Skip to content
CAI
Software that uses CAICheck a score

Orange-OpenSource/hurl

59.1

Adequate · 27 September 2026

68.4k

lines of production code

Python

with Rust, JavaScript

3

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Hurl is a command-line tool for defining and executing HTTP tests using a simple text-based format. It supports making HTTP requests, capturing response data, and asserting on headers, bodies, and JSON/XML content. The system includes a formatter for linting and exporting tests, and generates reports in HTML, JSON, JUnit, and TAP formats.

How it got here

2020–2022 — monorepo restructuring and HTTP client migration

54 changes.

The project underwent a major architectural shift, reorganizing from a monolithic crate into a multi-crate workspace and migrating the HTTP client from reqwest to libcurl. This period involved extensive refactoring of core modules, the parser, and the runner, alongside the removal of legacy test suites and internal HTML rendering logic. Concurrently, new features such as parallel execution, enhanced JSONPath support, and improved reporting were introduced to modernize the tooling.

2023–2025 — CLI expansion and parallel execution

98 changes.

This period focused on significantly expanding the Hurl CLI with new features such as parallel execution, shell completions, and curl command import support. It also introduced comprehensive reporting capabilities, including HTML timelines, TAP, and JUnit formats, alongside extensive integration test coverage for these new functionalities.

2026 — integration testing and CLI enhancements

18 changes.

This period focused on expanding integration test coverage across diverse features such as raw bytes, digest authentication, IPv6, and Server-Sent Events. It also introduced significant CLI improvements, including configurable default options, new flags for cookie and header management, and stricter JSONPath matching, alongside security fixes for HTML report generation.

Features

Add Chocolatey installation script for Hurl on Windows

The Chocolatey package definition for Hurl on Windows now includes a \chocolateyinstall.ps1\ script that automates the installation process. This script downloads the 64-bit Windows binary from the official GitHub releases, verifies the SHA-256 checksum, and extracts the package to the local directory, enabling users to install Hurl via the Chocolatey package manager.

_contrib/windows/windows\_package\managers/chocolatey/hurl/tools · high confidence

Add Emacs major mode for Hurl files

Users can now edit Hurl files in Emacs with syntax highlighting for HTTP methods (GET, POST, etc.) and assertion keywords (exists, contains, etc.). The new \hurl-mode.el\ file provides a major mode that automatically activates for \.hurl\ files and includes configuration for indentation and comments. Installation instructions for Doom Emacs and straight.el are provided in the README.

contrib/emacs · high confidence

Add Sublime Text syntax highlighting for Hurl files

Users can now enable syntax coloring for .hurl files in Sublime Text and compatible tools like bat. This change adds a Hurl.sublime-syntax definition that highlights HTTP methods, URLs, status codes, section headers, headers, templates, comments, and various body formats (JSON, XML, multiline, encoded). A README provides installation instructions for Sublime Text and bat, and a test.hurl file demonstrates the syntax coverage.

contrib/sublime-text · high confidence

Add TAP (Test Anything Protocol) report output

Hurl now supports generating test reports in the TAP format. This new capability allows users to export test results to a file, where each test case is recorded as passing or failing. The implementation handles both writing new reports and appending to existing TAP files, while also supporting the optional TAP version 13 header for compatibility with standard TAP parsers.

packages/hurl/src/report/tap · high confidence

Add Vim and Neovim syntax highlighting for Hurl files

Users can now enable syntax coloring for Hurl files in Vim and Neovim. This change introduces the necessary syntax and file-type detection scripts, along with documentation on how to install them into the respective configuration directories and activate highlighting.

contrib/vim · high confidence

Add shell completions for Hurl and Hurlfmt

New argument-completion scripts are now provided for Bash, Zsh, Fish, and PowerShell for both the \hurl\ and \hurlfmt\ commands. These files (e.g., \completions/\_hurl\, \completions/hurl.bash\, \completions/hurl.fish\, \completions/\_hurl.ps1\) enable tab-completion for all available CLI flags and file arguments, improving the command-line experience across major shells.

completions · high confidence

Add syntax highlighting for Hurl files

Vim users now get syntax highlighting support for Hurl files via the new contrib/vim/syntax/hurl.vim file. This adds keyword, section, and operator highlighting, supports HTTP methods (including LINK, UNLINK, PURGE, LOCK, UNLOCK, PROPFIND, VIEW), and enables spell checking in comments.

contrib/vim/syntax · high confidence

Added Chocolatey package manifest for Hurl

A new Chocolatey package specification (hurl.nuspec) has been added to the Windows package manager contributions, defining metadata such as the project URL, license, and source location for the Hurl CLI tool. This enables users to install Hurl via Chocolatey on Windows systems.

_contrib/windows/windows\_package\managers/chocolatey/hurl · high confidence

Added HTML entity escaping and unescaping capabilities

The \packages/hurl/src/html\ module now provides \HtmlEscape\ and \HtmlUnescape\ traits, allowing users to safely convert strings to HTML-safe sequences (escaping characters like &, \<, \>, quotes) and decode HTML entities (named and numeric references) back to Unicode characters. This implementation follows the HTML5 standard for character reference handling.

packages/hurl/src/html · high confidence

Added Hurl brand assets and color specifications

This change adds the official Hurl branding resources to the repository, including a \branding.md\ file that defines the product name usage and specific color codes (pink \\#ff0288\, light mode text \\#333333\, and dark mode text \\#dedede\). It also introduces several SVG logo files (\logo-full\, \logo-mini\, and \logo-icon\) for both light and dark modes, providing the visual assets used for the product's identity.

art · high confidence

Added npm distribution verification script

A new \check\_publish.py\ script has been added to the \contrib/npm\ directory to validate the integrity of the npm package before publishing. This tool verifies that the Hurl binary version and npm package version match their expected values, and checks that the checksums of the platform-specific binary archives match the expected hashes defined in \platform.json\. This ensures that published npm packages contain the correct, uncorrupted binaries.

contrib/npm · high confidence

Configurable default options via Hurl config file

Users can now define default CLI options in a Hurl configuration file, which are applied automatically to every run unless overridden by command-line arguments. The new \config\_file\ module parses a simple text format supporting options such as \--color\, \--compressed\, \--http1.1\, \--insecure\, \--proxy\, \--retry\, \--verbose\, and many others, allowing users to persist their preferred settings without repeating flags.

_packages/hurl/src/cli/options/config\file · high confidence

Experimental parallel execution engine for Hurl files

Hurl now supports running multiple Hurl files concurrently via a new parallel runner. This feature introduces a multi-threaded architecture where worker threads execute jobs from a queue, communicating results and progress back to the main thread via channels. Users benefit from reduced execution time for large test suites and a dedicated progress bar that tracks concurrent worker states, retry counts, and completion status. The implementation includes specific error handling for input and parsing failures, supports output modes for response bodies and JSON, and manages standard output/error buffering to ensure clean terminal display during parallel runs.

packages/hurl/src/parallel · high confidence

Hurl 8.1.0 release with security fixes and new options

This release introduces several new command-line options including --variables-file for per-request variable injection, --no-header to remove specific HTTP headers, --fail-with-body to output response bodies on errors, --proxy-header to send headers exclusively to a proxy, and --http2-prior-knowledge to use HTTP/2 without HTTP/1.1 Upgrade. It also adds a no-jsonpath coercion option and Sublime Text syntax highlighting. Security issues fixed include [CVE redacted] (cookie stripping during cross-host redirects), HTML report header escaping, and symlink file root escaping. Bug fixes address misleading error messages for not-equal predicates, variable option values starting with numbers or booleans, recorded headers with proxy CONNECT, and debug curl commands with binary bodies containing NUL characters.

(repo-wide) · high confidence

Initial Debian packaging for Hurl PPA

Added the complete set of Debian packaging files in contrib/ppa/debian to enable building Hurl and hurlfmt as .deb packages for Ubuntu/Debian distributions. This includes the control file specifying build dependencies (such as libclang-dev and debhelper), the rules file defining the build and install steps, the install manifest for binary placement, and supporting configuration files like cargo.config for vendored sources and the copyright file for license compliance.

contrib/ppa/debian · high confidence

Introduce npm package for Hurl with cross-platform binary installation

The \@orangeopensource/hurl\ npm package is now available, allowing JavaScript developers to install and run the Hurl command-line tool directly via npm scripts. The package includes a post-installation process that automatically downloads the correct pre-compiled Hurl binary for the user's platform (Windows, Linux, or macOS, including ARM64) from GitHub releases, verifies the archive's SHA256 checksum for security, and extracts it for immediate use. This enables seamless integration of Hurl's HTTP testing and data fetching capabilities into Node.js projects without manual binary management.

contrib/npm/hurl · high confidence

JSONPath filter expressions now support complex logical and comparison operations

The JSONPath parser in \packages/hurl/src/jsonpath/parser\ has been rewritten to support a richer set of filter expressions, including comparison operators (==, !=, \<, \>, \<=, \>=), logical operators (&&, \|\|, !), and RFC 9535 functions (length, count, value, match, search). This allows users to write more sophisticated queries, such as filtering arrays by nested object properties or applying regex-based matching within filters.

packages/hurl/src/jsonpath/parser · high confidence

New CI check scripts for code quality and compliance

The \bin/check\ directory now includes a comprehensive suite of new shell and Python scripts that enforce code quality, licensing, and consistency standards. These scripts validate shell script shebangs and error handling, enforce snake\_case for shell functions, check PowerShell strict mode, and ensure consistency between shell and PowerShell integration tests. Additional checks cover Rust code formatting (clippy, rustfmt), semantic versioning, changelog accuracy, dependency license compliance (forbidding GPL, allowing MIT, Apache-2.0, BSD, ISC, etc.), and GitHub Actions security (zizmor). The suite also includes tools for validating Dockerfiles (hadolint), XML output (xmllint), documentation generation, and code coverage.

bin/check · high confidence

New CI infrastructure and maintenance tooling

This change introduces a comprehensive set of new scripts in the bin directory to standardize and improve the continuous integration environment. It adds platform-specific prerequisite installation scripts for Ubuntu, Debian, Fedora, Arch Linux, Alpine, macOS, and Windows, ensuring consistent dependency setups across all supported operating systems. New environment diagnostic scripts (environment.sh, environment.ps1) allow for detailed logging of system states, while dedicated scripts handle Python virtual environment activation, Rust installation, and grcov coverage tooling. Additionally, the legacy shell-based crate update script has been replaced by a new Python utility (update\_crates.py) that leverages the crates.io API to manage dependency updates, and a helper script is provided to disable PAM for sudo in Fedora CI environments.

bin · high confidence

New HTML export formatter with syntax highlighting and dark mode support

The Hurl core library now includes a new HTML formatter that converts Hurl files into syntax-highlighted HTML output. This feature introduces a dedicated \html.rs\ module and accompanying \hurl.css\ stylesheet, enabling users to generate standalone HTML reports or embedded \\<pre\>\ blocks with semantic class names for elements like methods, URLs, strings, and filters. The styling includes support for system dark mode preferences, ensuring readable output in both light and dark themes.

_packages/hurl\core/src/format · high confidence

New HTML timeline report with waterfall visualization and secret redaction

The HTML report now includes a dedicated Timeline tab that displays a waterfall chart of HTTP calls, showing request durations, status codes, and source file links. This view supports hovering over URLs to see the full address and automatically redacts secrets from displayed values. The report also ensures that sensitive data in cookies is redacted and that debug table values are HTML-escaped to prevent XSS vulnerabilities.

packages/hurl/src/report/html/timeline · high confidence

New JSON and text export formats for Hurl files

The \hurlfmt\ tool now supports exporting Hurl test files into structured JSON and human-readable text formats. The new JSON exporter serializes the entire Hurl AST—including entries, requests, responses, captures, asserts, and options—into a JSON representation, enabling programmatic analysis or integration with other tools. The new text exporter renders Hurl files with optional ANSI color styling, providing a readable, syntax-highlighted view of the test cases. These additions expand \hurlfmt\ beyond its previous role as a formatter, allowing users to inspect or share test definitions in alternative, machine- and human-friendly formats.

packages/hurlfmt/src/format · high confidence

New JSON pretty-printing capability with automatic and forced modes

Hurl now includes a built-in, zero-dependency JSON formatter that prettifies JSON responses with syntax highlighting (ANSI colors) and indentation. Users can control this behavior via a new \PrettyMode\ enum, which supports automatic detection based on the response's \Content-Type\ header, forced prettification regardless of headers, or disabling prettification entirely. This change introduces the \packages/hurl/src/pretty\ module, containing the core \json.rs\ formatter and \mod.rs\ configuration, enabling more readable output for JSON API responses without requiring external tools.

packages/hurl/src/pretty · high confidence

New JSON serialization module for Hurl results and values

A new \packages/hurl/src/json\ module has been introduced to handle the serialization and deserialization of \HurlResult\ and capture \Value\ types to JSON. This module defines the JSON schema for exporting test outcomes, including entries, calls, timings, cookies, and certificate details, while ensuring that secrets are redacted from the output. It also implements specific serialization logic for various value types, such as converting nodesets and units to structured JSON objects and encoding byte arrays as base64 strings.

packages/hurl/src/json · high confidence

New and updated value transformation filters

The filter evaluation engine in the runner now supports a broader set of value transformations. New capabilities include Base64 encoding and decoding (standard and URL-safe), character set decoding, counting items in collections, extracting the first or last element of a list, and calculating the number of days before or after the current date. Existing filters have been updated or refined, including the deprecation of the \format\ filter in favor of \dateFormat\, the addition of a \replaceRegex\ filter, and improved error handling for invalid inputs and format specifiers across the filter chain.

packages/hurl/src/runner/filter · high confidence

New curl command export capability for test results

Users can now export executed HTTP requests as curl commands. This change introduces a new \curl\ report module that aggregates Hurl test results and writes them to a file, automatically redacting sensitive information (such as cookies) from the generated commands to enhance security.

packages/hurl/src/report · high confidence

New release infrastructure scripts and automated release note generation

The release process now includes a comprehensive set of new scripts in bin/release to build, package, and publish Hurl across Linux (deb, tarball), macOS (tarball), and Windows (NSIS installer, zip, Chocolatey, winget). A new Python utility (get\_release\_note.py) automatically generates release notes by querying the GitHub GraphQL API for closed issues and pull requests, replacing manual or web-scraping methods. Supporting scripts handle changelog extraction, version detection, man page generation, SHA256 checksums, and regression testing against external projects like Caddy and Python infra.

bin/release · high confidence

New styled text rendering and formatting capabilities

The \hurl\_core\ text module now provides a new \StyledString\ type that allows building and rendering text with specific styles (foreground colors and bold attributes) in either plain or ANSI formats. This change introduces methods to append styled content, split strings by delimiter, wrap lines to a maximum width, and check string properties, enabling more structured and formatted output in the application's console and logging interfaces.

_packages/hurl\core/src/text · high confidence

New utility modules for logging, terminal output, path security, and secret redaction

This change introduces a new \util\ module in the Hurl package, adding four key components: \logger.rs\ provides a structured logger with configurable verbosity, error formatting, and ANSI color support; \term.rs\ introduces \Stdout\ and \Stderr\ wrappers that support both immediate and buffered writing modes, along with progress bar management; \path.rs\ adds a \ContextDir\ struct with \is\_access\_allowed\ checks to prevent symlink-based path traversal escapes when resolving file roots; and \redacted.rs\ provides a \Redact\ trait to mask sensitive values in logs and reports. These utilities form the foundation for improved security, output control, and logging flexibility in Hurl runs.

packages/hurl/src/util · high confidence

Per-request verbosity control via Hurl options

Users can now set the verbosity level (brief, verbose, or debug) for individual requests within a Hurl file using the \[Options\] section. This allows for fine-grained control over the amount of diagnostic output—such as request/response headers, timing data, and curl equivalents—generated during test execution, independent of global CLI flags or environment variables.

_integration/hurl/tests\ok/verbosity · high confidence

Retry configuration via command line, config file, and environment variables

Users can now configure HTTP request retry behavior in Hurl using three methods: passing \--retry\ and \--retry-interval\ flags directly on the command line, defining \retry\ and \retry-interval\ in a Hurl config file (via \XDG\_CONFIG\_HOME\), or setting the \HURL\_RETRY\ and \HURL\_RETRY\_INTERVAL\ environment variables. This allows tests to automatically retry failed assertions (such as polling for a job state change) with a specified maximum count and delay between attempts.

_integration/hurl/tests\ok/retry · high confidence

Hurl now allows users to deactivate the internal cookie store for a specific run using the new \--no-cookie-store\ command-line flag, the \no\_cookie\_store\ option in the Hurl configuration file, or the \HURL\_NO\_COOKIE\_STORE\ environment variable. This ensures that cookies received in responses (e.g., via \Set-Cookie\ headers) are not persisted or automatically sent in subsequent requests within the same file, while still allowing explicit cookie injection via the \\[Cookies\]\ section. This is useful for testing scenarios where cookie persistence should be isolated per execution.

_integration/hurl/tests\_ok/no\_cookie\store · high confidence

Support for setting User-Agent via CLI, config file, and environment variable

Users can now configure the HTTP User-Agent header sent by Hurl using three methods: the \--user-agent\ command-line option, the \--user-agent\ setting in the Hurl configuration file, or the \HURL\_USER\_AGENT\ environment variable. This allows for flexible control over the client identity string used in requests without modifying the \.hurl\ test files themselves.

_integration/hurl/tests\_ok/user\agent · high confidence

Support for suppressing Hurl output via config file and environment variable

Users can now suppress the standard output of Hurl test runs using three methods: passing the \--no-output\ flag, setting the \HURL\_NO\_OUTPUT\ environment variable, or adding \--no-output\ to a Hurl configuration file. This location provides the integration tests that verify these mechanisms work correctly across shell, PowerShell, and Python execution contexts.

_integration/hurl/tests\_ok/no\output · high confidence

Windows installer now includes PowerShell completions and HTTP/2 support

The Windows installer (hurl.nsi) has been updated to include PowerShell completion scripts (\_hurl.ps1 and \_hurlfmt.ps1) in the documentation section, making shell autocompletion available to Windows users. Additionally, the installer now bundles libcurl.dll and nghttp2.dll, enabling HTTP/2 support on Windows platforms.

bin/windows · high confidence

curl command import support in hurlfmt

The hurlfmt tool now accepts curl command-line strings as input and converts them into Hurl format. This new capability parses curl options such as --data-raw, --cookie, --user, --digest, --ntlm, --negotiate, --retry, and --verbose, handling argument splitting, quote escaping (including $'...' syntax), and header validation. The conversion maps these options to Hurl HTTP methods, URLs, headers, cookies, and options, automatically inferring POST for data payloads and adding retry-related assertions.

packages/hurlfmt/src/curl · high confidence

hurlfmt now supports multiple input files and curl command-line parsing

The hurlfmt tool has been updated to accept multiple input files, allowing users to format, check, or export several Hurl files in a single invocation. Additionally, it can now parse and format curl command-line strings as input, expanding its utility beyond standard Hurl files. The tool also supports exporting the parsed AST to JSON format.

packages/hurlfmt/src · high confidence

Removals

Removal of internal HTML AST and rendering module

The internal \html\ module, which previously contained the Abstract Syntax Tree (AST) definitions and the logic for rendering HTML output, has been removed from the library. This change eliminates the code responsible for generating HTML representations of parsed documents, meaning the library no longer provides this specific output format capability.

src, src/html · high confidence

Removal of legacy Travis CI deployment scripts

The CI pipeline no longer includes the legacy shell scripts used for tag validation, tarball creation, and GitHub release uploads. Specifically, the files \ci/check\_tag\, \ci/create\_tarballs\, \ci/deploy.sh\, and \ci/upload.sh\ have been deleted, indicating that the automated process for building release artifacts and publishing them to GitHub releases via these specific scripts has been removed or replaced by a different mechanism.

ci · high confidence

Removal of legacy binary entry points and assets

The \hurl\, \hurlfmt\ binaries and the \report.css\ stylesheet have been removed from the source tree. This deletion indicates that the standalone binary implementations and their associated static assets are no longer part of this codebase location, likely having been replaced by a new architecture or build structure.

src/bin · high confidence

Removal of legacy formatting and JSONPath modules

The \src/format\ and \src/jsonpath\ modules have been removed from the codebase. This deletes the legacy implementation for terminal color formatting, error logging, HTML/text output generation, and the custom JSONPath parser and evaluator. Users relying on these specific internal formatting or JSONPath query capabilities will no longer have access to them in this location.

src/format, src/jsonpath · high confidence

Removal of legacy integration test report artifacts

The static HTML report page (index.html), its associated stylesheet (report.css), and the raw JSON test results file (tests.json) located in the integration/report directory have been deleted. This change removes the previously generated, hardcoded test execution summaries and styling, indicating a shift away from these specific static artifacts in the integration testing workflow.

integration/report · high confidence

Removed integration test fixtures for error linting

Deleted the integration test fixtures in the \integration/tests\_error\_lint\ directory, including the \.hurl\ request files, their corresponding \.err\ expected error outputs, and \.lint\ files. This removes the test cases that previously validated linting behavior for HTTP request formatting issues, such as excessive spaces and cookie/query string parameter ordering.

_integration/tests\_error\lint · high confidence

Removed legacy libcurl HTTP client implementation

The internal libcurl-based HTTP client module (client.rs, core.rs, mod.rs) has been removed from the codebase. This eliminates the previous implementation that used the libcurl library to execute HTTP requests and handle responses, indicating a shift away from this specific backend for HTTP operations.

src/http/libcurl · high confidence

Security

HTML report now redacts secrets and escapes HTML to prevent injection

The HTML report generation in \packages/hurl/src/report/html\ now automatically redacts sensitive data (such as cookies and headers) and escapes all debug table values (headers, captures, etc.) to prevent script injection. This ensures that sensitive information is not exposed in the generated HTML files and that malicious content in responses cannot be executed when viewing the report.

packages/hurl/src/report/html · high confidence

Prevent XSS in HTML reports by escaping debug table values

The HTML report generator now escapes special characters in debug table values, including HTTP headers and captures, to prevent Cross-Site Scripting (XSS) attacks. This ensures that malicious content injected via headers (such as script tags) is rendered as plain text in the generated HTML reports rather than being executed.

_integration/hurl/tests\_ok/html\_report\injection · high confidence

Architecture

Hurl CLI restructured into a modular package with parallel execution support

The Hurl command-line tool has been refactored from a single binary into a modular Rust crate structure, separating the core library (lib.rs) from the CLI entry point (main.rs) and execution logic (run.rs). This change introduces a parallel runner that executes Hurl files concurrently using a thread pool, configurable via the --jobs option, while maintaining sequential execution as the default. The refactoring also standardizes error handling with specific exit codes, improves secret redaction across all report formats (HTML, JUnit, TAP, JSON, curl), and enhances output formatting with better color support and JSON pretty-printing capabilities.

packages/hurl/src · high confidence

Behavioural changes

AWS SigV4 integration test moved to subfolder

The AWS SigV4 integration test suite has been reorganized into a dedicated subfolder (integration/hurl/tests\_ok/aws\_sigv4). This change includes the test server implementation (aws\_sigv4.py) and the client-side test scripts (curl, hurl, shell, and PowerShell) that verify the handling of AWS Signature Version 4 authentication headers.

_integration/hurl/tests\_ok/aws\sigv4 · high confidence

Automated PPA build environment setup and cleanup

The PPA contribution scripts now include dedicated automation for preparing and cleaning the build environment. A new prerequisites.sh script automatically extracts the vendor sources, installs the specific Rust toolchain version defined in Cargo.toml, and configures the PATH to ensure the correct compiler is used. A new clean.sh script provides a standardized way to reset the build state by running dh\_clean and removing generated artifacts like the vendor and target directories.

contrib/ppa/debian/bin · high confidence

Core library refactoring: new input handling, parser combinators, and reader types

The \hurl\_core\ library has been restructured to improve modularity and correctness. A new \Input\ type now manages file and standard input sources, caching stdin content to allow multiple reads and stripping UTF-8 BOMs. Parser logic has been extracted into a generic \combinator\ module featuring reusable functions like \optional\, \zero\_or\_more\, and \choice\ that work with a new \ParseError\ trait. The \Reader\ has been redesigned with a \Cursor\ struct (containing \CharPos\ and \Pos\) to track character offsets and line/column positions more accurately, supporting sub-readers via \with\_pos\. Additionally, shared types like \Count\ (supporting infinite counts via -1) and \Index\ (1-based) have been consolidated into a \types\ module.

_packages/hurl\core/src · high confidence

Expanded filter capabilities and integration test coverage

This change introduces new filter functions and enhances existing ones, specifically adding a \replaceRegex\ filter for regular-expression-based replacements and fixing the \replace\ filter to treat its first argument as a literal string rather than a regex. It also adds support for template variables in the \nth\ filter parameter, enabling dynamic indexing (including negative values), and includes integration tests for \utf8Encode\/\utf8Decode\, \first\/\last\, and \toDate\ filters. These updates are validated by new integration test files in the \integration/hurl/tests\_ok/filter\ directory, which exercise the new and modified behaviors against a local test server.

_integration/hurl/tests\ok/filter · high confidence

HTTP client module refactored and cleaned up

The HTTP client implementation in src/http has been significantly refactored and cleaned up. This change removes the previous client.rs, cookie.rs, core.rs, export.rs, import.rs, request.rs, and response.rs files, indicating a major restructuring of how HTTP requests and responses are handled. The commit messages suggest this refactor accompanies the addition of new features like timeout options, compressed response support, and explicit Expect headers, as well as fixes for cookie handling and insecure flag logic. Users will experience these changes as an updated HTTP engine with potentially improved error messages and more robust request construction.

src/http · medium confidence

The HTTP client implementation has been restructured to introduce dedicated models for SSL/TLS certificates, cookie storage, and request-response timings. Users can now access detailed certificate attributes (subject, issuer, serial number, and subject alternative names) on HTTP responses, enabling assertions on server identity. A new cookie store manages cookies across redirects and supports Netscape format import/export, while the \Call\ struct now exposes granular timing data (DNS lookup, connection, SSL handshake, and transfer times) for performance analysis. Additionally, the client now caches certificates on reused connections to improve efficiency.

packages/hurl/src/http · high confidence

Hurl 8.0.1 release with Windows icon support and native library build

This release introduces a build script (build.rs) that compiles a native C library (libxml.c) and, on Windows, embeds a custom application icon (logo.ico) into the executable. The README has been updated to reflect the current state of the project, including dark mode logo support and CI badges. This change represents a shift in how the binary is constructed, integrating native code compilation directly into the Rust build process.

packages/hurl · medium confidence

Hurl AST restructured with new primitive types and per-request options

The Hurl AST core has been reorganized to support a richer set of request configurations and data types. The \OptionKind\ enum now exposes a wide range of per-request options (such as \http1.0\, \http2\, \http3\, \digest\, \ntlm\, \negotiate\, \aws-sigv4\, \pinnedpubkey\, \connect-to\, \unix-socket\, and \variables-file\), allowing users to configure HTTP behavior on a per-request basis. The AST primitives have been updated to use \SourceString\ for source preservation and \Template\ for values, while \JsonValue\ now supports \Placeholder\ expressions for dynamic content. Additionally, new query types like \Certificate\, \Ip\, \Redirects\, and \RawBytes\ are available for assertions, and the \SectionValue\ enum supports short syntax for \Query\, \Form\, and \Multipart\ sections.

_packages/hurl\core/src/ast · high confidence

Hurl CLI options and configuration engine refactored

The command-line argument parsing and configuration management in the Hurl CLI has been completely rewritten. This change introduces a new \CliOptions\ struct and a modular parsing architecture (split into \args\, \commands\, \context\, \env\vars\, and \duration\ modules) to handle the tool's extensive set of HTTP, output, and run options. It adds support for a wide range of new command-line flags (such as \--aws-sigv4\, \--http3\, \--fail-with-body\, \--error-format\, and \--unix-socket\) and environment variables (prefixed with \HURL\\), while also introducing a new \BoolOpt\ type for handling auto-detected boolean settings and a \RunContext\ for capturing execution environment details like terminal status and CI detection.

packages/hurl/src/cli/options · high confidence

Hurl file type comment string configuration

The Hurl file type plugin now sets the comment string to '\# ', enabling correct comment handling in Vim for Hurl files.

contrib/vim/ftplugin · high confidence

Hurlfmt linter rewritten to preserve and reformat AST structure

The linter in \packages/hurlfmt/src/linter\ has been completely rewritten to operate by transforming the parsed Hurl AST back into a string, rather than recreating an AST from scratch. This change ensures that formatting rules—such as consistent spacing, line terminator handling, and the specific ordering of sections like \\[Options\]\, \\[Query\]\, and \\[BasicAuth\]\—are applied deterministically. Users will see more consistent output from \hurlfmt\, with improved handling of new syntax features like one-line strings, redacted captures, and various predicate values, while maintaining the logical structure of their test files.

packages/hurlfmt/src/linter · high confidence

Improved parser error messages for Hurl files

The Hurl parser now provides more specific and helpful error messages when encountering syntax issues in .hurl files. Users will see clearer diagnostics for problems such as invalid JSON structures (e.g., trailing commas, missing elements), malformed HTTP methods, incorrect option values (like invalid durations or verbosity levels), and issues with literals like base64, file paths, and regular expressions. The errors now often include suggestions for correction, such as valid option names or expected formats, making it easier to identify and fix mistakes in test definitions.

_integration/hurl/tests\_error\parser · high confidence

Improved redirect handling and credential security

This update refines how Hurl follows HTTP redirects to align more closely with curl's behavior. It introduces the \--location\ and \--location-trusted\ flags (and corresponding \HURL\_LOCATION\ and \HURL\_LOCATION\_TRUSTED\ environment variables) to control redirect following. A key behavioral change is the strict filtering of \Authorization\ and \Cookie\ headers when a redirect crosses hosts, preventing credential leakage; the \--location-trusted\ flag allows users to explicitly opt-in to forwarding these credentials across hosts. Additionally, the tool now correctly handles implicit \Content-Type\ headers during redirections and preserves request bodies for 308 redirects.

_integration/hurl/tests\_ok/follow\redirect · high confidence

Integration test suite migrated to Python with PTY support

The integration testing infrastructure has been rewritten from shell scripts to Python, introducing a new \test\_script.py\ runner that executes tests against a local Flask server. This migration adds support for pseudo-terminal (PTY) execution via \term.py\, enabling the testing of terminal-specific behaviors (such as color codes and interactive output) on non-Windows platforms. The new suite also includes pattern-based output matching (replacing the \\~\~\~\ wildcard with standard regex), improved diagnostics for stdout/stderr mismatches, and a structured directory layout separating \hurl\ and \hurlfmt\ test cases into \tests\_ok\, \tests\_failed\, and specialized folders like \tests\_pty\ and \tests\_ssl\.

integration · high confidence

Integration tests for path-as-is URL handling moved to subfolder

The integration tests verifying the \--path-as-is\ option behavior have been reorganized into a dedicated \path\_as\_is\ subfolder. This change groups the test fixtures (including Hurl files, shell/PowerShell runners, and a Flask reference implementation) together, ensuring that requests with dot-segments like \../\ are preserved in the path when the option is enabled, while still validating the default behavior where such segments are resolved.

_integration/hurl/tests\_ok/path\_as\is · high confidence

Integration tests reorganized into a dedicated bench subfolder

The integration test suite has been restructured to isolate benchmarking tests. The previous test file located at integration/tests/data.bin has been renamed to bench.out and moved into the new integration/hurl/tests\_ok/bench directory. Additionally, new shell (bench.sh) and PowerShell (bench.ps1) scripts have been added to this subfolder to execute the Hurl benchmark tests (bench.hurl) using IPv4, ensuring these specific integration tests are now run from a dedicated location.

_integration/hurl/tests\_ok/bench, integration/hurl/tests\_ok/ip\_query, integration/hurl/tests\ok/patch · high confidence

JSONPath evaluation engine refactored into modular components

The JSONPath evaluation logic in the \jsonpath/eval\ module has been restructured into distinct, focused files (comparison, expr, literal, query, segment, selector, singular\_query) to improve maintainability and clarity. This refactoring preserves the existing JSONPath query capabilities—including name, wildcard, index, array slice, and filter selectors, as well as logical and comparison expressions—while ensuring that index selectors correctly handle negative indices and out-of-bounds access, and that numeric comparisons use epsilon-based equality for floating-point values. Users will see no change in JSONPath query results, but the underlying implementation is now more robust and easier to extend.

packages/hurl/src/jsonpath/eval · high confidence

JSONPath match and search functions now enforce full-string matching

The JSONPath evaluation logic for the \match\ and \search\ functions has been updated to handle regex patterns more strictly. Specifically, the \match\ function now automatically anchors patterns with \^\ and \$\, ensuring that the regular expression must match the entire string rather than just a substring. This behavioral change affects how string comparisons are performed within JSONPath queries, requiring patterns to cover the full value for a match to succeed.

packages/hurl/src/jsonpath/eval/function · high confidence

JSONPath module restructured and exposed via RFC 9535

The JSONPath implementation has been reorganized into a new module structure (ast, eval, parser) and now exposes the \parse\ function publicly, aligning with the RFC 9535 standard. This change replaces the previous internal or legacy JSONPath handling with a cleaner, standardized API for parsing JSONPath expressions.

packages/hurl/src/jsonpath · high confidence

JSONPath results are no longer coerced to primitive types by default

Hurl now returns JSONPath query results as native JSON values (objects, arrays, numbers, booleans) instead of automatically converting them to strings. This behavioral change means that assertions like \jsonpath "$.store.book\[2\].title" == "Moby Dick"\ will fail if the result is an object or array, requiring users to use selectors like \first\ or \nth\ to extract specific values. To restore the previous string-coercion behavior, users can enable the \--no-jsonpath-coercion\ flag via the CLI, the \no-jsonpath-coercion\ option in the Hurl config file, or the \HURL\_NO\_JSONPATH\_COERCION\ environment variable.

_integration/hurl/tests\ok/jsonpath · high confidence

JUnit report generation now redacts secrets and includes source context in errors

The JUnit XML report output has been updated to improve security and debugging. When generating reports, sensitive strings (secrets) are automatically redacted from error and failure messages. Additionally, the report now includes detailed source context (file path, line numbers, and code snippets) for assertion and runtime errors, making it easier to diagnose failures in CI/CD pipelines.

packages/hurl/src/report/junit · high confidence

Major internal refactoring of the HTTP client and core modules

The runner's internal architecture has been significantly restructured. The HTTP client implementation has been migrated from the \reqwest\ library to \libcurl\, which also enables the addition of explicit connection and request timeout options (\--connect-timeout\ and \--max-time\). Concurrently, the core module has undergone a large-scale refactoring to clean and isolate its components, including the removal of the \src/cli\ module and the restructuring of the HTTP request and response serialization logic.

src/runner · high confidence

New CLI error handling and logging infrastructure

The hurlfmt CLI now includes a dedicated error and logging subsystem. A new \CliError\ struct standardizes error representation, while a \Logger\ component handles terminal output with support for ANSI color formatting. This logger provides specific methods to display application errors and rich parsing errors, integrating with the core \DisplaySourceError\ trait to ensure consistent, styled error messages for users.

packages/hurlfmt/src/cli · high confidence

New DOM-based XML parser for JUnit reports

Hurl now includes a new in-memory XML DOM implementation in the JUnit report module, replacing the previous tree manipulation approach. This change introduces dedicated reader and writer components that serialize and deserialize XML documents using the \xml\ crate, enabling more robust handling of JUnit report structures without relying on external dependencies like \xmltree\ or \indexmap\.

packages/hurl/src/report/junit/xml · high confidence

New HTML report templates with dark mode and error highlighting

The HTML report generation now uses a new set of template files (HTML) and stylesheets (CSS) located in the resources directory. This update introduces a dark mode theme that adapts to system preferences, highlights source code lines with errors using red dashed borders, and adds a dedicated navigation bar with links to Source, Timeline, and Run views. The report also includes a waterfall visualization for call timing and displays error counts and details in the summary.

packages/hurl/src/report/html/resources · high confidence

New modular runner architecture with structured error handling and diff-based assertions

The runner logic in \packages/hurl/src/runner\ has been restructured into a modular architecture, introducing dedicated files for assertions (\assert.rs\), body evaluation (\body.rs\), caching (\cache.rs\), captures (\capture.rs\), and error management (\error.rs\). This change introduces a new \RunnerError\ and \RunnerErrorKind\ system to replace previous error handling, providing more granular and descriptive error messages. A key behavioral improvement is the addition of diff-based assertions for body comparisons; when a body assertion fails, the runner now generates a \DiffHunk\ (via \diff.rs\) to highlight the exact differences between expected and actual content, rather than just reporting a generic mismatch. Additionally, a \BodyCache\ is introduced to store parsed XML/JSON data, optimizing performance by avoiding redundant parsing for multiple queries on the same response.

packages/hurl/src/runner · high confidence

Parser refactoring and new parsing modules

The parser module has been restructured into dedicated files (base64, bytes, cookiepath, duration, error, expr, filename, filename\_password, filter, function, json) to improve modularity and maintainability. This change introduces new parsing capabilities for durations with units (ms, s, m, h), cookie path attributes, and filename templates with password support, while also adding comprehensive error handling and filter parsing logic.

_packages/hurl\core/src/parser · high confidence

Refactored CLI error handling, logging, and test summary output

The CLI module has been restructured to improve error reporting and test-mode output. CLI errors are now represented by a dedicated \CliError\ enum (in \error.rs\) that cleanly maps internal issues like input read failures, invalid options, parsing errors, and I/O errors, including conversions from parallel job and report errors. A new \BaseLogger\ (in \logger.rs\) provides colored, styled output for info, debug, and error messages, supporting ANSI formatting. The \--test\ mode summary (in \summary.rs\) now displays a detailed breakdown including executed files and requests, success/failure percentages, and a formatted duration (h:m:s:ms), with a guard against division-by-zero for very short durations. These changes are accompanied by unit tests for the summary generation logic.

packages/hurl/src/cli · high confidence

Refactored error reporting with structured rendering and output formats

The error handling system has been restructured to support distinct output formats (Plain and Terminal) and a more detailed error message layout. The \DisplaySourceError\ trait now includes a \render\ method that constructs error messages including source line context, column position indicators (carets), and filename prefixes, replacing the previous simpler string-based approach. This change enables users to see more precise location information and context when parsing errors occur, with the output style adapting based on the selected format.

_packages/hurl\core/src/error · high confidence

Refactored hurlfmt commands into a modular command structure

The \hurlfmt\ tool's internal logic has been reorganized into a dedicated \command\ module, separating the implementation of the \--check\, \--export\, and \--in-place\ (format) operations into distinct files (\check.rs\, \export.rs\, \format.rs\). This change introduces a uniform error-handling approach for IO and parsing issues across these commands and supports processing multiple input files for the \--check\ operation, while the \--export\ command now explicitly handles input format conversion (Hurl vs. cURL) and output formatting (Hurl, JSON, HTML).

packages/hurlfmt/src/command · high confidence

Refactored output module with new error handling and JSON serialization

The output module has been restructured to improve error reporting and result serialization. A new \OutputError\ type now wraps runner errors, implementing \DisplaySourceError\ to include source location details (line/column) and fixme suggestions in error messages. JSON report generation (\write\_json\) has been updated to support appending to existing files and explicitly redacts secrets from the output. Additionally, the raw response writer (\write\_last\_body\) now supports pretty-printing and header inclusion, with tests verifying correct formatting for multi-header responses.

packages/hurl/src/output · high confidence

Restructure input\_dir integration test into a subfolder

The integration test for the input\_dir feature has been moved into a dedicated subfolder. This change reorganizes the test files (including shell and PowerShell runners, the error pattern, and the Hurl test cases) to improve project structure without altering the test's behavior.

_integration/hurl/tests\_ok/input\dir · high confidence

Restructure version integration tests into a dedicated subfolder

The integration tests for the version command have been moved into a dedicated subfolder (integration/hurl/tests\_ok/version). This change organizes the test suite by creating specific shell (version.sh) and PowerShell (version.ps1) scripts to execute the version check, along with a pattern file (version.out.pattern) to validate the output format, improving the maintainability and structure of the integration test suite.

_integration/hurl/tests\ok/version · high confidence

Restructured Hurl integration test runner and server

The Hurl integration test infrastructure has been reorganized to improve modularity and test coverage. A new dedicated test runner (integration/hurl/integration.py) now executes shell scripts across multiple test directories (tests\_ok, tests\_failed, tests\_pty, etc.), including specific support for PTY-based terminal tests on non-Windows platforms. The integration server (integration/hurl/server.py) has been updated to use Waitress as the WSGI server with a fixed thread count of 4, replacing the previous configuration. Additionally, the test loading logic (integration/hurl/app.py) has been refactored to dynamically discover and import test modules from subdirectories, and a new curl command validation script (integration/hurl/test\_curl\_commands.sh) has been added to verify curl compatibility and execution.

integration/hurl · high confidence

Support for ignoring assertion failures via config, CLI, and environment variable

Users can now suppress assertion failures in HURL test runs using three methods: the \--no-assert\ command-line flag, the \--no-assert\ setting in the HURL configuration file, or the \HURL\_NO\_ASSERT\ environment variable. This allows tests to proceed even when response body or header assertions do not match, which is useful for debugging or when assertions are not required for the specific test scenario.

_integration/hurl/tests\_ok/ignore\asserts · high confidence

Support for raw multiline strings in Hurl tests

The Hurl test format now supports raw multiline strings, allowing users to include literal content (such as \{{var}}\ placeholders) without variable evaluation by using the \raw\ language hint (e.g., \\\raw). This change also removes the previous \multiline\` attribute in favor of this new syntax, enabling more predictable handling of multiline bodies in requests and assertions for plain text, JSON, XML, and GraphQL.

_integration/hurl/tests\ok/multilines · high confidence

Suppresses libxml2 error messages via native callback

A new native C file (libxml.c) is introduced in the native package to define a silent error callback for libxml2. This callback prevents error messages from being output, addressing the need to suppress libxml2's default error reporting which cannot be handled directly in Rust due to the variadic nature of the error function.

packages/hurl/native · high confidence

Updated CLI help output with new options and renamed flags

The Hurl CLI help text has been updated to reflect several command-line changes: the \--ignore-asserts\ flag is now \--no-assert\, and new options \--http2-prior-knowledge\, \--no-header\, \--fail-with-body\, and \--no-jsonpath-coercion\ are now available. The help also documents the \--proxy-header\ option (currently a no-op) and clarifies that the \--jobs\ option requires a minimum value of 1. These changes are verified by new PTY integration tests that capture the help output.

_integration/hurl/tests\pty/help · high confidence

hurlfmt gains multi-file support, curl input, and new output formats

The hurlfmt CLI now accepts multiple input files and can read curl-format input via the new --in option, while the --out option allows formatting output as Hurl, JSON, or HTML. The tool also introduces a --check mode for validation, --in-place for direct file modification, and --standalone for generating self-contained HTML reports, replacing the deprecated --format flag.

packages/hurlfmt/src/cli/options · high confidence

Test coverage

Add JUnit integration test suite; Add TAP integration tests for Hurl; Add integration test for Hurl config file parsing; Add integration test for localized HTTP reason phrases; Add integration tests for HTTP response captures; Add integration tests for Hello and GB2312 charset handling; Add integration tests for Hurl's insecure option and config file support; Add integration tests for stdout output handling; Add integration tests for the /function endpoint; Added HTTP test fixtures for request and response objects; Added JSON parsing tests; Added JSONPath compliance and unit tests; Added binary compatibility check sample for Hurl Rust crates; Added integration test for Server-Sent Events (SSE) endpoint; Added integration test for environment variable injection; Added integration test suite and sample assets for Hurl runner; Added integration tests for HTTP Digest authentication; Added integration tests for HTTP header override functionality; Added integration tests for HTTP redirect handling; Added integration tests for Hurl's test mode configuration and repetition; Added integration tests for Unix domain socket support; Added integration tests for hurlfmt error handling and multi-file checks; Added integration tests for hurlfmt output formats and HTML export; Added integration tests for multipart form data handling; Added integration tests for parallel execution errors and tab character handling; Added integration tests for progress bar and color output; Added integration tests for rawbytes endpoints; Added integration tests for request content-length truncation; Added integration tests for stdin input with repeat flag; Added integration tests for the entry route; Added integration tests for the file-root feature; Added integration tests for the progress bar display; Added integration tests for the proxy-header option; Added tests for the CLI option specification parser; Completion integration tests moved to subfolder and updated for verbosity flags; Expanded SSL integration tests for certificate validation and proxy configuration; Expanded cookie handling integration tests; Expanded integration test coverage for assertion failure scenarios; Expanded integration test coverage for hurlfmt export formats; Expanded integration test coverage for response assertions; Expanded integration tests for POST request handling; Integration test for --fail-with-body assertion failures; Integration test for Hurl entry skipping; Integration test for binary output error handling; Integration test for large file download endpoint; Integration test runner scripts for HTML report generation; Integration tests added for deprecated Hurl syntax; Integration tests for BOM handling, cookie attributes, and empty sections; Integration tests for Content-Type header handling; Integration tests for HTTP version negotiation and configuration; Integration tests for HURL header configuration via environment variables and config files; Integration tests for Hurl basic authentication options; Integration tests for Hurl rate limiting via CLI, config file, and environment variable; Integration tests for Hurl's repeat and parallel execution options; Integration tests for IPv6 support via CLI flag, config file, and environment variable; Integration tests for JSON output moved to dedicated subfolder; Integration tests for JSON report output moved to subfolder; Integration tests for NTLM authentication support; Integration tests for binary and empty byte responses; Integration tests for color output configuration; Integration tests for compressed response handling; Integration tests for connect-to option moved to subfolder; Integration tests for custom DNS resolution moved to subfolder; Integration tests for hurlfmt added; Integration tests for infinite redirect handling via config and options; Integration tests for key template variable substitution; Integration tests for output formatting and config file overrides; Integration tests for pretty-printing output modes; Integration tests for request delay configuration; Integration tests for response parsing cache moved to subfolder; Integration tests for secret injection and redaction; Integration tests for the --no-header option; Integration tests for variables from config files and command-line options; Integration tests for verbose and very-verbose output modes; Integration tests for very-verbose mode and config file support; Integration tests reorganized into subfolders with parallel execution support; Proxy configuration via command-line option and config file; Removal of integration test suite; Removal of legacy test suite and fixtures; Removed integration error-parser test fixtures; Reorganized netrc and options\_template integration tests into dedicated subfolders; Separate ANSI color codes for standard output and standard error; Standardized test runner scripts for unit and integration tests.

Dependencies

Hurl project restructured into a multi-crate workspace with updated dependencies

The Hurl codebase has been reorganized from a single monolithic crate into a multi-crate workspace containing \hurl\, \hurlfmt\, and \hurl\_core\, all targeting Rust edition 2024 and requiring Rust 1.98.1. This structural change is accompanied by a significant dependency update: the core HTTP client library has moved from \reqwest\ to \curl\ (v0.4.50), and the CLI argument parser has been upgraded from \structopt\ to \clap\ (v4.6.7). Additionally, the npm package dependencies for the Hurl installer have been updated to \tar\ 7.5.22 and \extract-zip\ 2.0.1, while Python development dependencies in \bin/requirements.txt\ have been refreshed to include Flask 3.1.3, ruff 0.15.21, and mypy 2.2.0.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 43 → 59 (+16.6)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 72 → 71 (-0.7)
  • Architecture 97 → 96 (-0.2)
  • Maturity 62 → 69 (+6.9)
  • Readiness 14 → 80 (+66.0)
  • Security 70 → 71 (+1.0)
  • Accessibility 44 (new)

Resolved (20)

  • Dimension evaluation failed
  • Duplicated block (18 lines × 2) (bin/spec/options/option.py)
  • Leaked secret: private-key (integration/hurl/tests_ssl/certs/ca/key.pem)
  • Leaked secret: private-key (integration/hurl/tests_ssl/certs/client/key.pem)
  • Leaked secret: private-key (integration/hurl/tests_ssl/certs/server/key.pem)
  • Low IaC: DS-0026 (contrib/docker/Dockerfile)
  • No SBOM
  • No artifact signing
  • No automated tests
  • No exposed public API
  • No tests found
  • Secret: private-key (integration/hurl/tests_ssl/certs/ca/key.pem)
  • Secret: private-key (integration/hurl/tests_ssl/certs/ca/key.pem)
  • Secret: private-key (integration/hurl/tests_ssl/certs/client/encrypted.key.pem)
  • Secret: private-key (integration/hurl/tests_ssl/certs/client/key.pem)
  • Secret: private-key (integration/hurl/tests_ssl/certs/client/key.pem)
  • Secret: private-key (integration/hurl/tests_ssl/certs/server/key.pem)
  • Secret: private-key (integration/hurl/tests_ssl/certs/server/key.pem)
  • Test reliability not included
  • The What's Hurl? section mentions curl but does not state which CLI tools or libraries Hurl depends on (e.g., Rust/Python). (README.md)

New (62)

  • CI runs a third-party container image from a mutable tag (.github/workflows/check.yml)
  • Coverage not measured — no coverage collector is wired up
  • Duplicated block (6 lines × 3) (integration/hurl/tests_failed/runner_errors/runner_errors.py)
  • Duplicated block (6 lines × 7) (integration/hurl/tests_failed/assert_bytearray/assert_bytearray.py)
  • Duplicated block (9 lines × 6) (integration/hurl/tests_ok/compressed/compressed.py)
  • FixmeComment (contrib/sample/src/main.rs)
  • High CVE: [GHSA redacted] (contrib/npm/hurl/package-lock.json)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Hotspot: packages/hurl/src/cli/options/config_file/mod.rs (packages/hurl/src/cli/options/config_file/mod.rs)
  • Hotspot: packages/hurl/src/http/client.rs (packages/hurl/src/http/client.rs)
  • Hotspot: packages/hurl/src/http/curl_cmd.rs (packages/hurl/src/http/curl_cmd.rs)
  • Hotspot: packages/hurl/src/runner/options.rs (packages/hurl/src/runner/options.rs)
  • …and 42 more

Changes since last survey

  • 97 commits — 88 feature/other, 9 fixes

By area

  • (root) — 33 commits
  • packages/hurl — 18 commits
  • integration/hurl — 17 commits
  • .github/workflows — 13 commits
  • docs/spec — 8 commits
  • art/branding.md — 1 commit
  • bin/install_prerequisites_windows.ps1 — 1 commit
  • contrib/sublime-text — 1 commit
  • docs/asserting-response.md — 1 commit
  • docs/filters.md — 1 commit
  • docs/grammar.md — 1 commit
  • docs/installation.md — 1 commit
  • docs/manual — 1 commit

Notable commits

  • fix: Fix CodeQL access on invalid pointer warnings.
  • fix: Fix XSS: HTML escape all debug tables values (headers, captures etc...)
  • fix: Fix credentials leaking using --header and following redirection.
  • fix: Fix hurl.dev ssl integration test.
  • fix: Fix integration test for cookie value on curl 8.22 due to <https://github.com/curl/curl/pull/22730>
  • fix: Fix libcurl-8.18 downgrade on Windows vcpkg
  • fix: Fix output_type configuration.
  • fix: Fix symlinks escaping file root.
  • fix: Minor typo fix to test the CodeQL config file.
  • change: Add CodeQL analysis configuration file.
  • change: Add Sublime Text syntax highlighting
  • change: Add Validation step for workflow_call input branch in package.yml
  • change: Add deprecation notice for decode in filters page
  • change: Add integ test for assert body JSON
  • change: Add integration test for no-proxy option
  • change: Add integration test for proxy_header option
  • change: Add max_filesize option in config file
  • change: Add more unit tests.
  • change: Add no_pretty option in config_file
  • change: Add no_proxy option in config_file
  • …and 77 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

Orange-OpenSource/hurl was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 561067479bdfbb406803bca91d8ce73db105e3cb — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d00c643c3f66.