Skip to content
CAI
Software that uses CAICheck a score

restify/node-restify

46.1

Weak · 2 October 2026

8.9k

lines of production code

JavaScript

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Node.js HTTP server framework that provides a modular architecture for building RESTful APIs and handling network requests. It features a high-performance router, a configurable middleware chain, and a plugin system for tasks like authentication, logging, and body parsing. The framework supports modern web standards including HTTP/2, JSONP, and Socket.IO, while offering tools for performance benchmarking, latency analysis, and automated API documentation.

How it got here

2011 — Core architecture modernization

6 changes.

The project underwent a significant architectural overhaul, replacing the legacy routing and middleware systems with a new Chain and Router structure backed by find-my-way. This period also involved modernizing the dependency tree, upgrading to Node 22, and migrating logging and error handling to contemporary libraries like Pino and restify-errors. Legacy test helpers and HTTP method tests were removed to align with the refactored infrastructure.

2012 — Router, middleware, and formatter expansion

11 changes.

This period focused on expanding the framework's core capabilities by introducing a new router and middleware system, along with comprehensive response formatters for JSON, JSONP, and binary content. Significant effort was dedicated to enhancing developer experience through standardized build infrastructure, extensive test coverage, and practical examples for integration with tools like Socket.IO and DTrace.

2017 — HTTP/2 support and testing infrastructure

5 changes.

This period focused on enabling native HTTP/2 support through new examples, test certificates, and logging updates. The team also established a comprehensive testing framework for server plugins and introduced an automated API documentation generator. Additionally, a new benchmark suite was implemented to measure and compare server performance under various load conditions.

Features

Add HTTP/2 example with native support and downgrade capability

The http2 example now demonstrates native HTTP/2 support by configuring the server with TLS certificates and enabling the allowHTTP1 option, which allows clients that do not support HTTP/2 to connect using HTTP/1.x. The example also switches the logging implementation from Bunyan to Pino for audit logging.

examples/http2 · high confidence

Added Socket.IO integration example

A new example script (examples/sockio/sockio.js) demonstrates how to integrate Socket.IO with the restify server. The example sets up a server on port 8080 that serves an HTML page containing a client-side script to connect to the server via Socket.IO, emit a 'news' event upon connection, and listen for a 'my other event' from the client.

examples/sockio · high confidence

Automated API documentation generation tool

A new build tool (\tools/docsBuild.js\) has been added to automatically generate API documentation from JSDoc comments in the library code. This tool processes source files for the Server, Request, Response, Plugins, and Formatters APIs, converting JSDoc annotations into Markdown files formatted for Jekyll, and outputs them to the \docs/\_api\ directory.

tools · high confidence

Initial release of response formatters

Introduces the core response formatting logic for the library, providing built-in support for JSON, JSONP, plain text, and binary content types. The JSON formatter handles serialization and error wrapping, JSONP adds callback invocation with unicode escaping, and the new binary formatter ensures proper Content-Length headers for buffer responses. These formatters are registered in the index with specific quality values to define their priority during content negotiation.

lib/formatters · high confidence

New DTrace instrumentation examples for performance monitoring

Added new example scripts in the examples/dtrace directory to demonstrate how to use Restify's DTrace probes for runtime performance analysis. The 'demo.js' example showcases a server configured with the 'pino' logger and custom formatters, while 'handler-timing.d' provides a DTrace script to quantify the duration of individual route handlers. These additions allow users to easily observe and debug handler execution times and route start/done events using system-level tracing tools.

examples/dtrace · high confidence

New JSONP example added to demonstrate callback support

An example application has been added at examples/jsonp/jsonp.js that demonstrates how to enable JSONP support in a Restify server. The example configures the server to use the queryParser and jsonp plugins, allowing clients to request data with a callback parameter, and listens on port 8080.

examples/jsonp · high confidence

New benchmark suite for performance testing

A new benchmark suite has been added to the project, allowing users to measure and compare server performance. The suite includes specific benchmarks for middleware handling, JSON and text responses, and heavy routing scenarios. It utilizes the \autocannon\ library to run load tests and provides an interactive CLI (via \inquirer\) to configure connection counts, pipelining, and duration. Users can also opt to compare the current HEAD version against the stable release to track performance regressions or improvements.

benchmark · high confidence

New common Makefile infrastructure for builds and checks

The tools/mk directory now provides a set of shared Makefile definitions (Makefile.defs, Makefile.deps, Makefile.targ) that standardize build processes across repositories. This includes automatic version stamping based on git branch and timestamp, dependency management for tools like restdown, and standardized targets for checking JavaScript linting and style via ESLint and Prettier, as well as bash syntax checking. Users can now include these files to gain consistent build, test, and documentation generation capabilities without maintaining custom Makefile logic.

tools/mk · high confidence

New latency reporting tool for audit logs

A new executable script, bin/report-latency, has been added to the project. This tool allows users to analyze audit log files to generate latency reports, supporting features such as calculating average latency, tracking request counts, and computing specific percentiles over configurable time periods. It accepts command-line arguments to define time ranges, output formats, and filtering criteria, enabling users to gain insights into system performance from their audit data.

bin · high confidence

New pre-request plugins for context, URL sanitization, and request handling

This change introduces several new pre-request plugins to \lib/plugins/pre\ that enhance request handling and URL management. The \context\ plugin adds \req.set()\, \req.get()\, and \req.getAll()\ methods to store and retrieve request-specific data. URL handling is improved with \dedupeSlashes\ and \prePath\ (exported as \sanitizePath\), which clean up malformed URLs by removing redundant slashes. Request identification is supported by \reqIdHeaders\, which allows setting the request ID from incoming headers. Additionally, \strictQueryParams\ enforces strict key-value query parameter formats, \pause\ prevents Node.js hanging issues with async handlers before body parsing, and \userAgent\ optimizes responses for \curl\ by managing connection headers and content-length on HEAD requests.

lib/plugins/pre · high confidence

Ship full TodoApp example with Pino logging and client wrapper

The todoapp example now includes a complete, runnable implementation featuring a dedicated client wrapper (lib/client.js) for interacting with the REST API, a server implementation (lib/server.js) that uses Pino for structured logging instead of the previous logger, and a main entry point (main.js) that supports command-line options for authentication, port, and verbose logging. The example also ships with unit tests and a README detailing how to run and interact with the app.

examples/todoapp · high confidence

Behavioural changes

Adopts ESLint and Prettier for code quality and formatting

The project has replaced its previous linting and style tools with ESLint and Prettier. This change introduces a new \.eslintrc.js\ configuration that enforces strict error rules, JSDoc validation, and code style via Prettier, alongside a \.prettierrc\ for consistent formatting. A \.eslintignore\ file is added to exclude specific directories from linting, and the \Makefile\ is updated to use the new ESLint and Prettier binaries for checks.

(repo-wide) · high confidence

Major plugin restructuring and dependency migration

The plugin system has been reorganized into individual files and migrated to use the \restify-errors\ library for consistent error handling. The audit logger now supports Pino, custom context objects, and request timers, while the authorization plugin now allows username-only HTTP Basic Auth. New capabilities include a \cpuUsageThrottle\ for load shedding based on CPU utilization, a \conditionalHandler\ for version/content-type based routing, and a \fieldedTextBodyParser\ for CSV/TSV bodies. Additionally, the \bodyParser\ now handles extended JSON content types, and the \accept\ plugin ensures proper MIME type mapping.

lib/plugins · high confidence

New middleware chain and router architecture

The library introduces a new \Chain\ class to manage middleware execution, supporting both async/await and callback-based handlers with options like \strictNext\ to prevent calling \next()\ multiple times. The routing system has been replaced with a new \Router\ class backed by the \find-my-way\ radix tree registry, which handles route matching, parameter extraction, and handler invocation. This change also includes a new \compose\ helper for building handler chains and updates the default logging to use \pino\ instead of Bunyan.

lib · high confidence

Test coverage

Added comprehensive test suite for server plugins; Added test certificates for HTTP/2 support; Added test helper utilities and test infrastructure; Added test suite for the new router and middleware system; Added unit tests for the TodoApp example; Removal of legacy test helper module; Removed legacy HTTP method test files.

Dependencies

Restify 12.0.0 release with Node 22 requirement and dependency overhaul

This release updates the Restify framework to version 12.0.0, raising the minimum supported Node.js version to 22.0.0. The dependency tree has been significantly modernized: the core now uses \find-my-way\ (^9.6.0) for routing, \pino\ (^8.7.0) for logging, \mime\ (^3.0.0), \send\ (^1.2.1), \lru-cache\ (^7.14.1), \qs\ (^6.15.2), and \http-signature\ (^1.3.6). Development dependencies have also been updated, including \mocha\ (^7.1.1), \chai\ (^4.2.0), and \eslint\ (^5.16.0). Example applications (todoapp, sockio) and the benchmark suite have been added with their own \package.json\ files to reflect these new dependencies.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 45 → 46 (+0.7)
  • Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 51 → 51 (+0.0)
  • Architecture 100 → 90 (-10.4)
  • Maturity 33 → 33 (+0.0)
  • Readiness 50 → 54 (+4.1)
  • Security 67 → 72 (+4.7)

Resolved (5)

  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no licence statement (README.md)
  • Hotspot: lib/server.js (lib/server.js)
  • Off-boarding risk: anonymized user #1

New (13)

  • High CVE: [GHSA redacted] (package-lock.json)
  • Medium CVE: [GHSA redacted] (package-lock.json)
  • Off-boarding risk: anonymized user #1
  • Outdated (npm): csv
  • Outdated (npm): formidable
  • Outdated (npm): lru-cache
  • Outdated (npm): mime
  • Outdated (npm): negotiator
  • Outdated (npm): pidusage
  • Outdated (npm): pino
  • Outdated (npm): qs
  • Outdated (npm): restify-errors
  • Projects may be oversized for their cohesion

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

restify/node-restify was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit b1a14eee7ca9c0ef1b3142df1b5de33304d68955 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.