falcoframework/Falco
68.1
Adequate · 23 September 2026
2.6k
lines of production code
F#
primary language
5
measurements over time
What this system is
Falco is an F\# web framework for ASP.NET Core that provides a structured approach to building HTTP services. It features a comprehensive routing API, automatic CSRF validation, and request body size limiting. The system supports diverse response types including HTML, JSON, and binary data, with examples demonstrating integration with SQLite, external template engines, and dependency injection.
How it got here
2020–2021 — Falco framework v6.0.0 release
6 changes.
This period was defined by the release of Falco 6.0.0, which introduced a comprehensive new HTTP handling and routing API alongside automatic CSRF validation and request size limits. The update also included a major dependency upgrade to .NET 10 and added extensive test coverage for the new core modules.
2022–2025 — Example expansion and documentation
12 changes.
This period focused on expanding the project's example suite to demonstrate various integration patterns, including ASP.NET Core MVC, SQLite, dependency injection, external view engines, and OpenAPI. The documentation site was also redesigned to better showcase these new examples and security features.
Features
Add External View Engine example using Scriban templates
A new example project, ExternalViewEngine, demonstrates how to integrate an external template engine (Scriban) with Falco. It defines an ITemplate interface and a ScribanTemplate implementation, registers the template service via dependency injection, and shows how to render HTML pages using Scriban templates within Falco HTTP handlers.
examples/ExternalViewEngine · high confidence
Add F\# ASP.NET Core MVC example with HTML, JSON, and plain text greetings
A new example project, HelloWorldMvc, has been added to demonstrate an ASP.NET Core application built with F\#. It showcases a multi-format greeting service that renders responses in HTML, JSON, and plain text, along with explicit error handling for 404 and 500 status codes.
HelloWorldMvc · high confidence
Add Falco dependency injection example
Added a new example demonstrating how to integrate the Falco framework with .NET's built-in dependency injection container. The example shows registering a singleton service (IGreeter) and resolving it within a route handler using the ctx.Plug method.
examples/DependencyInjection · medium confidence
Introduce core HTTP handling, request parsing, and response generation modules
The Falco framework now provides a comprehensive set of modules for building HTTP applications. The new \Core\ module defines the \HttpHandler\ type and \HttpVerb\ enum. \Request.fs\ and \RequestData.fs\ add functions to parse request bodies, headers, cookies, and form data (including streaming support for multipart uploads), with configurable size limits and automatic CSRF validation. \Response.fs\ introduces handlers for generating text, HTML, and binary responses, as well as redirects. \Security.fs\ provides utilities for generating and validating anti-forgery tokens. \Multipart.fs\ implements efficient streaming of form data and files. \WebApplication.fs\ adds extension methods to integrate Falco with the ASP.NET Core pipeline, including endpoint registration and exception handling.
src/Falco · high confidence
New BasicRestApi example using SQLite
A new example, BasicRestApi, has been added to demonstrate a REST API built with Falco and SQLite. The example implements a user store with CRUD operations (list, create, read, delete) backed by an in-memory or file-based SQLite database, exposing endpoints for managing user data.
BasicRestApi · high confidence
New htmx example demonstrating fragment responses
Added a new htmx example in the examples/Htmx directory that demonstrates using fragment responses via Falco.Markup. The example includes Htmx.fs and appsettings.json, showcasing a click-and-swap interaction where the /reset endpoint returns a fragment response for the 'clicker' element, while other endpoints return full HTML. This provides a concrete reference for implementing htmx-based interactions with fragment responses.
examples/Htmx · medium confidence
New routing API with HTTP verb-specific and mapped route constructors
The Falco library introduces a new routing module (src/Falco/Routing.fs) that provides a comprehensive set of functions for defining HTTP endpoints. This includes constructors for each standard HTTP verb (GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS, TRACE) as well as an 'any' method for all verbs. Additionally, 'map' variants are provided for each verb, allowing developers to extract and pass route data into their handlers via the HttpContext. This represents a significant expansion of the routing capabilities, moving towards a more explicit and structured approach to defining routes.
Falco · high confidence
New solution file for the examples project
A new solution file, Falco.Examples.sln, has been added to the examples directory. This file defines the build configuration for the examples, including projects such as BasicRestApi, Falco, Htmx, HelloWorldMvc, HelloWorld, DependencyInjection, OpenApi, and ExternalViewEngine, each with their respective .fsproj files and build configurations for Debug and Release modes.
examples · high confidence
Redesign of the Falco documentation site with new navigation and layout
The documentation site has been rebuilt using the Falco.Markup module, introducing a new two-column layout and a structured navigation menu. The header now displays the site title derived from the first H1 heading in each document, and the sidebar includes dedicated sections for Security (Authentication & Authorization, Cross-Site Request Forgery) and Examples. The site also integrates Google Analytics and updates the footer copyright year.
Site · high confidence
Behavioural changes
Add OpenAPI example demonstrating Fortune API
A new example project at examples/OpenApi/OpenApi.fs has been added, showcasing the integration of Falco's OpenAPI support. This example configures a web application to generate and serve Swagger/OpenAPI documentation for a 'Fortune' endpoint, illustrating how to define routes, request/response types, and metadata such as name, summary, and description within the OpenAPI specification.
OpenApi · medium confidence
HelloWorld example updated to use new Run extension
The HelloWorld example in the examples/HelloWorld directory has been updated to use the new run extension, reflecting changes in the framework's API. The example now utilizes the updated routing and Falco integration, demonstrating the latest patterns for setting up a basic web application.
examples/HelloWorld · medium confidence
HelloWorldMvc example adds logging config and custom styling
The HelloWorldMvc example now includes an appsettings.json file that configures the default logging level to Information, and a wwwroot/style.css file that applies a Comic Sans MS font to the body. These additions provide basic logging configuration and a distinct visual style for the example application.
examples/HelloWorldMvc · medium confidence
Release 6.0.0 introduces automatic CSRF validation and request body size limits
The 6.0.0 release changes how form submissions are handled: \Request.getForm\ now automatically performs CSRF validation if antiforgery services are registered and the request method is POST, PUT, PATCH, or DELETE, returning an option of \FormData\ on failure. This replaces the previous explicit \Request.getFormSecure\ and \Request.mapFormSecure\ methods, which have been removed. Additionally, new configuration options \Request.getBodyStringOptions\ and \Request.getFormOptions\ allow setting maximum request body and form sizes (defaulting to 32MB).
(repo-wide) · high confidence
Test coverage
Added comprehensive tests for request, response, routing, and multipart handling; Added integration test application for Falco; Added integration tests for HTTP endpoints and antiforgery handling; Added test utilities for HTTP context and authentication.
Dependencies
Upgrade to .NET 10 and update package dependencies
The project files have been updated to target .NET 10.0, with the main library (Falco) now supporting net8.0, net9.0, and net10.0. Additionally, several package references have been updated or added, including Falco.Markup 1.4.\, FSharp.Core 6.0.0, and various test dependencies such as FsUnit.Xunit 6.\, xUnit 2.\, and NSubstitute 5.\.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 61 → 68 (+6.8)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 97 → 97 (+0.0)
- Architecture 100 → 89 (-11.2)
- Maturity 54 → 66 (+11.3)
- Readiness 58 → 59 (+0.8)
- Security 59 → 83 (+24.5)
Resolved (18)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Low coverage: Core.fs (src/Falco/Core.fs)
- Low coverage: Multipart.fs (src/Falco/Multipart.fs)
- Low coverage: Request.fs (src/Falco/Request.fs)
- Low coverage: RequestData.fs (src/Falco/RequestData.fs)
- Low coverage: RequestValue.fs (src/Falco/RequestValue.fs)
- Low coverage: Response.fs (src/Falco/Response.fs)
- Low coverage: WebApplication.fs (src/Falco/WebApplication.fs)
- No exposed public API
- Off-boarding risk: anonymized user #1
- Test reliability not included
- The README installs Falco.Template and shows a dotnet new install command, but no manual-install alternative is shown in the body (the 'Manually installing' section does exist). (docs/docs/get-started.html)
- The welcome page links only to 'Getting Started' but the README's learn section already directs readers to documentation at falcoframework.com/docs. (docs/docs/index.html)
New (10)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- No dependency advisory monitoring
- Scattered collaborators
Architecture
- Containers 0 added · 0 removed · contexts 0 added · 8 removed · edges 0 added · 1 removed
Removed bounded contexts (8)
- BasicRestApi
- Falco
- Falco.IntegrationTests
- Falco.IntegrationTests.App
- Falco.Tests
- HelloWorldMvc
- OpenApi
- Site
Removed dependency edges (was a dependency, now gone) (1)
- Falco.IntegrationTests → Falco.IntegrationTests.App
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
falcoframework/Falco was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit d768bc5f512aeb372227d81646ec3dee2522df63 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.