Skip to content
CAI
Software that uses CAICheck a score

psf/requests

72.6

Strong · 26 September 2026

5.3k

lines of production code

Python

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the Requests HTTP library for Python, providing a high-level interface for making HTTP requests. It manages core networking capabilities including connection handling, TLS/mTLS certificate validation, and dependency compatibility checks for underlying libraries like urllib3 and certifi. The codebase includes a comprehensive test infrastructure with local server utilities to verify HTTP behavior and security edge cases.

Features

Add brand assets and license

The ext directory now includes the project's official logo in both Adobe Illustrator (.ai) and SVG formats, along with a LICENSE file containing the 2019 Kenneth Reitz copyright notice.

ext · high confidence

Architecture

Repository restructured with modern tooling and Python 3.10+ requirement

The project has been reorganized into a src-layout with a PEP 517 build system, enforcing a minimum Python version of 3.10. Development workflows are standardized using pre-commit hooks (ruff), tox for multi-version testing, and a Makefile for common tasks. Documentation is now configured for Read the Docs, and the license has been updated to Apache-2.0.

(repo-wide) · high confidence

Behavioural changes

Requests library moved to src/requests and updated to version 2.34.2

The Requests HTTP library has been restructured with its source code relocated to the src/requests directory and the package version updated to 2.34.2. This change includes the addition of comprehensive type annotations and type aliases in the new \types.py module, as well as the introduction of a dependency compatibility check in \\init\\_.py that validates the installed versions of urllib3, chardet, and charset\_normalizer to ensure they fall within supported ranges.

src/requests · high confidence

Test coverage

Added test certificates for expired, valid, and mTLS scenarios; Added test server utilities for unit testing; Establishes a new, comprehensive test suite structure.

Dependencies

Migrate build system to pyproject.toml and update documentation requirements

The project has migrated its build configuration to a modern \pyproject.toml\ file, establishing a PEP 517 build backend using setuptools and defining the package metadata, Python version requirements (\>=3.10), and core dependencies (charset\_normalizer, idna, urllib3, certifi) directly in the manifest. This change introduces a new \docs/requirements.txt\ file to pin Sphinx to version 7.2.6 for ReadTheDocs compatibility, while the \requirements-dev.txt\ file is updated to reflect the new development environment, including specific versions for pytest-httpbin (2.1.0) and httpbin (\~=0.10.0), and adjusting the pytest version constraint to \<10.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 50 → 73 (+22.5)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 97 → 91 (-6.2)
  • Architecture 96 → 92 (-4.0)
  • Maturity 59 → 59 (+0.0)
  • Readiness 30 → 78 (+47.6)
  • Security 59 → 92 (+32.7)

Resolved (16)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No artifact signing
  • No build provenance
  • No exposed public API
  • No tests found
  • Test reliability not included

New (39)

  • Dependency hygiene PARTLY measured — Python dependencies read, no exact pin to grade for currency
  • Documentation: contradicts the code (docs/community/release-process.rst)
  • FileTooLong: requests/models.py (src/requests/models.py)
  • FileTooLong: requests/utils.py (src/requests/utils.py)
  • HTTPAdapter.cert_verify (cognitive 23) (src/requests/adapters.py)
  • HTTPAdapter.send (cognitive 25) (src/requests/adapters.py)
  • HTTPAdapter.send (cyclomatic 19) (src/requests/adapters.py)
  • HTTPDigestAuth.build_digest_header (cognitive 17) (src/requests/auth.py)
  • HTTPDigestAuth.build_digest_header (cyclomatic 19) (src/requests/auth.py)
  • Job token omits the contents scope its checkout needs
  • PreparedRequest.prepare_body (cognitive 32) (src/requests/models.py)
  • PreparedRequest.prepare_body (cyclomatic 19) (src/requests/models.py)
  • PreparedRequest.prepare_url (cognitive 21) (src/requests/models.py)
  • PreparedRequest.prepare_url (cyclomatic 18) (src/requests/models.py)
  • RequestEncodingMixin._encode_files (cognitive 36) (src/requests/models.py)
  • RequestEncodingMixin._encode_files (cyclomatic 21) (src/requests/models.py)
  • RequestEncodingMixin._encode_params (cognitive 25) (src/requests/models.py)
  • RequestsCookieJar._find_no_duplicates (cognitive 18) (src/requests/cookies.py)
  • Secret: crypto-key-passphrase (requests/packages/oauthlib/oauth1/rfc5849/parameters.py)
  • Secret: generic-api-key (requests/packages/oauthlib/oauth2/draft25/parameters.py)
  • …and 19 more

Changes since last survey

  • 6 commits — 6 feature/other, 0 fixes

By area

  • (root) — 4 commits
  • .github/workflows — 2 commits

Notable commits

  • change: Bump https://github.com/astral-sh/ruff-pre-commit (#7603)
  • change: Bump https://github.com/astral-sh/ruff-pre-commit (#7606)
  • change: Bump https://github.com/astral-sh/ruff-pre-commit (#7608)
  • change: Bump https://github.com/astral-sh/ruff-pre-commit (#7616)
  • change: Bump the actions group with 3 updates (#7628)
  • change: Update lock-issues.yml to latest dependencies (#7609)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

psf/requests was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 611c6162cbc4ac2020a2f91c7cfa4f3abf9bbb60 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-09659c52afae.