Skip to content
CAI
Software that uses CAICheck a score

urfave/cli

67.4

Adequate · 24 September 2026

6.3k

lines of production code

Go

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the urfave/cli v3 library, a Go-based framework for building command-line interfaces. It provides core functionality for defining CLI commands and flags, along with features for generating shell autocompletion scripts and producing formatted documentation in Markdown and man-page formats. The project also includes tooling for managing builds, testing, and validating example code.

Features

Add shell completion scripts for Bash, Zsh, Fish, and PowerShell

Users can now enable command-line autocompletion for the application in Bash, Zsh, Fish, and PowerShell environments. The new scripts in the autocomplete directory generate completions dynamically by invoking the application's \--generate-shell-completion\ flag, supporting both subcommands and flags with optional descriptions where available.

autocomplete · high confidence

Added example programs for binary size checking

New example programs have been added to the examples directory to serve as benchmarks for binary size analysis. This includes a minimal CLI example using the urfave/cli/v3 library and a basic hello-world program, both located in their respective subdirectories within examples/.

examples · high confidence

Initial project scaffolding and configuration

This change introduces the foundational project structure for the urfave/cli v3 library. It adds essential configuration files including a .gitignore, a .golangci.yaml linter configuration (enabling gofumpt, makezero, and misspell), and a Makefile to streamline build, test, and documentation workflows. It also includes the MIT LICENSE, a CODE\_OF\_CONDUCT.md, and an updated README.md that documents the library's features and links to the new v3 documentation site.

(repo-wide) · high confidence

Behavioural changes

New build script with gfmrun counter fix

A new build script (scripts/build.go) has been introduced to manage project tasks, including vetting, testing, and documentation generation. This script includes a fix to align the gfmrun example counter with the actual number of runnable examples, ensuring accurate validation of markdown content.

scripts · high confidence

Test coverage

Updated test fixtures for v3 documentation and shell completion generation

The testdata directory has been refreshed with new expected output files to validate the v3 documentation and completion features. This includes new markdown and man-page templates (e.g., \expected-doc-full.md\, \expected-doc-full.man\) that now include command descriptions, usage text, and global options, alongside tabular markdown variants (\expected-tabular-markdown-full.md\) that present flags in tables with environment variables. Additionally, new fish shell completion scripts (\expected-fish-full.fish\) are added to verify command and flag completion logic, and the \godoc-v3.x.txt\ baseline has been updated to reflect the current v3 API surface.

testdata · high confidence

Dependencies

Introduce Go modules and update dependencies

The project now uses Go modules, declaring a minimum Go version of 1.22 in the root go.mod and introducing a separate go.mod for the docs subdirectory (requiring Go 1.23.2). Dependencies have been updated: the root module requires github.com/stretchr/testify v1.12.1 and go.yaml.in/yaml/v3 v3.0.5, while the docs module requires github.com/urfave/cli/v3 v3.1.1, github.com/urfave/cli-altsrc/v3 v3.0.1, github.com/BurntSushi/toml v1.5.0, github.com/stretchr/testify v1.11.1, and gopkg.in/yaml.v3 v3.0.1.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 63 → 67 (+4.0)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 83 → 88 (+4.2)
  • Architecture 100 → 99 (-1.2)
  • Maturity 57 → 53 (-3.4)
  • Readiness 66 → 79 (+13.2)
  • Security 62 → 76 (+13.5)

Resolved (18)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (command_run.go)
  • Duplicated block (12 lines × 2) (command_setup.go)
  • Duplicated block (12 lines × 2) (flag_ext.go)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Medium CVE: GO-2025-3503 (go.mod)
  • No exposed public API
  • Test reliability not included
  • The New Names section lists cli.App.EnableBashCompletion but the corresponding v2 code example shows BashComplete instead of ShellComplete; this is a one-line change that needs to be verified in the migration guide. (docs/migrate-v2-to-v3.md)

New (41)

  • Command.VisiblePersistentFlags (cognitive 18) (command.go)
  • Documentation: no architecture or design documentation (docs/index.md)
  • Documentation: no installation or build instructions (README.md)
  • Duplicated block (12 lines × 2) (flag_ext.go)
  • Duplicated block (18 lines × 2) (command_setup.go)
  • Duplicated block (6 lines × 2) (command_run.go)
  • Duplicated block (8 lines × 2) (flag_int.go)
  • FixmeComment (help_test.go)
  • FixmeComment (help_test.go)
  • FlagBase.PostParse (cognitive 16) (flag_impl.go)
  • HackComment (flag_slice_base.go)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 21 more

Changes since last survey

  • 87 commits — 54 feature/other, 33 fixes

By area

  • (root) — 43 commits
  • (repo) — 41 commits
  • docs/v3 — 2 commits
  • testdata/godoc-v3.x.txt — 1 commit

Notable commits

  • fix: Fix a year-less timestamp layout losing January 1
  • fix: Fix index out of range panic when Run is given no arguments
  • fix: Fix inverse bool flag counting with an external counter
  • fix: Fix nil pointer dereference for interface-typed flag values
  • fix: Merge branch 'main' into fix-bare-dash-keeps-following-args
  • fix: Merge branch 'main' into fix-mutex-flags-stringer
  • fix: Merge branch 'main' into fix/1993-urfave
  • fix: Merge branch 'main' into fix/hide-help-command-inheritance
  • fix: Merge pull request #2388 from vidigoat/fix/hidden-flag-completion
  • fix: Merge pull request #2395 from utkarshalpha/fix/hide-help-command-inheritance
  • fix: Merge pull request #2400 from mrueg/fix/nil-deref-interface-typed-flags
  • fix: Merge pull request #2401 from mrueg/fix/panic-on-empty-osargs
  • fix: Merge pull request #2403 from fzlzjerry/fix/2402-bool-inverse-default-text
  • fix: Merge pull request #2412 from dearchap/fix/1993-urfave
  • fix: Merge pull request #2414 from SHIVANSHGARG07/fix-mutex-flags-stringer
  • fix: Merge pull request #2419 from official-burak/fix-bare-dash-keeps-following-args
  • fix: Merge pull request #2421 from justadityaraj/fix/show-inherited-persistent-flags
  • fix: Merge pull request #2426 from fzlzjerry/fix/2248-partial-flags-after-positional-args
  • fix: Merge pull request #2432 from jakezwang/fix/inverse-bool-external-count
  • fix: Merge pull request #2434 from znnnnnnn-wil/fix/2433-unicode-flag-runes
  • …and 67 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

urfave/cli was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit d1d810845dbc6b7074c159f2ebb9bbb7a91619b6 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-5f8d0eb43fd7.