Skip to content
CAI
Software that uses CAICheck a score

tsenart/vegeta

61.5

Adequate · 24 September 2026

4.2k

lines of production code

Go

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a command-line load testing tool that generates configurable HTTP traffic to measure server performance. It provides a library for defining attack patterns and pacing, while offering CLI commands to execute tests, export results in various formats, and generate interactive latency plots. The system also supports monitoring via Prometheus metrics and includes internal utilities for benchmarking and DNS resolution.

Features

Add LTTB downsampling library

Introduces a new \lib/lttb\ package that implements the Largest-Triangle-Three-Buckets (LTTB) algorithm to downsample data points while preserving visual similarity. The library provides a \Downsample\ function that accepts an iterator to limit memory usage, and includes comprehensive tests and benchmarks comparing the implementation against the \dgryski/go-lttb\ library.

lib/lttb · high confidence

Add Prometheus metrics and Grafana dashboard for attack monitoring

Users can now monitor attack metrics via Prometheus and visualize them in Grafana. The \lib/prom\ package introduces a new Prometheus exporter that exposes request latency, bytes in/out, and failure counts, along with a corresponding Grafana dashboard JSON file for immediate visualization of request status and performance.

lib/prom · high confidence

Add internal DNS resolver for custom address resolution

A new internal resolver package has been introduced, allowing the application to override the default DNS resolution behavior. This enables the system to route DNS queries to specific IP addresses, which is essential for the new DNS-based service discovery mechanism.

internal/resolver · high confidence

Add internal echo server for benchmarking

A new internal echo server command has been added at internal/cmd/echosrv/main.go. The server accepts HTTP requests, performs an optional artificial workload (hashing), and logs the request rate to stderr every second. It also supports dumping HTTP requests to stdout via the -dump flag and simulating latency with the -sleep flag.

internal/cmd/echosrv · high confidence

Add jsonschema tool to generate JSON schema for Vegeta types

A new command-line tool at internal/cmd/jsonschema has been added to generate JSON schema definitions for Vegeta types. The tool accepts a type name (e.g., Target) and outputs the corresponding JSON schema, supporting both stdout and file output.

internal/cmd/jsonschema · medium confidence

Add web server benchmarking script

A new automated load-testing tool has been added to the scripts directory. The Python script (ramp-requests.py) uses the 'vegeta' tool to run load tests against a target URL at varying request rates. It generates data files that are then visualized using 'gnuplot' to show success rates and latency distributions, helping users analyze server performance under different loads.

scripts · high confidence

Introduce Attacker struct and Pacer interface for configurable load testing

The library now exposes an \Attacker\ struct that encapsulates HTTP client configuration, allowing users to configure workers, connection limits, timeouts, redirects, proxy settings, and local address binding via functional options. A new \Pacer\ interface and implementations (\ConstantPacer\, \SinePacer\) define how request rates are controlled during attacks. Additionally, a \Histogram\ type and \LatencyMetrics\ with percentile calculations (P50, P90, P95, P99) are introduced to provide detailed latency analysis, while the \Metrics\ struct is expanded to include throughput, wait time, and error tracking.

lib · high confidence

Introduce new CLI commands and refactor internal structure

The CLI is restructured with new subcommands: 'encode' for converting between result formats (JSON, CSV, Gob), 'plot' for generating HTML latency plots, and 'report' for text/JSON/histogram reports. The legacy 'dump' command is deprecated in favor of 'encode'. The 'attack' command gains support for HTTP/2, h2c, TLS client certificates, Unix sockets, and Prometheus metrics export. The codebase is reorganized into separate files (attack.go, report.go, plot.go, etc.) with platform-specific handling for screen clearing and signal handling.

(repo-wide) · high confidence

Behavioural changes

Migrate plot command from Dygraphs to uPlot

The plot command now uses the uPlot library (v1.6.32) instead of the previous Dygraphs implementation. This change introduces a new HTML template (plot.html.tpl) and the uPlot JavaScript and CSS assets (uPlot.min.js, uPlot.min.css) to render charts. Additionally, a new uPlot plugin file (uplot-plugins.js) provides data transformation and export utilities for the new charting engine.

lib/plot/assets · high confidence

Migrate plot rendering to uPlot with embedded assets

The plot functionality has been moved to an independent package (lib/plot) and now uses uPlot for rendering interactive HTML time series plots, replacing the previous Dygraphs-based implementation. Assets are now embedded into the binary via Go's embed package, ensuring the plot renders correctly in all build environments. The change also introduces deterministic output for the WriteTo method and improves test coverage with golden file comparisons.

lib/plot · high confidence

Updated plot test golden file for uPlot migration

The golden test file for plot output has been updated to reflect the migration from Dygraphs to uPlot. This change updates the expected HTML/CSS output for the plot component, ensuring that automated tests pass against the new charting library's DOM structure and styling.

lib/plot/testdata · high confidence

Dependencies

Updated Go dependencies and upgraded to Go 1.22

The project's Go dependencies have been updated, including significant version bumps for \github.com/miekg/dns\ (to 1.1.61), \github.com/prometheus/prometheus\ (to 0.53.1), and \golang.org/x/net\ (to 0.27.0). The \go.mod\ file has been updated to specify Go version 1.22, and the \go.sum\ file has been regenerated to reflect the new dependency graph.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 63 → 62 (-2.0)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 89 → 93 (+3.3)
  • Architecture 100 → 100 (+0.0)
  • Maturity 56 → 48 (-8.4)
  • Readiness 63 → 65 (+2.2)
  • Security 64 → 72 (+8.4)

Resolved (23)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (go.mod)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low IaC: DS-0005 (Dockerfile)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: GO-2025-3503 (go.mod)
  • Medium CVE: GO-2026-5024 (go.mod)
  • Medium CVE: GO-2026-5970 (go.mod)
  • Medium IaC: CKV_DOCKER_3 (Dockerfile)
  • Medium IaC: CKV_DOCKER_4 (Dockerfile)
  • Medium IaC: CKV_DOCKER_4 (Dockerfile)
  • Medium IaC: CKV_DOCKER_4 (Dockerfile)
  • …and 3 more

New (47)

  • Dependency pinned to a stale untagged commit: github.com/alecthomas/jsonschema
  • Dependency pinned to a stale untagged commit: github.com/bmizerany/perks
  • Dependency pinned to a stale untagged commit: github.com/dgryski/go-gk
  • Dependency pinned to a stale untagged commit: github.com/dgryski/go-lttb
  • Dependency pinned to a stale untagged commit: github.com/rs/dnscache
  • Dependency pinned to a stale untagged commit: github.com/streadway/quantile
  • Dependency pinned to a stale untagged commit: github.com/tsenart/go-tsz
  • Duplicated block (13 lines × 2) (lib/attack_fuzz.go)
  • Duplicated block (20 lines × 2) (lib/attack_fuzz.go)
  • High CVE: [GHSA redacted] (go.mod)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 27 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

tsenart/vegeta was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit cf5811269046c672a604b1eb352204d30f16ae4a — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-5f8d0eb43fd7.