daltoniam/Starscream
62.4
Adequate · 27 September 2026
2.9k
lines of production code
Swift
primary language
4
measurements over time
What this system is
Features
Add SimpleTest example with WebSocket server
Added a new example project named SimpleTest, which includes a Ruby-based WebSocket server (ws-server.rb) that listens on port 8080, handles connections, and responds to messages using the em-websocket and faker libraries. The example also includes a .gitignore file for Xcode/CocoaPods and a README.md with usage instructions.
examples/SimpleTest · high confidence
Add Swift iOS example app for WebSocket testing
A new iOS example project named SimpleTest has been added to demonstrate WebSocket connectivity. The example includes an AppDelegate, an Info.plist configuration, and a ViewController that initializes a WebSocket connection to a local server, handling connection states and data reception via the Starscream library.
examples/SimpleTest/SimpleTest · high confidence
Add iOS example app for WebSocket echo
The WebSocketsOrgEcho example now includes a complete iOS application built with Swift and CocoaPods. The project integrates the Starscream library (version 3.0.6) to demonstrate a WebSocket echo client, featuring a user interface with a 'Connect' button that triggers the connection to wss://echo.websocket.org. The example includes all necessary configuration files, build scripts, and source code to run the demo on iOS devices.
examples/WebSocketsOrgEcho · high confidence
Add iOS release workflow and test lane via fastlane
Introduced a new fastlane configuration for iOS that adds a 'test' lane to run tests on specific devices and a 'release' lane to automate version bumping, GitHub releases, and CocoaPods pushing. The accompanying README documents these new fastlane actions for users.
fastlane · high confidence
Added Autobahn WebSocket conformance test suite
The AutobahnTest example project has been added, providing a complete Xcode project for running the Autobahn test suite against the Starscream library. This includes the necessary Swift source files, storyboards, and configuration to execute WebSocket conformance tests on iOS.
examples/AutobahnTest · high confidence
Added Network.framework-based WebSocket server implementation
A new WebSocket server implementation using Apple's Network.framework is now available for iOS 12.0+, macOS 10.14+, and tvOS 12.0+. This introduces new types including \WebSocketServer\, \ServerConnection\, and associated protocols and enums (\ServerEvent\, \ConnectionEvent\) to handle server-side WebSocket connections, enabling developers to build WebSocket servers on modern Apple platforms.
Sources/Server · high confidence
Added SimpleTest Xcode project for the example app
A new Xcode project file (project.pbxproj) was added for the SimpleTest example, configuring the build for the Starscream framework. This provides a ready-to-open project for developers to run the example application.
examples/SimpleTest/SimpleTest.xcodeproj · high confidence
Added SimpleTest example with navigation controller and test view
A new example application, SimpleTest, has been added to the repository. This includes a Main.storyboard defining a navigation controller that presents a 'Test' view controller. The test view features a navigation bar with 'Disconnect' and 'Write Text' action buttons, providing a concrete example of the library's usage.
examples/SimpleTest/SimpleTest/Base.lproj · high confidence
Introduce FoundationTransport and TCPTransport transport implementations
Added new transport layer implementations: FoundationTransport, which uses CFStream for network communication, and TCPTransport, which leverages Apple's Network framework (available on macOS 10.14+, iOS 12.0+, watchOS 5.0+, tvOS 12.0+). These new classes implement the Transport protocol, providing a modern, secure foundation for WebSocket connections with support for TLS and certificate pinning. The changes also include the Transport protocol definition and ConnectionState enum to manage connection states.
Sources/Transport · high confidence
Introduce WebSocket compression support
Added new \Compression.swift\ and \WSCompression.swift\ files that implement the RFC 7692 compression extensions for WebSocket. This introduces a \CompressionHandler\ protocol and a \WSCompression\ class that manages header-based configuration for compressor and decompressor instances, enabling compressed data transfer over WebSocket connections.
Sources/Compression · high confidence
Introduction of a pluggable engine architecture for WebSocket connections
The library now supports multiple WebSocket engine implementations through a new \Engine\ protocol and \EngineDelegate\ interface. This change introduces \NativeEngine\ (using Apple's \URLSessionWebSocketTask\ for iOS 13+/macOS 10.15+) and \WSEngine\ (the previous implementation) as interchangeable backends. Users can now choose between the native, higher-performance engine or the legacy engine, allowing for backward compatibility and access to newer platform features.
Sources/Engine · high confidence
New Foundation-based HTTP and WebSocket framing implementation
The library now includes a new \FoundationHTTPHandler\ that uses Apple's \CFHTTPMessage\ APIs to handle HTTP upgrades and WebSocket framing, providing a native Foundation-based alternative to the existing string-based parsing. This is accompanied by new \FrameCollector\ and \WSFramer\ components that manage WebSocket frame assembly, compression, and error handling, while also introducing \FoundationHTTPServerHandler\ for server-side HTTP parsing. These changes introduce a new path for handling network data that may affect how headers, cookies, and frame boundaries are processed, potentially altering behavior for users relying on the previous string-based HTTP handler or manual frame assembly.
Sources/Framer · high confidence
Behavioural changes
Added Xcode scheme for the Starscream framework and its tests
A new Xcode scheme file (Starscream.xcscheme) was added to the project, defining build, test, launch, profile, analyze, and archive actions for the Starscream framework and its associated test bundle. This ensures that the project can be built, tested, and archived directly from Xcode's scheme interface.
Starscream.xcodeproj/xcshareddata · high confidence
Added certificate pinning and header validation support
Users can now enforce certificate pinning and validate WebSocket handshake headers. The new \CertificatePinning\ protocol and \FoundationSecurity\ implementation allow applications to verify server trust and reject invalid responses, while the \HeaderValidator\ protocol ensures the \Sec-WebSocket-Accept\ header matches the expected value, improving security against man-in-the-middle attacks.
Sources/Security · medium confidence
Added iOS 12.1+ privacy manifest and standard Info.plist
The Sources directory now includes a PrivacyInfo.xcprivacy file declaring no tracked data or API access, satisfying Apple's App Privacy Manifest requirements. Additionally, a standard Info.plist was added to define bundle identifiers, package types, and versioning metadata for the framework.
Sources · high confidence
Refactored WebSocket client with modern Swift protocols and dual-engine support
The WebSocket client has been refactored to use the \WebSocketClient\ protocol and \WebSocketDelegate\ interface, providing a more modern and testable API. The implementation now supports both the native Apple Network framework engine (on iOS 13+/macOS 10.15+) and the legacy Foundation-based engine, automatically selecting the appropriate backend based on the target platform. This change introduces a \peerClosed\ event to better signal when the remote peer closes the connection, and allows users to specify a custom engine or certificate pinning strategy during initialization.
Sources/Starscream · high confidence
Swift 5 compatibility for Data extensions
Added Swift 5-specific overloads for \withUnsafeBytes\ and \withUnsafeMutableBytes\ on \Data\ to resolve deprecation warnings and ensure compatibility with Swift 5. These extensions provide the necessary unsafe byte access methods required by the library.
Sources/DataBytes · medium confidence
Updated SimpleTest example project configuration
The SimpleTest example project has been updated with new Xcode workspace and scheme configuration files. These changes ensure the example builds and runs correctly within the current development environment, supporting the latest Xcode tooling and project structure requirements.
examples/SimpleTest/SimpleTest.xcodeproj/project.xcworkspace · medium confidence
Updated project documentation and configuration files
The project's README has been significantly expanded to include comprehensive usage examples, covering connection setup, data handling, and configuration options. Additionally, the .gitignore file was updated to include Carthage build directories, and the LICENSE file was updated with the current copyright years.
(repo-wide) · high confidence
Updated project file with modern build settings and structure
The Xcode project file (project.pbxproj) has been updated to objectVersion 54 and includes a reorganized source tree with dedicated groups for Engine, Transport, Compression, and Security modules. The build configuration now explicitly links libz.tbd and includes a PrivacyInfo.xcprivacy file for iOS 14+ privacy manifest requirements. These changes reflect a structural update to the project configuration rather than a change in the library's public API or runtime behavior.
Starscream.xcodeproj · medium confidence
Test coverage
Added initial test suite for Starscream; Added unit tests for compression, fuzzing, and mock server transport.
Dependencies
Add CocoaPods and Swift Package Manager support for Starscream
The project now supports installation via CocoaPods and Swift Package Manager (SPM). A new \Starscream.podspec\ file defines the CocoaPod, specifying Swift 5.0 and minimum deployment targets for iOS 12.0, macOS 10.13, tvOS 12.0, and watchOS 2.0. For SPM, a \Package.swift\ file is added, configuring the 'Starscream' library target and conditionally including the 'swift-nio-zlib-support' dependency on Linux. Additionally, a \Gemfile\ and \Gemfile.lock\ are introduced to manage Ruby dependencies like fastlane and cocoapods for the build and release process.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 44 → 62 (+18.7)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 95 (-5.2)
- Architecture 98 (new)
- Maturity 55 → 53 (-2.9)
- Readiness 24 → 61 (+36.8)
- Security 57 → 69 (+12.5)
Resolved (7)
- Dimension evaluation failed
- High: security finding (details withheld)
- High: security finding (details withheld)
- No automated tests
- No exposed public API
- No tests found
- Test reliability not included
New (51)
- Coverage not measured — Swift suite
- Duplicate functionality across types. Decompression logic is exposed on the dedicated CompressionHandler, the Engine, and the ServerConnection. This suggests a leaky abstraction where the Engine and ServerConnection are exposing internal implementation details (decompression) that should be handled internally or via a unified interface.
- Duplicated block (15 lines × 2) (Sources/Framer/FoundationHTTPHandler.swift)
- Duplicated block (8 lines × 2) (Sources/Framer/FoundationHTTPHandler.swift)
- Edited copy of a member (17 corresponding lines) (Sources/Framer/FoundationHTTPHandler.swift)
- FoundationTransport.stream (cognitive 19) (Sources/Transport/FoundationTransport.swift)
- FrameCollector.add (cognitive 21) (Sources/Framer/FrameCollector.swift)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Inconsistent naming for termination operations. The public API exposes 'disconnect' and 'forceDisconnect' on the high-level WebSocket type, while the underlying Engine types use 'stop' and 'forceStop'. This creates confusion about whether these are distinct operations or synonyms.
- Low cohesion: ViewController (LCOM4 5) (examples/WebSocketsOrgEcho/WebSocketsOrgEcho/ViewController.swift)
- Medium CVE: [GHSA redacted] (Gemfile.lock)
- Medium CVE: [GHSA redacted] (Gemfile.lock)
- Medium CVE: [GHSA redacted] (Gemfile.lock)
- …and 31 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
daltoniam/Starscream was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit c6bfd1af48efcc9a9ad203665db12375ba6b145a — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-d00c643c3f66.