Skip to content
CAI
Software that uses CAICheck a score

wojtekmach/req

60.5

Adequate · 23 September 2026

7.8k

lines of production code

Elixir

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the Req HTTP client library for Elixir, providing a high-level, composable API for making HTTP requests. It features a modular step-based architecture that handles authentication, compression, decoding, and error management, with built-in support for streaming large responses. The library abstracts underlying HTTP transports via an adapter behavior, defaulting to Finch, and includes comprehensive tooling for testing concurrent and stateful client behavior.

Features

Added example scripts for OpenAI streaming and reverse proxying

New Livemd example files have been added to the examples directory. The openai.livemd file demonstrates how to use Req to stream chat completions from the OpenAI API, handling chunked responses and usage statistics. The reverse\_proxy.livemd file provides a complete example of building a reverse proxy using Req and Bandit, showing how to stream request and response bodies between a client and an upstream server.

examples · high confidence

Behavioural changes

Redesigned high-level API with new request struct and streaming support

The \Req\ module has been completely redesigned to serve as the high-level API, built on top of a new \Req.Request\ struct and a modular step system (\Req.Steps\). This change introduces a new \Req.new/1\ function for building requests and adds dedicated functions for HTTP methods (\Req.get/2\, \Req.post/2\, etc.). A key behavioral change is the introduction of response body streaming via the \Req.stream/4\ function and the \:into\ option, allowing users to handle large responses as enumerables or stream directly to a collectable. The module documentation has also been expanded to cover these new capabilities, including header handling and connection options.

lib · high confidence

Req v0.8 introduces streaming, step wrappers, and modular step modules

Req v0.8 requires Elixir 1.18+ and brings ergonomic streaming via \Req.stream/4\, request body streaming with \body: fun\, and automatic NDJSON & SSE decoding. Internally, the library replaces legacy steps (such as \compressed\, \auth\, \redirect\, \retry\, \decode\_body\, \handle\_http\_errors\, and \checksum\) with dedicated modules (\Req.Decompress\, \Req.Auth\, \Req.Redirect\, \Req.Retry\, \Req.Decode\, \Req.Expect\, \Req.Checksum\) and introduces step wrappers to support extensible streaming decoding. This release also removes the \jason\ dependency in favor of the \JSON.Encoder\ protocol, deprecates \into: fun\ in favor of \Req.stream/4\, and adds support for setting private options and inspecting the final request via \resp.request\.

(repo-wide) · high confidence

Req v0.9 redesign: new step-based architecture and API

The library has been redesigned around a composable step-based architecture, replacing the previous monolithic request flow with dedicated modules for each concern. Authentication is now handled by \Req.Auth\ (supporting basic, bearer, digest, and netrc), while response handling is split into \Req.Decompress\ (for gzip, brotli, zstd) and \Req.Decode\ (for JSON, NDJSON, SSE, and opt-in archive/CSV formats). Error handling is managed by \Req.Expect\ (replacing \:http\_errors\) and \Req.Checksum\ (for body integrity). The HTTP transport is abstracted via the \Req.Adapter\ behaviour with \Req.Finch\ as the default, and the API now uses \Req.Request\ for building requests and \Req.Response\ for results, introducing options like \:decoders\, \:compressed\, and \:expect\.

lib/req · high confidence

Test environment logger configuration added

A new configuration file for the test environment has been introduced to customize the logger output. Specifically, the logger formatter is set to a simplified plain-text format without color codes when running in the :test environment, ensuring cleaner and more readable test logs.

config · high confidence

Test coverage

Added comprehensive test suite for Req core modules; Added documentation, integration, and unit tests for the Req library; Added test helpers for process ownership tracking; Added test support infrastructure for HTTP adapters and testing.

Dependencies

Upgrade to Req 0.8.0-rc.0 with Elixir 1.18 and Finch 0.21

This release bumps the minimum Elixir requirement to 1.18 and updates the Finch HTTP adapter dependency to version 0.21. The project also drops the Jason dependency in favor of Elixir's built-in JSON support, adds optional support for NimbleCSV and Brotli compression, and introduces new test dependencies including Bandit and AWS Signature. The lockfile reflects these changes with updated versions for core libraries like Plug (1.16.1), Mint (1.8.0), and Telemetry (1.4.2).

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 60 → 61 (+0.8)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 95 → 95 (+0.2)
  • Architecture 100 → 100 (-0.2)
  • Maturity 58 → 39 (-18.6)
  • Readiness 50 → 66 (+16.8)
  • Security 65 → 90 (+24.8)

Resolved (30)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • Duplicated block (13 lines × 3) (lib/req/brotli.ex)
  • Duplicated block (15 lines × 2) (lib/req/gzip.ex)
  • Duplicated block (17 lines × 2) (lib/req/gzip.ex)
  • Duplicated block (5 lines × 2) (lib/req/request.ex)
  • Duplicated block (5 lines × 2) (lib/req/utils.ex)
  • FileTooLong: req/request.ex (lib/req/request.ex)
  • FileTooLong: req/steps.ex (lib/req/steps.ex)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 10 more

New (56)

  • Decode.decode_stream (cyclomatic 18) (lib/req/decode.ex)
  • Decompress.decompress_stream (cognitive 21) (lib/req/decompress.ex)
  • Decompress.decompress_stream (cyclomatic 18) (lib/req/decompress.ex)
  • Documentation: no installation or build instructions (README.md)
  • Duplicated block (15 lines × 2) (lib/req.ex)
  • Duplicated block (18 lines × 2) (lib/req/gzip.ex)
  • Duplicated block (18 lines × 3) (lib/req/brotli.ex)
  • Duplicated block (5 lines × 2) (lib/req/utils.ex)
  • Duplicated block (5 lines × 3) (lib/req/decode.ex)
  • Duplicated block (9 lines × 4) (lib/req/finch.ex)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 36 more

Changes since last survey

  • 72 commits — 65 feature/other, 7 fixes

By area

  • lib/req — 41 commits
  • (root) — 13 commits
  • test/req — 10 commits
  • lib/req.ex — 3 commits
  • test/test_helper.exs — 2 commits
  • examples/openai.livemd — 1 commit
  • test/docs_test.exs — 1 commit
  • test/httpbin_test.exs — 1 commit

Notable commits

  • fix: Fix retry-after header delay docs from seconds to milliseconds (#563)
  • fix: Revert "Add Req.CSV decoding to %Req.CSV{}"
  • fix: Revert "Req.Tar: decode to %Req.Tar{}"
  • fix: Revert "Req.ZIP: decode to %Req.ZIP{}"
  • fix: Revert "Support decoders: [{format, options}]"
  • fix: Revert "Treat binary/octet-stream as application/octet-stream"
  • fix: Revert "encode_body: Automatically change GET to POST when request body is set (#494)"
  • change: :cont -> :ok
  • change: Add Req.CSV decoding to %Req.CSV{}
  • change: Add Req.Into
  • change: Add Req.NDJSON
  • change: Add Req.SSE
  • change: Add Req.Tar and Req.ZIP tests
  • change: Add examples/openai.livemd, examples/reverse_proxy.livemd
  • change: Add internal Req.prepare(req, options \\ [])
  • change: Add missing test for decompressing into: collectable
  • change: Add test/readme_test.exs
  • change: Bump server_sent_events requirement
  • change: Delegate Req.Steps.auth,handle_http_digest to Req.Auth
  • change: Delegate Req.Steps.checksum,verify_checksum to Req.Checksum
  • …and 52 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

wojtekmach/req was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 58e94146b446205a4db2ebcacbe8e918fc691a6a — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.