Skip to content
CAI
Software that uses CAICheck a score

sneako/finch

73.3

Strong · 23 September 2026

4.1k

lines of production code

Elixir

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Finch is an Elixir HTTP client library that manages connection pooling and supports both HTTP/1 and HTTP/2 protocols. It provides configurable strategies for worker selection, dynamic pool resizing, and structured error handling, while exposing detailed telemetry and metrics for monitoring connection health. The system allows users to define named pools with specific behaviors, such as idle timeouts and multiplexed streaming, to optimize resource usage for various workloads.

How it got here

2019 — HTTP/2 support and API overhaul

6 changes.

Finch underwent a major refactoring to introduce HTTP/2 multiplexing, structured error handling, and support for multiple named connection pools. The public API was significantly restructured to use NimbleOptions for configuration validation, and core dependencies were upgraded to require Elixir 1.15 and Mint 1.8.

2020 — HTTP/2 support and connection pooling

4 changes.

This period focused on implementing core HTTP/2 support with multiplexed streaming and flow control, alongside enhancing HTTP/1 connection pooling with idle timeouts. Comprehensive test infrastructure and integration tests were added to validate both protocol implementations, including ALPN negotiation and detailed telemetry metrics.

2025–2026 — Configurable pool strategies and dynamic management

4 changes.

This period introduced configurable pool worker selection strategies, including Hash, Random, and RoundRobin, allowing users to tailor request distribution. It also added dynamic pool management capabilities for runtime resizing and enhanced test coverage for these new features and error handling.

Features

Add configurable pool worker selection strategies

Users can now choose how Finch distributes requests across pool workers by specifying a \pool\_strategy\ option. Three strategies are available: \Hash\ for connection affinity (routing the same key to the same worker), \Random\ for uniform distribution (the new default, optimized for short tasks), and \RoundRobin\ for even load balancing using an atomics counter. This allows users to tailor connection reuse and load distribution to their specific workload requirements.

lib/finch/pool/strategy · high confidence

Introduce HTTP/2 pool implementation with multiplexed streaming and flow control

Adds the core HTTP/2 pool infrastructure (\Finch.HTTP2.Pool\, \Finch.HTTP2.PoolMetrics\, and \Finch.HTTP2.RequestStream\) to enable HTTP/2 support. This implementation manages persistent connections using a state machine, handles request multiplexing via stream IDs, and implements HTTP/2 flow control by respecting window sizes when streaming request bodies. It also provides specific metrics for tracking in-flight requests and max concurrent streams, while explicitly raising an error for body streaming functions not yet supported on HTTP/2 pools.

lib/finch/http2 · high confidence

Behavioural changes

Configurable pool worker selection strategies and dynamic pool management

Finch now supports configurable strategies for selecting pool workers when multiple connections are available, allowing users to implement custom logic (such as round-robin, hash-based affinity, or least-busy) via the \Finch.Pool.Strategy\ behaviour. Additionally, the pool manager introduces dynamic pool creation and runtime resizing capabilities, enabling users to adjust the number of pool workers on the fly using \get\_pool\_count\ and \set\_pool\_count\, while ensuring proper initialization and readiness checks for newly started or resized pools.

lib/finch/pool · high confidence

Finch refactored to support multiple connection pools and structured error handling

Finch has been restructured to support multiple named connection pools, allowing users to manage and target specific pools via tags and user-managed child specs. The library now introduces a structured error hierarchy (Finch.Error, Finch.HTTPError, Finch.TransportError) to replace previous exception handling, and adds support for Unix sockets via http+unix:// and https+unix:// URL schemes. Additionally, pool metrics are now tracked using a unified ETS table for better performance, and private request metadata can be attached to requests for custom telemetry.

lib/finch · high confidence

HTTP/1 connection pooling with idle timeouts and enhanced telemetry

Finch now implements a dedicated HTTP/1 connection pool that supports configurable \conn\_max\_idle\_time\ to automatically close and reuse connections based on inactivity, improving resource management for long-lived services. The new pool integrates with the Telemetry system to emit detailed events for connection lifecycle stages (connect, send, receive, queue) and exposes granular pool metrics (available vs. in-use connections) via an ETS-backed registry, allowing users to monitor pool health and adjust sizing based on real-time usage data.

lib/finch/http1 · high confidence

Major API overhaul with HTTP/2 support and configurable connection pooling

Finch has been significantly refactored to support HTTP/2 multiplexing alongside HTTP/1, introducing a new \protocols\ configuration option to select connection types. The library now uses \NimbleOptions\ for robust validation of pool settings, allowing users to configure shard counts, connection sizes, idle timeouts, and HTTP/2-specific behaviors like keep-alive pings and connection age limits. The public API has changed: \Finch.request/3\ is now the primary synchronous method, \Finch.stream/3\ handles streaming, and a new \Finch.async\_request/3\ is available for asynchronous operations. Users must now define pools via \Finch.start\_link/1\ with explicit configuration or use the default pool, and can query pool status and metrics via \get\_pool\_status/2\. Deprecated options like \:max\_idle\_time\ have been replaced by \:conn\_max\_idle\_time\, and the library no longer ties itself to a specific module, requiring configuration to be passed at startup.

lib · high confidence

Removal of legacy config/config.exs file

The project has removed the main configuration file (config/config.exs) which previously contained boilerplate comments and the Mix.Config module usage. This change eliminates the default configuration structure for the application, likely as part of a migration to a different configuration strategy or to clean up unused legacy code.

config · high confidence

Test coverage

Added HTTP/2 integration, pool, metrics, and telemetry tests; Added test infrastructure for HTTP/1, HTTP/2, and ALPN scenarios; Added tests for ALPN large-body handling, SSLKEYLOGFILE parsing, and error wrapping; Added tests for pool worker selection strategies and supervisor shutdown behavior; Expanded test coverage for request metadata and pool configuration.

Dependencies

Major dependency upgrade and Elixir version requirement bump

Finch now requires Elixir 1.15 or higher and upgrades its core HTTP client dependency from Mint 0.4 to Mint 1.8, bringing significant performance and protocol improvements. The pool implementation has been replaced with NimblePool 1.1, and configuration validation now uses NimbleOptions 1.0. Support for Telemetry 1.0 and MIME 2.0 is added alongside relaxed version constraints for these libraries. Development tooling is updated with Credo, Dialyxir, and ExDoc, while test dependencies like Bypass and Mimic are modernized. The Castore dependency has been removed as Mint now handles TLS certificates internally.

(dependencies) · high confidence

Housekeeping

Initial project scaffolding and configuration

The repository is initialized with core project files, including a Credo linting configuration (.credo.exs), a comprehensive changelog (CHANGELOG.md) documenting versions from v0.1.1 through v0.23.0, an MIT license (LICENSE.md), and a detailed README.md. The README provides usage instructions for the Finch HTTP client, covering pool configuration, tagging, user-managed pools, telemetry, and TLS secret logging.

(repo-wide) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 67 → 73 (+6.8)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 95 → 97 (+1.7)
  • Architecture 100 → 100 (+0.0)
  • Maturity 58 → 57 (-0.5)
  • Readiness 64 → 80 (+15.4)
  • Security 74 → 94 (+19.9)

Resolved (19)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • Duplicated block (13 lines × 2) (lib/finch/http2/pool.ex)
  • Duplicated block (14 lines × 2) (lib/finch/http2/pool.ex)
  • Duplicated block (20 lines × 2) (lib/finch/http2/pool.ex)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • Test reliability not included
  • TooManyMethods: Pool (lib/finch/http2/pool.ex)

New (26)

  • Documentation: no installation or build instructions (README.md)
  • Duplicated block (14 lines × 2) (lib/finch/http2/pool.ex)
  • Duplicated block (18 lines × 2) (lib/finch/http2/pool.ex)
  • Duplicated block (18 lines × 2) (lib/finch/http2/pool.ex)
  • High CVE: [GHSA redacted] (mix.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • No dependency advisory monitoring
  • Off-boarding risk: anonymized user #1
  • Orphaned files with no living knowledge
  • Outdated: cowboy
  • Outdated: dialyxir
  • Outdated: ex_doc
  • …and 6 more

Changes since last survey

  • 17 commits — 11 feature/other, 6 fixes

By area

  • (repo) — 7 commits
  • lib/finch — 7 commits
  • (root) — 1 commit
  • .github/workflows — 1 commit
  • test/finch — 1 commit

Notable commits

  • fix: Fix MatchError when cancelling while HTTP/2 pool is disconnected
  • fix: Fix first request to dynamically started HTTP/2 pools
  • fix: Merge pull request #381 from mvanhorn/fix/376-sslkeylogfile-empty-string
  • fix: Merge pull request #387 from britto/fix/http2-pool-cancel-disconnected
  • fix: Merge pull request #391 from sneako/fix/pool-resize-registry-cleanup
  • fix: fix warning during mix docs
  • change: Close terminated HTTP/1 connections outside the pool process
  • change: Merge pull request #382 from wojtekmach/wm-pool-opt
  • change: Merge pull request #388 from sneako/h2-readiness-issue
  • change: Merge pull request #389 from sneako/upgrade-ci-1.20.4
  • change: Merge pull request #392 from ericmj/async-worker-close
  • change: Remove timing races from pool checkout idle test
  • change: Share pool shutdown cleanup between HTTP protocols
  • change: Unregister pool workers before shutdown completes
  • change: Wait for dynamically started HTTP/2 pools
  • change: track pools that are started but not ready
  • change: update ci to run elixir 1.20.4 and otp 29.0.6

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

sneako/finch was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 79885b6cd1ca072824149389b6ab8899f8b970d1 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.