junegunn/fzf
65.6
Adequate · 24 September 2026
24.5k
lines of production code
Go
primary language
5
measurements over time
What this system is
This system is fzf, a high-performance fuzzy finder rewritten in Go to replace its previous ncurses-based implementation. It provides core terminal UI capabilities for filtering and searching, enhanced by SIMD-accelerated matching and Unicode normalization. The tool integrates deeply with various shell environments (Bash, Zsh, Fish, Nushell) and Vim, offering features like file previewing, layout management via tmux or popups, and robust cross-platform support.
How it got here
2013–2015 — Go rewrite and platform modernization
9 changes.
The project underwent a major rewrite of its core fuzzy finder engine from ncurses to Go, introducing SIMD-accelerated matching and Unicode normalization for improved performance. This period also saw the modernization of shell integrations to support Nushell and refined cross-platform compatibility, particularly for Windows and tmux environments.
2016–2025 — Terminal UI and security hardening
5 changes.
The project replaced the ncurses-based terminal UI with a lightweight ANSI renderer to reduce dependencies and improve compatibility. Security was enhanced by introducing an OpenBSD-specific protector package that applies pledge restrictions. Additionally, comprehensive test suites were added to cover core functionality, shell integration, and Vim plugin behavior.
Features
Add OpenBSD pledge support via a new protector package
A new \protector\ package has been introduced to apply OS-specific security restrictions on OpenBSD. On OpenBSD, the package invokes \pledge(2)\ with a comprehensive set of promises (stdio, cpath, dpath, wpath, rpath, inet, fattr, unix, tty, proc, exec) to restrict system calls, while on other platforms the package provides a no-op implementation to maintain build compatibility.
src/protector · high confidence
Add fzf-tmux and fzf-preview.sh helper scripts
Introduces two new shell scripts to the bin directory. The fzf-tmux script allows launching fzf in a tmux split pane or popup window, handling layout options, tmux version compatibility, and cleanup of temporary resources. The fzf-preview.sh script provides a file previewer for fzf that supports syntax highlighting via bat, image preview via kitty icat, chafa, or imgcat, and handles file paths with line numbers.
bin · high confidence
Add man page for fzf-tmux wrapper script
Users can now access documentation for the fzf-tmux wrapper script via the new man/man1/fzf-tmux.1 file, which details its layout options for opening fzf in tmux split panes or popup windows.
man · high confidence
Initial project scaffolding and build configuration
The repository has been initialized with essential configuration files to support the project's development and release workflow. This includes an EditorConfig for consistent shell script formatting, a Gitignore file to exclude build artifacts and IDE files, and a GoReleaser configuration to automate cross-platform binary builds, notarization, and package distribution. Additionally, tool versions for Go, Ruby, and shfmt are defined, and build/test instructions are documented in BUILD.md.
(repo-wide) · high confidence
Initial release of fzf in Go
The fzf fuzzy finder has been rewritten in Go, replacing the previous ncurses-based implementation. This location introduces the core source files for the new binary, including the ANSI escape sequence processor, the action type definitions, and the associated unit tests, establishing the foundation for the tool's terminal UI and filtering capabilities.
src · high confidence
Behavioural changes
Major plugin rewrite with improved Windows and layout support
The Vim plugin has been significantly refactored to enhance cross-platform compatibility and user experience. It now features robust Windows support, including proper UTF-8 encoding for commands, correct handling of file paths with spaces, and specific fixes for cmd.exe and PowerShell environments. The default interface behavior has changed to utilize floating popup windows or tmux panes where available, replacing older split-window layouts. Additionally, the plugin introduces a new \fzf\#install()\ function for automatic binary management and exposes \fzf\#shellescape()\ for safer command-line argument handling.
plugin · high confidence
New light renderer replaces ncurses for Unix terminals
The terminal UI now uses a new 'light' renderer (light.go) on Unix systems instead of the previous ncurses-based approach. This renderer handles terminal initialization, cursor positioning, and bracketed paste mode queries directly via ANSI escape sequences and the golang.org/x/term library, improving compatibility and reducing external dependencies. A dummy renderer (dummy.go) is provided for non-tcell/non-Windows builds where the light renderer is not active, and platform-specific implementations (light\_unix.go, light\_windows.go) manage TTY access and console modes. Comprehensive tests (light\_test.go, light\_query\_test.go, light\_escape\_test.go) validate event parsing, startup queries, and escape sequence handling.
src/tui · high confidence
Refactored utility library with new concurrency primitives and improved text handling
The src/util package has been restructured to introduce several new concurrency-safe utilities, including an AtExit handler for registered termination functions, an AtomicBool for thread-safe boolean state, a ConcurrentSet for generic thread-safe sets, and an EventBox for coordinating asynchronous events. Text processing capabilities have been enhanced with a new Chars type that optimizes ASCII string handling and supports word wrapping, while string width calculations now rely on the rivo/uniseg library to correctly handle grapheme clusters and emoji. Platform-specific command execution is managed via new Executor implementations for Unix and Windows, featuring improved shell detection and argument escaping.
src/util · high confidence
SIMD-accelerated byte search and Unicode normalization for faster fuzzy matching
The fuzzy matching engine now uses SIMD-optimized assembly (AVX2/SSE2 on x86, NEON on ARM64) to scan for character occurrences in a single pass, significantly speeding up case-insensitive searches. Additionally, the algorithm now supports normalizing accented Latin characters (e.g., Vietnamese, French) before matching, allowing users to find items like 'cafe' by typing 'cafe' with accents, and improves overall search performance through pre-calculated character classes and bonus matrices.
src/algo · high confidence
Shell integration rewritten for Nushell and modernized for Bash, Zsh, and Fish
The shell integration scripts have been completely rewritten to introduce first-class support for Nushell (key-bindings.nu, completion.nu) and to modernize the existing Bash, Zsh, and Fish implementations. This update introduces a shared \common.sh\ module to standardize default option handling across shells, adds a configurable \FZF\_COMPLETERS\ API for Nushell to define custom completers, and enforces a minimum Fish version of 3.4.0. The new architecture also improves robustness by handling edge cases like Solaris awk, mawk versioning, and tmux pane detection more consistently, while providing example completers for package managers like pacman/paru and password stores like pass.
shell · high confidence
Test coverage
Added integration tests for Vim fzf plugin behavior; Added test infrastructure for multiple shell environments; New comprehensive test suite for fzf core features and shell integration.
Dependencies
Add Ruby development dependencies and update Go module versions
The project now includes a Gemfile and Gemfile.lock to manage Ruby development dependencies, specifically adding minitest 5.25.4, rubocop 1.71.0, rubocop-minitest 0.36.0, and rubocop-performance 1.23.1. Additionally, the Go module dependencies have been updated, including golang.org/x/sys to v0.35.0, golang.org/x/term to v0.34.0, github.com/gdamore/tcell/v2 to v2.9.0, and github.com/charlievieth/fastwalk to v1.0.14, with the Go version requirement set to 1.23.0.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 61 → 66 (+5.0)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 56 → 73 (+17.1)
- Architecture 100 → 99 (-1.2)
- Maturity 57 → 56 (-1.1)
- Readiness 69 → 81 (+11.1)
- Security 64 → 69 (+4.5)
Resolved (47)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (12 lines × 2) (src/algo/algo.go)
- Duplicated block (12 lines × 2) (src/options.go)
- Duplicated block (13 lines × 2) (src/algo/algo.go)
- Duplicated block (15 lines × 3) (src/tui/tui.go)
- Duplicated block (5 lines × 2) (src/terminal.go)
- Duplicated block (6 lines × 2) (src/pattern.go)
- Duplicated block (7 lines × 2) (src/tui/light.go)
- Duplicated block (8 lines × 2) (src/terminal.go)
- Duplicated block (8 lines × 2) (src/tui/tcell.go)
- FileTooLong: algo/normalize.go (src/algo/normalize.go)
- High IaC: DS-0029 (Dockerfile)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 27 more
New (148)
- ClassTooLong: LightRenderer (src/tui/light.go)
- ClassTooLong: Terminal (src/terminal.go)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (11 lines × 2) (src/options.go)
- Duplicated block (14–15 lines × 2) (src/algo/algo.go)
- Duplicated block (16 lines × 2) (src/algo/algo.go)
- Duplicated block (16 lines × 2) (src/tui/light.go)
- Duplicated block (16 lines × 2) (src/tui/light.go)
- Duplicated block (16 lines × 2) (src/tui/light.go)
- Duplicated block (16 lines × 2) (src/tui/light.go)
- Duplicated block (16 lines × 2) (src/tui/light.go)
- Duplicated block (22 lines × 2) (src/tui/light.go)
- Duplicated block (26 lines × 3) (src/tui/tui.go)
- Duplicated block (37 lines × 2) (src/tui/tui.go)
- Duplicated block (5 lines × 2) (src/terminal.go)
- Duplicated block (5 lines × 2) (src/terminal.go)
- Duplicated block (8 lines × 2) (src/terminal.go)
- Duplicated block (8 lines × 2) (src/tui/tcell.go)
- Duplicated block (9 lines × 2) (src/pattern.go)
- …and 128 more
Changes since last survey
- 38 commits — 32 feature/other, 6 fixes
By area
- (root) — 14 commits
- src/tui — 7 commits
- src/algo — 4 commits
- src/terminal_test.go — 4 commits
- src/util — 4 commits
- .github/ISSUE_TEMPLATE — 1 commit
- .github/workflows — 1 commit
- man/man1 — 1 commit
- shell/key-bindings.nu — 1 commit
- test/test_shell_integration.rb — 1 commit
Notable commits
- fix: Fix --gap-line cutting a grapheme cluster
- fix: Fix --tiebreak=pathname with non-ASCII text
- fix: Fix CI: Pin nushell version to 0.114 (#4898)
- fix: Fix adaptive height with an inline header or footer border
- fix: Fix spurious exit while waiting for a key with --listen
- fix: Fix stale progress in --listen status payload (#4907)
- change: 0.74.3
- change: 0.74.4
- change: Avoid over-allocation in ToChars
- change: Break preview lines on IND to support chafa in preview window on tmux
- change: Clean up comments and tests
- change: Close the temp ttyout file in the SGR deduplication test
- change: Copy the item text in replace-query
- change: Do not erase the line the prompt was on (#4918)
- change: Document adaptive height waiting for the input (#4915)
- change: Erase 'p' on Terminal.app
- change: Keep a minimum wait for a sequence in flight
- change: Match the current temp file name in the powershell {f} test
- change: Parenthesize an assert_equal argument in the zsh chpwd test
- change: Pin $SHELL to cmd in TestQuoteEntry and TestReplacePlaceholder
- …and 18 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
junegunn/fzf was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit b1be3a8be1b833ce5b92fbbac11637643d60a046 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-923689c465cf.