schollz/croc
65.9
Adequate · 6 August 2026
16.5k
lines of production code
Go
with TypeScript
4
measurements over time
What this system is
Croc is a secure file transfer application that enables users to send and receive files via a command-line interface or a browser-based web client. The system facilitates direct peer-to-peer connections and optional encrypted temporary storage, utilizing advanced cryptographic protocols and compression to ensure data integrity and privacy. It features a modular architecture with a configurable TCP relay server, robust network handling, and cross-platform support for both CLI and web environments.
How it got here
2017–2018 — croc v10 rewrite
9 changes.
The project underwent a major architectural overhaul to version 10, introducing a comprehensive CLI, a web client, and Docker support. This period focused on replacing the legacy codebase with a modular structure featuring enhanced encryption, proxy support, and improved DNS resolution.
2019–2026 — Web client and storage infrastructure
15 changes.
This period focused on expanding the project's capabilities through a comprehensive web-based interface and a new encrypted temporary storage service. The team built a React-based web client with WebAssembly integration for secure peer-to-peer transfers, while simultaneously introducing a backend service for storing and retrieving encrypted files. These features were supported by foundational utilities for disk usage, file handling, and automated release processes.
Features
Add WebAssembly client for secure peer-to-peer transfers
The web client now runs cryptographic operations (PAKE, encryption, compression, hashing, and store sealing) in the browser via a new Go/WASM module. This enables encrypted temporary stored transfers and binds PAKE handshakes to participants and sessions, improving security and performance for web users.
web/src/wasm, web/wasm · high confidence
Add context-aware file handling and multiple hash algorithms
The utility package now supports context cancellation for file operations, allowing long-running file reads and hashing to be interrupted gracefully. Additionally, the system introduces support for multiple file hashing algorithms (MD5, xxhash, highwayhash, and imohash), each with optional progress reporting. This change also includes a new \ctx.go\ file that wraps \os.File\ to respect context deadlines, ensuring that file operations can be cancelled when needed.
src/utils · high confidence
Add cross-platform disk usage utility
A new \diskusage\ package has been added to provide a unified interface for querying disk space information across different operating systems. The implementation uses platform-specific code: \diskusage.go\ and \statfs\_unix.go\ handle standard Unix-like systems, \diskusage\_netbsd.go\ provides a dedicated implementation for NetBSD, and \diskusage\_windows.go\ uses Windows API calls. Each platform-specific file exposes the same public methods (\Free\, \Available\, \Size\, \Used\, \Usage\) to allow consistent access to disk usage metrics regardless of the underlying OS.
src/diskusage · high confidence
Add encrypted temporary stored transfers
The application now supports uploading and downloading temporary, encrypted files via a new stored-transfer service. This feature introduces a server-side service (src/store) that manages file storage with configurable limits, rate limiting, and cross-platform file locking (src/store/lock\_unix.go, src/store/lock\_windows.go). It includes a client library (src/storeclient) for CLI integration, handling upload, download, and inspection of encrypted chunks and manifests. The cryptographic layer (src/storecrypto) ensures that file metadata and content are encrypted before storage, with capabilities for redeeming and claiming transfers. Tests (src/store/service\_test.go, src/storeclient/client\_test.go, src/storecrypto/storecrypto\_test.go) verify the full lifecycle of stored transfers.
src/store, src/storeclient, src/storecrypto · high confidence
Add mnemonicode encoding and decoding logic
The mnemonicode package is introduced, providing functions to encode byte slices into lists of mnemonic words and calculate the required word count. The implementation includes the core encoding logic in mnemonicode.go, a comprehensive word list in wordlist.go, and unit tests in mnemonicode\_test.go to verify correctness.
src/mnemonicode · high confidence
Add privacy consent and analytics tracking to the web client
The web client now requires explicit user consent before loading the Umami analytics script, ensuring that no tracking occurs unless the user opts in. A new PrivacyModal dialog presents the user with an 'Allow analytics' or 'Reject analytics' choice, and the application state for this consent is persisted in browser storage. The analytics module tracks specific transfer events (send direct, send with storage, receive) only after consent is granted, and the UI includes a footer link to change privacy choices later.
web/src · high confidence
Added ChaCha20-Poly1305 encryption support alongside existing AES-GCM
The cryptographic module now supports two encryption algorithms: the existing AES-GCM and a new ChaCha20-Poly1305 implementation. Users can generate keys using either PBKDF2 (for AES) or Argon2 (for ChaCha20), and encrypt/decrypt data using the corresponding functions. This provides an alternative encryption path that may offer better performance on devices without AES hardware acceleration.
src/crypt · high confidence
Added automated release and autocomplete infrastructure
The installation directory now includes a Makefile to automate release workflows, including version updates, git tagging, and source tarball preparation. New shell completion scripts for Bash and Zsh have been added to provide command-line autocompletion, and a Go utility (updateversion.go) was introduced to automatically update version strings across the codebase. Additionally, a script was added to upload source tarballs to GitHub releases.
src/install · high confidence
Added build and embed scripts for WebAssembly and distribution assets
New Node.js scripts were added to the web/scripts directory to automate the build process. build-wasm.mjs locates the Go wasm\_exec.js file and compiles the Go WebAssembly module (croc.wasm) into the public directory. Additionally, embed-dist.mjs copies the compiled distribution assets and an installer file into the webassets directory, streamlining the build and packaging workflow for the web client.
web/scripts · medium confidence
Added web client infrastructure for Croc
The web client is now available at croc.com, supported by new public assets including a service worker (croc-download-sw.js) that handles streaming downloads via the MessagePort API, a Web Worker (croc-worker.js) that loads and executes the Croc WebAssembly module, and a configuration file (config.js) for runtime settings.
web/public · high confidence
Embedded web client assets and tests
The Go package src/webassets now embeds the production web client into the binary via Go's embed directive, making the client's HTML, CSS, and JavaScript available to the application at runtime. A corresponding test verifies that the embedded assets include the expected entry points, metadata, and WASM files.
src/webassets · high confidence
Introduce CLI v2 migration and new relay configuration options
The command-line interface has been migrated to the cli/v2 framework, introducing new global and command-specific flags for the relay and serve commands. Users can now configure relay behavior with new options such as --max-rooms-open, --max-pending-handshakes, and --handshake-timeout, which can be set via flags or environment variables (CROC\_MAX\_ROOMS\_OPEN, CROC\_MAX\_PENDING\_HANDShAKES, CROC\_HANDSHAKE\_TIMEOUT). The CLI also adds support for generating fish shell completions and includes a new 'serve' command to host the web client and relay. Additionally, the 'send' command now supports a --store flag for encrypted temporary storage transfers, with associated receipt management in the config directory.
src/cli · high confidence
Introduce new TCP communication layer with proxy support and safety limits
The \src/comm\ package now provides a new TCP communication implementation (\comm.go\) that supports connecting through SOCKS5 and HTTP proxies, addressing network limitations. This change introduces a structured \Comm\ type with explicit read/write methods, enforcing a 64MB message size limit to prevent memory issues and using magic bytes for stream validation. The implementation includes robust deadline handling to prevent memory leaks and ensure timely disconnection, alongside comprehensive unit tests (\comm\_test.go\) validating large message handling, proxy dialing, and timeout behaviors.
src/comm · high confidence
Introduce new compress package for data compression and decompression
Added a new \compress\ package that provides functions to compress and decompress byte slices using the \flate\ algorithm. The \Compress\ and \CompressWithOption\ functions handle data compression, while \Decompress\ handles decompression with a configurable maximum output size limit. The implementation includes error handling for oversized decompressed data and malformed input, along with comprehensive unit and benchmark tests.
src/compress · high confidence
Introduce structured, encrypted message format
The application now uses a new \message\ package to handle all internal communication. Messages are serialized into a structured format that supports encryption and compression, with a 64 MB limit on decompressed payloads to prevent excessive memory usage. This change introduces specific message types (such as PAKE, file info, and error messages) and ensures that all transmitted data is safely encoded and decoded.
src/message · high confidence
Introduce the croc web client for browser-based file transfers
A new React/Vite-based web client is added to the project, enabling users to send and receive files directly from a browser. The client supports both direct peer-to-peer transfers and an optional encrypted temporary storage mode (24-hour retention) for sharing files without requiring the recipient to have the CLI tool. The web client communicates with the Go backend via a WebSocket bridge and includes configuration for local development, end-to-end testing with Playwright, and optional Umami analytics tracking.
web · high confidence
Introduce web-based file transfer interface
A new web client is now available for file transfers, exposing a WebSocket-to-TCP bridge that forwards an opaque byte stream to a fixed relay host and allowlisted ports. The web server serves the embedded client, a runtime configuration endpoint (/config.js), a health check (/healthz), and optional Umami analytics. The relay host defaults to croc.schollz.com, and the default listening address is 127.0.0.1:9014.
src/webrelay · high confidence
Introduces a new codephrase format for share codes
The croc client now supports a new four-word share code format (e.g., 'abbot-abide-abandon-abandoned') alongside the legacy byte-based format. This change introduces a new \codephrase\ package that handles parsing and generating these codes, using embedded wordlists ('Orchard Street Alpha' and 'Orchard Street Long') to create memorable, human-readable codes. The \croc\ package is updated to use this new codephrase logic, and the \pakekey\ package is introduced to bind PAKE handshakes to participants and sessions. Additionally, the \termui\ package is added to handle terminal-safe styling for the command-line interface, and \sender\_output\ is refactored to support colored output and clipboard-friendly text formats.
src/croc · high confidence
Refactor TCP server into a configurable, context-aware architecture
The TCP server implementation has been refactored to support configurable options and graceful shutdown. A new \ctx.go\ file introduces a \stop\ struct for managing the server's lifecycle and context cancellation, allowing for clean shutdowns. The \options.go\ file adds a builder-style configuration system (\WithMaxRoomsOpen\, \WithMaxPendingHandshakes\, \WithHandshakeTimeout\, etc.) that allows users to customize server behavior. The \defaults.go\ file defines constants for these new configuration parameters. The main \tcp.go\ file has been updated to use these options, and \tcp\_test.go\ has been added to verify the new configuration and room eviction logic.
src/tcp · high confidence
croc v10: major rewrite with CLI, Docker, and web client support
The application has been completely rewritten as croc v10, moving from a simple TCP file transfer tool to a full-featured CLI application with a web client. This release introduces a new \cli\ package for command-line handling, a Dockerfile for containerized relay/server deployment, and a \croc-entrypoint.sh\ script to manage relay ports and environment variables. The old \client.go\, \server.go\, and \rendevouz.go\ files have been removed, and the project now supports multiple TCP ports, a web interface at getcroc.com, and improved signal handling for graceful shutdowns.
(repo-wide) · high confidence
Behavioural changes
Complete rewrite of the web client protocol layer
The web client's protocol implementation has been entirely rewritten, introducing a new framing system for WebSocket messages, a compact JSON codec for control messages, and a modular storage layer that supports both file-system and browser-download sinks. The rewrite adds comprehensive test coverage for the framing, codec, metadata validation, and storage components, and includes fixes for silent hangs and early socket failures during file transfers.
web/src/protocol · high confidence
Improved DNS resolution with fallback to public DNS servers
The application now resolves hostnames using the local DNS resolver by default, with a fallback to a built-in list of public DNS servers (including Cloudflare, Google, Quad9, and OpenDNS) if the local lookup fails. This change improves reliability, particularly in environments with broken or slow DNS, and supports both IPv4 and IPv6 resolution. The new behavior is controlled by the \--internal-dns\ flag and a config file, and includes a 500ms timeout for DNS lookups to prevent hanging.
src/models · high confidence
Test coverage
Added test setup configuration
Added a new test setup file that imports @testing-library/jest-dom/vitest to extend Vitest's assertions and matchers for DOM testing.
web/src/test · high confidence
Dependencies
Update Go and web client dependencies
The Go module (go.mod) has been updated to use Go 1.25.0 and includes updated versions of key dependencies such as golang.org/x/crypto (v0.54.0), golang.org/x/net (v0.57.0), and golang.org/x/sys (v0.47.0). Additionally, the web client's package.json and package-lock.json have been added, establishing the frontend dependencies for the web interface, including React 19.0.0 and related tooling.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 66 → 66 (-0.1)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.19) — scores are not directly comparable.
Lenses
- Code Health 69 → 69 (+0.5)
- Architecture 100 → 100 (+0.0)
- Maturity 63 → 63 (+0.0)
- Readiness 67 → 69 (+1.7)
- Security 66 → 65 (-1.5)
- Accessibility 75 → 75 (+0.1)
Resolved (1)
- Off-boarding risk: anonymized user #1
New (4)
- High CVE: [GHSA redacted] (web/package-lock.json)
- Medium CVE: [GHSA redacted] (web/package-lock.json)
- Medium IaC: CKV_DOCKER_7 (Dockerfile)
- Off-boarding risk: anonymized user #1
Changes since last survey
- 8 commits — 7 feature/other, 1 fixes
By area
- src/webassets — 4 commits
- (root) — 2 commits
- .github/workflows — 1 commit
- web/src — 1 commit
Notable commits
- fix: fix: DS_STORE
- change: Add Swamp Swamp link (#1227)
- change: build(deps): bump docker/login-action from 4.5.2 to 4.6.0 (#1225)
- change: chore: add favicon
- change: chore: update index
- change: docs: list croc-desktop among unofficial desktop GUIs (#1207)
- change: feat: add privacy
- change: feat: use croc.schollz.com temporarily
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
schollz/croc was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 6 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit fea1eca158a9ee5126a4646e3531af17930e422c — the exact code this score is about.
- Scored under rubric-2026.08.19 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer latest.