giraffe-fsharp/Giraffe
69.5
Adequate · 23 September 2026
4.2k
lines of production code
F#
primary language
5
measurements over time
What this system is
Giraffe is an F\# micro web framework built on ASP.NET Core that provides composable HTTP handlers and routing capabilities. It supports modern web development needs through integrated authentication, authorization, CSRF protection, and various middleware patterns like rate limiting and response caching. The system facilitates data handling via model binding and offers extensibility for JSON serialization, ensuring compatibility across multiple .NET versions.
Features
Add EndpointRoutingApp sample demonstrating named route parameters
A new sample application has been added to the samples/EndpointRoutingApp directory, showcasing the Giraffe EndpointRouting library. This sample demonstrates how to define HTTP handlers that accept typed parameters, including specific support for named route parameters (e.g., /pet/%i:petId) alongside standard positional parameters, and includes examples for JSON binding and sub-routing.
samples/EndpointRoutingApp · high confidence
Add F\# sample for Newtonsoft.Json serialization
A new F\# sample application has been added to demonstrate how to integrate Newtonsoft.Json with Giraffe. This sample provides a concrete implementation of the \Json.ISerializer\ interface using Newtonsoft.Json, showing users how to configure dependency injection and handle JSON serialization and deserialization in an F\# web application.
samples/NewtonsoftJson · high confidence
Add ResponseCachingApp sample demonstrating Giraffe response caching
A new sample application has been added to demonstrate how to configure the Giraffe server to use ASP.NET Core's response caching feature. The sample includes a \Program.fs\ that sets up various endpoints (public, private, no-cache, and vary-by-query-keys) to illustrate different caching behaviors, along with a \test-run.fsx\ script and a \README.md\ that provide instructions and expected log outputs for verifying the caching middleware.
samples/ResponseCachingApp · high confidence
Add global rate limiting sample
A new sample project demonstrating how to configure ASP.NET Core's built-in rate limiting middleware with Giraffe. The sample implements a fixed-window limiter that allows 10 requests per second per host, returning a 429 status code when the limit is exceeded, and includes a test script to verify the behavior.
samples/GlobalRateLimiting · high confidence
Initial project scaffolding and documentation structure
The repository has been initialized with the core Giraffe project structure, including the solution file (Giraffe.slnx), build targets, and a comprehensive documentation suite (README, DOCUMENTATION, CHANGELOG, RELEASE\_NOTES). This entry establishes the foundational configuration for the F\# ASP.NET Core micro web framework, including code formatting rules via .editorconfig, line-ending consistency via .gitattributes, and the official Code of Conduct and Security policies.
(repo-wide) · high confidence
New authentication, authorization, and CSRF protection handlers
Giraffe now includes dedicated modules for security: Auth.fs provides handlers for challenging authentication, signing out, and enforcing authorization via custom predicates, roles, or ASP.NET Core policies; Csrf.fs adds handlers to validate anti-forgery tokens (with optional custom error handling) and generate tokens for views or JSON responses; and Auth.fs also introduces a deprecation warning for evaluateUserPolicy, recommending authorizeUser instead. These additions give developers built-in, composable tools for securing Giraffe applications without relying on external middleware configurations.
src/Giraffe · high confidence
Test coverage
Added comprehensive test coverage for authentication, routing, and model binding
Added new test suites in the \tests/Giraffe.Tests\ directory to verify core framework capabilities. \AuthTests.fs\ validates role-based and user-specific authorization handlers (e.g., \requiresRole\, \authorizeUser\). \EndpointRoutingTests.fs\ and \FormatExpressionTests.fs\ cover the new endpoint routing integration, including \routef\ with GUID/integer placeholders, \routeWithExtensions\, and the \QUERY\ HTTP method. \ModelBindingTests.fs\ and \ModelValidationTests.fs\ ensure correct parsing of complex models from query strings and JSON, including nested objects and F\#-friendly serialization. Additional tests in \GuidAndIdTests.fs\ and \DateTimeTests.fs\ verify short GUID/ID conversion and date formatting utilities.
tests · high confidence
Dependencies
Update to .NET 10 and add .NET 9 support
The Giraffe library and its test suite now target .NET 10, with .NET 9 added as a supported framework alongside the existing .NET 6, 7, and 8 targets. This update ensures compatibility with the latest .NET runtime versions and includes corresponding updates to test dependencies like Microsoft.AspNetCore.TestHost and xUnit to support the new frameworks.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 65 → 70 (+4.9)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 86 → 86 (+0.0)
- Architecture 100 → 99 (-0.7)
- Maturity 55 → 55 (+0.0)
- Readiness 68 → 84 (+15.6)
- Security 67 → 77 (+10.4)
Resolved (15)
- Adult.HasErrors (cognitive 27) (tests/Giraffe.Tests/ModelValidationTests.fs)
- Duplicated block (11 lines × 2) (src/Giraffe/Auth.fs)
- Duplicated block (14 lines × 2) (samples/EndpointRoutingApp/Program.fs)
- Duplicated block (5 lines × 2) (src/Giraffe/EndpointRouting.fs)
- Duplicated block (8 lines × 2) (src/Giraffe/FormatExpressions.fs)
- Duplicated block (8 lines × 2) (src/Giraffe/Routing.fs)
- Duplicated block (9 lines × 2) (src/Giraffe/EndpointRouting.fs)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- No exposed public API
- Outdated: FsCheck
- Outdated: FsCheck.Xunit.v3
- Test reliability not included
New (25)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (10 lines × 2) (src/Giraffe/EndpointRouting.fs)
- Duplicated block (11 lines × 2) (src/Giraffe/Auth.fs)
- Duplicated block (5 lines × 2) (src/Giraffe/EndpointRouting.fs)
- Duplicated block (5 lines × 2) (src/Giraffe/EndpointRouting.fs)
- Duplicated block (7–8 lines × 2) (src/Giraffe/Routing.fs)
- Duplicated block (7–9 lines × 2) (src/Giraffe/EndpointRouting.fs)
- Duplicated block (8 lines × 2) (samples/GlobalRateLimiting/Program.fs)
- End-of-life runtime: .NET net9.0
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: Microsoft.Build.Tasks.Git 8.0.0
- …and 5 more
Changes since last survey
- 18 commits — 17 feature/other, 1 fixes
By area
- tests/Giraffe.Tests — 9 commits
- src/Giraffe — 5 commits
- .config/dotnet-tools.json — 3 commits
- (root) — 1 commit
Notable commits
- fix: Fix Fantomas style due to update to v8 (#774)
- change: Add a new function that writes a Markdown response (#751)
- change: Bump FsCheck and FsCheck.Xunit.v3 (#749)
- change: Bump G-Research.FSharp.Analyzers from 0.23.0 to 0.24.0 (#763)
- change: Bump Ionide.Analyzers from 0.14.11 to 0.16.0 (#752)
- change: Bump Ionide.Analyzers from 0.16.0 to 0.17.0 (#759)
- change: Bump Ionide.KeepAChangelog.Tasks from 0.3.3 to 0.4.0 (#770)
- change: Bump Microsoft.NET.Test.Sdk from 18.10.0 to 18.10.1 (#771)
- change: Bump Microsoft.NET.Test.Sdk from 18.8.1 to 18.9.0 (#753)
- change: Bump Microsoft.NET.Test.Sdk from 18.9.0 to 18.10.0 (#767)
- change: Bump NSubstitute from 6.0.0 to 6.1.0 (#750)
- change: Bump NSubstitute from 6.1.0 to 6.2.0 (#755)
- change: Bump fantomas from 7.0.5 to 7.0.6 (#757)
- change: Bump fantomas from 7.0.6 to 8.0.1 (#769)
- change: Bump fsharp-analyzers from 0.37.2 to 0.38.0 (#762)
- change: Bump xunit.runner.visualstudio from 3.1.5 to 4.0.0 (#760)
- change: Bump xunit.v3 from 3.2.2 to 4.0.0 (#761)
- change: Bump xunit.v3 from 4.0.0 to 4.0.1 (#773)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
giraffe-fsharp/Giraffe was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 279fe3a30c27bd647d2655745f71190c74bdd749 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.