Skip to content
CAI
Software that uses CAICheck a score

fsprojects/SwaggerProvider

62.3

Adequate · 24 September 2026

2.6k

lines of production code

F#

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

SwaggerProvider is an F\# type provider that generates strongly-typed client code from OpenAPI schemas at compile time. It separates design-time schema processing from runtime HTTP execution, offering SSRF protection, comprehensive error handling, and support for modern .NET types. The system includes a dedicated runtime library for making API calls and a design-time component for type generation, validated against both OpenAPI v2 and v3 standards.

Removals

Removal of legacy scaffolding and metadata files

The SwaggerProvider source directory has been cleaned of legacy scaffolding artifacts. Specifically, the AssemblyInfo.fs file (containing version metadata), the Library.fs placeholder module, the Script.fsx sample script, and the paket.references and paket.template dependency configuration files have been deleted. This removes unused boilerplate and external dependency manifest files from the project structure.

src/SwaggerProvider · high confidence

Security

Introduce SSRF protection and schema validation controls in the design-time provider

The design-time provider now includes Server-Side Request Forgery (SSRF) protection by default, blocking HTTP URLs, localhost, and private IP ranges (both IPv4 and IPv6) when fetching remote schemas. A new \SsrfProtection\ static parameter allows users to disable this validation for development or testing. Additionally, an \IgnoreParseErrors\ parameter lets the provider continue generating types even if the OpenAPI schema contains validation errors, exposing any tolerated errors via the new \SchemaReaderErrors\ property.

src/SwaggerProvider.DesignTime · high confidence

Behavioural changes

Introduce dedicated runtime assembly with improved error handling and performance

SwaggerProvider now ships a dedicated runtime library (SwaggerProvider.Runtime) that separates runtime helpers from design-time logic. This change enhances error reporting by including the HTTP response body in OpenApiException messages, ensuring users see the full server error context. It also improves performance by reducing allocations and reflection overhead in generated operation code, and adds support for text/plain payload types and DateOnly/TimeOnly serialization.

src/SwaggerProvider.Runtime · high confidence

Migrate build system to .NET SDK and update solution structure

The build infrastructure has been migrated from the legacy Paket/FAKE runner to the modern .NET SDK tooling, replacing the old \build.cmd\ and \build.sh\ scripts with \dotnet tool restore\ and \dotnet fsi\ commands. The solution file has been restructured to explicitly include the new \SwaggerProvider.DesignTime\ and \Swashbuckle.WebApi.Server\ projects, and the global SDK baseline has been updated to version 10.0.301. Additionally, an \.editorconfig\ file has been added to enforce consistent F\# coding styles, and legacy CI configurations for Travis CI and AppVeyor have been removed.

(repo-wide) · high confidence

Test coverage

Added F\# test server for Swashbuckle integration; Added test fixture controllers for file uploads, text formats, and type variations; Added test script for SwaggerClientProvider; Expanded test coverage for SwaggerProvider internals; Expanded test coverage for SwaggerProvider type provider.

Dependencies

Upgrade to .NET 10 and modernize build infrastructure

The project has migrated its target framework from .NET Framework 4.0 to .NET 10.0 (net10.0) across the runtime, design-time, and test assemblies. This upgrade is accompanied by a transition from the legacy .csproj format to the SDK-style project system and a switch from NuGet v2 to the v3 API. Additionally, the documentation site now uses VitePress, and the dependency graph has been updated to include FSharp.Core 10.1, System.Text.Json 10.0, and Microsoft.OpenApi 2.12.

(dependencies) · high confidence

Housekeeping

Version bump to 4.2.0

The assembly version information in src/Common/AssemblyInfo.fs has been updated to 4.2.0, reflecting the current release version of the SwaggerProvider library.

src/Common · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 59 → 62 (+3.0)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 83 → 83 (-0.3)
  • Architecture 100 → 99 (-0.9)
  • Maturity 46 → 51 (+5.1)
  • Readiness 70 → 65 (-4.9)
  • Security 64 → 72 (+8.3)

Resolved (16)

  • Dependency hygiene not measured — no packages were read
  • Duplicated block (13 lines × 2) (src/SwaggerProvider.Runtime/RuntimeHelpers.fs)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • Secret passed as a command-line argument
  • Test reliability not included
  • TooManyMethods: RuntimeHelpers (src/SwaggerProvider.Runtime/RuntimeHelpers.fs)
  • complexity unreadable for .fs — churn × complexity hotspots could not be measured

New (15)

  • Duplicated block (12 lines × 2) (src/SwaggerProvider.Runtime/RuntimeHelpers.fs)
  • Duplicated block (6 lines × 2) (src/SwaggerProvider.DesignTime/OperationCompiler.fs)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Secret exported as workflow-level env

Changes since last survey

  • 12 commits — 12 feature/other, 0 fixes

By area

  • (root) — 3 commits
  • tests/SwaggerProvider.Tests — 3 commits
  • .github/workflows — 2 commits
  • .config/dotnet-tools.json — 1 commit
  • .github/aw — 1 commit
  • src/SwaggerProvider.DesignTime — 1 commit
  • src/SwaggerProvider.Runtime — 1 commit

Notable commits

  • change: Bump fantomas from 7.0.5 to 7.0.6 (#484)
  • change: Bump fantomas from 7.0.6 to 8.0.0 (#495)
  • change: [repo-assist] test: add coverage for in-memory cache (Caching.fs) (#493)
  • change: chore(deps): update paket.lock to latest compatible package versions (#486)
  • change: chore: gh aw update
  • change: eng: bump Microsoft.Identity.Client/Extensions.Msal 4.88 -> 4.89 (transitive, patch) (#494)
  • change: hk: update deps
  • change: perf: avoid intermediate array allocation in toStrArray helpers (#488)
  • change: test: add coverage for CallAsync readBody exception fallback (#496)
  • change: test: add unit tests for SchemaReader.validateContentType (#491)
  • change: update repo assist
  • change: update repo assist

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

fsprojects/SwaggerProvider was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 9201a3606d40ed0b04be9c2d54c41f927751872d — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-923689c465cf.