Skip to content
CAI
Software that uses CAICheck a score

finagle/finch

58.4

Adequate · 27 September 2026

3.9k

lines of production code

Scala

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This release delivers a comprehensive architectural overhaul of Finch's core, introducing new abstractions for HTTP handling, endpoint mapping, and streaming support. It significantly expands JSON and streaming capabilities by adding native integration with Argonaut, Circe, fs2, and Iteratee, alongside new modules for generic derivation and refined types. The update also modernizes the build and benchmarking infrastructure, while providing extensive test coverage and example applications to demonstrate the new features.

Features

Add Argonaut JSON support to Finch

Users can now encode and decode JSON using the Argonaut library. This change introduces new \Decoders\ and \Encoders\ traits that map Argonaut's \DecodeJson\ and \EncodeJson\ to Finch's \Decode\ and \Encode\ interfaces. The \package.scala\ file provides convenient access to these capabilities, including pre-configured instances for handling null keys and preserving field order.

argonaut/src/main · high confidence

Add accumulating JSON decoding and stream support for Circe

The Circe integration now supports accumulating decoders, which allow multiple validation errors to be collected rather than failing on the first error. Additionally, new stream-based decoding is available via \iterateeCirceDecoder\ and \fs2Circe\ methods, enabling efficient processing of large JSON streams. The \AccumulatingDecoders\ trait and \CirceError\ class are introduced to support these features.

circe/src/main · high confidence

Add fs2 Stream support for Finch endpoints

The fs2 integration now provides native support for streaming responses using fs2's Stream type. This change introduces implicit conversions and encoders that allow Finch endpoints to return fs2 Streams, enabling more efficient handling of large or infinite data streams. The implementation leverages cats-effect's Async type class to manage asynchronous stream processing, supporting content types such as JSON, SSE (Server-Sent Events), and plain text. This allows developers to build streaming APIs with better resource management and backpressure support compared to previous approaches.

fs2/src/main · high confidence

Add refined types support for path and entity decoding

The Finch library now includes a new 'refined' module that enables automatic decoding of HTTP path and entity data into Refined types. This allows users to leverage Refined's validation constraints directly in their API endpoints, with validation failures automatically mapped to a 'PredicateFailed' error.

refined/src/main · high confidence

Introduce generic endpoint derivation for query parameters

A new \finch-generic\ module has been added, providing automatic derivation of \Endpoint\ instances for case classes based on their field names. This allows users to generically map query string parameters to case class fields, simplifying the creation of endpoints that accept complex, nested query parameters.

generic/src/main · high confidence

Introduces internal helper classes and type classes for Finch's core

The internal package now includes several new components to support Finch's API: a \Mapper\ type class for mapping endpoints, a \PairAdjoin\ for handling singleton results, a \ParseNumber\ utility for fast string-to-number conversion, a \currentTime\ object for generating RFC-compliant date headers, a \newLine\ utility for charset-specific line breaks, and extension methods on \HttpMessage\ and \HttpContent\ for header and content handling. These additions provide the foundational building blocks for endpoint mapping, number parsing, and header formatting within the Finch core.

core/src/main/scala/io/finch/internal · high confidence

Introduces new core abstractions for HTTP handling

The core library now includes new types for handling HTTP interactions, including \Bootstrap\ for server configuration, \Compile\ for endpoint compilation, and dedicated typeclasses for decoding (\Decode\, \DecodeEntity\, \DecodePath\, \DecodeStream\) and encoding (\Encode\, \EncodeStream\) payloads. Additionally, \Accept\ models HTTP Accept headers, \Input\ wraps requests with routes, and \Output\ represents response structures, providing a more explicit and composable foundation for building endpoints.

core/src/main/scala/io/finch · high confidence

New endpoint types for request bodies, headers, cookies, and path parameters

The library introduces new endpoint implementations for extracting request bodies (including binary, string, and streaming variants), headers, cookies, and path segments. These endpoints provide a consistent, effect-agnostic way to parse and validate incoming request data, supporting both required and optional extraction patterns.

core/src/main/scala/io/finch/endpoint · high confidence

New examples for Finch applications

Added example applications demonstrating core Finch capabilities: a division service (io.finch.div), an iteratee-based streaming example (io.finch.iteratee), a middleware example with authentication and logging (io.finch.middleware), and a complete TODO application (io.finch.todo) with its HTML/JS frontend. Additionally, benchmarking examples using wrk were added for both Finagle and Finch.

examples/src/main · high confidence

Behavioural changes

Add Foo data class for Finagle benchmarks

A new benchmark data class, Foo, is introduced in the io.finch.data package. It includes implicit instances for decoding and encoding text content, enabling the benchmarking of serialization and deserialization logic for this specific data structure.

benchmarks/src/main/scala/io/finch/data · high confidence

Added iteratee-based streaming support for endpoints

The library now supports streaming responses using the Iteratee library, enabling more efficient handling of large or continuous data streams. This includes new implicit conversions for enumerators to readers, allowing endpoints to stream JSON, Server-Sent Events (SSE), and text content. The implementation leverages cats-effect's Async type class to manage asynchronous stream processing, providing a more explicit and flexible way to handle streaming in Finch applications.

iteratee/src/main · medium confidence

Centralized build script for GitHub Actions

The build process is now managed by a new \build/build.sh\ script, which replaces previous build configurations. This script handles environment-specific logic: it decrypts sensitive files (GPG keys, credentials, deploy keys) using OpenSSL, configures Git for releases on the master branch, and runs SBT commands for validation, coverage, and publishing. The script differentiates between push events on master (releases), master branch builds (SNAPSHOT), and other branch builds, ensuring consistent artifact release workflows via GitHub Actions.

build · medium confidence

Finch project maintenance and documentation overhaul

The project has been updated to version 0.35.0-SNAPSHOT and includes a comprehensive update to the README, which now features a detailed project description, installation instructions, a 'Hello World' example, performance benchmarks, and an adopters list. Additionally, the repository has been configured with a \.codecov.yml\ for coverage reporting, a \.git-blame-ignore-revs\ file to ignore auto-formatting commits, a \.gitignore\ for IDE and build artifacts, and a \.scala-steward.conf\ for dependency updates. A \scalafmt.conf\ has been added to enforce code formatting rules, and a \scalafix.conf\ has been introduced to organize imports and remove unused ones.

(repo-wide) · high confidence

Modernize Finch benchmarks with cats-effect 3.x and JMH

The benchmark suite has been modernized to use cats-effect 3.x, replacing the previous effect system. This update introduces new JMH-based benchmark classes for input parsing, body extraction, path matching, and JSON encoding/decoding, providing more accurate performance measurements for the Finch framework.

benchmarks/src/main/scala/io/finch · medium confidence

Test coverage

Add streaming tests for fs2 integration; Add tests for refined type decoding and error handling; Add tests for the examples; Added Argonaut JSON specification tests; Added JSON test infrastructure using Circe; Added comprehensive test coverage for Finch core components; Added convenience traits for testing Finagle services; Added property-based tests for generic endpoint derivation; Added streaming tests for Iteratee; Added tests for Circe integration features; Added tests for the Todo example application.

Dependencies

Updated build configuration with latest dependency versions

The build configuration has been updated to use the latest versions of key dependencies, including Finagle 24.2.0, Circe 0.14.10, Cats 2.12.0, and fs2 3.12.2, ensuring the project uses the most recent stable releases for its core libraries.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 50 → 58 (+8.8)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 96 (-3.8)
  • Architecture 88 (new)
  • Maturity 54 → 42 (-11.6)
  • Readiness 30 → 64 (+34.7)
  • Security 80 → 73 (-7.0)

Resolved (9)

  • Dimension evaluation failed
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • LLM evaluation failed
  • No automated tests
  • No exposed public API
  • No tests found
  • Rotate the exposed credentials — git history can't be un-committed
  • Test reliability not included

New (16)

  • Compile.hlistTS (cognitive 18) (core/src/main/scala/io/finch/Compile.scala)
  • Dormant codebase
  • Endpoint.coproduct (cognitive 16) (core/src/main/scala/io/finch/Endpoint.scala)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low cohesion: HttpContent (LCOM4 4) (core/src/main/scala/io/finch/internal/package.scala)
  • Medium: security finding (details withheld)
  • Most significant orphaned file (core/src/main/scala/io/finch/Endpoint.scala)
  • No SBOM
  • No build provenance
  • Off-boarding risk: anonymized user #1
  • ParseNumber.apply (cognitive 31) (core/src/main/scala/io/finch/internal/ParseNumber.scala)
  • TooManyMethods: Endpoint (core/src/main/scala/io/finch/Endpoint.scala)
  • TooManyMethods: EndpointModule (core/src/main/scala/io/finch/EndpointModule.scala)
  • Unpinned build actions
  • Workflow token permissions not restricted

Architecture

  • Containers 0 added · 0 removed · contexts 1 added · 0 removed · edges 0 added · 0 removed

Added bounded contexts (1)

  • repository

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

finagle/finch was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 5834b3c0d42f6ce14dc0ef20d550202468820bc1 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d00c643c3f66.