Skip to content
CAI
Software that uses CAICheck a score

spf13/viper

57.7

Adequate · 24 September 2026

3k

lines of production code

Go

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a configuration management library that provides a unified interface for reading and writing configuration data in multiple formats, including JSON, YAML, TOML, and Dotenv. It supports pluggable encoders and decoders, allowing for custom file finding mechanisms and additional format support. The system also enables remote configuration retrieval from various backends like etcd, Firestore, and NATS. Additionally, it offers optional struct binding and customizable file search behaviors, all of which can be enabled via feature flags.

Features

Add JSON encoding and decoding codec

A new JSON codec has been added to the internal encoding package, implementing the encoder and decoder interfaces to serialize and deserialize Go maps into JSON format. The implementation uses standard library functions for marshaling and unmarshaling, supporting nested structures and error handling for invalid data.

internal/encoding/json · high confidence

Add TOML v2 encoding support

A new TOML codec has been added to the encoding package, implementing the standard Encoder and Decoder interfaces using the go-toml v2 library. The Codec struct handles serialization of map\[string\]any data structures to and from TOML format, enabling users to encode and decode TOML content with the v2 library.

internal/encoding/toml · high confidence

Add YAML encoding and decoding support

Users can now encode and decode YAML data using the new internal YAML codec. The codec implements the standard encoder and decoder interfaces, allowing YAML to be used as a serialization format alongside existing options. The implementation uses the go.yaml.in/yaml/v3 library and supports round-trip conversion between YAML byte slices and Go maps.

internal/encoding/yaml · medium confidence

Add support for encoding and decoding .env (dotenv) files

Users can now encode and decode data to and from the dotenv format, which is commonly used for environment variables. The new \Codec\ in \internal/encoding/dotenv\ provides \Encode\ and \Decode\ methods that utilize the \gotenv\ library for parsing and the \spf13/cast\ library for type conversion, allowing seamless integration with existing encoding interfaces.

internal/encoding/dotenv · high confidence

Add support for multiple remote configuration backends

The remote configuration feature now supports multiple backend providers, including etcd, etcd3, Firestore, and NATS, in addition to the existing Consul support. This allows users to store and retrieve configuration from various distributed systems. The implementation uses a switch statement to instantiate the appropriate config manager based on the provider type, enabling flexible remote configuration sources.

remote · high confidence

Introduces new file searching and encoding APIs

Viper now supports a customizable file searching mechanism via a new \Finder\ interface and a pluggable encoding layer through \Encoder\, \Decoder\, and \Codec\ interfaces. Users can now provide custom finders to control how configuration files are located, and can register custom codecs to handle additional or alternative file formats. The default codec registry includes support for JSON, TOML, YAML, and Dotenv, while other formats like HCL, Java properties, and INI have been moved to a separate \go-viper/encoding\ module.

(repo-wide) · high confidence

Behavioural changes

Config binding and finder behavior now controlled by feature flags

The behavior for binding configuration to structs and the config finder are now gated by feature flags. By default, struct binding is disabled (BindStruct=false) and the finder is disabled (Finder=false), requiring the build tags viper\_bind\_struct and viper\_finder respectively to enable these capabilities.

internal/features · high confidence

Fixes

Add cross-platform file path utility for tests

A new helper function AbsFilePath has been added to the internal test utilities, wrapping Go's filepath.Abs to safely resolve absolute paths in tests. This utility aids test authors in writing portable file path assertions that work correctly across different operating systems, addressing previous issues with file path handling on Windows.

internal/testutil · medium confidence

Dependencies

Update Go module dependencies and structure

The project's Go module files (go.mod and go.sum) have been updated to specify Go 1.23.0 and upgrade various dependencies, including mapstructure, afero, cast, and testify. Additionally, the remote package has been separated into its own module (remote/go.mod) with updated dependencies.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 57 → 58 (+1.1)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 90 → 91 (+1.4)
  • Architecture 100 → 100 (+0.0)
  • Maturity 38 → 38 (-0.3)
  • Readiness 91 → 80 (-11.5)
  • Security 54 → 64 (+10.4)

Resolved (18)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (remote/go.mod)
  • Critical CVE: [GHSA redacted] (remote/go.mod)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (remote.go)
  • Duplicated block (10 lines × 2) (viper.go)
  • Duplicated block (11 lines × 2) (viper.go)
  • Duplicated block (9 lines × 2) (viper.go)
  • High CVE: [GHSA redacted] (remote/go.mod)
  • Medium CVE: [GHSA redacted] (remote/go.mod)
  • Medium CVE: GO-2026-4601 (go.mod)
  • Medium CVE: GO-2026-4601 (remote/go.mod)
  • Medium CVE: GO-2026-5024 (go.mod)
  • Medium CVE: GO-2026-5024 (remote/go.mod)
  • Medium CVE: GO-2026-5970 (go.mod)
  • Medium vulnerability: GO-2026-5841 (remote/go.mod)
  • No exposed public API
  • Test reliability not included

New (44)

  • ClassTooLong: Viper (viper.go)
  • Critical CVE: [GHSA redacted] (remote/go.mod)
  • Critical CVE: [GHSA redacted] (remote/go.mod)
  • Duplicated block (10 lines × 2) (remote.go)
  • Duplicated block (16–17 lines × 2) (viper.go)
  • Duplicated block (30 lines × 2) (viper.go)
  • Duplicated block (8 lines × 2) (internal/encoding/dotenv/map_utils.go)
  • HackComment (flags_test.go)
  • HackComment (viper_test.go)
  • HackComment (viper_test.go)
  • High CVE: [GHSA redacted] (remote/go.mod)
  • High: security finding (details withheld)
  • Hotspot: viper.go (viper.go)
  • Job token omits the contents scope its checkout needs
  • Medium CVE: [GHSA redacted] (remote/go.mod)
  • Medium CVE: GO-2026-4601 (go.mod)
  • Medium CVE: GO-2026-4601 (remote/go.mod)
  • Medium CVE: GO-2026-5024 (go.mod)
  • Medium CVE: GO-2026-5024 (remote/go.mod)
  • Medium CVE: GO-2026-5970 (go.mod)
  • …and 24 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

spf13/viper was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 528f7416c4b56a4948673984b190bf8713f0c3c4 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-5f8d0eb43fd7.