Skip to content
CAI
Software that uses CAICheck a score

grpc/grpc-web

47.0

Weak · 2 October 2026

5.9k

lines of production code

JavaScript

with TypeScript, C++, Python

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a gRPC-Web library and tooling suite that enables browser-based JavaScript clients to communicate with gRPC backends via an Envoy proxy. It provides a client runtime for handling RPCs, a protoc code generator for creating TypeScript definitions, and a collection of reference examples demonstrating Node.js server implementations. The project also includes comprehensive interop and unit tests to verify compatibility and correct behavior across different environments.

How it got here

2016–2018 — gRPC-Web JavaScript client launch

14 changes.

This period focused on the initial release of the gRPC-Web JavaScript client library, establishing core RPC handling, TypeScript definitions, and npm packaging. It also involved migrating the build system to Bazel with bzlmod support and creating comprehensive Node.js and browser-based examples to demonstrate client-server communication via Envoy.

2020–2026 — gRPC-Web generator and TypeScript migration

5 changes.

This period focused on establishing the core infrastructure for gRPC-Web, including the initial release of the C++ protoc plugin generator and the migration of the client library to TypeScript. It also expanded test coverage by adding automated interop tests for gRPC-Web and introducing new debugging tools for developers.

Features

Add Node.js gRPC Echo Server Example

A new Node.js gRPC server example has been added to the echo service directory, providing a reference implementation for Node.js clients and servers. The server uses the @grpc/grpc-js library to load the echo.proto definition and implements unary, abort, and server-streaming RPC handlers, binding them to the EchoService on port 9090.

net/grpc/gateway/examples/echo/node-server · high confidence

Add Node.js gRPC-Web Hello World example

The helloworld example now includes a complete Node.js implementation for gRPC-Web, featuring a server that handles both unary and server-streaming RPCs, a browser-based client, and an Envoy proxy configuration. This addition provides users with a ready-to-run reference for setting up gRPC-Web communication using the @grpc/grpc-js library and modern Envoy filter syntax.

net/grpc/gateway/examples/helloworld · high confidence

Add TypeScript-based Echo example

This location introduces a new TypeScript client example for the Echo service, providing users with a modern, type-safe way to interact with gRPC-Web. The change includes the core client implementation (client.ts), a build configuration (tsconfig.json, webpack.config.js), and an HTML interface (echotest.html) that demonstrates sending messages, handling server-streaming responses, and managing errors. Documentation (README.md) and build artifacts (.gitignore) are also added to guide users through running the example via Docker or manually.

net/grpc/gateway/examples/echo/ts-example · high confidence

Added localhost SSL certificate and private key

The repository now includes a self-signed SSL certificate (localhost.crt) and its corresponding RSA private key (localhost.key) in the etc directory. This addition enables local development environments to serve content over HTTPS using these specific credentials, facilitating secure local testing for features like proxy interoperability without requiring external certificate management.

etc · high confidence

Added standalone Node.js debugging client

A new Node.js client script has been added to the debugging example directory to allow developers to test the gRPC server directly without requiring an Envoy proxy or the gRPC-Web protocol. This tool facilitates local debugging by connecting directly to localhost:9090 and executing standard gRPC calls for both unary and streaming responses.

net/grpc/gateway/examples/helloworld/debugging · high confidence

Initial Echo example with Node.js backend and Envoy proxy

Adds a complete end-to-end Echo example demonstrating gRPC-Web communication. The example includes a Node.js gRPC backend server, an Envoy proxy configuration to handle gRPC-Web requests, and a browser-based JavaScript client (using ClosureJS) that sends unary and server-streaming echo requests. Build automation is provided via a Makefile and Bazel rules, and documentation guides users through running the components via Docker.

net/grpc/gateway/examples/echo · high confidence

Initial release of the C++ protoc plugin generator

This change introduces the core source files for the \protoc-gen-grpc-web\ code generator, including the main C++ implementation (\grpc\_generator.cc\) and build configurations (\BUILD.bazel\, \Makefile\). The generator is initialized at version 2.1.1 and supports generating TypeScript definitions, handling various import styles (Closure, CommonJS, TypeScript), and managing different gRPC-web modes. It includes logic for handling reserved keywords, versioning, and platform-specific compilation flags for macOS and Linux.

javascript/net/grpc/web/generator · high confidence

Initial release of the gRPC-Web JavaScript client library

This change introduces the initial version of the gRPC-Web JavaScript client library, providing the core components needed to make gRPC calls from the browser. It includes the \GrpcWebClientBase\ for handling RPCs, \ClientReadableStream\ for managing server-streaming responses, and a \GrpcWebStreamParser\ for decoding the gRPC-Web wire format. The library supports both callback-based and promise-based (thenable) call patterns, allows configuration of client options such as CORS preflight suppression and credentials, and enforces a 4 MB maximum receive message size to match other gRPC runtimes.

javascript/net/grpc/web · high confidence

Introduces npm package structure with TypeScript definitions and build tooling

The \packages/grpc-web\ directory now includes the necessary files to publish and consume the gRPC-Web client runtime as an npm package. This adds a \README.md\ with installation and usage instructions, \index.d.ts\ providing TypeScript definitions for the client API (including \AbstractClientBase\, \MethodDescriptor\, and interceptors), and build configuration files (\rollup.config.js\, \gulpfile.js\) to bundle the Closure-compiled source into CommonJS and ES modules. It also introduces a new Protractor-based test runner (\protractor.conf.js\, \protractor\_spec.js\) to execute the existing Closure JSUnit tests in a headless browser environment.

packages/grpc-web · high confidence

New CI/CD and testing scripts for Dockerized builds and interop tests

This change introduces a suite of new shell scripts in the \scripts/\ directory to automate the build, test, and release processes. It adds \run\_basic\_tests.sh\ and \run\_interop\_tests.sh\ to orchestrate Docker-based unit, mocha, and interop tests (including Envoy proxy integration), alongside specific runners like \docker-run-build-tests.sh\ and \docker-run-jsunit-tests.sh\. A new \release\_notes.py\ script is added to generate changelogs from GitHub PRs, and \init\_submodules.sh\ is updated to pin the protobuf submodule to v3.15.6. Additionally, a \README.md\ provides troubleshooting guidance for Bazel OOM crashes on macOS.

scripts · high confidence

New CommonJS-based echo example with webpack and interceptors

The commonjs-example directory now provides a self-contained demonstration of the gRPC-Web client using CommonJS modules. It includes a webpack configuration to bundle client.js into dist/main.js, an HTML page (echotest.html) that loads the bundle with cache-busting, and a .gitignore for Node artifacts. The client code imports generated protobuf and gRPC-web stubs, instantiates an EchoServiceClient, and wires it into the EchoApp UI. A sample StreamResponseInterceptor is defined to modify request and response messages, illustrating how interceptors can be used in a CommonJS environment.

net/grpc/gateway/examples/echo/commonjs-example · high confidence

Architecture

Migrate build system to Bazel with bzlmod support

The project has replaced its previous build configuration with a modern Bazel setup, introducing \MODULE.bazel\ and \MODULE.bazel.lock\ files to manage dependencies (including protobuf 29.1, grpc 1.65.0, and rules\_cc 0.2.17) via the new bzlmod system. This change is enabled by default in \.bazelrc\ and \.bazelrc.windows\, and the build environment is now pinned to Bazel version 7.3.0 via \.bazelversion\. The migration also includes updated ignore files (\.bazelignore\, \.gitignore\) to handle Bazel-generated artifacts and a new \Makefile\ wrapper for plugin builds.

(repo-wide) · high confidence

Behavioural changes

Migration of gRPC-Web client library to TypeScript

The core gRPC-Web client library in \src/typescript\ has been rewritten in TypeScript, introducing strongly-typed interfaces for client options, method descriptors, and interceptors, alongside a new \GrpcWebStreamParser\ for handling binary wire formats. This change also adds a \closure-wrapper\ package with a Rollup build configuration to bundle the Closure-based \@closure-net/blob\ dependencies into ESM/CJS modules, ensuring deterministic builds via pinned TypeScript and Node types.

packages/closure-wrapper, src/typescript · high confidence

Revamped test and build infrastructure for grpc-web

The build and test workflows have been overhauled to support the TypeScript migration and optimize compilation. The build script now uses the npm-installed Google Closure Compiler with ADVANCED\_OPTIMIZATIONS enabled to produce the final library bundle, replacing previous methods. Additionally, a new Python-based test generation system has been introduced to automatically create HTML test wrappers from JavaScript test files and generate a consolidated test manifest, streamlining the execution of unit tests via Protractor and headless Chrome.

packages/grpc-web/scripts · high confidence

Test coverage

Added automated gRPC-Web interop tests; Added gRPC interop test protocol definitions; Added test proto definitions for code generation coverage; Expanded test coverage for TypeScript generation and client interceptors.

Dependencies

Updated Protobuf submodule to version 27.1

The third-party Protobuf dependency has been updated to commit 3d9f7c4, corresponding to version 27.1. This change brings the latest protocol buffer implementation into the project, which includes modernized code generation APIs such as \has\_presence()\ that may affect how generated code behaves or is structured.

_third\party · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 50 → 47 (-3.2)
  • Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 83 → 83 (+0.1)
  • Architecture 69 → 76 (+7.6)
  • Maturity 65 → 65 (+0.0)
  • Readiness 33 → 26 (-7.5)
  • Security 62 → 61 (-0.9)

Resolved (4)

  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Off-boarding risk: anonymized user #1

New (3)

  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (the committed lockfile resolved no direct production dependency)
  • High CVE: [GHSA redacted] (packages/closure-wrapper/yarn.lock)
  • Off-boarding risk: anonymized user #1

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

grpc/grpc-web was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 7c572794c45b91f096fe06fbbafbb5411612a414 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.