Actix Web is a powerful, pragmatic, and extremely fast web framework for Rust.
This week focused on WebSocket protocol correctness and maintainability. Several RFC 6455 compliance gaps were fixed: the library now returns 426 Upgrade Required for unsupported WebSocket versions, validates the Sec-WebSocket-Key nonce properly, and rejects oversized close frames. Across HTTP and…
Get this in your inbox every Monday →A deterministic 0–100 hygiene score — README, license, CI, tests, docs, and freshness.
Who ships this repo — author concentration and the bus factor across the last 300 mainline commits.
How welcoming this repo is to contributors — issue throughput, close time, responsiveness, and good-first-issue count.
What this project is built on — dependency count by ecosystem, the license mix, and anything worth a legal look before you adopt it.
Whether this project's CI can be trusted — pass rate, run times, flaky runs, and which workflow is the weak link.
Grounded in actix-web's README, structure, and recent commits — answers won't invent code they haven't seen.
A Monday email with what shipped, in plain English — no account needed.
Showing raw commit titles for the newest commits. Sign in to generate AI summaries.
refactor(http): replace HTTP/1.1 framing and encoder magic numbers with named constants (#4293)
fix(ws): return 426 Upgrade Required on unsupported version (RFC 6455 §4.2.2) (#4295)
fix(ws): validate 16-byte base64 nonce in Sec-WebSocket-Key (RFC 6455 §4.2.1) (#4296)
refactor(ws): replace framing and protocol magic numbers with named constants (#4292)
build(deps): bump taiki-e/install-action from 2.87.12 to 2.87.21 (#4284)
refactor(http): replace magic slicing with named constants for Date header buffer (#4291)
A floor, not a guess: counts only commits whose author, co-author trailer, or message explicitly credits an AI tool (Claude, Copilot, Cursor, aider, Codex…). Based on 30 mainline commits. Unattributed AI code isn't counted here — the full audit estimates that separately.