forwardemail/superagent
53.2
Adequate · 1 October 2026
4.2k
lines of production code
JavaScript
primary language
2
measurements over time
What this system is
This system is a modernized HTTP client library for Node.js and browsers, designed to handle GET, POST, and other HTTP requests with robust form and JSON serialization. It features a rewritten core architecture that enforces strict security practices, including hardened redirect handling, safe cookie scoping, and protection against prototype pollution. The library supports advanced capabilities such as HTTP/2 connections, Brotli compression, and persistent agent sessions for managing state across multiple requests.
How it got here
2011 — Build infrastructure modernization
6 changes.
The project overhauled its build infrastructure by replacing the legacy Makefile system with a Babel-based pipeline and modern tooling like ESLint and Commitlint. This structural shift included dropping support for older Node.js versions and removing internal source files to streamline the architecture. Concurrently, the test suite was comprehensively rewritten using native assertions and expanded to cover new features like HTTPS client certificates and HTTP/2 support.
2013–2018 — HTTP/2 support and test infrastructure
4 changes.
This period focused on expanding test coverage for core HTTP functionality, including request handling, serialization, and cross-domain behavior. Significant effort was dedicated to establishing a robust test infrastructure that supports both HTTP/1.1 and HTTP/2, enabling validation of new protocol features and server-side interactions.
2019–2022 — HTTP client modernization and security hardening
4 changes.
The core HTTP client was completely rewritten to improve maintainability, security, and performance, introducing modern ES6 classes, HTTP/2 support, and hardened protections against session fixation and prototype pollution. The Node.js implementation was updated to use WHATWG URL APIs and enforce strict cookie scoping, while the build process was refined with updated Husky hooks and CI scripts to manage dependency compatibility across Node.js versions.
Features
Added simple GET request example
A new example file (examples/simple-get.js) has been added to demonstrate making a simple HTTP GET request using the library. The example fetches content from a specific Gist URL and logs the response text to the console, providing a basic usage pattern for users.
examples · high confidence
Modern rewrite and refactoring of core HTTP client
The library has been completely rewritten to improve maintainability and security. The new architecture introduces a dedicated Agent class for managing request defaults and a unified RequestBase for shared Node/browser functionality. Security is strengthened by hardening redirects, response handling, and cookie scoping against hostile servers, and by preventing prototype pollution via safe key checks. Users also gain support for Brotli compression, a custom JSON encoder (fast-safe-stringify) to handle BigInts safely, and more robust timeout and retry mechanisms.
src · high confidence
Modernized Node.js HTTP client implementation with hardened security and HTTP/2 support
The Node.js-specific request handling has been rewritten to use modern ES6 classes and WHATWG URL APIs, replacing deprecated methods like \url.parse()\. This update introduces a new \Agent\ class that enforces strict cookie scoping per RFC 6265 to prevent session fixation attacks across redirects, and adds native support for HTTP/2 connections via \http2wrapper\. The decompression layer now supports Brotli encoding alongside Gzip/Deflate, and the JSON parser preserves the original HTTP status code and headers on parse failures. Additionally, the implementation ensures proper resource disposal of underlying sockets and HTTP/2 sessions when request setup fails, and fixes IPv6 address handling in HTTP/2 requests.
src/node · high confidence
Removals
Removal of internal EventEmitter and Superagent source files
The internal \lib/events.js\ EventEmitter implementation and the \lib/superagent.js\ source file have been deleted from the library. This change removes the bundled event-emitting logic and the core HTTP client implementation code that was previously maintained within these specific library files, likely as part of a refactoring to externalize these dependencies or restructure the module architecture.
lib · high confidence
Architecture
Repository modernization and build infrastructure overhaul
The project has undergone a significant structural modernization, replacing the legacy build system with a standardized, tooling-driven workflow. The old Makefile-based build process and pre-generated distribution files (superagent.js, superagent.min.js) have been removed in favor of a Babel-based compilation pipeline configured via separate .babelrc files for the library, distribution, and test targets. Code quality is now enforced through ESLint (with node and browser environments), Prettier, and XO, while commit messages are validated using Commitlint. Browser support is explicitly defined in .browserslistrc (excluding IE 11) and tested via Zuul, with CI migrated to Travis CI for Node 14, 16, and 18. Documentation has been consolidated into a new README.md and index.html, and legacy files like History.md and Readme.md have been removed.
(repo-wide) · high confidence
Behavioural changes
CI script removes unsupported dev dependencies for older Node.js versions
A new CI script (ci/remove-deps-4-old-node.js) has been added to automatically remove specific development dependencies from package.json when running on older Node.js versions. The script targets a predefined set of packages including @commitlint/cli, eslint, husky, lint-staged, and xo, setting their values to undefined in the devDependencies section to prevent compatibility issues during CI builds.
ci · high confidence
Updated Husky pre-commit and commit-msg hooks
The .husky directory now contains explicit shell scripts for pre-commit and commit-msg hooks. The pre-commit hook runs \npx lint-staged\, and the commit-msg hook runs \npx commitlint --edit $1\. This replaces previous configurations, ensuring these linting checks are executed via npx directly from the hooks.
.husky · high confidence
Test coverage
Added HTTP/2 test support utilities for Express; Added client-side unit tests for request handling, serialization, and cross-domain behavior; Added test fixtures for HTTPS client certificate authentication and sample user data; Comprehensive Node.js test suite rewrite; Comprehensive test suite for request, agent, and form handling; New test support infrastructure for HTTP/2 and shared server setup.
Dependencies
Superagent v10.4.1 release with modernized dependencies and Node 14+ requirement
Superagent has been updated to version 10.4.1, introducing a comprehensive overhaul of its dependency tree and build configuration. The package now requires Node.js 14.18.0 or later, dropping support for older versions. Key dependency updates include form-data to ^4.0.5, formidable to ^3.5.4, qs to ^6.14.1, and mime to 2.6.0, alongside significant upgrades to development tools such as Babel 7, ESLint 8, and Mocha 6.2.3. The release also adds browser-specific build scripts and configuration, including browserify and babelify integration, to support client-side usage via jsDelivr and unpkg.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 52 → 53 (+1.4)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 48 → 47 (-1.2)
- Architecture 93 → 94 (+1.1)
- Maturity 54 → 56 (+1.4)
- Readiness 46 → 48 (+1.8)
- Security 71 → 77 (+5.9)
- Accessibility 72 → 72 (+0.0)
- Performance 100 (new)
Resolved (23)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no contributor guidance (README.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Request (cognitive 17) (src/client.js)
- _end (cognitive 116) (src/node/index.js)
- _end (cyclomatic 35) (src/client.js)
- _end (cyclomatic 74) (src/node/index.js)
- _shouldRetry (cognitive 20) (src/request-base.js)
- _shouldRetry (cyclomatic 16) (src/request-base.js)
- callback (cognitive 23) (src/node/index.js)
- callback (cyclomatic 16) (src/node/index.js)
- field (cognitive 20) (src/request-base.js)
- request (cognitive 43) (src/node/index.js)
- …and 3 more
New (34)
- Documentation: no architecture or design documentation (docs/index.md)
- Documentation: no usage examples (docs/index.md)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Hotspot: src/client.js (src/client.js)
- Hotspot: src/node/index.js (src/node/index.js)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Off-boarding risk: anonymized user #1
- Outdated (npm): component-emitter
- Outdated (npm): form-data
- Outdated (npm): mime
- Outdated (npm): qs
- Repeated repair: src/node/http2wrapper.js (src/node/http2wrapper.js)
- Skipped (documented): should follow a relative redirect within the same Unix domain socket (test/node/security.js)
- Skipped (documented): should not follow a redirect from one Unix domain socket to another (test/node/security.js)
- Skipped (documented): should not follow a redirect into a Unix domain socket (test/node/security.js)
- Skipped (documented): should reject the promise for a redirect into a Unix domain socket (test/node/security.js)
- …and 14 more
Changes since last survey
- 9 commits — 2 feature/other, 7 fixes
By area
- (root) — 3 commits
- (repo) — 2 commits
- src/node — 2 commits
- test/node — 2 commits
Notable commits
- fix: Merge pull request #1852 from official-burak/fix/max-response-size-double-callback
- fix: Merge pull request #1859 from dyk1454683243-sudo/cursor/fix-request-dispose-error-efa5
- fix: fix(ci): restore matrix installs and stabilize HTTP2 pipe test
- fix: fix(node): handle early streamed responses and multipart length errors
- fix: fix: consolidate safe request, redirect, and CI regressions
- fix: fix: dispose request on header and request-path errors
- fix: fix: harden redirects, response handling and cookie scoping against hostile servers
- change: 10.4.0
- change: 10.4.1
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
forwardemail/superagent was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit d73b68f942c96cb8f61fe1d53600ceadc6d381b6 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.