Skip to content
CAI
Software that uses CAICheck a score

gorilla/websocket

63.8

Adequate · 24 September 2026

3.8k

lines of production code

Go

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This is a Go library for the WebSocket protocol, providing core connectivity features such as proxy support and prepared message handling. It also includes a suite of practical examples demonstrating common use cases, including a chat application, a command-line bridge, an echo service, and a file watcher. The project enforces modern Go standards, requiring Go 1.20 and updated dependencies.

Features

Add command example to demonstrate WebSocket-to-stdin/stdout bridging

A new example named 'command' has been added to the repository. It demonstrates how to bridge a WebSocket connection to the standard input and output of a command-line process. The example includes a Go server (main.go) that manages the bidirectional flow between the WebSocket client and the external process, a static HTML page (home.html) for the user interface, and a README.md with usage instructions. The server enforces GET for the home page and handles connection lifecycle, including pings and graceful shutdowns.

examples/command · high confidence

Add echo example with web client

The echo example now includes a web-based client alongside the existing Go client. Users can open the server's root URL in a browser to interact with the echo service via a simple HTML interface, in addition to using the command-line client.

examples/echo · high confidence

Add proxy support for WebSocket clients

The library now supports connecting to WebSocket servers through HTTP or SOCKS5 proxies. Users can configure a \Dialer\ with a \Proxy\ function to route connections through an intermediary, and the library provides a \proxyFromURL\ helper to parse standard proxy URLs. This enables WebSocket clients to operate in network environments that require proxying.

(repo-wide) · high confidence

Added file watch example

A new example demonstrating how to watch a file for changes and push updates to a browser client via WebSocket. The example includes a Go server that periodically checks a specified file for modifications and sends the updated content to connected clients, along with the necessary HTML/JavaScript client code to display the file contents in real-time.

examples/filewatch · high confidence

Behavioural changes

Add prepared message support to the Autobahn test server

The Autobahn test server now supports the new PreparedMessage API, allowing it to handle test cases that use prepared messages. This change updates the server implementation to use a package-level Upgrader and adds a new endpoint (/p) for the ReadAllWritePreparedMessage test case, enabling more comprehensive WebSocket conformance testing.

examples/autobahn · high confidence

Refactor chat example to remove jQuery dependency and improve WebSocket handling

The chat example was refactored to remove the jQuery dependency, replacing it with native browser APIs (e.g., \document.getElementById\ instead of \$('\#id')\). The \connection\ type was renamed to \Client\ and restructured to hold the \\*websocket.Conn\ as \conn\ instead of \ws\. The \writePump\ was updated to coalesce outbound messages into a single WebSocket message for efficiency. The \home.html\ frontend was updated to use vanilla JavaScript, and the \main.go\ was adjusted to use \http.StatusNotFound\ and \http.MethodGet\ constants. The \hub.go\ was updated to use \\*Client\ instead of \\*connection\.

examples/chat · medium confidence

Dependencies

Go 1.20 minimum version and golang.org/x/net upgrade

The project now requires Go 1.20 or later. The dependency on golang.org/x/net has been updated to version 0.26.0, and version 1.5.2 has been retracted from the module to correct an accidental tag overwrite.

(dependencies) · medium confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 59 → 64 (+5.0)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 77 → 86 (+9.6)
  • Architecture 100 → 100 (+0.0)
  • Maturity 51 → 50 (-1.5)
  • Readiness 49 → 65 (+15.3)
  • Security 87 → 86 (-0.7)

Resolved (17)

  • Client.writePump (cognitive 18) (examples/chat/client.go)
  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (11 lines × 2) (conn.go)
  • Duplicated block (9 lines × 2) (conn.go)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: GO-2024-2598 (go.mod)
  • Medium: security finding (details withheld)
  • No exposed public API
  • Test reliability not included
  • main.echoCopy (cognitive 23) (examples/autobahn/server.go)
  • main.echoReadAll (cognitive 40) (examples/autobahn/server.go)
  • main.writer (cognitive 21) (examples/filewatch/main.go)

New (20)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (12 lines × 2) (conn.go)
  • Duplicated block (12 lines × 2) (conn.go)
  • Flaky test: .::github.com/gorilla/websocket.TestHTTPSProxyHTTPBackend
  • Flaky test: .::github.com/gorilla/websocket.TestTLSValidationErrors
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: GO-2024-2598 (go.mod)
  • MethodTooLong: Conn.advanceFrame (conn.go)
  • MethodTooLong: Dialer.DialContext (client.go)
  • No dependency advisory monitoring
  • Outdated: golang.org/x/net
  • TodoComment (prepared.go)
  • TooManyFields: Conn (conn.go)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

gorilla/websocket was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit e064f32e3674d9d79a8fd417b5bc06fa5c6cad8f — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-5f8d0eb43fd7.