ninenines/cowboy
64.7
Adequate · 22 September 2026
12.7k
lines of production code
Erlang
primary language
6
measurements over time
What this system is
Cowboy is an Erlang HTTP server library that manages connections and processes requests for HTTP/1.1, HTTP/2, and experimental HTTP/3/WebTransport protocols. It provides core capabilities for handling REST resources, WebSocket communication, and static file serving, while supporting stream handlers for compression, metrics, and tracing. The system relies on Ranch for connection management and includes comprehensive documentation and examples for configuration and integration.
How it got here
2011–2012 — Initial release and example expansion
9 changes.
This period marks the initial release of the Cowboy HTTP server, establishing core support for HTTP/1.1, HTTP/2, WebSockets, and RESTful resources. The work focused on building out a comprehensive suite of examples to demonstrate key features such as SSL, chunked encoding, and cookie handling, while simultaneously refining the build system and removing legacy type definitions.
2013 — Expanded example suite and release tooling
7 changes.
This period focused on expanding the project's example directory with new demonstrations for WebSocket, Server-Sent Events, Markdown middleware, and REST authentication. Existing examples were refactored to use relx for release management and updated to reflect current API practices, such as automatic compression and dynamic host detection.
2014–2016 — HTTP/3 support and documentation modernization
7 changes.
Cowboy 2.19.0 introduced HTTP/3 and WebTransport support, expanding the server's protocol capabilities. Concurrently, the project standardized its documentation infrastructure by migrating guides, manuals, and examples to Asciidoc, while adding detailed specification references for HTTP/1.1 compliance. New example applications were also provided to demonstrate multipart uploads and static file serving with UTF-8 support.
Features
Add Chunked Hello World example with release support
A new example demonstrating HTTP chunked transfer encoding has been added to the examples directory. The example includes source code for a Cowboy handler that streams responses in chunks, a release configuration using relx, and build instructions via erlang.mk. Users can now build and run this standalone release to observe chunked HTTP/1.1 and HTTP/2 responses.
_examples/chunked\_hello\world · high confidence
Add Cowboy WebSocket example with release support
A new WebSocket example has been added to the examples directory, demonstrating how to set up a Cowboy listener on port 8080 that serves a static index page and handles WebSocket connections. The example includes a handler that echoes received text messages with a prefix and sends periodic timeout messages. It is configured as a release using relx, allowing users to build and run it via make.
examples/websocket · high confidence
Add EventSource example application
A new example application demonstrating Server-Sent Events (SSE) using Cowboy has been added. It includes a release configuration via relx, a static HTML client that connects to the /eventsource endpoint, and an Erlang handler that streams periodic 'Tick' messages to the browser.
examples/eventsource · high confidence
Add POST echo example with HTTP/2 support
A new example application, echo\_post, has been added to demonstrate a POST parameter echo service using the Cowboy web server. The example includes a release configuration via relx and provides documentation for testing via both HTTP/1.1 (using curl) and HTTP/2 (using nghttp2). It serves as a reference for implementing a simple HTTP handler that reads URL-encoded bodies and returns them as plain text responses.
_examples/echo\_get, examples/echo\post · high confidence
Add REST Hello World example with Cowboy and relx
The rest\_hello\_world example now provides a complete, runnable demonstration of a Cowboy REST application. It includes source code for a handler that serves HTML, JSON, and plain text responses based on content negotiation, a supervisor, and an application module that starts a Cowboy listener on port 8080. The example is built using erlang.mk and configured with relx to produce a standalone release, allowing users to easily build and run the service via 'make run'.
_examples/rest\_hello\world · high confidence
Add REST basic authentication example for Cowboy
A new example demonstrating how to implement basic HTTP authentication with Cowboy's REST handler has been added to the \examples/rest\_basic\_auth\ directory. The example includes the necessary application, supervisor, and handler source files, along with a Makefile and relx configuration to build and run the service. Users can now run the example to see how to protect REST endpoints, where unauthenticated requests receive a 401 Unauthorized response and authenticated requests (using the hardcoded credentials 'Alladin:open sesame') receive a 200 OK response.
_examples/rest\_basic\auth · high confidence
Add SSL Hello World example with HTTP/2 support and release packaging
A new SSL Hello World example has been added to the examples directory, demonstrating a secure HTTPS server using Cowboy on port 8443 with a self-signed certificate. The example now supports HTTP/2 for modern browsers while falling back to HTTP/1.1, and includes updated documentation showing output for both protocols. The project structure has been converted to use a release via relx, simplifying build and run instructions through a Makefile.
_examples/hello\_world, examples/ssl\_hello\world · high confidence
Add cookie example demonstrating server and client cookie handling
A new cookie example has been added to the examples directory, providing a complete Erlang application that demonstrates setting and reading cookies. The example includes a release configuration (relx), a Makefile for building, and source code for an application, supervisor, and handler. The handler sets a server-side cookie and reads both server and client-side cookies, rendering them in an HTML template via ErlyDTL. Users can build and run the example to see cookies in action at http://localhost:8080.
examples/cookie · high confidence
Add markdown\_middleware example with on-the-fly conversion
A new example demonstrates how to use a custom Cowboy middleware to serve static files while automatically converting Markdown sources to HTML. The example includes a \markdown\_converter\ middleware that checks if a \.md\ file is newer than its corresponding \.html\ output and regenerates it on request. It is packaged as a release using relx, listens on port 8080, and serves files from the \priv\ directory.
_examples/markdown\middleware · high confidence
Add multipart upload example
A new example application demonstrating how to handle multipart file uploads using Cowboy has been added. It includes a simple HTML form for selecting files, a handler that reads the uploaded part and logs the filename, content type, and data to the shell, and the necessary application and supervisor modules to run the server on port 8080.
examples/upload · high confidence
Cowboy 2.19.0 release with HTTP/3, WebTransport, and build system overhaul
This release introduces experimental HTTP/3 and WebTransport support, enabled via the COWBOY\_QUICER compile flag, and updates the project to version 2.19.0. The build system has been migrated from Rebar to Erlang.mk, introducing new targets for documentation, testing, and static analysis, while dependencies are pinned to Cowlib 2.20.0 and Ranch 1.8.1. Documentation has been converted to Asciidoc, and the project now includes an AGENTS.md guide for contributors and a comprehensive CONTRIBUTING.asciidoc file.
(repo-wide) · high confidence
Initial release of the Cowboy HTTP server
This entry introduces the Cowboy HTTP server library, providing a complete implementation for handling HTTP/1.1 and HTTP/2 protocols over TCP and SSL transports. The release includes core modules for managing listeners (\cowboy\), protocol handlers (\cowboy\_clear\, \cowboy\_tls\), and request/response processing (\cowboy\_req\). It also adds support for WebSockets, RESTful resource handling, static file serving, and various stream handlers for compression, metrics, and tracing. The library relies on Ranch for connection management and includes utilities for binary string manipulation and time formatting.
src · high confidence
New file server example with directory listing and UTF-8 support
The examples/file\_server directory now contains a complete, standalone Cowboy file server example that serves static files from the priv directory and provides a directory listing interface. The listing supports both HTML and JSON responses, handles UTF-8 encoded filenames (demonstrated by a Chinese-named directory), and includes a middleware component to redirect directory requests to the handler. The example is configured to run on port 8080 and includes documentation and test assets.
_examples/file\server · high confidence
Removals
Removal of legacy HTTP type and record definitions
The \include/http.hrl\ and \include/types.hrl\ header files have been removed from the project. This deletion eliminates the legacy Erlang record definitions for HTTP requests (\\#http\_req\) and various type specifications (such as \http\_method\, \http\_uri\, \http\_version\, and dispatch rules) that were previously used for internal type checking and documentation. Users relying on these specific include files for custom type definitions or record patterns will need to update their code to use the current API or remove these dependencies, as these low-level structural definitions are no longer provided in the public include directory.
include · high confidence
Behavioural changes
Compressed response example now uses automatic compression handler
The compress\_response example has been updated to demonstrate automatic response body compression using the new cowboy\_compress\_h stream handler. The application now configures the HTTP listener to include cowboy\_compress\_h in its stream handlers, allowing responses to be automatically compressed (e.g., gzip) when the client supports it, as shown in the updated README with both HTTP/1.1 and HTTP/2 examples.
_examples/compress\response · high confidence
Cowboy User Guide converted to Asciidoc
The documentation source has been migrated from its previous format to Asciidoc. This change introduces a new book structure (book.asciidoc) that organizes the guide into logical sections including Introduction, Configuration, Handlers, Request and response, REST, Websocket, Advanced topics, and a comprehensive set of migration guides for versions 1.0 through 2.18. The conversion also includes new or updated chapters for constraints, cookies, listeners, loop handlers, middlewares, and the flow diagram, providing a more structured and maintainable documentation base for users.
doc/src/guide · high confidence
Cowboy manual converted to Asciidoc with new listener management and constraint functions
The Cowboy documentation has been converted to Asciidoc format, introducing new manual pages for listener management functions \cowboy:get\_env/2,3\ and \cowboy:set\_env/3\ (introduced in 2.11) which allow retrieving and updating listener environment values, and \cowboy\_constraints:from\_fun/1\ (introduced in 2.15) which enables creating custom constraints from 1-arity functions. The manual also documents the \cowboy:start\_clear/3\ and \cowboy:start\_tls/3\ functions that replace the older \start\_http\ and \start\_https\ APIs, and includes updated documentation for stream handlers like \cowboy\_compress\_h\ and the new \cowboy\_decompress\_h\.
doc/src/manual · high confidence
Examples documentation converted to AsciiDoc
The README for the examples directory has been converted from Markdown to AsciiDoc format, providing a standardized documentation structure for the available Cowboy examples such as chunked transfer, SSL, and WebSocket demonstrations.
examples · high confidence
REST pastebin example converted to a release with syntax highlighting and input validation
The REST pastebin example has been restructured into a standalone release using relx, simplifying build and run instructions via a Makefile. Functionally, the example now accepts a broader range of media types for input and enforces a constraint on the 'lang' query parameter to validate syntax highlighting languages. It also includes a web interface for submitting pastes and supports syntax-highlighted output via the 'highlight' tool when requested.
_examples/rest\pastebin · high confidence
Release version 2.19.0 with HTTP/3 and WebTransport support
The Cowboy HTTP server has been updated to version 2.19.0. This release includes the application metadata for the new version and registers modules supporting HTTP/3 (via \cowboy\_http3\ and \cowboy\_quicer\) and WebTransport (\cowboy\_webtransport\), alongside other stream handlers like compression, decompression, metrics, and tracing.
ebin · high confidence
WebSocket example now uses current host for connection URL
The WebSocket client example has been updated to automatically use the current host as the base URL for the WebSocket connection. This change simplifies the setup process by removing the need to manually configure the server address, allowing users to test the example directly by navigating to the page in their browser.
examples/websocket/priv · high confidence
Test coverage
Added documentation for RFC6585 and RFC7230 HTTP/1.1 server specifications; Added test suites for response compression and request decompression.
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 61 → 65 (+4.2)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 90 → 91 (+1.6)
- Architecture 96 → 100 (+4.1)
- Maturity 54 → 56 (+2.7)
- Readiness 58 → 54 (-3.8)
- Security 61 → 89 (+28.6)
Resolved (17)
- Change coupling: cowboy_clear.erl ↔ cowboy_tls.erl (src/cowboy_clear.erl)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- No exposed public API
- Off-boarding risk: anonymized user #1
- Test reliability not included
- TooManyMethods: cowboy_http (src/cowboy_http.erl)
- TooManyMethods: cowboy_http2 (src/cowboy_http2.erl)
- TooManyMethods: cowboy_req (src/cowboy_req.erl)
- TooManyMethods: cowboy_rest (src/cowboy_rest.erl)
- TooManyMethods: cowboy_websocket (src/cowboy_websocket.erl)
- complexity unreadable for .erl, .hrl — churn × complexity hotspots could not be measured
New (50)
- Coverage not measured — no coverage collector is wired up
- Dependency hygiene PARTLY measured — rebar3 pinning read, dependency currency not (no rebar.lock-pinned Hex declaration to grade)
- Documentation: no usage examples (examples/chunked_hello_world/README.asciidoc)
- Duplicated block (10–13 lines × 2) (src/cowboy_http.erl)
- Duplicated block (12 lines × 2) (src/cowboy_http.erl)
- Duplicated block (15 lines × 2) (src/cowboy_http.erl)
- Duplicated block (15 lines × 2) (src/cowboy_http.erl)
- Duplicated block (18 lines × 2) (src/cowboy_http.erl)
- Duplicated block (5 lines × 2) (examples/hello_world/src/toppage_h.erl)
- Duplicated block (5 lines × 2) (src/cowboy_http.erl)
- Duplicated block (5 lines × 2) (src/cowboy_rest.erl)
- Duplicated block (6 lines × 2) (src/cowboy_clear.erl)
- Duplicated block (6 lines × 2) (src/cowboy_compress_h.erl)
- Duplicated block (6 lines × 2) (src/cowboy_http.erl)
- Duplicated block (6 lines × 2) (src/cowboy_http.erl)
- Duplicated block (6 lines × 2) (src/cowboy_rest.erl)
- Duplicated block (6 lines × 2) (src/cowboy_rest.erl)
- Duplicated block (6 lines × 2) (src/cowboy_websocket.erl)
- Duplicated block (6–7 lines × 2) (src/cowboy_http.erl)
- Duplicated block (7 lines × 2) (src/cowboy_http.erl)
- …and 30 more
Changes since last survey
- 7 commits — 7 feature/other, 0 fixes
By area
- (root) — 2 commits
- doc/src — 1 commit
- src/cowboy_http.erl — 1 commit
- test/handlers — 1 commit
- test/http2_SUITE.erl — 1 commit
- test/req_SUITE.erl — 1 commit
Notable commits
- change: Cowboy 2.19.0
- change: Remove unnecessary section in AGENTS.md
- change: Require Erlang/OTP 27.0 or greater
- change: Resolve http_SUITE:graceful_shutdown_listener flake
- change: Set process labels on Cowboy processes
- change: Tweak some HTTP/2 tests
- change: Update tests for most recent Gun
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
ninenines/cowboy was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit c965d1a3bffa0708b0570e83233ddd3bf77b97c1 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.