http-party/http-server
47.0
Weak · 1 October 2026
1.4k
lines of production code
JavaScript
primary language
2
measurements over time
What this system is
This system is a command-line static file server that serves local directories over HTTP and HTTPS. It provides features such as directory listings with file type icons, content compression, and configurable caching. The server supports security measures like basic authentication, CORS, and host restrictions, along with proxying capabilities and TLS configuration.
Features
Add HTTPS server shim with environment-based SSL passphrase support
A new shim at lib/shims/https-server-shim.js enables creating HTTPS servers using provided key and certificate files. It reads the SSL passphrase from the NODE\_HTTP\_SERVER\_SSL\_PASSPHRASE environment variable, allowing users to configure encrypted connections without hardcoding secrets in the application code.
lib/shims · high confidence
Added default public assets and 404 page
The application now includes a default public folder containing an index.html page that serves as a landing page for the static file server, and a 404.html page to handle missing resources. This provides immediate, user-facing content for the static server example without requiring external assets.
public · high confidence
Directory listings now display file-type icons
The directory listing view now includes visual icons next to file names to help users quickly identify file types. This is achieved by introducing a new \icons.json\ resource in the \lib/core/show-dir\ module, which maps file extensions to embedded SVG icons. This change enhances the usability of the file browser by providing immediate visual cues for common file formats.
lib/core/show-dir · high confidence
Initial release of the http-server CLI binary
This change introduces the \bin/http-server\ executable, establishing the command-line interface for the static file server. The binary handles argument parsing via \minimist\, manages server lifecycle events (including graceful shutdown and error logging), and exposes a comprehensive set of options for users, such as port binding, TLS/SSL configuration, CORS and COOP headers, proxying, basic authentication, and brotli/gzip compression support.
bin · high confidence
Behavioural changes
Core server logic and configuration options are restructured
The \lib/core\ module has been refactored to centralize middleware logic, option parsing, and status handling. This change introduces a new \aliases.json\ configuration file that maps various option names (such as \coop\, \cors\, and \dirOverrides404\) to their canonical forms, allowing for more flexible CLI and programmatic configuration. The core middleware in \index.js\ now explicitly handles cross-origin isolation (\coop\), CORS, and private network access headers, while also implementing robust etag generation and comparison logic in \etag.js\. Additionally, status handlers in \status-handlers.js\ have been updated to comply with RFC 9110, specifically ensuring that 416 Range Not Satisfiable responses include the required \Content-Range\ header, and input validation has been strengthened to prevent header injection via CRLF checks.
lib/core · high confidence
Major API refactor and security hardening for the HTTP server library
The lib/http-server.js module has been rewritten to provide a more robust, programmatic API and improved security posture. The server now uses a constructor-based pattern (HttpServer) instead of a singleton, allowing multiple instances and better state management. Security has been significantly enhanced with the addition of HTTP Basic Authentication using secure comparison to prevent timing attacks, CRLF injection prevention in headers, and an --allowed-hosts flag to restrict access to specific hosts. New features include support for Cross-Origin-Opener-Policy (COOP), private network access headers, dynamic robots.txt serving, and configurable proxy rules with path rewriting. Caching behavior is now more explicit, supporting a -1 value to disable caching entirely, and the default root directory logic has been refined to check for a ./public folder first.
lib · high confidence
Test coverage
Added test fixtures for static serving scenarios; Expanded test coverage for HTTP server features and edge cases.
Dependencies
http-server v14.1.2 release with dependency updates
This release updates the http-server package to version 14.1.2, introducing a new package-lock.json to ensure deterministic dependency resolution. The project now requires Node.js version 16.20.2 or higher. Key dependency updates include upgrading minimatch to ^10.1.1, portfinder to ^1.0.28, and html-encoding-sniffer to ^3.0.0, while dev dependencies such as tap have been updated to ^21.0.1.
(dependencies) · high confidence
Housekeeping
Initial man page for http-server
Added a new man page (http-server.1) that documents the command-line interface, including options for port configuration, caching, TLS/SSL, proxying, authentication, and new flags like --coop, --allowed-hosts, and --hide-permissions.
doc · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 52 → 47 (-5.2)
- Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 49 → 49 (+0.0)
- Architecture 69 → 69 (+0.0)
- Maturity 58 → 58 (-0.2)
- Readiness 47 → 36 (-11.2)
- Security 80 → 83 (+2.9)
Resolved (4)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no usage examples (README.md)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
New (17)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Outdated (npm): basic-auth
- Outdated (npm): chalk
- Outdated (npm): html-encoding-sniffer
- Outdated (npm): mime
- Outdated (npm): minimatch
- Outdated (npm): minimist
- Outdated (npm): portfinder
- Outdated (npm): union
- Outdated (npm): url-join
- index.createMiddleware (cognitive 119) (lib/core/index.js)
- index.createMiddleware (cyclomatic 87) (lib/core/index.js)
- index.default (cognitive 42) (lib/core/show-dir/index.js)
- index.default (cyclomatic 31) (lib/core/show-dir/index.js)
- opts.default (cognitive 77) (lib/core/opts.js)
- opts.default (cyclomatic 47) (lib/core/opts.js)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
http-party/http-server was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 0d3b7bb5b6e8a59fd450ae2dca65870009cfcd8b — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.