psf/requests
72.6
Strong · 26 September 2026
5.3k
lines of production code
Python
primary language
4
measurements over time
What this system is
This system is the Requests HTTP library for Python, providing a high-level interface for making HTTP requests. It manages core networking capabilities including connection handling, TLS/mTLS certificate validation, and dependency compatibility checks for underlying libraries like urllib3 and certifi. The codebase includes a comprehensive test infrastructure with local server utilities to verify HTTP behavior and security edge cases.
Features
Add brand assets and license
The ext directory now includes the project's official logo in both Adobe Illustrator (.ai) and SVG formats, along with a LICENSE file containing the 2019 Kenneth Reitz copyright notice.
ext · high confidence
Architecture
Repository restructured with modern tooling and Python 3.10+ requirement
The project has been reorganized into a src-layout with a PEP 517 build system, enforcing a minimum Python version of 3.10. Development workflows are standardized using pre-commit hooks (ruff), tox for multi-version testing, and a Makefile for common tasks. Documentation is now configured for Read the Docs, and the license has been updated to Apache-2.0.
(repo-wide) · high confidence
Behavioural changes
Requests library moved to src/requests and updated to version 2.34.2
The Requests HTTP library has been restructured with its source code relocated to the src/requests directory and the package version updated to 2.34.2. This change includes the addition of comprehensive type annotations and type aliases in the new \types.py module, as well as the introduction of a dependency compatibility check in \\init\\_.py that validates the installed versions of urllib3, chardet, and charset\_normalizer to ensure they fall within supported ranges.
src/requests · high confidence
Test coverage
Added test certificates for expired, valid, and mTLS scenarios; Added test server utilities for unit testing; Establishes a new, comprehensive test suite structure.
Dependencies
Migrate build system to pyproject.toml and update documentation requirements
The project has migrated its build configuration to a modern \pyproject.toml\ file, establishing a PEP 517 build backend using setuptools and defining the package metadata, Python version requirements (\>=3.10), and core dependencies (charset\_normalizer, idna, urllib3, certifi) directly in the manifest. This change introduces a new \docs/requirements.txt\ file to pin Sphinx to version 7.2.6 for ReadTheDocs compatibility, while the \requirements-dev.txt\ file is updated to reflect the new development environment, including specific versions for pytest-httpbin (2.1.0) and httpbin (\~=0.10.0), and adjusting the pytest version constraint to \<10.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 50 → 73 (+22.5)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 97 → 91 (-6.2)
- Architecture 96 → 92 (-4.0)
- Maturity 59 → 59 (+0.0)
- Readiness 30 → 78 (+47.6)
- Security 59 → 92 (+32.7)
Resolved (16)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- No artifact signing
- No build provenance
- No exposed public API
- No tests found
- Test reliability not included
New (39)
- Dependency hygiene PARTLY measured — Python dependencies read, no exact pin to grade for currency
- Documentation: contradicts the code (docs/community/release-process.rst)
- FileTooLong: requests/models.py (src/requests/models.py)
- FileTooLong: requests/utils.py (src/requests/utils.py)
- HTTPAdapter.cert_verify (cognitive 23) (src/requests/adapters.py)
- HTTPAdapter.send (cognitive 25) (src/requests/adapters.py)
- HTTPAdapter.send (cyclomatic 19) (src/requests/adapters.py)
- HTTPDigestAuth.build_digest_header (cognitive 17) (src/requests/auth.py)
- HTTPDigestAuth.build_digest_header (cyclomatic 19) (src/requests/auth.py)
- Job token omits the contents scope its checkout needs
- PreparedRequest.prepare_body (cognitive 32) (src/requests/models.py)
- PreparedRequest.prepare_body (cyclomatic 19) (src/requests/models.py)
- PreparedRequest.prepare_url (cognitive 21) (src/requests/models.py)
- PreparedRequest.prepare_url (cyclomatic 18) (src/requests/models.py)
- RequestEncodingMixin._encode_files (cognitive 36) (src/requests/models.py)
- RequestEncodingMixin._encode_files (cyclomatic 21) (src/requests/models.py)
- RequestEncodingMixin._encode_params (cognitive 25) (src/requests/models.py)
- RequestsCookieJar._find_no_duplicates (cognitive 18) (src/requests/cookies.py)
- Secret: crypto-key-passphrase (requests/packages/oauthlib/oauth1/rfc5849/parameters.py)
- Secret: generic-api-key (requests/packages/oauthlib/oauth2/draft25/parameters.py)
- …and 19 more
Changes since last survey
- 6 commits — 6 feature/other, 0 fixes
By area
- (root) — 4 commits
- .github/workflows — 2 commits
Notable commits
- change: Bump https://github.com/astral-sh/ruff-pre-commit (#7603)
- change: Bump https://github.com/astral-sh/ruff-pre-commit (#7606)
- change: Bump https://github.com/astral-sh/ruff-pre-commit (#7608)
- change: Bump https://github.com/astral-sh/ruff-pre-commit (#7616)
- change: Bump the actions group with 3 updates (#7628)
- change: Update lock-issues.yml to latest dependencies (#7609)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
psf/requests was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 611c6162cbc4ac2020a2f91c7cfa4f3abf9bbb60 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-09659c52afae.