Skip to content
CAI
Software that uses CAICheck a score

daltoniam/Starscream

62.4

Adequate · 27 September 2026

2.9k

lines of production code

Swift

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Add SimpleTest example with WebSocket server

Added a new example project named SimpleTest, which includes a Ruby-based WebSocket server (ws-server.rb) that listens on port 8080, handles connections, and responds to messages using the em-websocket and faker libraries. The example also includes a .gitignore file for Xcode/CocoaPods and a README.md with usage instructions.

examples/SimpleTest · high confidence

Add Swift iOS example app for WebSocket testing

A new iOS example project named SimpleTest has been added to demonstrate WebSocket connectivity. The example includes an AppDelegate, an Info.plist configuration, and a ViewController that initializes a WebSocket connection to a local server, handling connection states and data reception via the Starscream library.

examples/SimpleTest/SimpleTest · high confidence

Add iOS example app for WebSocket echo

The WebSocketsOrgEcho example now includes a complete iOS application built with Swift and CocoaPods. The project integrates the Starscream library (version 3.0.6) to demonstrate a WebSocket echo client, featuring a user interface with a 'Connect' button that triggers the connection to wss://echo.websocket.org. The example includes all necessary configuration files, build scripts, and source code to run the demo on iOS devices.

examples/WebSocketsOrgEcho · high confidence

Add iOS release workflow and test lane via fastlane

Introduced a new fastlane configuration for iOS that adds a 'test' lane to run tests on specific devices and a 'release' lane to automate version bumping, GitHub releases, and CocoaPods pushing. The accompanying README documents these new fastlane actions for users.

fastlane · high confidence

Added Autobahn WebSocket conformance test suite

The AutobahnTest example project has been added, providing a complete Xcode project for running the Autobahn test suite against the Starscream library. This includes the necessary Swift source files, storyboards, and configuration to execute WebSocket conformance tests on iOS.

examples/AutobahnTest · high confidence

Added Network.framework-based WebSocket server implementation

A new WebSocket server implementation using Apple's Network.framework is now available for iOS 12.0+, macOS 10.14+, and tvOS 12.0+. This introduces new types including \WebSocketServer\, \ServerConnection\, and associated protocols and enums (\ServerEvent\, \ConnectionEvent\) to handle server-side WebSocket connections, enabling developers to build WebSocket servers on modern Apple platforms.

Sources/Server · high confidence

Added SimpleTest Xcode project for the example app

A new Xcode project file (project.pbxproj) was added for the SimpleTest example, configuring the build for the Starscream framework. This provides a ready-to-open project for developers to run the example application.

examples/SimpleTest/SimpleTest.xcodeproj · high confidence

Added SimpleTest example with navigation controller and test view

A new example application, SimpleTest, has been added to the repository. This includes a Main.storyboard defining a navigation controller that presents a 'Test' view controller. The test view features a navigation bar with 'Disconnect' and 'Write Text' action buttons, providing a concrete example of the library's usage.

examples/SimpleTest/SimpleTest/Base.lproj · high confidence

Introduce FoundationTransport and TCPTransport transport implementations

Added new transport layer implementations: FoundationTransport, which uses CFStream for network communication, and TCPTransport, which leverages Apple's Network framework (available on macOS 10.14+, iOS 12.0+, watchOS 5.0+, tvOS 12.0+). These new classes implement the Transport protocol, providing a modern, secure foundation for WebSocket connections with support for TLS and certificate pinning. The changes also include the Transport protocol definition and ConnectionState enum to manage connection states.

Sources/Transport · high confidence

Introduce WebSocket compression support

Added new \Compression.swift\ and \WSCompression.swift\ files that implement the RFC 7692 compression extensions for WebSocket. This introduces a \CompressionHandler\ protocol and a \WSCompression\ class that manages header-based configuration for compressor and decompressor instances, enabling compressed data transfer over WebSocket connections.

Sources/Compression · high confidence

Introduction of a pluggable engine architecture for WebSocket connections

The library now supports multiple WebSocket engine implementations through a new \Engine\ protocol and \EngineDelegate\ interface. This change introduces \NativeEngine\ (using Apple's \URLSessionWebSocketTask\ for iOS 13+/macOS 10.15+) and \WSEngine\ (the previous implementation) as interchangeable backends. Users can now choose between the native, higher-performance engine or the legacy engine, allowing for backward compatibility and access to newer platform features.

Sources/Engine · high confidence

New Foundation-based HTTP and WebSocket framing implementation

The library now includes a new \FoundationHTTPHandler\ that uses Apple's \CFHTTPMessage\ APIs to handle HTTP upgrades and WebSocket framing, providing a native Foundation-based alternative to the existing string-based parsing. This is accompanied by new \FrameCollector\ and \WSFramer\ components that manage WebSocket frame assembly, compression, and error handling, while also introducing \FoundationHTTPServerHandler\ for server-side HTTP parsing. These changes introduce a new path for handling network data that may affect how headers, cookies, and frame boundaries are processed, potentially altering behavior for users relying on the previous string-based HTTP handler or manual frame assembly.

Sources/Framer · high confidence

Behavioural changes

Added Xcode scheme for the Starscream framework and its tests

A new Xcode scheme file (Starscream.xcscheme) was added to the project, defining build, test, launch, profile, analyze, and archive actions for the Starscream framework and its associated test bundle. This ensures that the project can be built, tested, and archived directly from Xcode's scheme interface.

Starscream.xcodeproj/xcshareddata · high confidence

Added certificate pinning and header validation support

Users can now enforce certificate pinning and validate WebSocket handshake headers. The new \CertificatePinning\ protocol and \FoundationSecurity\ implementation allow applications to verify server trust and reject invalid responses, while the \HeaderValidator\ protocol ensures the \Sec-WebSocket-Accept\ header matches the expected value, improving security against man-in-the-middle attacks.

Sources/Security · medium confidence

Added iOS 12.1+ privacy manifest and standard Info.plist

The Sources directory now includes a PrivacyInfo.xcprivacy file declaring no tracked data or API access, satisfying Apple's App Privacy Manifest requirements. Additionally, a standard Info.plist was added to define bundle identifiers, package types, and versioning metadata for the framework.

Sources · high confidence

Refactored WebSocket client with modern Swift protocols and dual-engine support

The WebSocket client has been refactored to use the \WebSocketClient\ protocol and \WebSocketDelegate\ interface, providing a more modern and testable API. The implementation now supports both the native Apple Network framework engine (on iOS 13+/macOS 10.15+) and the legacy Foundation-based engine, automatically selecting the appropriate backend based on the target platform. This change introduces a \peerClosed\ event to better signal when the remote peer closes the connection, and allows users to specify a custom engine or certificate pinning strategy during initialization.

Sources/Starscream · high confidence

Swift 5 compatibility for Data extensions

Added Swift 5-specific overloads for \withUnsafeBytes\ and \withUnsafeMutableBytes\ on \Data\ to resolve deprecation warnings and ensure compatibility with Swift 5. These extensions provide the necessary unsafe byte access methods required by the library.

Sources/DataBytes · medium confidence

Updated SimpleTest example project configuration

The SimpleTest example project has been updated with new Xcode workspace and scheme configuration files. These changes ensure the example builds and runs correctly within the current development environment, supporting the latest Xcode tooling and project structure requirements.

examples/SimpleTest/SimpleTest.xcodeproj/project.xcworkspace · medium confidence

Updated project documentation and configuration files

The project's README has been significantly expanded to include comprehensive usage examples, covering connection setup, data handling, and configuration options. Additionally, the .gitignore file was updated to include Carthage build directories, and the LICENSE file was updated with the current copyright years.

(repo-wide) · high confidence

Updated project file with modern build settings and structure

The Xcode project file (project.pbxproj) has been updated to objectVersion 54 and includes a reorganized source tree with dedicated groups for Engine, Transport, Compression, and Security modules. The build configuration now explicitly links libz.tbd and includes a PrivacyInfo.xcprivacy file for iOS 14+ privacy manifest requirements. These changes reflect a structural update to the project configuration rather than a change in the library's public API or runtime behavior.

Starscream.xcodeproj · medium confidence

Test coverage

Added initial test suite for Starscream; Added unit tests for compression, fuzzing, and mock server transport.

Dependencies

Add CocoaPods and Swift Package Manager support for Starscream

The project now supports installation via CocoaPods and Swift Package Manager (SPM). A new \Starscream.podspec\ file defines the CocoaPod, specifying Swift 5.0 and minimum deployment targets for iOS 12.0, macOS 10.13, tvOS 12.0, and watchOS 2.0. For SPM, a \Package.swift\ file is added, configuring the 'Starscream' library target and conditionally including the 'swift-nio-zlib-support' dependency on Linux. Additionally, a \Gemfile\ and \Gemfile.lock\ are introduced to manage Ruby dependencies like fastlane and cocoapods for the build and release process.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 44 → 62 (+18.7)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 95 (-5.2)
  • Architecture 98 (new)
  • Maturity 55 → 53 (-2.9)
  • Readiness 24 → 61 (+36.8)
  • Security 57 → 69 (+12.5)

Resolved (7)

  • Dimension evaluation failed
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No automated tests
  • No exposed public API
  • No tests found
  • Test reliability not included

New (51)

  • Coverage not measured — Swift suite
  • Duplicate functionality across types. Decompression logic is exposed on the dedicated CompressionHandler, the Engine, and the ServerConnection. This suggests a leaky abstraction where the Engine and ServerConnection are exposing internal implementation details (decompression) that should be handled internally or via a unified interface.
  • Duplicated block (15 lines × 2) (Sources/Framer/FoundationHTTPHandler.swift)
  • Duplicated block (8 lines × 2) (Sources/Framer/FoundationHTTPHandler.swift)
  • Edited copy of a member (17 corresponding lines) (Sources/Framer/FoundationHTTPHandler.swift)
  • FoundationTransport.stream (cognitive 19) (Sources/Transport/FoundationTransport.swift)
  • FrameCollector.add (cognitive 21) (Sources/Framer/FrameCollector.swift)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Inconsistent naming for termination operations. The public API exposes 'disconnect' and 'forceDisconnect' on the high-level WebSocket type, while the underlying Engine types use 'stop' and 'forceStop'. This creates confusion about whether these are distinct operations or synonyms.
  • Low cohesion: ViewController (LCOM4 5) (examples/WebSocketsOrgEcho/WebSocketsOrgEcho/ViewController.swift)
  • Medium CVE: [GHSA redacted] (Gemfile.lock)
  • Medium CVE: [GHSA redacted] (Gemfile.lock)
  • Medium CVE: [GHSA redacted] (Gemfile.lock)
  • …and 31 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

daltoniam/Starscream was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit c6bfd1af48efcc9a9ad203665db12375ba6b145a — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d00c643c3f66.