forwardemail/supertest
49.6
Weak · 1 October 2026
1k
lines of production code
JavaScript
primary language
2
measurements over time
What this system is
This system is a Node.js HTTP testing library built on SuperAgent, designed to facilitate integration testing for web applications. It provides capabilities for making HTTP requests, managing server lifecycles, and asserting on responses, with specific support for HTTP/2, HTTPS, and detailed cookie validation. The library also includes utilities for handling authentication cookies and ensures compatibility across various Node.js versions through its CI infrastructure.
Features
Add cookie assertion module for validating request and response cookies
The lib/cookies directory now includes a new assertion module (assertion.js) and an entry point (index.js) that allows users to validate cookie properties in HTTP requests and responses. This module provides functions to assert the presence or absence of specific cookie properties, check for equality or inequality of cookie values, and verify cookie options such as domain, path, expires, max-age, secure, and httponly. The assertion module uses the cookie-signature library for signature verification and supports both array and object formats for specifying expected properties. This enables more robust testing and validation of cookie handling in applications.
lib/cookies · high confidence
Behavioural changes
CI script to downgrade dependencies for older Node.js versions
A new CI script (ci/remove-deps-4-old-node.js) has been added to modify package.json before running tests on older Node.js environments. The script downgrades specific devDependencies (eslint to undefined, mocha to 6.x) and removes the lint script to ensure compatibility with unsupported Node versions.
ci · high confidence
HTTP/2 support and refactored API surface
The library now supports HTTP/2 requests via an optional \http2: true\ option passed to \request()\ or \request.agent()\, which automatically creates an HTTP/2 server when the application is a function. The public API has been refactored to expose \Test\, \agent\, and \cookies\ directly on the module exports, and the internal \Test\ class has been moved to \lib/test.js\. Additionally, the legacy \del\ method is preserved as an alias for \delete\, and the codebase has been updated to use ES6+ syntax with strict mode and ESLint airbnb-base/legacy rules.
(repo-wide) · high confidence
Refactor test execution to use a dedicated TestAgent and Test class with HTTP/2 support
The library has been restructured to decouple the test agent from SuperAgent's internal Agent, introducing a new \TestAgent\ class in \lib/agent.js\ and a \Test\ class in \lib/test.js\ that extends SuperAgent's Request. This change enables native HTTP/2 support for local app testing when the \http2\ option is enabled, improves server lifecycle management by properly handling ephemeral server startup and closing, and consolidates assertion logic into the \Test\ class. The previous \lib/methods.js\ file containing a hardcoded list of HTTP verbs has been removed in favor of importing methods directly from the \methods\ package, and the test agent now correctly inherits from SuperAgent's Agent to preserve properties like cookie handling.
lib · high confidence
Test coverage
Added test fixtures for SSL certificate and key; Expanded test suite for cookie assertions, issue fixes, and HTTP/2 support.
Dependencies
Upgrade to SuperAgent 10 and Node.js 14.18+ requirement
The library has been upgraded to use SuperAgent version 10.3.0, replacing the previous 0.5.0 dependency, and now requires Node.js version 14.18.0 or higher. This update also introduces \cookie-signature\ and \methods\ as direct dependencies, updates the test suite to use Mocha 10 and Sinon 20, and adds linting scripts via ESLint.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 56 → 50 (-6.5)
- Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 52 → 44 (-7.4)
- Architecture 69 → 69 (+0.0)
- Maturity 61 → 61 (+0.0)
- Readiness 55 → 42 (-13.1)
- Security 70 → 92 (+22.8)
Resolved (20)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Low CVE: [GHSA redacted] (package-lock.json)
- Low CVE: [GHSA redacted] (package-lock.json)
- Low CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
New (5)
- Low CVE: [GHSA redacted] (package-lock.json)
- Low CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Outdated (npm): superagent
Changes since last survey
- 15 commits — 14 feature/other, 1 fixes
By area
- (repo) — 9 commits
- (root) — 6 commits
Notable commits
- fix: fix: stabilize ephemeral server requests and assertions
- change: 7.3.0
- change: Merge pull request #881 from forwardemail/dependabot/npm_and_yarn/qs-6.14.2
- change: Merge pull request #883 from forwardemail/dependabot/npm_and_yarn/multi-acd8535d99
- change: Merge pull request #886 from forwardemail/dependabot/npm_and_yarn/picomatch-2.3.2
- change: Merge pull request #887 from forwardemail/dependabot/npm_and_yarn/lodash-4.18.1
- change: Merge pull request #896 from pnookala-godaddy/codex/ephemeral-loopback-bind
- change: Merge pull request #898 from forwardemail/dependabot/npm_and_yarn/brace-expansion-1.1.21
- change: Merge pull request #899 from forwardemail/dependabot/npm_and_yarn/browserslist-4.29.0
- change: Merge pull request #900 from forwardemail/dependabot/npm_and_yarn/fast-uri-3.1.8
- change: Merge pull request #901 from forwardemail/dependabot/npm_and_yarn/js-yaml-3.15.2
- change: chore(deps-dev): bump brace-expansion from 1.1.12 to 1.1.21
- change: chore(deps-dev): bump browserslist from 4.25.1 to 4.29.0
- change: chore(deps-dev): bump fast-uri from 3.0.6 to 3.1.8
- change: chore(deps-dev): bump js-yaml from 3.14.2 to 3.15.2
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
forwardemail/supertest was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit a3f5cb85b9aacc16c95987660ffe12f7d2cb2415 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.