Skip to content
CAI
Software that uses CAICheck a score

charmbracelet/glow

67.3

Adequate · 24 September 2026

3.5k

lines of production code

Go

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Glow is a command-line tool and terminal user interface for rendering Markdown files. It provides a modern, feature-rich experience by replacing legacy rendering with Glamour v2, enabling support for local files, remote sources, and stdin. The system includes a TUI for browsing and editing documents, along with configuration management and terminal-specific enhancements like text sizing.

Features

Add support for Kitty terminal text sizing on headings

The application now automatically scales Markdown headings (H1, H2, H3) in terminals that support the Kitty text sizing protocol (OSC 66). This feature is enabled by default when the terminal is detected as compatible, or can be explicitly controlled via the GLOW\_TEXT\_SIZING environment variable. Headings with background colors are excluded from scaling to prevent rendering artifacts. This capability is implemented in the utils package, which now includes text size detection, marker injection into style configurations, and the application of scaling sequences to rendered output.

utils · high confidence

Glow v3: Complete rewrite with TUI, config management, and Glamour v2 integration

Glow has been rewritten for v3, replacing the previous Blackfriday-based rendering with Glamour v2 to provide a modern, feature-rich Markdown experience. This release introduces a full Text User Interface (TUI) for browsing local Markdown files, a new \glow config\ command for managing settings (style, width, pager, mouse support), and support for reading from stdin, local directories, and remote sources (GitHub, GitLab, and arbitrary HTTP URLs). The CLI now uses Cobra for robust command-line handling, includes shell completion and man page generation, and supports Windows ANSI colors. The default rendering width is set to 80 characters, and the application automatically detects terminal background colors to select appropriate styles.

(repo-wide) · high confidence

Introduce new TUI with Bubble Tea and Bubbles v2

The terminal user interface has been rewritten using the Charm ecosystem (Bubble Tea v2, Bubbles v2, Glamour v2, Lip Gloss v2). This new UI introduces a tabbed file listing view for browsing local, stashed, and news documents, a pager for viewing and editing markdown files, and a dedicated stash browser. It supports fuzzy filtering, line numbers, custom glamour styles, and a raw terminal painter for high-performance rendering with text sizing support.

ui · high confidence

Dependencies

Upgrade to Go modules v3 with updated dependencies

The project has been initialized as module charm.land/glow/v3 with Go 1.26.6, introducing a comprehensive set of dependency updates. Key upgrades include Charm ecosystem libraries (bubbletea v2.0.8, bubbles v2.1.1, glamour v2.0.1, lipgloss v2.0.6), configuration tools (viper v1.21.0, cobra v1.10.2), and system libraries (golang.org/x/term v0.43.0, golang.org/x/sys v0.47.0, golang.org/x/text v0.39.0).

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 65 → 67 (+2.0)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 85 → 88 (+3.4)
  • Architecture 100 → 100 (-0.3)
  • Maturity 57 → 52 (-4.2)
  • Readiness 71 → 78 (+7.4)
  • Security 67 → 77 (+10.2)

Resolved (13)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (12 lines × 2) (github.go)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: GO-2026-5024 (go.mod)
  • Medium IaC: CKV_DOCKER_7 (Dockerfile)
  • No exposed public API
  • Test reliability not included
  • pagerModel.update (cognitive 26) (ui/pager.go)

New (44)

  • Dependency advisory scan runs only on code events
  • Duplicated block (14 lines × 2) (github.go)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Hotspot: main.go (main.go)
  • Hotspot: ui/pager.go (ui/pager.go)
  • Hotspot: ui/stash.go (ui/stash.go)
  • Hotspot: ui/ui.go (ui/ui.go)
  • Medium CVE: GO-2026-5942 (go.mod)
  • …and 24 more

Changes since last survey

  • 8 commits — 6 feature/other, 2 fixes

By area

  • (root) — 5 commits
  • .github/dependabot.yml — 1 commit
  • .github/workflows — 1 commit
  • ui/stash.go — 1 commit

Notable commits

  • fix: chore: fix govuln, ruleguard (#1030)
  • fix: fix: adaptive document(s) (#998)
  • change: chore(deps): bump lipgloss to v2.0.6 (#1011)
  • change: chore(deps): bump the all group with 3 updates (#1013)
  • change: chore(v3): prepare v3 (#1009)
  • change: chore: bump bubbletea to v2 (#1002)
  • change: ci: sync dependabot config (#1012)
  • change: feat: text sizing protocol for headers (#1029)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

charmbracelet/glow was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 6b365eea95f7541d4af441d971010b09f6082a0e — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-5f8d0eb43fd7.