SAFE-Stack/SAFE-Chat
51.4
Weak · 24 September 2026
2.3k
lines of production code
F#
primary language
5
measurements over time
What this system is
This system is a real-time chat application built with F\# and .NET 8, featuring an Elmish-based client and an Akka.NET actor-based server. It facilitates multi-channel messaging, user presence, and session management via WebSockets. The codebase includes end-to-end tests to verify core chat functionalities.
Features
Introduce server-side chat infrastructure with Akka.NET actors
The server now features a complete chat backend built on Akka.NET and Akkling. This includes a central ChatServer actor that manages channel creation, user sessions, and notifications. Specific actors handle group chat logic (GroupChatChannelActor), a static 'About' channel (AboutChannelActor), and user state management (UserStore). The system supports joining/leaving channels, updating user profiles (nick, status, avatar), and real-time messaging via WebSockets, all coordinated through a new Giraffe-based HTTP/WebSocket handler.
src/Server · high confidence
Introduced Elmish-based chat client with real-time messaging and channel management
The client application has been rebuilt using the Elmish architecture, introducing a structured state management system for the chat interface. Users can now connect to the server via WebSockets, view a list of available channels, and join or leave channels. The interface includes a sidebar for channel navigation, a main area for displaying messages and user lists, and an input panel for sending messages. The implementation handles real-time updates for user presence, message history, and channel events, providing a complete single-page application experience for chat functionality.
src/Client · high confidence
Removals
Removal of legacy ASP.NET Core and Giraffe-based application components
The legacy ASP.NET Core application, including the main host and app modules, has been removed. This deletion includes the F\# source files (app.fs, Program.fs), the Message model, Razor view templates (Index.cshtml), launch configuration files, and dependency manifests (paket.references, script.fsx). As a result, the application no longer runs on the Giraffe framework or the previous ASP.NET Core hosting infrastructure.
src/app · high confidence
Behavioural changes
Modernized build system and project structure
The project's build process has been modernized by replacing the legacy \script.fsx\ with a new \build.fsx\ script powered by the Xake build system, which manages restore, build, and test targets. The solution structure has been reorganized to explicitly define the Client, Server, and E2E test projects, and the \.gitignore\ has been updated to exclude modern development artifacts like \node\_modules\ and \.ionide/\ while removing outdated entries like \.paket/\.
(repo-wide) · high confidence
Removed cached dependency manifest
The cached dependency manifest file (paket.restore.cached) has been removed from the repository. This file previously contained the resolved versions of all NuGet packages and their transitive dependencies, including the Giraffe web framework and Microsoft.AspNetCore libraries. Its removal indicates a shift in how dependencies are managed or cached locally, requiring developers to regenerate the cache from the source paket files.
paket-files · high confidence
Test coverage
Added end-to-end test suite for the application; Added end-to-end tests for core application features.
Dependencies
Migrated client and server projects to .NET 8 and modernized dependencies
The client and server projects have been updated to target .NET 8.0, replacing the previous .NET Core 2.0 and .NET Standard 2.0 targets. The client project now uses Fable Elmish with React, while the server project has been refactored to use Akka.NET (Akkling) and Giraffe, removing the legacy Paket dependency management in favor of standard .NET SDK project files. The e2e test project has also been updated to use .NET 4.6.1 with modernized test dependencies.
(dependencies) · medium confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 60 → 51 (-8.9)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 98 → 100 (+2.2)
- Architecture 100 → 99 (-1.5)
- Maturity 51 → 37 (-13.9)
- Readiness 47 → 47 (+0.0)
- Security 89 → 66 (-23.1)
Resolved (18)
- ChatServer.startServer (cognitive 20) (src/Server/ChatServer.fs)
- ChatServer.startServer (cyclomatic 22) (src/Server/ChatServer.fs)
- Dependency hygiene not measured — no packages were read
- High CVE: [GHSA redacted] (src/Client/yarn.lock)
- High CVE: [GHSA redacted] (src/Client/yarn.lock)
- High CVE: [GHSA redacted] (src/Client/yarn.lock)
- High CVE: [GHSA redacted] (src/Client/yarn.lock)
- High CVE: [GHSA redacted] (src/Client/yarn.lock)
- High CVE: [GHSA redacted] (src/Client/yarn.lock)
- Medium CVE: [GHSA redacted] (src/Client/yarn.lock)
- Medium CVE: [GHSA redacted] (src/Client/yarn.lock)
- Medium IaC: CKV_DOCKER_10 (src/Dockerfile)
- Medium IaC: CKV_DOCKER_3 (src/Dockerfile)
- Medium IaC: CKV_DOCKER_4 (src/Dockerfile)
- Medium vulnerability: [GHSA redacted] (src/Client/yarn.lock)
- No exposed public API
- Test reliability not included
- dormant codebase — no living knowledge left to concentrate
New (23)
- Documentation: no project overview (README.md)
- End-of-life runtime: .NET Framework net461
- High CVE: [GHSA redacted] (src/Client/yarn.lock)
- High CVE: [GHSA redacted] (src/Client/yarn.lock)
- High CVE: [GHSA redacted] (src/Client/yarn.lock)
- High CVE: [GHSA redacted] (src/Client/yarn.lock)
- High CVE: [GHSA redacted] (src/Client/yarn.lock)
- High CVE: [GHSA redacted] (src/Client/yarn.lock)
- High CVE: [GHSA redacted] (src/Client/yarn.lock)
- High CVE: SQLitePCLRaw.lib.e_sqlite3 2.1.6
- High CVE: System.Net.Http 4.1.0
- High CVE: System.Security.Cryptography.X509Certificates 4.1.0
- High CVE: System.Text.Json 8.0.3
- High IaC: WD-DOCKER-0013 (src/Dockerfile)
- Medium CVE: [GHSA redacted] (src/Client/yarn.lock)
- Medium CVE: [GHSA redacted] (src/Client/yarn.lock)
- Medium IaC: WD-DOCKER-0003 (src/Dockerfile)
- Medium vulnerability: [GHSA redacted] (src/Client/yarn.lock)
- No ADRs found
- No SBOM
- …and 3 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
SAFE-Stack/SAFE-Chat was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit b08d61182d28dbe7420bec2e2a5a6753ddd3349a — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-923689c465cf.