Skip to content
CAI
Software that uses CAICheck a score

caolan/async

61.2

Adequate · 25 September 2026

7.3k

lines of production code

JavaScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the Async library, a JavaScript utility for managing asynchronous control flow and data processing. It provides a suite of functions for parallel execution, waterfall sequencing, and queue management, supporting both callback-based and modern Promise/async-await patterns. The codebase is structured as a modular ES library that compiles into UMD and ES module bundles for broad environment compatibility.

How it got here

2010 — Build tooling modernization and distribution

4 changes.

The project modernized its development environment by replacing legacy tools with ESLint, Babel, and Mocha, while removing the nodeunit dependency. This period also established a standardized build process via a Makefile and produced the initial distribution bundles for browser and Node.js integration.

2015 — Async library v3 rewrite

4 changes.

The codebase underwent a comprehensive rewrite for version 3, migrating to ES modules and introducing awaitable methods that return Promises. This modernization included internal refactoring with modern data structures and the addition of new control flow utilities. A new performance benchmarking suite and automated build verification infrastructure were also implemented to support the updated architecture.

2016–2018 — Build modernization and documentation overhaul

8 changes.

The project refactored its build system to support ES modules and UMD bundles using Rollup and Babel, enabling flexible module consumption. Simultaneously, the documentation was redesigned with the Minami theme, Bootstrap 3, and client-side search to improve usability and navigation. Test coverage was expanded to include core utilities and ES2017 async features, ensuring robustness for modern JavaScript environments.

Features

Add OpenSans webfont files to JSDoc theme

The JSDoc documentation theme now includes the OpenSans-Bold and OpenSans-BoldItalic SVG webfont files in its static assets directory, ensuring consistent typography for generated documentation pages.

support/jsdoc/theme/static · high confidence

Added Minami JSDoc theme support

The project now includes the Minami theme for JSDoc 3 documentation generation. This change adds the theme's source files, including the main publish script, configuration, and assets, along with its Apache 2.0 license and README documentation. Users can now utilize this clean, responsive template when generating API documentation for the project.

support/jsdoc/theme · high confidence

Added logo assets in SVG, AI, and PDF formats

The \logo\ directory now includes the project logo in multiple formats: a vector SVG (\async-logo.svg\), an editable Adobe Illustrator file (\async-logo.ai\), and a PDF version. These files provide the brand asset in scalable and editable formats for use in documentation, web headers, and design workflows.

logo · high confidence

Added performance benchmarking suite

A new performance testing infrastructure has been added to the \perf\ directory, allowing users to benchmark the library's execution speed. This includes a main runner script (\benchmark.js\) that compares specific library versions (e.g., a git tag against the current working version) using the \Benchmark\ library, with support for filtering tests via grep/reject options. The suite defines specific benchmarks for core functions such as \each\, \map\, \filter\, \concat\, and \eachOf\ across various input sizes (10, 300, 10000) in \suites.js\, and includes a separate memory usage test (\memory.js\) for waterfall operations.

perf · high confidence

Initial release of the async library distribution bundle

The \dist\ directory now contains the built \async.js\ and \async.min.js\ files, providing the complete library for browser and Node.js environments. This bundle exposes the full suite of asynchronous control flow functions (such as \parallel\, \waterfall\, \queue\, and \map\), utility helpers (like \asyncify\ and \memoize\), and the default export object, enabling users to integrate the library directly via script tags or module loaders.

dist · high confidence

Architecture

Modernized build tooling and project configuration

The project has introduced a standardized development environment by adding configuration files for ESLint (.eslintrc.json), Babel (.babelrc), EditorConfig (.editorconfig), and Git (.gitignore, .gitattributes). A comprehensive Makefile has been added to manage linting, testing, and building distribution bundles (UMD and ES modules). Additionally, legacy tooling has been removed, including the old test runner (test.js) and the nodeunit git submodule, in favor of the new ESLint and Mocha-based setup.

(repo-wide) · high confidence

Behavioural changes

Async library v3 rewrite with ES modules and awaitable methods

The \lib\ directory has been completely rewritten for version 3, migrating the codebase to ES modules (\.js\ files with \export default\) and introducing awaitable methods that return Promises when no callback is provided. This change adds new control flow utilities such as \cargoQueue\, \autoInject\, and \doUntil\, while updating existing functions like \asyncify\ to support ES2017 async functions and \auto\ to use Kahn's algorithm for cycle detection. The library now standardizes on \awaitify\ wrappers for promise support and includes internal helpers like \wrapAsync\ and \initialParams\ to handle modern function signatures.

lib · high confidence

Build system refactored to support ES modules and UMD bundles

The build process has been restructured to decouple module compilation from bundling, introducing separate scripts for compiling individual modules and aggregating them into final bundles. This change enables the generation of both ES module (\.mjs\) and UMD (\async.js\) formats from the same source, replacing the previous single-output approach. The new build pipeline uses Rollup for bundling and Babel for transpilation, allowing consumers to choose the module format that best fits their environment.

support/build · high confidence

Documentation theme updated to Minami with Bootstrap 3 and CDN assets

The JSDoc documentation theme has been replaced with the Minami theme, introducing a Bootstrap 3-based layout with a fixed navbar, scroll-spy navigation, and an autofocus search input. The visual presentation now uses the Tomorrow Night syntax highlighting style for code blocks and Montserrat fonts. Assets such as Bootstrap, jQuery, Ionicons, and Prettify are loaded via jsDelivr CDN, and the navigation includes a version dropdown for v3.0.x, v2.6.2, and v1.5.x, along with links to the changelog and GitHub.

support/jsdoc/theme/tmpl · high confidence

Internal refactoring to ES modules and modern data structures

The internal implementation has been rewritten using ES modules and modern JavaScript features. Queues now use a custom DoublyLinkedList for improved performance, and priority queues use a binary heap. The codebase now supports ES2015 iterators and async generators, and many internal functions are now awaitable (returning promises when no callback is provided).

lib/internal · high confidence

The documentation generation pipeline has been restructured to produce a modern, single-page-style documentation experience. A new JSDoc plugin automatically injects ES6 import examples into method comments, while post-processing scripts consolidate individual module pages into a single 'docs.html' view with a unified table of contents and Bootstrap scroll-spy for navigation. The site now features a client-side search bar powered by Bloodhound that indexes methods, source files, and GitHub issues, along with a fixed header and improved styling for better readability.

support/jsdoc · high confidence

Test coverage

Added test coverage for ES2017 async features; Automated index generation and build verification infrastructure; Expanded test coverage for async library functions.

Dependencies

Removal of nodeunit dependency

The nodeunit submodule has been removed from the project dependencies. This change eliminates the nodeunit testing framework from the codebase, likely as part of a migration to a different testing solution or to reduce external dependencies.

deps · high confidence

Update development dependencies and lockfile for Async 3.2.6

The project's development tooling has been updated to support the 3.2.6 release, including a new package-lock.json and refreshed package.json. Key upgrades include Babel core to 7.29.0, ESLint parser to 7.28.6, Rollup to 4.2.0, and Yargs to 18.0.0. Additionally, security overrides have been added for elliptic and browserify-sign to address known vulnerabilities.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 46 → 61 (+15.1)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 54 → 64 (+9.7)
  • Architecture 93 (new)
  • Maturity 62 → 55 (-7.1)
  • Readiness 32 → 72 (+39.7)
  • Security 75 → 63 (-12.5)

Resolved (63)

  • Change coupling: applyEach.js ↔ initialParams.js (lib/internal/applyEach.js)
  • Change coupling: constant.js ↔ initialParams.js (lib/constant.js)
  • Change coupling: initialParams.js ↔ memoize.js (lib/internal/initialParams.js)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Dimension evaluation failed
  • Documentation for whilst.js is clipped mid-sentence, so the next function body and callback details are not visible. (docs/v3/whilst.js.html)
  • FileTooLong: theme/publish.js (support/jsdoc/theme/publish.js)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • …and 43 more

New (106)

  • (anonymous) (cognitive 16) (support/jsdoc/jsdoc-custom.js)
  • (anonymous) (cognitive 18) (lib/internal/eachOfLimit.js)
  • (anonymous) (cyclomatic 16) (lib/internal/eachOfLimit.js)
  • Concentrated knowledge decay
  • Coverage not measured — JavaScript/TypeScript suite
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (the committed lockfile resolved no direct production dependency)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • FunctionTooLong: auto.auto (lib/auto.js)
  • FunctionTooLong: queue.queue (lib/internal/queue.js)
  • Further sole-owners (lower concentration)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • …and 86 more

Changes since last survey

  • 21 commits — 15 feature/other, 6 fixes

By area

  • (root) — 10 commits
  • .github/workflows — 4 commits
  • docs/v3 — 2 commits
  • lib/timeout.js — 2 commits
  • lib/autoInject.js — 1 commit
  • lib/internal — 1 commit
  • lib/tryEach.js — 1 commit

Notable commits

  • fix: fix(autoInject): eliminate O(n²) stripComments and regex stack overflow (#2076)
  • fix: fix: clear timeout before invoking the callback (#2082)
  • fix: fix: override elliptic and browserify-sign to patch crypto CVEs (#2081)
  • fix: fix: preserve falsy timeout info (#2085)
  • fix: fix: propagate async iterator errors from tryEach (#2083)
  • fix: fix: recheck queue state before emitting deferred drain (#2086)
  • change: build(deps): bump actions/checkout from 5 to 6 (#2063)
  • change: build(deps): bump actions/setup-node from 5 to 6 (#2056)
  • change: build(deps): bump coverallsapp/github-action from 2.3.6 to 2.3.7 (#2062)
  • change: build(deps): bump styfle/cancel-workflow-action from 0.12.1 to 0.13.0 (#2069)
  • change: build(deps-dev): bump @babel/core from 7.28.3 to 7.29.0 (#2071)
  • change: build(deps-dev): bump @babel/eslint-parser from 7.28.0 to 7.28.6 (#2070)
  • change: build(deps-dev): bump babel-plugin-istanbul from 7.0.0 to 7.0.1 (#2054)
  • change: build(deps-dev): bump cheerio from 1.1.2 to 1.2.0 (#2072)
  • change: build(deps-dev): bump fs-extra from 11.3.1 to 11.3.3 (#2068)
  • change: build(deps-dev): bump jsdoc from 4.0.4 to 4.0.5 (#2061)
  • change: build(deps-dev): bump rollup from 4.50.0 to 4.57.1 (#2073)
  • change: build(deps-dev): bump semver from 7.7.2 to 7.7.3 (#2058)
  • change: docs: add missing changelog entry for v3.2.6 (#2077)
  • change: docs: clarify series cancellation behavior (#2084)
  • …and 1 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

caolan/async was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit c2ba6566f12c5cf5a6e421eb74138db558d05e36 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-dd72cc24c749.