apache/pouchdb
58.1
Adequate · 1 October 2026
278
lines of production code
JavaScript
primary language
2
measurements over time
What this system is
This system is PouchDB, a client-side JavaScript database designed to run in both Node.js and browser environments. It provides core data persistence capabilities alongside advanced features such as map/reduce views, full-text search via the find API, and bidirectional replication with CouchDB-compatible servers. The codebase includes extensive tooling for building, testing, and releasing the library, with a strong emphasis on verifying data consistency, performance, and memory stability across various storage adapters.
How it got here
2010–2014 — Apache incubation and test infrastructure
10 changes.
The project underwent a structural reorganization to support its transition into an Apache Software Foundation incubating project, introducing new governance files and a modernized build system. Significant effort was directed toward establishing comprehensive test coverage, including new performance benchmarks, stress tests, and integration suites for various browser environments and core database operations.
2015–2016 — Comprehensive test suite expansion
5 changes.
This period focused on significantly broadening the project's test coverage by introducing new suites for HTTP adapters, fuzzy replication, map/reduce views, capacity limits, and memory leak detection. The work established robust, deterministic, and browser-based testing infrastructure to verify core functionality and edge cases.
2017–2020 — find query test coverage
4 changes.
This period focused on expanding test coverage for the PouchDB find functionality by introducing a browser-based test runner and comprehensive test suites. The work validated query operators, sorting, and edge cases, while specifically addressing regressions related to index usage and composite index behavior.
Features
New build, release, and test automation scripts in bin/
The repository now includes a comprehensive set of new shell and Node.js scripts in the bin/ directory to manage the build, release, and testing workflows. Key additions include build-module.js and build-pouchdb.js for generating library bundles via Rollup and Browserify, a new dev-server.js for local development with live reloading, and updated test runners (test-browser.js using Playwright, test-node.sh, test-webpack.sh) to execute unit, integration, and performance tests. Release management is handled by new scripts like release.sh, publish-packages.sh, and update-package-json-for-publish.js, which automate versioning, dependency resolution, and npm publishing. Additional utilities such as verify-build.sh, verify-bundle-size.sh, and verify-dependencies.js ensure build integrity, while down-server.js and wait-for-couch.sh support test infrastructure.
bin · high confidence
Behavioural changes
Project restructured for Apache Software Foundation incubation
The repository has been reorganized to support its new status as an Apache Software Foundation (ASF) incubating project. This includes adding ASF-specific configuration files (.asf.yaml, DISCLAIMER, NOTICE, LICENSE), updating the README and CONTRIBUTING guides to reflect the new governance and community channels (such as Slack and Mastodon), and implementing a new Eleventy-based build system for the documentation website. Additionally, legacy build artifacts and configuration files (like fileserver.js) have been removed, and the project now enforces stricter code quality standards via a new ESLint configuration.
(repo-wide) · high confidence
Test coverage
Added WebSQL storage limit stress test; Added browser integration tests for database info, migration, and worker contexts; Added browser-based test for PouchDB capacity limits; Added browser-based test runner for find functionality; Added browser-based test runner for map/reduce views; Added component tests for HTTP adapter behavior and replication edge cases; Added comprehensive test suites for PouchDB find queries; Added deterministic fuzzy replication tests; Added integration test for large image handling; Added memory leak detection tests for PouchDB; Added test infrastructure for PouchDB and Sync Gateway configurations; Added tests for find queries with and without indexes (issues \#7810, \#8389); Expanded test coverage for PouchDB find queries; Expanded unit test coverage for core PouchDB utilities and modules; New performance test suite for core database operations; Standardized test environment configuration and utilities.
Dependencies
Initial monorepo dependency lockfiles and manifests
The repository now includes \package-lock.json\ and individual \package.json\ files for the monorepo structure, establishing the baseline dependency tree for version 7.0.0-prerelease. This change introduces specific runtime dependencies such as \level\ 6.0.1, \leveldown\ 6.1.1, and \node-fetch\ 2.6.9, while setting up development tooling including \mocha\ 10.8.2, \eslint\ 8.7.0, and \@11ty/eleventy\ 3.1.2 for site generation.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 53 → 58 (+5.0)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 100 → 100 (+0.0)
- Architecture 69 → 69 (+0.0)
- Maturity 50 → 50 (+0.0)
- Readiness 53 → 55 (+1.9)
- Security 48 → 69 (+20.9)
- Performance 85 (new)
Resolved (7)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no installation or build instructions (README.md)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Off-boarding risk: anonymized user #1
New (18)
- Documentation: no installation or build instructions (docs/download.md)
- Documentation: no installation or build instructions (docs/index.md)
- Documentation: no licence statement (docs/index.md)
- Documentation: no usage examples (docs/index.md)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Medium vulnerability: [GHSA redacted] (package-lock.json)
- Off-boarding risk: anonymized user #1
- Outdated (npm): execa
- Outdated (npm): fetch-cookie
- Outdated (npm): level
- Outdated (npm): level-codec
- Outdated (npm): levelup
- Outdated (npm): memdown
- Outdated (npm): node-fetch
- Outdated (npm): readable-stream
- Outdated (npm): through2
- Outdated (npm): uuid
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
apache/pouchdb was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 27de91f1105a8074ddd06f5a23156dd99c4eb016 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.