cfug/dio
70.3
Strong · 22 September 2026
9.4k
lines of production code
Dart
with C++
6
measurements over time
What this system is
This system is a monorepo for the Dio HTTP client library, providing a unified API for making network requests across native Dart, Flutter, and web platforms. It features platform-specific adapters for browser and native environments, along with plugins for HTTP/2, cookie management, and alternative HTTP client integration. The codebase includes comprehensive tooling for testing, background processing, and response transformation to ensure performance and reliability.
How it got here
2018–2019 — Monorepo restructuring and platform adaptation
21 changes.
The project underwent a major architectural shift, reorganizing into a Melos-managed monorepo with distinct packages for web, native, and HTTP/2 adapters. This period focused on modernizing the codebase by removing legacy entry points and examples, introducing platform-specific client implementations, and expanding plugin support for cookies and HTTP/2.
2021–2023 — Performance optimization and testing infrastructure
10 changes.
This period focused on enhancing Dio's performance through a new transformer architecture that enables background JSON decoding and fused parsing, alongside improvements to native download handling and background compute utilities. Significant effort was also dedicated to expanding test coverage, including new mock adapters, stream handling tests, and CI scripts for SDK-compatible package filtering.
2024 — Adapter extensibility and testing infrastructure
8 changes.
This period focused on enhancing Dio's plugin ecosystem by introducing the dio\_compatibility\_layer and dio\_web\_adapter packages to support alternative HTTP clients and WebAssembly. Significant effort was dedicated to establishing robust testing standards through the new dio\_test shared suite and comprehensive coverage for adapter implementations. The work also included restructuring example projects and refactoring the web adapter to improve browser-specific behaviors and developer diagnostics.
Features
Add CI scripts for SDK-compatible package filtering and certificate pinning
Two new scripts are introduced to support the CI pipeline. The \melos\_packages.dart\ script filters workspace packages based on the current Dart SDK version, writing a list of compatible packages to \.melos\_packages\ and individual \.melos\_package\ markers to enable selective melos execution in CI. The \prepare\_pinning\_certs.sh\ script fetches SSL certificates from \badssl.com\ and \httpbun.com\ to generate fingerprint files required for dio and http2\_adapter pinning tests.
scripts · high confidence
Add Dio cookie manager example
Added a new example file demonstrating how to integrate the dio\_cookie\_manager package with the Dio HTTP client to automatically handle cookies across requests.
_plugins/cookie\manager/example · high confidence
Add Dio usage example file
A new example file (dio/example/dio.dart) has been added to demonstrate basic Dio usage, showing how to initialize the client and perform a GET request to pub.dev.
dio/example · high confidence
Add HTTP/2 adapter example for Dio
The example application now demonstrates how to configure Dio to use the HTTP/2 adapter. It shows setting up a \Http2Adapter\ with a \ConnectionManager\ that has a 10-second idle timeout, and includes logic to print redirect information and response data.
_plugins/http2\adapter/example · high confidence
Expose CookieManager library entry point
The \dio\_cookie\_manager\ library now explicitly exports its core implementation (\src/cookie\_mgr.dart\) and exception definitions (\src/exception.dart\) via a dedicated entry point file. This allows consumers to import the cookie manager functionality and handle specific exceptions in a standardized way.
_plugins/cookie\manager/lib · high confidence
Introduce CookieManager interceptor with ignoreInvalidCookies option
Adds a new CookieManager interceptor that automatically loads and saves cookies using a provided CookieJar for Dio requests. The manager now supports an \ignoreInvalidCookies\ configuration flag to silently discard malformed Set-Cookie headers instead of throwing errors, and includes logic to prevent duplicate cookies when request options are reused by tracking the state of generated Cookie headers.
_plugins/cookie\manager/lib/src · high confidence
Introduce Http2Adapter plugin for HTTP/2 support in Dio
Adds the \dio\_http2\_adapter\ plugin, providing an \Http2Adapter\ that implements the \HttpClientAdapter\ interface to enable HTTP/2.0 communication. The adapter includes a \ConnectionManager\ for handling connection reuse, idle timeouts, and ALPN protocol negotiation, along with \ClientSetting\ options for configuring TLS certificates, proxy settings, and custom certificate validation. It also supports fallback to a standard HTTP/1.1 adapter when HTTP/2 is not supported by the server or connection fails.
_plugins/http2\adapter/lib · high confidence
Introduction of platform-specific entry points for Dio
Dio now provides distinct entry points to support different execution environments. Users can import \dio/lib/browser.dart\ to access \BrowserHttpClientAdapter\ and \DioForBrowser\ for web contexts, and \dio/lib/io.dart\ to access \IOHttpClientAdapter\ and \DioForNative\ for native Dart/Flutter applications. The main \dio.dart\ library remains the central export for core types like \Dio\, \FormData\, and interceptors, ensuring a unified API while allowing platform-specific adapter selection.
dio/lib · high confidence
New ImplyContentTypeInterceptor and enhanced LogInterceptor
The library now includes an ImplyContentTypeInterceptor that automatically sets the Content-Type header based on the request payload type (e.g., multipart/form-data for FormData, application/json for Maps or Lists of Maps), removing the need for manual header configuration in many cases. Additionally, the LogInterceptor has been improved with granular control over logged details, including new options to toggle logging of request/response URLs and headers, and it now supports custom log printers for better integration with Flutter's debugPrint or file logging.
dio/lib/src/interceptors · high confidence
New dio\_compatibility\_layer package for using alternative HTTP clients with Dio
The \dio\_compatibility\_layer\ package (v0.1.1) is introduced, providing a \ConversionLayerAdapter\ that allows Dio to use underlying HTTP clients from the \http\ package ecosystem (such as \http\, \cronet\_http\, or \cupertino\_http\) instead of its default adapter. This enables users to leverage platform-specific or alternative HTTP implementations within Dio. The release also includes a fix for \kIsWeb\ detection to ensure compatibility across different Flutter SDK versions.
_plugins/compatibility\layer · high confidence
Repository governance and contribution standards established
The repository now includes formalized governance documents: Agent Contribution Guidelines (AGENTS.md/AGENTS-ZH.md) defining rules for AI-assisted contributions, a Code of Conduct, a Compatibility Policy, and a Security Policy. The root README has been refactored to serve as a mono-repo index pointing to individual package documentation, and the legacy Travis CI configuration has been removed in favor of a Melos-based workspace setup (melos.yaml) with standardized scripts for testing, formatting, and analysis.
(repo-wide) · high confidence
Web adapter package initialization and release history
The \plugins/web\_adapter\ directory is established as a standalone Dart package (\dio\_web\_adapter\) that provides the \BrowserHttpClientAdapter\ for Dio on web platforms. The included CHANGELOG documents the package's evolution from its initial split from the main Dio library (v1.0.0) through version 2.2.2, highlighting key user-facing capabilities such as WebAssembly support (v2.0.0), file download support via Blob URLs (v2.2.0), and CORS preflight warnings (v2.2.1). The package structure includes the necessary library exports, an example application, and test configuration for headless browsers.
_plugins/web\adapter · high confidence
Removals
Removal of core HTTP client implementation files
The source files defining the core HTTP client functionality—including the main Dio class, request cancellation logic (CancelToken), error handling (DioError), form data processing (FormData), request/response interceptors, configuration options, response structures, and data transformation logic—have been deleted from the library.
lib/src · high confidence
Removal of legacy example files
The \example/\ directory has been cleaned up by deleting several outdated demonstration files, including \ResponseStreamInfo.dart\, \cancelRequest.dart\, \dio.dart\, \download.dart\, \formdata.dart\, \interceptorLock.dart\, \options.dart\, \proxy.dart\, \requestInterceptors.dart\, and \responseInterceptor.dart\. Users relying on these specific snippets for reference will need to consult updated documentation or other available examples.
example · high confidence
Behavioural changes
Background computation now supports timeouts and WebAssembly
The \compute\ utility used for offloading heavy tasks to background isolates now supports an optional \timeout\ parameter, allowing users to prevent long-running background decodings from hanging indefinitely. Additionally, the implementation has been split to support WebAssembly environments by delegating to the \dio\_web\_adapter\ for web targets, ensuring consistent background processing capabilities across native, web, and WASM platforms.
dio/lib/src/compute · high confidence
Cookie manager v3.5.0 release with duplicate prevention and invalid cookie handling
The cookie manager plugin has been updated to version 3.5.0, introducing a fix to prevent duplicate cookies when reusing request options while preserving caller-provided cookies. This release also includes improvements from v3.4.0, such as better compatibility with different Flutter SDKs for the \kIsWeb\ check and the new \ignoreInvalidCookies\ option that allows the manager to skip parsing invalid cookies instead of throwing errors. Additionally, v3.3.0 enhanced exception handling by including \CookieManagerLoadException\ and \CookieManagerSaveException\ within \DioException\ and exposed \loadCookies\ and \saveCookies\ methods for direct access.
_plugins/cookie\manager · high confidence
Dio 4.0 core library restructure and API updates
The \dio/lib/src\ package has been restructured for version 4.0, introducing a new \DioException\ class to replace the deprecated \DioError\ and adding a \transformTimeout\ error type. The library now supports the HTTP QUERY method via new \query\ and \queryUri\ convenience methods. Multipart file uploads have been enhanced to allow additional headers on \MultipartFile\ entries and support cloning. The \FormData\ class now supports camelCase \Content-Disposition\ headers and allows null entry values to be sent as empty strings. Interceptor handling has been improved to prevent request hangs when async interceptors throw exceptions, and the default transformer now uses \FusedTransformer\ to decode large JSON responses in an isolate.
dio/lib/src · high confidence
Dio package repository structure and documentation updates
The dio package repository has been reorganized with the main package files moved into a dedicated \dio/\ directory, accompanied by the addition of a \.gitignore\ file to exclude build artifacts and IDE configurations. Documentation has been updated to include a new \QUERY\ HTTP method (RFC 10008) with \query\ and \queryUri\ convenience methods, and the \README\ now clarifies that Web platform downloads use the browser's suggested filename rather than a local filesystem path. Configuration files for analysis, testing, and documentation generation have also been added to standardize the development environment.
dio · high confidence
Example project restructured and updated for modern Dart/Dio standards
The example project has been reorganized into a standard Dart package layout, moving source files from the root into a lib/ directory and adding standard configuration files (.gitignore, analysis\_options.yaml, dart\_test.yaml). The examples have been updated to reflect current Dio APIs: the custom transformer now extends BackgroundTransformer and uses RequestOptions/ResponseBody, the CSRF token example now uses QueuedInterceptorsWrapper to handle concurrent requests safely, and the adapter example demonstrates the new HttpClientAdapter interface. Additionally, the project now supports HTTP/2 via dio\_http2\_adapter and includes examples for certificate pinning, chunked downloads, and cookie management.
_example\dart · high confidence
HTTP/2 adapter v2.9.0 release
This update introduces a new \supportedProtocols\ configuration on \ConnectionManager\ (defaulting to \\['h2'\]\) to allow users to explicitly advertise protocols, which fixes fallback behavior against RFC 7301-compliant servers that abort TLS handshakes when only \h2\ is advertised. It also resolves a socket leak by ensuring the \SecureSocket\ is destroyed before routing to the fallback adapter when the server selects \http/1.1\. Additionally, the misspelled \handshakeTimout\ parameter is deprecated in favor of the correctly spelled \handshakeTimeout\.
_plugins/http2\adapter · high confidence
Native Dio Adapter v1.8.0: Cronet provider fallback and memory leak fix
The native\_dio\_adapter package now supports \cronet\_http\ 1.9.0 and includes an opt-in fallback mechanism for Android devices where Cronet providers are disabled (such as AOSP emulators). By passing a \createFallbackAdapter\ to \NativeAdapter\, requests will automatically fall back to a standard HTTP adapter when Cronet is unavailable, ensuring connectivity on restricted devices. Additionally, a memory leak on Android has been fixed by properly releasing \CronetUrlRequest\ and upload body references after request completion, allowing them to be garbage collected.
_plugins/native\_dio\adapter · high confidence
Native download implementation supports asynchronous save paths and configurable file access modes
The native platform implementation of Dio now allows the \savePath\ argument in \download\ to be an asynchronous function that receives response headers, enabling dynamic file path generation based on redirect or URI information. Additionally, a new \FileAccessMode\ parameter lets users choose between write and append modes for downloaded files, and the implementation ensures that partially downloaded files are cleaned up on data handling errors.
dio/lib/src/dio · high confidence
New transformer architecture with FusedTransformer and background decoding
The response transformation logic has been restructured into three distinct transformer implementations: FusedTransformer, BackgroundTransformer, and SyncTransformer. FusedTransformer is introduced as a high-performance option that uses a fused UTF-8 and JSON decoder for faster parsing of JSON responses, with an optional threshold to offload large payloads to a background isolate. BackgroundTransformer handles JSON deserialization in a background isolate for responses exceeding 50 KB to prevent main-thread jank. SyncTransformer serves as the standard synchronous transformer, now deprecated in favor of BackgroundTransformer for default usage. Utility helpers for consolidating byte streams and handling empty responses are also added to support these transformations.
dio/lib/src/transformers · high confidence
Refreshed Flutter example app to modern standards
The example Flutter application has been completely regenerated to align with current Flutter tooling and best practices. This update includes migrating the Android platform code to Kotlin, updating the iOS minimum deployment target to iOS 12, and upgrading the Android Gradle wrapper to version 8.14.3. The project now uses shared analysis options for consistent code linting, adds a \.gitignore\ file to properly exclude build artifacts and IDE configurations, and refreshes the core Dart code to demonstrate Dio usage with modern \Duration\-based timeout settings and a \LogInterceptor\.
_example\_flutter\app · high confidence
Removal of legacy dio.dart library entry point
The main library entry point \lib/dio.dart\ has been removed. This file previously served as the single export hub for core components such as \Dio\, \FormData\, \DioError\, \TransFormer\, \Interceptor\, \Options\, \Response\, and \UploadFileInfo\. Users relying on this specific import path will need to update their imports to reference the individual source files or the new library structure directly.
lib · high confidence
Split browser and IO adapters into separate files
The adapter implementation files have been reorganized: \browser\_adapter.dart\ now acts as a thin re-export layer for the \dio\_web\_adapter\ package, while \io\_adapter.dart\ contains the full native HTTP client logic. This change introduces deprecation warnings for the legacy \DefaultHttpClientAdapter\ typedef and the \onHttpClientCreate\ callback, directing users to use \IOHttpClientAdapter\ and the new \createHttpClient\ callback instead.
dio/lib/src/adapters · high confidence
Web adapter restructured for WASM support with improved CORS warnings and download handling
The web adapter has been refactored to support WebAssembly (WASM) by moving implementation details into \\*\_impl.dart\ files and using \dart:js\_interop\ instead of \dart:html\. This change introduces a warning log when requests trigger CORS preflight (OPTIONS) requests, helping developers diagnose cross-origin issues. Additionally, the adapter now supports file downloads in the browser via a new \download\_trigger\ mechanism and introduces a \FileAccessMode\ parameter for downloads, while fixing timeout detection to use \readyState\ for more accurate classification of connection versus receive timeouts.
_plugins/web\adapter/lib/src · high confidence
Fixes
Fixes for streamed response handling, timeouts, and cancellation
The library now uses a dedicated \ResponseStreamHandler\ to manage streamed responses, ensuring that the receive timeout timer starts immediately after headers are received rather than waiting for the first body byte, which prevents premature timeouts on slow connections. It also correctly propagates backpressure from the response stream to the source, stops watching the receive timeout when a request is cancelled, and properly handles stream cancellation and progress updates.
dio/lib/src/response · high confidence
Test coverage
Added comprehensive test suite for HTTP/2 adapter; Added dio\_test shared test package; Added mock HTTP adapters and test fixtures for Dio testing; Added test coverage for web adapter browser functionality; Added test suite for cookie manager functionality; Added tests for response stream handling; Added tests for the Conversion Layer Adapter; Expanded test coverage for Dio core features; New shared integration test suite for Dio adapters; Removal of legacy integration test suite.
Dependencies
Dio monorepo restructured with updated dependencies and SDK constraints
The Dio project has been reorganized into a monorepo managed by Melos, introducing new packages such as dio\_compatibility\_layer, dio\_cookie\_manager, dio\_http2\_adapter, native\_dio\_adapter, and dio\_web\_adapter. The main dio package is now version 5.11.1, requiring Dart SDK \>=2.18.0, and depends on dio\_web\_adapter (\>=1.1.0 \<3.0.0). The cookie\_manager plugin now depends on cookie\_jar ^4.0.0, and the http2\_adapter plugin depends on http2 ^2.1.0. The native\_dio\_adapter plugin supports cupertino\_http \>=2.3.0 \<4.0.0 and cronet\_http ^1.9.0, with a direct dependency on jni ^1.0.0. The web\_adapter plugin requires dio ^5.8.0 and the web package \>=0.5.0 \<2.0.0. The workspace root now uses melos for management.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 62 → 70 (+7.9)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 95 → 91 (-4.5)
- Architecture 100 → 97 (-3.2)
- Maturity 51 → 56 (+4.6)
- Readiness 56 → 90 (+34.2)
- Security 75 → 75 (+0.0)
Resolved (8)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High: security finding (details withheld)
- No exposed public API
- Off-boarding risk: anonymized user #1
- Test reliability not included
- The 'Getting Started' section links to the Flutter codelab and a cookbook, but it does not mention how to run or test the dio package locally. (example_flutter_app/README.md)
- complexity unreadable for .dart, .swift — churn × complexity hotspots could not be measured
New (38)
- BrowserHttpClientAdapter.fetch (cognitive 58) (plugins/web_adapter/lib/src/adapter_impl.dart)
- BrowserHttpClientAdapter.fetch (cyclomatic 38) (plugins/web_adapter/lib/src/adapter_impl.dart)
- ClassTooLong: DioMixin (dio/lib/src/dio_mixin.dart)
- Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
- DioMixin._transformData (cognitive 30) (dio/lib/src/dio_mixin.dart)
- DioMixin.fetch (cognitive 34) (dio/lib/src/dio_mixin.dart)
- DioMixin.fetch (cyclomatic 25) (dio/lib/src/dio_mixin.dart)
- Duplicated block (12 lines × 2) (dio/lib/src/dio_mixin.dart)
- Duplicated block (12 lines × 2) (plugins/cookie_manager/lib/src/cookie_mgr.dart)
- Duplicated block (14 lines × 2) (dio/lib/src/dio_mixin.dart)
- Duplicated block (14–15 lines × 2) (plugins/compatibility_layer/lib/src/conversion_layer_adapter.dart)
- Duplicated block (16 lines × 4) (dio/lib/src/dio_mixin.dart)
- Duplicated block (18 lines × 3) (dio/lib/src/dio_mixin.dart)
- FusedTransformer._fastUtf8JsonDecode (cognitive 21) (dio/lib/src/transformers/fused_transformer.dart)
- High: security finding (details withheld)
- Hotspot: dio/lib/src/dio_mixin.dart (dio/lib/src/dio_mixin.dart)
- Hotspot: plugins/http2_adapter/lib/src/http2_adapter.dart (plugins/http2_adapter/lib/src/http2_adapter.dart)
- Hotspot: plugins/web_adapter/lib/src/adapter_impl.dart (plugins/web_adapter/lib/src/adapter_impl.dart)
- Http2Adapter._fetch (cognitive 61) (plugins/http2_adapter/lib/src/http2_adapter.dart)
- Http2Adapter._fetch (cyclomatic 38) (plugins/http2_adapter/lib/src/http2_adapter.dart)
- …and 18 more
Changes since last survey
- 13 commits — 9 feature/other, 4 fixes
By area
- (root) — 3 commits
- plugins/http2_adapter — 3 commits
- dio/CHANGELOG.md — 2 commits
- plugins/web_adapter — 2 commits
- .github/workflows — 1 commit
- dio/lib — 1 commit
- plugins/native_dio_adapter — 1 commit
Notable commits
- fix: fix(dio): propagate response-stream backpressure to the source (#2588)
- fix: fix(dio): support classes that implement Interceptor (#2591)
- fix: fix(web): classify XHR timeout by connection phase (#2593)
- fix: 🐛 Expose supportedProtocols on ConnectionManager to fix fallback for RFC-strict servers (#2583)
- change: Update README for clarity and remove star history (#2589)
- change: ci: add CI/CD security analysis workflow (#2587)
- change: ✨ Deprecate misspelled handshakeTimout in favor of handshakeTimeout (#2595)
- change: 💚 Adopt CI to Flutter 3.47 (#2592)
- change: 💚 Fail web test runs on the first failing compiler round (#2594)
- change: 📝 Add test-certificate-and-key convention to AGENTS.md (#2585)
- change: 🔖 dio v5.11.1 Triggered by @AlexV525 on https://github.com/cfug/dio/issues/1633#issuecomment-5534919587
- change: 🔖 http2_adapter v2.9.0 Triggered by @AlexV525 on https://github.com/cfug/dio/issues/1633#issuecomment-5534919587
- change: 🔖 web_adapter v2.2.2 Triggered by @AlexV525 on https://github.com/cfug/dio/issues/1633#issuecomment-5534919587
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
cfug/dio was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 4684e29dabaa2655606f1620a4ed316ee3f8c963 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.