Skip to content
CAI
Software that uses CAICheck a score

uber-go/zap

70.8

Strong · 24 September 2026

8.6k

lines of production code

Go

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Zap is a high-performance, structured logging library for Go that provides both a type-safe Logger for critical paths and a SugaredLogger for convenience. It supports advanced features such as zero-allocation buffering, configurable console and JSON encoding, and buffered I/O to minimize overhead. The system includes integration adapters for gRPC and Go's standard slog, as well as comprehensive testing utilities for capturing and verifying log output.

How it got here

2016–2017 — Initial release and core feature expansion

12 changes.

This period marks the initial release of the zap structured logging library, establishing its core high-performance architecture with type-safe and sugared APIs. Subsequent work focused on enhancing performance and usability through buffered logging, zero-allocation buffers, and configurable console output. The period also expanded the ecosystem with test isolation utilities, gRPC compatibility, and automated benchmarking to validate performance against other Go logging libraries.

2019–2023 — slog integration and internal refactoring

8 changes.

This period focused on integrating Go's standard slog API via the experimental zapslog package and enhancing the zapio.Writer for io.Writer compatibility. Internal architecture was refined through the introduction of generic pooling, stack trace handling, and leveled enabler interfaces to resolve cyclic dependencies and improve type safety.

Features

Add experimental generic string field helpers

The exp/zapfield package now provides generic helper functions Str and Strs for creating zap fields. Str accepts string-like keys and values, while Strs accepts a key and a slice of string-like values, allowing users to log string data without explicit type conversions. These helpers are part of the experimental API and may be unstable.

exp/zapfield · high confidence

Add generic object pooling utility

The internal/pool package now provides a generic Pool wrapper around sync.Pool, allowing callers to manage strongly-typed object pools with New, Get, and Put methods. This replaces direct usage of sync.Pool in internal code, improving type safety and reducing boilerplate for object reuse.

internal/pool · high confidence

Add internal color utility for TTY output

Added a new internal \color\ package that provides functionality for coloring terminal (TTY) output. The package defines a \Color\ type with constants for standard foreground colors (Black, Red, Green, Yellow, Blue, Magenta, Cyan, White) and an \Add\ method to wrap strings with ANSI escape codes. A corresponding test verifies that the color formatting produces the expected ANSI output.

internal/color · high confidence

Add structured logging benchmarks for Go 1.21 slog and other libraries

The benchmarks package now includes performance comparisons for the standard library's log/slog alongside existing comparisons for zap, apex/log, log15, logrus, and zerolog. This addition allows users to evaluate zap's performance relative to the new standard logging interface introduced in Go 1.21, as well as other popular structured logging libraries, using consistent test scenarios such as disabled logging without fields and accumulated context.

benchmarks · high confidence

Add zapgrpc compatibility wrapper for gRPC logging

The new zapgrpc package provides a Logger that adapts zap to be compatible with both the deprecated grpclog.Logger API and the newer grpclog.LoggerV2 interface. Users can now use zap as the underlying logger for gRPC by wrapping it with NewLogger, allowing gRPC to output logs through zap's structured logging capabilities while maintaining level mapping between gRPC and zap log levels.

zapgrpc · high confidence

Added internal exit stubbing for test isolation

The internal/exit package now provides a mechanism to stub os.Exit calls, allowing unit tests to verify that code paths triggering process termination do so with the expected exit code without actually terminating the running test process. This includes a With function for direct exit simulation and a StubbedExit struct that records exit state, enabling safer testing of fatal error handling.

internal/exit · high confidence

Initial release of zap structured logging library

This change introduces the initial version of zap, a high-performance, structured, leveled logging library for Go. It provides both a type-safe \Logger\ for performance-critical paths and a \SugaredLogger\ with a more familiar, loosely-typed API. The release includes comprehensive documentation, a benchmarking suite comparing zap against other logging packages, and a complete test suite.

(repo-wide) · high confidence

Internal buffer pool implementation exposed

The internal buffer pool package now exposes the \Get\ function, allowing third-party packages to retrieve buffers from the shared pool via \buffer.NewPool()\. This change enables external encoders to reuse the same buffer allocation strategy as the core library, improving memory efficiency for custom implementations.

internal/bufferpool · high confidence

Introduce buffered logging and configurable console output

The zapcore package now includes a BufferedWriteSyncer that batches log writes in memory (defaulting to 256 kB or a 30-second interval) before flushing to the underlying destination, reducing I/O overhead. A new Clock interface allows time sources to be mocked or customized, which is required for the buffered syncer's periodic flushing. Additionally, a ConsoleEncoder is provided for human-readable, plain-text log output with configurable separators, and the encoder configuration now supports custom time layouts via TimeEncoderOfLayout.

zapcore · high confidence

Introduce zapslog package for slog integration

The new \exp/zapslog\ package provides a \slog.Handler\ implementation that writes structured logs to an existing \zapcore.Core\, allowing users to adopt Go's standard \log/slog\ API while retaining Zap's performance and features. The handler supports configuring logger names, caller annotations, caller skip counts, and stack traces for specific log levels via \HandlerOption\ functions like \WithName\, \WithCaller\, and \AddStacktraceAt\. It correctly handles slog groups (including inline groups), ignores empty attributes, and maps slog levels to Zap's continuous level system.

exp/zapslog · high confidence

Introduce zaptest/observer package for testing log output

The new \zaptest/observer\ package provides an in-memory, encoding-agnostic \zapcore.Core\ that captures log entries for unit testing. It exposes \ObservedLogs\ with methods to retrieve entries (\All\, \TakeAll\, \AllUntimed\) and filter them by level, message, message snippet, logger name, or specific field keys and values. Additionally, \LoggedEntry\ now includes a \ContextMap\ method to easily inspect contextual fields as a map, simplifying assertions in tests.

zaptest/observer · high confidence

Introduce zero-allocation buffer with pooling

The \buffer\ package now provides a \Buffer\ type that wraps a byte slice and supports zero-allocation formatting for integers, floats, booleans, and times via \strconv\ methods, alongside standard \Write\/\WriteByte\/\WriteString\ implementations. Buffers are managed through a \Pool\ (backed by an internal generic pool) to minimize allocations, and include utilities like \TrimNewline\ and \Free\ for efficient reuse.

buffer · high confidence

New internal ztest package for test utilities

The internal/ztest package has been added to provide low-level helpers for testing log output. This includes a MockClock for controlling time in tests, timeout scaling via the TEST\_TIMEOUT\_SCALE environment variable, and various WriteSyncer implementations (Buffer, Discarder, FailWriter, ShortWriter) to facilitate assertions on log writes.

internal/ztest · high confidence

New zapio.Writer for logging io.Writer output

The zapio package now includes a Writer type that implements the io.Writer interface, allowing users to direct output from libraries expecting an io.Writer (such as os/exec) directly into a Zap logger. The Writer buffers data until it encounters a newline or is explicitly closed/synced, splitting multi-line output into individual log entries at the configured log level.

zapio · high confidence

Architecture

Internal stack trace capture and formatting moved to dedicated package

Stack trace capturing and formatting logic has been moved into a new internal \stacktrace\ package. This change introduces efficient stack trace gathering with resource pooling and a formatter for readable output, along with comprehensive tests to verify correct frame capture and skipping behavior.

internal/stacktrace · high confidence

Behavioural changes

Automated README generation with sorted benchmark comparisons

The internal tool for generating the project README has been rewritten to automatically execute Go benchmarks, parse the results, and render them into a Markdown table using a template. The generated table now includes performance metrics for multiple logging libraries (including standard library, logrus, go-kit, log15, apex/log, zerolog, and slog) and sorts the entries by execution time to highlight the fastest implementations. This change replaces manual maintenance of benchmark data with a dynamic, code-driven process that ensures the documentation always reflects current performance characteristics.

internal/readme · high confidence

Internal LeveledEnabler interface added to break cyclic dependencies

An internal LeveledEnabler interface has been introduced in the internal package to allow non-zapcore packages and tests to check a logger's level without creating a cyclic dependency on the zapcore package. This interface embeds zapcore.LevelEnabler and adds a Level() method, providing a convenient way for internal consumers to determine the effective log level.

internal · high confidence

zaptest package restructured with new test logger and public TestingWriter

The zaptest package has been reorganized to provide a dedicated test logger and public writer utilities. NewLogger now builds a \*zap.Logger that writes to the testing.TB, defaulting to debug level and supporting configuration via Level and WrapOptions. The previously internal TestingWriter is now public, allowing users to create custom log cores that write to test output. Additionally, the package includes aliases for internal test helpers (Syncer, Discarder, FailWriter, ShortWriter, Buffer) and deprecated timeout utilities.

zaptest · high confidence

Test coverage

Added integration tests for zapgrpc LoggerV2 support

Added a new test submodule under zapgrpc/internal/test that verifies zapgrpc correctly implements the grpclog.LoggerV2 interface. The new test ensures that log messages emitted by gRPC are captured and validated by Zap's observer, confirming that the integration between the two logging systems functions as expected without requiring a direct dependency on grpc-go in the main Zap package.

zapgrpc/internal · high confidence

Dependencies

Update Go dependencies and module configurations

This change updates the Go module definitions and dependency manifests across the project, including the main module, benchmarks, experimental packages, and internal test suites. Key updates include upgrading \github.com/stretchr/testify\ to v1.12.1, \go.uber.org/goleak\ to v1.3.0, \go.uber.org/multierr\ to v1.10.0, and \go.yaml.in/yaml/v3\ to v3.0.5. The benchmarks module now includes specific versions for comparison libraries like \github.com/rs/zerolog\ v1.30.0 and \github.com/sirupsen/logrus\ v1.9.3, while the internal test module updates \google.golang.org/grpc\ to v1.83.2. The Go language directive is set to 1.19 or 1.21.5 depending on the module scope.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 64 → 71 (+7.2)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 94 → 96 (+1.5)
  • Architecture 100 → 98 (-2.4)
  • Maturity 54 → 55 (+0.6)
  • Readiness 79 → 97 (+17.6)
  • Security 57 → 74 (+17.2)

Resolved (14)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (12 lines × 2) (zapcore/error.go)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: GO-2026-5024 (tools/go.mod)
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • Test reliability not included
  • The 'Development Status: Stable' badge is present but no release history or changelog is shown, even though the outline lists it. (README.md)

New (19)

  • Dependency advisory scan runs only on code events
  • Duplicated block (13 lines × 2) (zapcore/error.go)
  • FunctionTooLong: zap.Any (field.go)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No ADRs found
  • Off-boarding risk: anonymized user #1
  • Outdated: github.com/rs/zerolog
  • Outdated: github.com/sirupsen/logrus
  • Outdated: go.uber.org/multierr
  • TodoComment (exp/zapslog/handler.go)
  • TodoComment (zapcore/encoder.go)
  • TodoComment (zapcore/encoder.go)

Changes since last survey

  • 12 commits — 9 feature/other, 3 fixes

By area

  • (root) — 6 commits
  • .github/workflows — 4 commits
  • exp/zapslog — 1 commit
  • zapgrpc/internal — 1 commit

Notable commits

  • fix: fix(zapslog): return the receiver from WithGroup("") (#1591)
  • fix: fix: accept parameters in AtomicLevel form content types (#1587)
  • fix: fix: validate Level before opening sinks in Config.Build (#1589)
  • change: build(deps): bump actions/checkout from 4 to 7 (#1577)
  • change: build(deps): bump actions/setup-go from 5 to 7 (#1578)
  • change: build(deps): bump codecov/codecov-action from 5 to 7 (#1579)
  • change: build: install govulncheck via official action, drop tools module (#1580)
  • change: chore(deps): github.com/stretchr/testify v1.12.1 (#1570)
  • change: chore(lint): migrate to golangci-lint v2 (#1573)
  • change: chore: bump zapgrpc/internal/test deps (#1581)
  • change: ci: test on Go 1.27, drop 1.25 (#1574)
  • change: test: add sub-millisecond and negative timestamp test cases to TestTimeToMillis (#1568)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

uber-go/zap was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 4892335e05f14bce8a98a69a577fcf3844a42623 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-5f8d0eb43fd7.