Skip to content
CAI
Software that uses CAICheck a score

stretchr/testify

75.6

Strong · 24 September 2026

7.4k

lines of production code

Go

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a comprehensive Go testing utility library that provides assertion, mocking, and suite management capabilities. It includes an assert package for flexible test verification, a require package for fail-fast testing, and a mock package for object interaction verification. Additionally, it offers a suite framework for organizing tests with lifecycle hooks and supports code generation to maintain consistency across these components.

How it got here

2012 — Mock package introduction and CI hardening

4 changes.

This period focused on expanding the testing toolkit with the initial release of the mock package, which provides comprehensive object mocking and call verification capabilities. Concurrently, the assert package was enhanced with new ordering assertions and code-generated API variants to improve ergonomics. The team also strengthened development practices by implementing CI checks for GitHub Actions pinning and Go code generation, while officially deprecating the custom http package in favor of the standard library.

2013–2015 — Testing framework expansion

3 changes.

This period focused on expanding the testing capabilities by introducing a suite framework with lifecycle hooks and subtest support. It also added a require package for fail-fast assertions and a code generation tool to maintain consistency between the assert and require packages.

2018–2026 — Go module migration and tooling

5 changes.

The project established a formal Go module structure with explicit dependency management, replacing implicit states. It introduced pluggable YAML assertion behavior to support license and size constraints, while adding internal code generation logic and vendored debugging utilities to support development workflows.

Features

Add README code formatting validation tool

A new command-line tool (\_readme-gofmt) has been added to automatically format Go code blocks within README.md using gofmt. This tool ensures that code examples in the documentation remain syntactically correct and consistently formatted, exiting with an error code if any formatting changes are required.

_\readme-gofmt · high confidence

Initial release of the mock package

The mock package is introduced, providing a system to mock objects and verify that method calls occur as expected. It includes the core Mock struct, which tracks activity and allows users to define expectations using methods like On, Return, Once, and Times. The package supports advanced features such as blocking returns with After and WaitUntil, running handlers via Run, simulating panics, and handling variadic or functional option arguments. It also includes comprehensive assertion methods like AssertExpectations and AssertCalled, along with argument diffing and error reporting to help debug test failures.

mock · high confidence

Introduce \_codegen tool to generate require and forwarded assertion functions

A new code generation tool located in the \_codegen directory has been added to automatically generate the 'require' package and forwarded assertion functions based on the existing 'assert' package source. This tool parses the assert package's AST and documentation to produce corresponding test helper functions, ensuring consistency between the two packages and reducing manual maintenance of duplicated assertion logic.

_\codegen · high confidence

Introduce require package for failing-fast assertions

The new require package provides the same assertion functions as the assert package but stops test execution immediately when a test fails by calling testing.T.FailNow. This allows tests to fail fast, preventing further assertions from running on invalid state. The package includes generated wrapper functions for all standard assertions, an object-oriented Assertions struct for method-chaining style tests, and comprehensive tests to verify the fail-fast behavior.

require · high confidence

Introduce testing suite framework with setup/teardown and subtest support

Adds the suite package, providing a framework for organizing tests into structs with lifecycle hooks (SetupSuite, TearDownSuite, SetupTest, TearDownTest) and support for Go 1.7 subtests. The implementation includes a new TestingT interface for mock compatibility, stats tracking for suite execution, and panic recovery to ensure proper teardown even when tests fail unexpectedly.

suite · high confidence

New ordering assertions and refactored comparison logic

The assert package introduces IsIncreasing, IsNonIncreasing, IsDecreasing, and IsNonDecreasing assertions to verify that slices or arrays follow a specific sort order. These rely on a new internal compare function in assertion\_compare.go that handles type conversions for numeric, string, time, and byte types. Additionally, the package now generates formatted variants (e.g., Equalf) and method-wrapped assertions (e.g., a.Equal) via code generation, improving API ergonomics and test helper integration.

assert · high confidence

Vendored go-spew library for internal debugging

The internal \spew\ package has been added to the codebase, vendoring the \github.com/davecgh/go-spew\ library. This provides a deep pretty printer for Go data structures to aid in debugging, supporting features such as dereferencing pointers, detecting circular data structures, and invoking custom \Stringer\ or \error\ interfaces on unexported fields. The implementation includes build constraints to handle environments without \unsafe\ package access (like App Engine or GopherJS) and provides both dump-style and formatter-style output.

internal · high confidence

Behavioural changes

HTTP package marked as deprecated in favor of standard library

The http package, including TestResponseWriter, TestRoundTripper, and its documentation, is now officially deprecated. Users are advised to migrate to the standard library's net/http/httptest package, as the custom implementations provided here are no longer recommended for use.

http · high confidence

Internal import tracking logic added to codegen

The codegen tool now includes an internal package to track and manage Go import paths. This new component, copied from github.com/ernesto-jimenez/gogen/imports, provides logic to analyze types and extract their dependencies, automatically cleaning import paths by removing vendor prefixes and GOPATH segments. This supports the code generation process by ensuring accurate import statements are produced.

_\codegen/internal · high confidence

New CI checks for GitHub Actions pinning and Go code generation

The repository now includes CI scripts that verify GitHub Actions are pinned to specific commit hashes and that generated Go code matches the committed output, ensuring reproducible builds and preventing drift in generated files.

(repo-wide) · high confidence

YAML parsing in assertions is now pluggable via build tags

The YAML assertion functions (YAMLEq/YAMLEqf) no longer force a single YAML library dependency. By default, they use go.yaml.in/yaml/v3, but users can now select alternative behaviors at build time: using testify\_yaml\_custom to inject a custom Unmarshal implementation (e.g., to avoid linking with go.yaml.in/yaml/v3), or testify\_yaml\_fail to make YAML assertions always fail with an error. This allows teams to manage license compatibility or reduce binary size by excluding the default YAML parser when not needed.

assert/yaml · high confidence

Dependencies

Initial Go module setup with objx and yaml dependencies

The project is now managed as a Go module, introducing go.mod and go.sum files for the root package and a separate go.mod for the \_codegen tool. This establishes explicit dependencies on github.com/stretchr/objx v0.5.3 and go.yaml.in/yaml/v3 v3.0.5, replacing previous implicit or unmanaged dependency states.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 66 → 76 (+9.2)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 76 → 86 (+9.9)
  • Architecture 100 → 97 (-2.5)
  • Maturity 79 → 81 (+2.1)
  • Readiness 59 → 72 (+13.0)
  • Security 65 → 72 (+6.9)

Resolved (20)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (assert/assertions.go)
  • Duplicated block (12 lines × 2) (_codegen/main.go)
  • Duplicated block (12 lines × 2) (assert/assertions.go)
  • Duplicated block (16 lines × 2) (assert/assertions.go)
  • Duplicated block (6 lines × 2) (mock/mock.go)
  • Duplicated block (8 lines × 2) (assert/assertions.go)
  • Duplicated block (8 lines × 2) (assert/assertions.go)
  • Duplicated block (9 lines × 2) (assert/assertions.go)
  • Duplicated block (9 lines × 3) (assert/http_assertions.go)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Hotspot: assert/assertions.go (assert/assertions.go)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Medium CVE: GO-2022-0433 (_codegen/go.mod)
  • Medium CVE: GO-2022-0969 (go.mod)
  • No exposed public API
  • Test reliability not included

New (34)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 2) (assert/assertions.go)
  • Duplicated block (10 lines × 2) (assert/assertions.go)
  • Duplicated block (10 lines × 2) (assert/assertions.go)
  • Duplicated block (10 lines × 2) (assert/assertions.go)
  • Duplicated block (14 lines × 2) (_codegen/main.go)
  • Duplicated block (15 lines × 2) (assert/assertions.go)
  • Duplicated block (21 lines × 2) (assert/assertions.go)
  • Duplicated block (5 lines × 2) (assert/assertion_compare.go)
  • Duplicated block (5 lines × 2) (assert/assertions.go)
  • Duplicated block (7 lines × 2) (mock/mock.go)
  • Duplicated block (7 lines × 3) (assert/http_assertions.go)
  • Duplicated block (9 lines × 2) (assert/assertions.go)
  • FileTooLong: assert/assertions.go (assert/assertions.go)
  • FileTooLong: mock/mock.go (mock/mock.go)
  • FunctionTooLong: assert.compare (assert/assertion_compare.go)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low: security finding (details withheld)
  • …and 14 more

Changes since last survey

  • 11 commits — 9 feature/other, 2 fixes

By area

  • (repo) — 8 commits
  • (root) — 1 commit
  • .github/workflows — 1 commit
  • mock/mock.go — 1 commit

Notable commits

  • fix: Merge branch 'master' into fix/mock-missing-arg-sentinel
  • fix: Merge pull request #1938 from dylanpulver/fix/mock-missing-arg-sentinel
  • change: CI: retain Go 1.25 coverage
  • change: Merge branch 'master' into dependabot/github_actions/actions/checkout-7.0.1
  • change: Merge pull request #1923 from stretchr/dependabot/github_actions/softprops/action-gh-release-3.0.2
  • change: Merge pull request #1924 from stretchr/dependabot/github_actions/actions/setup-go-7.0.0
  • change: Merge pull request #1926 from stretchr/dependabot/github_actions/actions/checkout-7.0.1
  • change: Merge pull request #1935 from harryzcy/yaml-update
  • change: Merge pull request #1950 from mattjohnsonpint/mjp/ci-go1.25
  • change: Update go.yaml.in/yaml/v3 to v3.0.5
  • change: mock: do not let a surplus matcher match a missing argument

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

stretchr/testify was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 435c07b5cb95c88b82cf35f49da0dde33d24ad46 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-5f8d0eb43fd7.