDE settings. It also expanded observability by integrating Micrometer metrics and adding comprehensive tests for configuration sealing and secure logging.
Features
Add Dropwizard 5 metrics support and health checks
Hikari now provides a new metrics tracker and health check implementation for Dropwizard 5 (io.dropwizard.metrics5). The new CodaHaleMetricsTracker, CodahaleHealthChecker, and associated factory classes register pool metrics (such as connection wait times, usage, creation, and timeouts) and expose health checks for connectivity and 99th-percentile wait times, enabling users to integrate Hikari with modern Dropwizard-based monitoring stacks.
src/main/java/com/zaxxer/hikari/metrics/dropwizard · high confidence
Add Hibernate 4.3+ connection provider integration
Users can now configure HikariCP via Hibernate properties using the new HikariConfigurationUtil and HikariConnectionProvider classes. The provider automatically maps standard Hibernate settings (such as driver, URL, username, and password) to HikariCP configuration, while also supporting any property prefixed with 'hibernate.hikari.' for fine-grained control. A deprecation warning is logged for Hibernate versions 4.3.6 and newer, indicating that the built-in HikariCP provider should be used instead.
src/main/java/com/zaxxer/hikari/hibernate · high confidence
Add Micrometer metrics integration for connection pool monitoring
HikariCP now provides a built-in Micrometer metrics tracker, enabling users to export connection pool statistics (such as active, idle, and pending connections, as well as acquisition and usage timings) directly to a Micrometer MeterRegistry. This new \MicrometerMetricsTracker\ and its factory allow for standard, configurable metrics collection without requiring external instrumentation libraries.
src/main/java/com/zaxxer/hikari/metrics/micrometer · high confidence
Add Prometheus metrics support for HikariCP
HikariCP now includes built-in support for exporting metrics to Prometheus. This change introduces a new \prometheus\ package containing two metrics tracking implementations: \PrometheusMetricsTracker\ (using Prometheus Summaries) and \PrometheusHistogramMetricsTracker\ (using Histograms for better performance). Both implementations support multiple connection pools by labeling metrics with the pool name and allow registration to a custom \CollectorRegistry\ via their respective factories (\PrometheusMetricsTrackerFactory\ and \PrometheusHistogramMetricsTrackerFactory\).
src/main/java/com/zaxxer/hikari/metrics/prometheus · high confidence
HikariCP 7.1.0 release with virtual-thread yield spin fix
The release introduces a fix for the ConcurrentBag to avoid virtual-thread yield spin, addressing issue \#2402. The CHANGES file also documents previous fixes including setSchema behavior, metric registry NoSuchMethodException, and connection interruption handling. The README is updated to reflect the new version and configuration details.
(repo-wide) · high confidence
Introduce new metrics tracking API for connection pool monitoring
Added a new \com.zaxxer.hikari.metrics\ package containing the \IMetricsTracker\ interface, a default-implementation \MetricsTracker\ class, a \MetricsTrackerFactory\ interface, and a \PoolStats\ abstract class. This change provides the foundational classes for tracking connection pool metrics such as creation time, acquisition time, usage duration, and timeouts, enabling users to integrate with external monitoring systems.
src/main/java/com/zaxxer/hikari/metrics · high confidence
New utility classes and refactored core components
The utility package now includes new classes: ClockSource for resolution-independent time calculations, ConcurrentBag for high-performance connection management, Credentials for immutable username/password pairs, DriverDataSource for JDBC driver-based connections, FastList for optimized list operations, IsolationLevel for transaction isolation levels, JavassistProxyFactory for dynamic proxy generation, PropertyElf for reflective property setting, SuspendResumeLock for pool suspension, and UtilityElf for helper methods. These changes introduce new capabilities and refactor existing functionality to improve performance, maintainability, and feature support.
src/main/java/com/zaxxer/hikari/util · high confidence
Architecture
Refactored core pool classes into a new package structure
The core pool implementation classes, including HikariPool, PoolBase, PoolEntry, and the proxy classes for JDBC interfaces (ProxyConnection, ProxyStatement, etc.), have been reorganized into the com.zaxxer.hikari.pool package. This refactoring isolates the internal pool logic and proxy implementations, moving them out of the root com.zaxxer.hikari package to better separate public API from internal implementation details.
src/main/java/com/zaxxer/hikari/pool · high confidence
Behavioural changes
Added Eclipse IDE configuration files
New Eclipse project settings have been added to the repository, including .settings/org.eclipse.core.resources.prefs, .settings/org.eclipse.jdt.core.prefs, .settings/org.eclipse.jdt.apt.core.prefs, .settings/org.eclipse.m2e.core.prefs, and .settings/org.eclipse.pde.core.prefs. These files configure the Java compiler to target Java 11, set UTF-8 encoding for source and resource directories, and define workspace-specific preferences for the Eclipse IDE and M2E plugin.
.settings · high confidence
Adds Java 11+ module descriptor with Dropwizard 5 metrics support
The project now includes a module-info.java file, enabling Java Platform Module System (JPMS) support for Java 11 and above. This change explicitly declares dependencies on several libraries, including io.dropwizard.metrics5 and simpleclient, indicating support for Dropwizard 5 metrics alongside existing metrics integrations like Micrometer and Prometheus.
src/main/java · high confidence
HikariCP 5.0 introduces a new configuration and management API
HikariCP has been refactored into a new major version (5.0), introducing a redesigned configuration API where HikariConfig implements the new HikariConfigMXBean interface, allowing runtime modification of pool properties via JMX. The library now uses a Credentials class for atomic username/password handling and provides a HikariCredentialsProvider interface for dynamic credential retrieval. Additionally, the pool management is exposed through a new HikariPoolMXBean interface, and the codebase has been updated to Java 11 with improved validation and logging.
src/main/java/com/zaxxer/hikari · high confidence
Test coverage
Added OSGi bundle integration tests; Added and updated tests for the HikariCP pool; Added mock JDBC classes for testing; Added test coverage for JDBC URL logging; Added test resource files for configuration and logging; Added tests for idle timeout behavior; Added unit tests for Dropwizard metrics trackers; Added unit tests for Prometheus metrics integration; Added unit tests for utility classes; Tests for sealed configuration and accessible methods.
Dependencies
Updated build dependencies in pom.xml
The project's Maven build configuration (pom.xml) has been updated with newer versions of several dependencies, including Javassist (3.29.2-GA), Log4j (2.25.1), Micrometer (1.5.4), Mockito (3.7.7), and Testcontainers (2.0.5).
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 54 → 63 (+8.3)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 90 → 93 (+3.5)
- Architecture 100 → 99 (-0.6)
- Maturity 54 → 54 (-0.0)
- Readiness 42 → 58 (+16.1)
- Security 62 → 70 (+8.7)
Resolved (11)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (7 lines × 2) (src/main/java/com/zaxxer/hikari/metrics/dropwizard/CodaHaleMetricsTracker.java)
- Duplicated block (9 lines × 2) (src/main/java/com/zaxxer/hikari/util/ConcurrentBag.java)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- No exposed public API
- Off-boarding risk: anonymized user #1
- Scanner failed to run — not a clean result
- Test reliability not included
New (65)
- Change coupling: CodaHaleMetricsTracker.java ↔ HikariPool.java (src/main/java/com/zaxxer/hikari/metrics/dropwizard/CodaHaleMetricsTracker.java)
- ClassTooLong: HikariConfig (src/main/java/com/zaxxer/hikari/HikariConfig.java)
- ClassTooLong: HikariPool (src/main/java/com/zaxxer/hikari/pool/HikariPool.java)
- Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (10 lines × 4) (src/main/java/com/zaxxer/hikari/pool/ProxyConnection.java)
- Duplicated block (11 lines × 2) (src/main/java/com/zaxxer/hikari/metrics/dropwizard/CodaHaleMetricsTracker.java)
- Duplicated block (18 lines × 2) (src/main/java/com/zaxxer/hikari/metrics/dropwizard/CodaHaleMetricsTracker.java)
- Duplicated block (5 lines × 2) (src/main/java/com/zaxxer/hikari/metrics/prometheus/PrometheusHistogramMetricsTrackerFactory.java)
- Duplicated block (8 lines × 2) (src/main/java/com/zaxxer/hikari/metrics/prometheus/PrometheusHistogramMetricsTracker.java)
- Duplicated block (9 lines × 2) (src/main/java/com/zaxxer/hikari/util/ConcurrentBag.java)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Inconsistent naming convention for base implementation methods. The ClockSource abstract class uses currentTime for the public API but currentTime0 for the concrete implementation hook. Subclasses (MillisecondClockSource, NanosecondClockSource) expose currentTime0 directly. This suggests an internal implementation detail (0 suffix) leaking into the public type signatures, which is inconsistent with standard Java naming conventions for abstract vs concrete methods.
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- No assertions: connectionAcquisitionMetrics (src/test/java/com/zaxxer/hikari/metrics/prometheus/PrometheusHistogramMetricsTrackerTest.java)
- …and 45 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
brettwooldridge/HikariCP was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit a4d93f4f85517f90e632b795486d7102e933d7ff — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-ae95d6cad036.