Skip to content
CAI
Software that uses CAICheck a score

cablehead/http-nu

62.7

Adequate · 21 September 2026

6.9k

lines of production code

Rust

with JavaScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

http-nu is a Nushell-based HTTP server framework that provides a standard library for building web applications using declarative routing, an HTML DSL, and Server-Sent Events via the Datastar SDK. It enables developers to create reactive, real-time web interfaces and static sites entirely within Nushell scripts, supporting features like session management, template rendering, and structured event logging. The system includes a comprehensive suite of examples demonstrating these capabilities, ranging from interactive games and documentation sites to live data dashboards.

How it got here

2025 — Initial scaffolding and standard library development

18 changes.

This period established the project's foundational structure, including documentation, CI pipelines, and cross-platform build infrastructure. It focused on developing the core http-nu standard library with embedded modules for routing, HTML generation, and Datastar SSE integration, while simultaneously removing outdated tests and upgrading dependencies to Nushell 0.113.1.

2026 — Example expansion and 2048 refactoring

16 changes.

This period focused on expanding the project's example suite with diverse applications such as a blog, Mermaid editor, and Datastar SDK tests, while introducing performance benchmarks and HTTP module utilities. Significant effort was dedicated to refactoring the 2048 example into a modular architecture with session authentication, custom web components, and a comprehensive test suite.

Features

2048 example introduces session-based authentication and structured project layout

The 2048 example now requires session-based authentication for game moves, replacing the previous anonymous or legacy cookie approach. A new \auth.nu\ module handles session resolution, minting, and cookie management, ensuring that move intents are tied to a specific user identity. To support this, the project structure has been reorganized into submodules (\tfe/\) for game logic, rendering, SSE handling, and store helpers, along with new utility scripts like \migrate-topics.nu\ and \strip-store.nu\ for data migration and cleanup. The example also includes a \.gitignore\ to exclude test artifacts and a \CLAUDE.md\ with development guidelines.

examples/2048 · high confidence

Add 'The Tao of Datastar' interactive tutorial example

Introduces a new multi-page tutorial example in the \examples/tao\ directory that demonstrates Datastar development principles. The example includes a Nushell-based HTTP server (\serve.nu\) that renders lessons via templates, manages state through cookies, and implements keyboard navigation. It also provides static assets (CSS with view transitions), structured content data, and a unit test script (\test.nu\) to verify the handler's output.

examples/tao · high confidence

Add Dagger-based cross-platform build pipeline for http-nu

This change introduces a new Dagger module (\.dagger/main.go\) that defines a cross-platform build workflow for the http-nu project. It enables building release artifacts for Darwin (arm64), Windows (amd64), Linux (arm64 and amd64) using specific container images and Rust toolchains, with separate cache volumes for cargo registry, git, and target directories to optimize build times. The module also includes \.gitattributes\ and \.gitignore\ files to manage generated Dagger code and internal directories.

.dagger · high confidence

Add Datastar SDK example demonstrating reactive state and DOM updates

A new example application (\examples/datastar-sdk\) is introduced to demonstrate core Datastar SDK capabilities. The example serves an interactive UI that exercises three major commands: updating reactive state via \datastar-patch-signals\ (incrementing a counter), executing client-side JavaScript via \datastar-execute-script\ (triggering an alert), and modifying DOM elements via \datastar-patch-elements\ (updating a time display). It also includes a simpler counter example (\examples/datastar-counter\) to showcase basic signal binding.

examples/datastar-sdk · high confidence

Add Datastar and Splash snippet demos to the website

New Nushell snippets have been added to the www/snippets directory to demonstrate specific web capabilities. The new datastar.nu snippet implements a Server-Sent Events (SSE) handler that progressively types out a message using Datastar signals and patches the HTML into the page, while splash.nu provides a static HTML demo rendering a styled header and a list of items.

www/snippets · high confidence

Add Nushell syntax highlighting support

Users can now get syntax highlighting for Nushell scripts (.nu files) in their editor. This new syntax definition covers core language features including commands, keywords, operators, strings, and numbers, and specifically adds support for duration literals (e.g., 5sec, 10min).

syntaxes · high confidence

Add benchmarks for broadcast logging, mpsc logging, and Flask comparison

New benchmark suites have been added to the benchmarks directory to evaluate performance characteristics. The \bench-broadcast-logging\ suite measures throughput and latency for the new async broadcast-based event system, while \bench-mpsc-logging\ provides a comparison against the previous synchronous mpsc channel approach. Additionally, a \bench-flask-comparison\ suite has been introduced to benchmark a Flask+gunicorn application across various worker configurations, establishing a baseline for comparison against the http-nu server.

benchmarks · high confidence

Add blog example demonstrating routing and HTML composition

A new blog example has been added to the examples directory, showcasing how to build a simple HTTP server using http-nu. It demonstrates key features including URL routing (home, about, and dynamic post pages), HTML generation with layout composition, and metadata handling for HTTP responses such as 404 status codes.

examples/blog · high confidence

The HTTP module now includes a cookie submodule providing commands to parse incoming cookies, set new cookies with secure defaults (HttpOnly, SameSite=Lax, and Secure in production), and delete cookies by expiring them. These utilities allow users to manage session state and user preferences directly within HTTP response handling, with support for customizing path, domain, max-age, and security flags.

src/stdlib/http · high confidence

Add live Mermaid diagram editor example

A new example in the \examples/mermaid-editor\ directory provides a live, two-pane editor for Mermaid diagrams. It demonstrates a zero-client-JavaScript architecture using http-nu and Datastar, where a Nushell server handles rendering and a lightweight web component (\\<mermaid-diagram\>\) manages the client-side DOM updates via shadow DOM and MutationObserver.

examples/mermaid-editor · high confidence

Add live quotes example with real-time SSE updates

A new 'Live Quotes' example has been added to demonstrate Server-Sent Events (SSE) integration using the embedded cross.stream store. The example serves an HTML page that displays quotes in real-time; users can run the server via \http-nu\ with the \--store\ flag and add new quotes via POST requests, which are immediately pushed to connected clients through the SSE stream.

examples/quotes · high confidence

Add notes sub-site with multi-section markdown support

A new notes sub-site is introduced under /notes, allowing authors to group related topics in single markdown files where each H1 heading becomes a distinct page with its own URL. The implementation includes helper functions to slugify headings and split markdown content, a route handler that serves an index of all pages and individual page views, and proper asset path resolution to ensure styles and scripts load correctly whether the app is run standalone or mounted under a prefix.

examples/2048/notes · high confidence

Embedded http-nu standard library with router, HTML, Datastar, and HTTP modules

The http-nu standard library is now embedded directly into the binary, making modules like router, HTML DSL, Datastar SSE SDK, and HTTP utilities available for immediate use without external dependencies. Users can import these capabilities using standard Nushell module syntax (e.g., \use http-nu/router \*\), simplifying the setup for building web applications and handling server-sent events.

src/stdlib · high confidence

Initial project scaffolding and documentation

This release establishes the project's foundational structure by adding the MIT license, a Nushell-specific coding and commit-style guide (CLAUDE.md), and comprehensive documentation including a README with installation and reference guides, a NixOS packaging guide, and a Dagger build configuration. It also updates the .gitignore to exclude build artifacts, local store directories, and Claude-specific files.

(repo-wide) · high confidence

Introduce HTML DSL module with XSS protection and Jinja2 integration

The new \src/stdlib/html\ module provides a Domain Specific Language for generating HTML in Nushell, featuring automatic escaping of special characters to prevent XSS vulnerabilities. It supports Jinja2-style control flow (\\_for\, \\_if\) and variable expressions (\\_var\), allows style attributes to be passed as records or lists, and handles boolean attributes. The module includes definitions for standard HTML5 elements, SVG, and MathML, with the \HTML\ wrapper automatically prepending the DOCTYPE declaration.

src/stdlib/html · high confidence

Introduce in-process pub/sub bus and structured event logging

The server now includes an internal publish/subscribe bus (src/bus.rs) that allows components to exchange events by topic, supporting glob-style pattern matching for subscriptions. This bus powers a new structured logging and event system (src/logging.rs) that emits typed lifecycle and request/response events via a broadcast channel, replacing the previous logging approach. Users benefit from more granular, machine-readable observability and the ability for internal modules to react to server state changes without tight coupling.

src · high confidence

Introduction of the http-nu design system and base typography

The website now uses a new \core.css\ stylesheet that establishes the visual identity for the http-nu project. This change introduces a specific design palette with CSS variables for background, text, and accent colors, along with a reset and base typography system that styles HTML elements like headings, paragraphs, and code blocks. It also includes utility classes for layout (flexbox) and interactive elements such as copy buttons for code snippets, ensuring a consistent look and feel across the site.

www/assets · high confidence

Launch of the http-nu documentation website

The www directory now serves the official http-nu website, providing a landing page, a getting-started tutorial, and an examples hub. The site features a unified copy-button system for code snippets, interactive Datastar-powered demos, and a responsive design with anchor links and social meta tags. It is served via the \--datastar\ flag and the \serve.nu\ script, which handles routing and static asset delivery.

www · high confidence

New /design component viewer for nu2048

A new /design page has been added to the nu2048 example, providing a two-column component viewer with a sidebar catalog and a focused preview pane. This viewer allows users to inspect individual components like the board, badges, and palettes, featuring a dedicated playground for the \<game-board\> web component with scenario controls and a tile palette gallery that displays color progressions for tile values up to 64K.

examples/2048/design · high confidence

New Datastar SDK test endpoint example

Added a new example application in \examples/datastar-sdk-test\ that implements the \/test\ endpoint required by the official Datastar SDK test suite. This example serves as a reference implementation for SDK compliance, handling Datastar-specific events like \patchElements\, \patchSignals\, and \executeScript\ via a Nushell-based HTTP server.

examples/datastar-sdk-test · high confidence

New cargo-docs example for serving Rust documentation

Added a new example in the examples/cargo-docs directory that demonstrates how to serve Rust \cargo doc\ output using http-nu. The example includes a Nu script (serve.nu) that generates an index page listing all documented crates and serves static documentation files, with support for customizing the documentation root via the DOC\_ROOT environment variable.

examples/cargo-docs · high confidence

New declarative HTTP routing module

A new \router\ module has been added to the standard library, providing utilities for building declarative HTTP routers. It introduces a \route\ command that accepts test closures or records (supporting exact matches, path parameters via \path-matches\, and header checks via \has-header\) paired with handler closures. The module also includes helper functions like \path-matches\ for extracting URL parameters and \has-header\ for case-insensitive header validation, enabling users to define complex routing logic with fallback support.

src/stdlib/router · high confidence

New examples hub and markdown-mermaid demo

The examples directory now includes a central hub (examples/serve.nu) that aggregates and serves multiple demos, including a new markdown-mermaid example that renders Markdown with live Mermaid diagrams. The hub detects store availability and disables store-dependent examples when the --store flag is omitted. Additionally, the stor example has been updated to make its database creation idempotent, preventing errors during watch-mode reloads.

examples · high confidence

New templates example demonstrating file, inline, and store-backed topic modes

The examples/templates directory now includes a complete demo showing how to use the .mj template engine in three modes: inline, file-based, and store-backed (topic). The serve.nu script seeds a store with HTML templates from the topics/ subdirectory and routes requests to /file (rendering from disk), /topic (rendering from the store), and the root (inline rendering). This allows users to see how templates can be loaded from different sources and how the --topic flag enables store-based template resolution.

examples/templates · high confidence

Behavioural changes

2048 example restructured into modular TFE components

The 2048 example has been refactored into a structured \tfe/\ directory containing distinct modules for game logic (\game.nu\), state management (\store.nu\), rendering (\render.nu\), and server-sent events (\sse.nu\). This change introduces dedicated actors for maintaining the leaderboard (\leaderboard-actor.nu\), tracking site-wide presence (\presence-actor.nu\), and managing game snapshots (\snapshot-actor.nu\). The game logic now uses deterministic seeding for tile spawning, and the leaderboard exclusively ranks clean runs (excluding games with undos). Additionally, the example now supports a presence system that tracks active tabs and games, and the leaderboard queries have been optimized to use indexed topic prefixes rather than full scans.

examples/2048/tfe · high confidence

2048 example restructured with custom web components and live presence

The 2048 example has been rebuilt with a new architecture centered on custom web components: a \\<game-board\>\ component encapsulates the 4x4 grid, tile animations, and status badges, while a \\<scrub-knob\>\ component provides a high-precision slider for the splash screen's audio seek bar. The main \script.js\ now handles input delegation, move requests, and a new client-driven heartbeat system that pings a \/presence/ping\ endpoint to track user liveness and connection status, replacing the previous server-pulse model. The visual design has also been updated to use self-hosted Source Sans 3 and Source Code Pro fonts, a deep blue body background, and a warm-cream header palette aligned with the main site's design language.

examples/2048/static · high confidence

The site chrome (header, footer, and body structure) has been consolidated into a single \layout.html\ template. This change introduces a consistent site-wide header containing the nu2048 title, leaderboard link, player ID chip, and connection status indicators, along with a footer linking to the design page. The layout also injects shared resources like stylesheets, Datastar scripts, and custom web components (\\<game-board\>\, \\<scrub-knob\>\), ensuring all pages inherit the same visual structure and script dependencies.

examples/2048/tfe/templates · high confidence

New CI check script and macOS cross-compilation helper

The repository now includes a \scripts/check.sh\ script that automates the CI validation process by running Nushell tests for the router, HTML, and Datastar modules, checking code formatting with Deno and Cargo, enforcing Clippy lints (including \uninlined\_format\_args\), building the test plugin, and executing integration tests for the Tao and 2048 examples. Additionally, a \scripts/cross-build-darwin.sh\ script has been added to facilitate cross-compilation for the \aarch64-apple-darwin\ target, featuring logic to detect and work around a known \libproc\ build issue by patching source files before retrying the build.

scripts · high confidence

Test coverage

Added baseline screenshot test for 2048 example; Added integration and unit tests for core server and module features; Added test suite and benchmarks for the 2048 example; Removal of engine and handler unit tests.

Dependencies

Datastar SDK updated to v1.0.2 with embedded JavaScript bundle

The Datastar SDK has been upgraded from v1.0.0-RC.8 to v1.0.2. The JavaScript bundle is now embedded directly in the repository as \src/stdlib/datastar/[e-mail redacted]\ and served via the \/[e-mail redacted]\ path, removing the dependency on the external CDN URL previously defined in \mod.nu\. The Nushell SDK module (\mod.nu\) has been updated to align with the v1.0.2 specification, including the addition of the \to datastar-redirect\ command for handling redirects via SSE and the \from datastar-signals\ command for parsing request signals. The embedded JS bundle also includes support for MathML namespaces in element patching.

src/stdlib/datastar · high confidence

Upgrade to Nushell 0.113.1 and add Dagger build infrastructure

The project dependencies have been updated to Nushell 0.113.1 (including nu-cli, nu-cmd-extra, nu-command, nu-engine, nu-parser, nu-plugin-engine, nu-protocol, nu-std, and nu-utils), enabling the use of the latest Nushell features and plugins. Additionally, a new Dagger-based Go module has been introduced in the .dagger directory to support cross-platform release workflows, and a test plugin crate has been added to facilitate plugin testing.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 61 → 63 (+1.7)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 79 → 85 (+6.0)
  • Architecture 100 → 100 (+0.0)
  • Maturity 73 → 74 (+1.0)
  • Readiness 68 → 67 (-0.7)
  • Security 44 → 47 (+2.9)
  • Domain Modelling 100 → 100 (+0.0)
  • Event Sourcing 100 → 100 (+0.0)

Resolved (59)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (.dagger/go.mod)
  • Decision and consequences are present but trade-offs (e.g. delay/hack vs flaky acceptance) are not clearly stated (docs/issues/0000-flaky-parse-error-test.md)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (Cargo.lock)
  • High CVE: [GHSA redacted] (.dagger/go.mod)
  • High CVE: [GHSA redacted] (Cargo.lock)
  • High vulnerability: [GHSA redacted] (Cargo.lock)
  • High vulnerability: [GHSA redacted] (Cargo.lock)
  • High vulnerability: [GHSA redacted] (Cargo.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 39 more

New (90)

  • Critical CVE: [GHSA redacted] (.dagger/go.mod)
  • Dependency hygiene PARTLY measured — Cargo dependencies read, dependency currency not (crates.io unreachable)
  • Documentation: contradicts the code (docs/adr/0003-html-dsl-design.md)
  • Documentation: contradicts the code (docs/issues/0001-markdown-javascript-urls.md)
  • Duplicate method signature with different parameter names (one uses 'engine', the other '_engine'). This suggests a copy-paste error or unresolved conflict in the API surface.
  • Duplicated block (10 lines × 2) (src/commands.rs)
  • Duplicated block (12–13 lines × 2) (src/commands.rs)
  • Duplicated block (13 lines × 2) (src/listener.rs)
  • Duplicated block (15 lines × 2) (src/commands.rs)
  • Duplicated block (16 lines × 2) (src/main.rs)
  • Duplicated block (19 lines × 2) (src/commands.rs)
  • Duplicated block (20 lines × 2) (src/commands.rs)
  • Duplicated block (28–30 lines × 2) (src/engine.rs)
  • Duplicated block (5 lines × 2) (src/logging.rs)
  • Duplicated block (7 lines × 2) (src/commands.rs)
  • FunctionTooLong: http_nu::handler::build_normal_response (src/handler.rs)
  • FunctionTooLong: http_nu::handler::handle_inner (src/handler.rs)
  • FunctionTooLong: http_nu::logging::run_human_handler (src/logging.rs)
  • FunctionTooLong: http_nu::logging::run_jsonl_handler (src/logging.rs)
  • FunctionTooLong: http_nu::main (src/main.rs)
  • …and 70 more

Changes since last survey

  • 5 commits — 4 feature/other, 1 fixes

By area

  • src/compression.rs — 2 commits
  • examples/markdown-mermaid — 1 commit
  • src/engine.rs — 1 commit
  • src/logging.rs — 1 commit

Notable commits

  • fix: fix: run xs.stopping shutdown protocol on SIGTERM, not just SIGINT (#53)
  • change: feat: add an example which renders mermaid diagrams within markdown documents
  • change: feat: fit the access log to the terminal width, 96 columns at the narrowest
  • change: style: cargo fmt
  • change: test: pin per-burst release of brotli stream output

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

cablehead/http-nu was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit a8dab1b85bd1c65a31ade1981389296c3ef2af2b — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.