Skip to content
CAI
Software that uses CAICheck a score

pallets/flask

70.8

Strong · 26 September 2026

8k

lines of production code

Python

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the Flask web framework for Python, providing a core set of tools for building web applications. It features a modular architecture with a framework-agnostic Sans-IO layer, customizable JSON serialization, and support for background tasks via Celery. The project includes comprehensive test infrastructure and modernized examples demonstrating best practices such as application factories, blueprints, and AJAX interactions.

How it got here

2010 — Project scaffolding and cleanup

5 changes.

The project established its development infrastructure by introducing pre-commit hooks, uv tooling, and standardized configuration files. This period also involved cleaning up legacy code by removing the MiniTwit example application and adding test fixtures for templates and static files.

2014–2018 — Test infrastructure and tutorial modernization

9 changes.

This period focused on establishing a comprehensive test suite and infrastructure for the core framework, including fixtures for blueprints and subdomains. It also involved rewriting the Flaskr tutorial to demonstrate modern best practices like application factories and blueprints, accompanied by a new JavaScript AJAX example to showcase client-side integration.

2019–2023 — Modernization and architecture refactoring

6 changes.

This period focused on modernizing Flask's codebase by restructuring it into a standard src layout and extracting a framework-agnostic Sans-IO core to improve modularity and enable reuse by other frameworks. The project also updated its build system to pyproject.toml, raised minimum Python requirements, and introduced a pluggable JSON provider interface for customizable serialization.

Features

Add Celery background task example

Added a new example in the examples/celery directory demonstrating how to integrate Celery with Flask for background task execution. The example includes a Flask application that configures a Celery worker with Redis, defines sample tasks (add, block, process), and provides a web interface with JavaScript polling to submit tasks and monitor their progress and results.

examples/celery · high confidence

Add JavaScript AJAX example application

A new Flask-based example application has been added to demonstrate JavaScript AJAX interactions. The app serves templates for XHR, jQuery, and Fetch API implementations and includes a simple endpoint that accepts two numbers via POST and returns their sum as JSON.

_examples/javascript/js\example · high confidence

Add JavaScript AJAX examples using Fetch, XHR, and jQuery

The examples directory now includes a set of template files (base.html, fetch.html, xhr.html, jquery.html) that demonstrate how to perform AJAX requests in JavaScript using three different approaches: the modern Fetch API, the legacy XMLHttpRequest, and the jQuery library. These templates provide a shared UI for calculating sums and include specific script blocks showing the implementation details for each method, allowing users to compare the syntax and usage of these different JavaScript HTTP client techniques.

_examples/javascript/js\example/templates · high confidence

Add VS Code Dev Container configuration for Flask development

Developers can now use VS Code Dev Containers to set up a consistent Python 3 development environment for the Flask project. The new configuration automatically creates a virtual environment, installs development dependencies from requirements/dev.txt, installs the package in editable mode, and sets up pre-commit hooks upon container creation.

.devcontainer · high confidence

Removals

Removal of MiniTwit example templates

The Jinja2 template files for the MiniTwit example application (layout, login, register, and timeline) have been deleted. This removes the HTML structure and view logic for the example, effectively taking the MiniTwit demo application offline.

examples/minitwit/templates · high confidence

Removal of the minitwit example application

The minitwit example application, including its main Python script, database schema, and CSS styles, has been removed from the examples directory. This change eliminates the legacy codebase that relied on deprecated Flask hooks like request\_init and request\_shutdown, as well as older SQLite patterns, effectively cleaning up the repository by removing this specific demonstration project.

examples/apishowcase, examples/minitwit · high confidence

Architecture

Flask 3.0 source code restructured into src/flask

The Flask application package has been reorganized into the standard src layout, with all core modules (app, blueprints, CLI, config, context, globals, helpers, logging, sessions, etc.) now located under src/flask. This change improves package isolation and aligns with modern Python packaging practices, but does not alter the public API or runtime behavior for existing applications.

src/flask · high confidence

Flask core logic refactored into a framework-agnostic Sans-IO layer

The application and blueprint logic has been extracted into the new \src/flask/sansio\ package, creating a framework-agnostic core that performs no I/O and avoids Flask-specific globals. This change enables alternative WSGI servers, such as Quart, to reuse Flask's routing, templating, and configuration logic without being tied to Flask's specific I/O implementation.

src/flask/sansio · high confidence

Behavioural changes

New JSON provider interface for customizable serialization

Flask now uses a pluggable JSON provider system (via \app.json\) to handle serialization and deserialization, allowing applications to override default behaviors or swap in different JSON libraries. The default provider serializes \datetime\ objects to HTTP-date strings, \Decimal\ and \UUID\ to strings, and dataclasses to dictionaries. This change also removes the deprecated \encoding\ parameter from JSON functions and drops support for Python 3.6 and earlier versions.

src/flask/json · high confidence

Rewritten Flaskr tutorial with application factory and blueprints

The Flaskr tutorial example has been completely rewritten to demonstrate modern Flask best practices. The application now uses an application factory pattern (\create\_app\) instead of a global app instance, and organizes functionality into blueprints for authentication (\auth\) and blog posts (\blog\). The database layer (\db.py\) has been updated to use SQLite with proper connection handling via \g\ and teardown hooks, including a custom converter for timestamp columns. The UI templates have been refreshed with a new CSS stylesheet and include support for user registration, login, logout, and full CRUD operations for blog posts, with authorship checks enforced on updates and deletions.

examples/tutorial/flaskr · high confidence

Test coverage

Added Jinja2 template fixtures for testing; Added subdomain test module fixture; Added test fixtures for admin and frontend blueprints; Added test fixtures for static file serving; Added test infrastructure for blueprintapp; Added test suite for the Flask tutorial application; Added tests for the JavaScript example application; Initial test suite and test infrastructure.

Dependencies

Initial project scaffolding with pre-commit and uv tooling

The repository now includes configuration for development tooling: an \.editorconfig\ standardizes indentation (4 spaces for Python, 2 for other files) and line endings, a \.pre-commit-config.yaml\ sets up hooks for \ruff\ (linting/formatting), \uv\ (lockfile management), \codespell\, and standard git hooks, and a \.readthedocs.yaml\ configures the documentation build environment to use \uv\ and Python 3.13. A \uv.lock\ file is also added to manage dependencies, and the legacy \flask.py\ single-file module has been removed.

(repo-wide) · high confidence

Migrate to pyproject.toml and update dependencies

The project and its examples now use pyproject.toml for configuration, replacing older setup files. The main Flask package now requires Python 3.10+ and updates its core dependencies, including Werkzeug to \>=3.1.0 and blinker to \>=1.9.0. The build system has switched to flit\_core, and development tooling now includes ruff for linting and uv for dependency management. Example projects (celery, javascript, tutorial) also have their own pyproject.toml files with updated metadata and dependencies.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 46 → 71 (+24.7)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 98 → 95 (-3.4)
  • Architecture 94 → 98 (+3.8)
  • Maturity 57 → 67 (+9.5)
  • Readiness 30 → 63 (+33.3)
  • Security 47 → 83 (+35.8)

Resolved (15)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • LLM evaluation failed
  • Low: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No artifact signing
  • No build provenance
  • No exposed public API
  • No tests found
  • Secret: generic-api-key (docs/config.rst)
  • Secret: generic-api-key (docs/config.rst)
  • Test reliability not included

New (49)

  • Blueprint.register (cognitive 24) (src/flask/sansio/blueprints.py)
  • Blueprint.register (cyclomatic 22) (src/flask/sansio/blueprints.py)
  • Documentation: no architecture or design documentation (docs/index.rst)
  • Documentation: no installation or build instructions (README.md)
  • Duplicated block (13 lines × 2) (examples/tutorial/flaskr/blog.py)
  • Duplicated block (20 lines × 2) (src/flask/app.py)
  • Duplicated block (22 lines × 2) (src/flask/app.py)
  • Duplicated block (23 lines × 4) (src/flask/sansio/app.py)
  • FileTooLong: flask/app.py (src/flask/app.py)
  • FileTooLong: flask/cli.py (src/flask/cli.py)
  • Flask.make_response (cognitive 23) (src/flask/app.py)
  • Flask.make_response (cyclomatic 16) (src/flask/app.py)
  • Flask.preprocess_request (cognitive 16) (src/flask/app.py)
  • Flask.url_for (cognitive 22) (src/flask/app.py)
  • High CVE: [GHSA redacted] (uv.lock)
  • Hotspot: src/flask/app.py (src/flask/app.py)
  • No ADRs found
  • No dependency advisory monitoring
  • Off-boarding risk: anonymized user #1
  • Outdated: amqp
  • …and 29 more

Changes since last survey

  • 12 commits — 8 feature/other, 4 fixes

By area

  • src/flask — 6 commits
  • (repo) — 3 commits
  • (root) — 2 commits
  • tests/test_blueprints.py — 1 commit

Notable commits

  • fix: Fix IPv6 server name parsing
  • fix: Fix IPv6 session transactions
  • fix: Fix .partition(":") usage on potential IPv6 addresses (#6096)
  • fix: fix docs ref
  • change: Merge branch 'stable'
  • change: add app.query route decorator (#6133)
  • change: add app.query route decorator
  • change: add entry
  • change: explain seek
  • change: fix typos
  • change: support query in methodview
  • change: use header properties

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

pallets/flask was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit d73fa1cdcbd8b1465c151db8924ba58b1dd14e35 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.