ninenines/cowlib
47.2
Weak · 23 September 2026
21.7k
lines of production code
Erlang
primary language
5
measurements over time
What this system is
Cowlib is an Erlang support library for manipulating web protocols, providing parsers and builders for HTTP/1.1, HTTP/2, HTTP/3, and WebSockets. It includes utilities for handling structured headers, cookies, MIME types, and compression, alongside implementations for QPACK and WebTransport. The system serves as a foundational component for building and parsing modern web traffic in Erlang applications.
Features
Initial release of Cowlib 2.20.0 with HTTP/3 and structured headers support
Cowlib is introduced as a support library for manipulating Web protocols, providing parsers and builders for HTTP/1.1, HTTP/2, HTTP/3, and Websocket. This release adds initial HTTP/3 and QPACK implementation, updates the structured headers implementation to RFC 8941, and includes modules for multipart message parsing, URI templates, and mimetypes. The project is now built using erlang.mk with CI configured for OTP 27+, and the version is set to 2.20.0.
(repo-wide) · high confidence
New HTTP/3 and WebTransport support with HPACK and utility modules
This release introduces initial support for HTTP/3 and the WebTransport draft, including the QPACK header compression algorithm and WebTransport capsule parsing (cow\_capsule). It also adds a comprehensive set of new utility modules for HTTP development: cow\_cookie for parsing and building cookies (including SameSite support), cow\_date for HTTP date formatting, cow\_base64url for URL-safe Base64 encoding, cow\_deflate for safe decompression with size limits, and cow\_mimetypes for MIME type identification. The HPACK implementation (cow\_hpack) has been updated with performance optimizations and stricter validation, while existing HTTP/1.1 functionality is preserved via backward-compatible aliases in cow\_http.
src · high confidence
Behavioural changes
New HTTP parsing macros and inline utilities
The library introduces two new header files, cow\_inline.hrl and cow\_parse.hrl, which provide low-level Erlang macros for HTTP parsing. cow\_parse.hrl defines character classification macros (such as IS\_ALPHA, IS\_TOKEN, and IS\_URI\_CHAR) used to validate HTTP header values, while cow\_inline.hrl offers inline functions for case-insensitive string manipulation. These additions support the internal parsing logic for HTTP headers and URIs.
include · high confidence
Dependencies
Cowlib version bump to 2.20.0 with expanded module support
The cowlib application has been updated to version 2.20.0, introducing several new modules including cow\_base64url, cow\_http3, cow\_http3\_machine, cow\_qpack, and cow\_sse. This update also adds support for HTTP/3 and QPACK implementations, as well as Server-Sent Events (SSE) parsing, enhancing the library's capabilities for modern web protocols.
ebin · high confidence
Housekeeping
Documentation for cow\_cookie module and functions
Added comprehensive manual pages for the cow\_cookie module, including the main cow\_cookie(3) overview and specific documentation for functions like parse\_cookie, parse\_set\_cookie, cookie, and setcookie. The documentation details the cookie\_attrs and cookie\_opts types, explains options such as same\_site and max\_cookies, and notes behavioral changes like the removal of the Version attribute in setcookie since version 2.12.
doc · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 49 → 47 (-2.0)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 89 → 92 (+2.6)
- Architecture 100 → 100 (+0.0)
- Maturity 38 → 27 (-11.4)
- Readiness 36 → 43 (+7.3)
- Security 85 → 100 (+14.7)
- Event Sourcing 72 → 72 (+0.0)
Resolved (13)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- FileTooLong: src/cow_mimetypes.erl (src/cow_mimetypes.erl)
- High: security finding (details withheld)
- High: security finding (details withheld)
- No exposed public API
- Off-boarding risk: anonymized user #1
- TooManyMethods: cow_hpack (src/cow_hpack.erl)
- TooManyMethods: cow_http2_machine (src/cow_http2_machine.erl)
- TooManyMethods: cow_http3_machine (src/cow_http3_machine.erl)
- TooManyMethods: cow_http_hd (src/cow_http_hd.erl)
- TooManyMethods: cow_qpack (src/cow_qpack.erl)
- TooManyMethods: cow_ws (src/cow_ws.erl)
- complexity unreadable for .erl, .hrl — churn × complexity hotspots could not be measured
New (50)
- Documentation: no installation or build instructions (README.asciidoc)
- Documentation: no usage examples (README.asciidoc)
- Duplicated block (10 lines × 2) (src/cow_qs.erl)
- Duplicated block (11–12 lines × 2) (src/cow_qpack.erl)
- Duplicated block (15–16 lines × 2) (src/cow_http2_machine.erl)
- Duplicated block (5 lines × 2) (src/cow_ws.erl)
- Duplicated block (5 lines × 2) (src/cow_ws.erl)
- Duplicated block (56 lines × 2) (src/cow_http2_machine.erl)
- Duplicated block (6 lines × 2) (src/cow_http1.erl)
- Duplicated block (6 lines × 2) (src/cow_ws.erl)
- Duplicated block (7 lines × 2) (src/cow_http2_machine.erl)
- Duplicated block (7 lines × 2) (src/cow_qpack.erl)
- Duplicated block (7 lines × 4) (src/cow_qs.erl)
- Duplicated block (8 lines × 2) (src/cow_qs.erl)
- Duplicated block (9 lines × 2) (src/cow_qs.erl)
- Duplicated block (9 lines × 2) (src/cow_qs.erl)
- Duplicated block (9 lines × 2) (src/cow_qs.erl)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 30 more
Changes since last survey
- 9 commits — 7 feature/other, 2 fixes
By area
- (root) — 2 commits
- src/cow_hpack.erl — 2 commits
- src/cow_http_hd.erl — 2 commits
- include/cow_parse.hrl — 1 commit
- src/cow_cookie.erl — 1 commit
- src/cow_http_struct_hd.erl — 1 commit
Notable commits
- fix: Fix parsing/building decimals in cow_http_struct_hd
- fix: Fix table_find_name_dyn/3 dynamic table matching
- change: Accept 20-digit integers in header parsing
- change: Cowlib 2.20.0
- change: HPACK: never-index fields outside an allowlist
- change: Link: escape and validate values when building
- change: Parse digits better
- change: Remove a wrong todo
- change: Require Erlang/OTP-27+
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
ninenines/cowlib was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit c768a804565ff5b8178ed968a5921e469d6bd7b2 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.