Skip to content
CAI
Software that uses CAICheck a score

sigoden/dufs

55.6

Adequate · 29 September 2026

4.1k

lines of production code

Rust

with JavaScript

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a command-line file server that provides a web-based interface for browsing, editing, and managing files. It supports secure operations through TLS, authentication, and access control, while allowing users to create, move, and compress files via the UI. The server is designed for flexible deployment, supporting various network bindings and configuration methods.

Features

Initial project scaffolding and documentation

The repository is initialized with core project files, including the Apache 2.0 and MIT license texts, a security policy, and a comprehensive README detailing the CLI usage and features. Build and distribution infrastructure is added via Dockerfiles for multi-architecture builds and release packaging, alongside a .dockerignore file to optimize image construction. Source control is configured with a .gitignore that excludes build artifacts and IDE settings.

(repo-wide) · high confidence

Architecture

Major architecture overhaul: upgrade to Hyper 1.0 and Rust 2021 edition

The server has been rebuilt on top of Hyper 1.0 and the Rust 2021 edition, replacing the previous \hyper::Server\ binding with a modern \hyper\_util\ and \tokio\-based architecture. This change introduces a new modular codebase in \src/\ with dedicated modules for authentication (\auth.rs\), HTTP logging (\http\logger.rs\), and utility functions (\utils.rs\), while the main entry point (\main.rs\) now manages graceful shutdowns and TLS handshakes via \tokio\. The HTTP request/response types have been updated to use \hyper::body::Incoming\ and \BoxBody\, and the server now supports binding to both IPv4/IPv6 addresses and Unix sockets (including abstract sockets on Linux) through a new \BindAddr\ enum in \args.rs\. Additionally, the static assets have been moved to a separate \assets/\ directory, and the \index.html\ and \index.css\ files have been refactored to support the new \\\_dufs\v{version}\\_\ assets prefix.

src · high confidence

Behavioural changes

Web UI overhaul with CSS variables, dark mode support, and new file operations

The web interface has been redesigned to use CSS custom properties for theming, enabling a new basic dark mode and consistent styling across components. The layout now includes dedicated controls for creating new files and folders, viewing files, and moving/renaming items, alongside an improved login experience that displays the user name. Search behavior has been refined to ignore empty queries, and file size formatting now supports precise decimal values with tabular numerals for better alignment.

assets · high confidence

Test coverage

Integration test suite for server features and configuration

Added a comprehensive set of integration tests covering core server capabilities, including authentication (basic and digest), access control flags (upload, delete, archive, search), path prefix handling, asset serving and overriding, HTTP caching headers, CORS configuration, TLS binding (RSA and ECDSA), health checks, hidden file filtering, and HTTP range requests.

tests · high confidence

Dependencies

Upgrade to Dufs v0.46.0 with Hyper 1.0 and Clap 4

The file server has been upgraded to version 0.46.0 (renamed from duf2 to dufs), featuring a major migration to the Hyper 1.0 HTTP framework and an upgrade to Clap 4 for command-line argument parsing. This release introduces new capabilities including TLS support via tokio-rustls, file editing, hashed password authentication, and zip file compression. It also adds support for IPv4/IPv6 dual-stack listening, abstract Unix sockets, and flexible configuration via YAML files and environment variables.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 60 → 56 (-4.8)
  • Rubric changed (rubric-2026.09.8 → rubric-2026.09.17) — scores are not directly comparable.

Lenses

  • Code Health 86 → 86 (+0.1)
  • Architecture 100 → 100 (+0.0)
  • Maturity 54 → 54 (+0.3)
  • Readiness 68 → 66 (-1.7)
  • Security 73 → 76 (+3.1)
  • Accessibility 55 → 43 (-11.1)
  • Performance 100 (new)

Resolved (4)

  • Documentation: no architecture or design documentation (README.md)
  • Documentation: no usage examples (README.md)
  • Hotspot: src/args.rs (src/args.rs)
  • Hotspot: src/auth.rs (src/auth.rs)

New (4)

  • Dependency hygiene PARTLY measured — Cargo dependencies read, dependency currency not (crates.io unreachable)
  • Inverted test pyramid
  • Medium vulnerability: RUSTSEC-2026-0285 (Cargo.lock)
  • Medium: security finding (details withheld)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

sigoden/dufs was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 29 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit fe7fd564f80dfbac361c8e0589c3845638149d38 — the exact code this score is about.
  • Scored under rubric-2026.09.17 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fbec9b1e08c2.