tsenart/vegeta
61.5
Adequate · 24 September 2026
4.2k
lines of production code
Go
primary language
5
measurements over time
What this system is
This system is a command-line load testing tool that generates configurable HTTP traffic to measure server performance. It provides a library for defining attack patterns and pacing, while offering CLI commands to execute tests, export results in various formats, and generate interactive latency plots. The system also supports monitoring via Prometheus metrics and includes internal utilities for benchmarking and DNS resolution.
Features
Add LTTB downsampling library
Introduces a new \lib/lttb\ package that implements the Largest-Triangle-Three-Buckets (LTTB) algorithm to downsample data points while preserving visual similarity. The library provides a \Downsample\ function that accepts an iterator to limit memory usage, and includes comprehensive tests and benchmarks comparing the implementation against the \dgryski/go-lttb\ library.
lib/lttb · high confidence
Add Prometheus metrics and Grafana dashboard for attack monitoring
Users can now monitor attack metrics via Prometheus and visualize them in Grafana. The \lib/prom\ package introduces a new Prometheus exporter that exposes request latency, bytes in/out, and failure counts, along with a corresponding Grafana dashboard JSON file for immediate visualization of request status and performance.
lib/prom · high confidence
Add internal DNS resolver for custom address resolution
A new internal resolver package has been introduced, allowing the application to override the default DNS resolution behavior. This enables the system to route DNS queries to specific IP addresses, which is essential for the new DNS-based service discovery mechanism.
internal/resolver · high confidence
Add internal echo server for benchmarking
A new internal echo server command has been added at internal/cmd/echosrv/main.go. The server accepts HTTP requests, performs an optional artificial workload (hashing), and logs the request rate to stderr every second. It also supports dumping HTTP requests to stdout via the -dump flag and simulating latency with the -sleep flag.
internal/cmd/echosrv · high confidence
Add jsonschema tool to generate JSON schema for Vegeta types
A new command-line tool at internal/cmd/jsonschema has been added to generate JSON schema definitions for Vegeta types. The tool accepts a type name (e.g., Target) and outputs the corresponding JSON schema, supporting both stdout and file output.
internal/cmd/jsonschema · medium confidence
Add web server benchmarking script
A new automated load-testing tool has been added to the scripts directory. The Python script (ramp-requests.py) uses the 'vegeta' tool to run load tests against a target URL at varying request rates. It generates data files that are then visualized using 'gnuplot' to show success rates and latency distributions, helping users analyze server performance under different loads.
scripts · high confidence
Introduce Attacker struct and Pacer interface for configurable load testing
The library now exposes an \Attacker\ struct that encapsulates HTTP client configuration, allowing users to configure workers, connection limits, timeouts, redirects, proxy settings, and local address binding via functional options. A new \Pacer\ interface and implementations (\ConstantPacer\, \SinePacer\) define how request rates are controlled during attacks. Additionally, a \Histogram\ type and \LatencyMetrics\ with percentile calculations (P50, P90, P95, P99) are introduced to provide detailed latency analysis, while the \Metrics\ struct is expanded to include throughput, wait time, and error tracking.
lib · high confidence
Introduce new CLI commands and refactor internal structure
The CLI is restructured with new subcommands: 'encode' for converting between result formats (JSON, CSV, Gob), 'plot' for generating HTML latency plots, and 'report' for text/JSON/histogram reports. The legacy 'dump' command is deprecated in favor of 'encode'. The 'attack' command gains support for HTTP/2, h2c, TLS client certificates, Unix sockets, and Prometheus metrics export. The codebase is reorganized into separate files (attack.go, report.go, plot.go, etc.) with platform-specific handling for screen clearing and signal handling.
(repo-wide) · high confidence
Behavioural changes
Migrate plot command from Dygraphs to uPlot
The plot command now uses the uPlot library (v1.6.32) instead of the previous Dygraphs implementation. This change introduces a new HTML template (plot.html.tpl) and the uPlot JavaScript and CSS assets (uPlot.min.js, uPlot.min.css) to render charts. Additionally, a new uPlot plugin file (uplot-plugins.js) provides data transformation and export utilities for the new charting engine.
lib/plot/assets · high confidence
Migrate plot rendering to uPlot with embedded assets
The plot functionality has been moved to an independent package (lib/plot) and now uses uPlot for rendering interactive HTML time series plots, replacing the previous Dygraphs-based implementation. Assets are now embedded into the binary via Go's embed package, ensuring the plot renders correctly in all build environments. The change also introduces deterministic output for the WriteTo method and improves test coverage with golden file comparisons.
lib/plot · high confidence
Updated plot test golden file for uPlot migration
The golden test file for plot output has been updated to reflect the migration from Dygraphs to uPlot. This change updates the expected HTML/CSS output for the plot component, ensuring that automated tests pass against the new charting library's DOM structure and styling.
lib/plot/testdata · high confidence
Dependencies
Updated Go dependencies and upgraded to Go 1.22
The project's Go dependencies have been updated, including significant version bumps for \github.com/miekg/dns\ (to 1.1.61), \github.com/prometheus/prometheus\ (to 0.53.1), and \golang.org/x/net\ (to 0.27.0). The \go.mod\ file has been updated to specify Go version 1.22, and the \go.sum\ file has been regenerated to reflect the new dependency graph.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 63 → 62 (-2.0)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 89 → 93 (+3.3)
- Architecture 100 → 100 (+0.0)
- Maturity 56 → 48 (-8.4)
- Readiness 63 → 65 (+2.2)
- Security 64 → 72 (+8.4)
Resolved (23)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (go.mod)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Low IaC: DS-0005 (Dockerfile)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: GO-2025-3503 (go.mod)
- Medium CVE: GO-2026-5024 (go.mod)
- Medium CVE: GO-2026-5970 (go.mod)
- Medium IaC: CKV_DOCKER_3 (Dockerfile)
- Medium IaC: CKV_DOCKER_4 (Dockerfile)
- Medium IaC: CKV_DOCKER_4 (Dockerfile)
- Medium IaC: CKV_DOCKER_4 (Dockerfile)
- …and 3 more
New (47)
- Dependency pinned to a stale untagged commit: github.com/alecthomas/jsonschema
- Dependency pinned to a stale untagged commit: github.com/bmizerany/perks
- Dependency pinned to a stale untagged commit: github.com/dgryski/go-gk
- Dependency pinned to a stale untagged commit: github.com/dgryski/go-lttb
- Dependency pinned to a stale untagged commit: github.com/rs/dnscache
- Dependency pinned to a stale untagged commit: github.com/streadway/quantile
- Dependency pinned to a stale untagged commit: github.com/tsenart/go-tsz
- Duplicated block (13 lines × 2) (lib/attack_fuzz.go)
- Duplicated block (20 lines × 2) (lib/attack_fuzz.go)
- High CVE: [GHSA redacted] (go.mod)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 27 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
tsenart/vegeta was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit cf5811269046c672a604b1eb352204d30f16ae4a — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-5f8d0eb43fd7.