Skip to content
CAI
Software that uses CAICheck a score

coder/code-server

57.6

Adequate · 27 September 2026

4.4k

lines of production code

TypeScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is code-server, a tool that bundles the VS Code editor into a web application accessible via any modern browser. It provides a secure, remote development environment featuring authentication, reverse proxy support, and internationalization, while running as a containerized service or standalone binary. The platform supports extensive customization through plugins, custom themes, and Kubernetes deployment via Helm charts.

How it got here

2019–2020 — Infrastructure overhaul and architectural rewrite

16 changes.

This period focused on a comprehensive restructuring of the code-server project, introducing a new Nix-based development environment, modular CI/CD pipelines, and Docker/Helm deployment support. The core Node.js server and routing logic were completely rewritten using Express 5, while the VS Code integration was moved to a Git submodule for better version management. These changes established a modern, reproducible foundation for building, testing, and deploying the application across multiple platforms.

2021 — test infrastructure and CI automation

8 changes.

This period focused on establishing a robust testing framework by introducing a comprehensive Playwright-based end-to-end test suite and extensive unit tests for core node modules, routes, and utilities. Concurrently, CI pipeline capabilities were enhanced through the addition of helper scripts for Docker builds and standardized environment checks.

2022–2023 — proxy support and i18n infrastructure

4 changes.

This period focused on enhancing deployment flexibility by adding support for reverse proxy base paths and custom application names, alongside introducing node-side internationalization infrastructure. The work was complemented by expanded test coverage, including end-to-end tests for proxy URI validation and integration tests for CLI behavior.

Features

Add TypeScript definitions for httpolyglot

Added a new TypeScript declaration file for the httpolyglot library, defining the createServer function with overloads for both standard HTTP and HTTPS servers. This enables type-safe usage of the library in TypeScript projects.

typings · high confidence

Add static security and robots files, and register a service worker for PWA support

The browser distribution now includes a robots.txt file that disallows all crawling, a security.txt file providing contact and policy information for security researchers, and a service worker script. The service worker registers install, activate, and fetch event listeners to ensure the application is recognized as a Progressive Web App (PWA), although it currently does not implement specific caching or offline logic beyond the basic event handlers.

src/browser · high confidence

Added interactive CodeTour guides for development and contribution

New interactive tours have been added to help users understand the code-server architecture and start developing. The 'Contributing' tour walks through the source code structure, including the CLI parser, HTTP/WebSocket servers, plugin system, and VS Code integration. The 'Start Development' tour provides step-by-step instructions for setting up the development environment, running the server, and making changes with live reloading.

.tours · high confidence

Initial release of the code-server Helm chart

The Helm chart for code-server has been moved into the \ci/helm-chart\ directory and fully restructured, providing a comprehensive set of Kubernetes templates. This update introduces support for modern Kubernetes features, including \ingressClassName\ and Ingress v1 API compatibility, while adding configuration options for \imagePullSecrets\, \priorityClassName\, custom pod annotations, and lifecycle hooks. The deployment template now supports extra init containers, extra volume mounts (including emptyDir), and configurable liveness/readiness probes using the \/healthz\ endpoint. Additionally, the chart allows users to provide an \existingSecret\ for the password to avoid creating a new one, and includes a NOTES.txt file to guide users on accessing the application via NodePort, LoadBalancer, or ClusterIP.

ci/helm-chart, ci/helm-chart/templates · high confidence

New CI helper scripts for Docker builds and environment checks

The CI pipeline now includes two new shell scripts in the \ci/steps\ directory to standardize build and validation steps. \docker-buildx-push.sh\ automates the Docker image build and push process by invoking \docker buildx bake\ with the release configuration, assuming the version is set via an environment variable and release packages are pre-downloaded. \steps-lib.sh\ provides a shared library of utility functions (\is\_env\_var\_set\, \directory\_exists\, \file\_exists\, \is\_executable\) to simplify and unify environment and file existence checks across other CI step scripts.

ci/steps · high confidence

New CI infrastructure with shared library and local proxy

The CI system introduces a new shared build library (lib.sh) that standardizes environment detection for OS (including Alpine Linux and macOS), architecture (mapping to arm64/amd64), and VS Code targets, while also providing utilities for running build steps with a checklist and output indentation. Additionally, a Caddyfile is added to configure a local reverse proxy on port 8000, allowing development and testing by stripping version prefixes from IDE paths and forwarding requests to local services.

ci · high confidence

New common utilities for events, HTTP errors, and path normalization

The src/common module now provides foundational utilities to standardize application behavior. A new Emitter class enables asynchronous event handling with guaranteed completion tracking via promises, while the HttpError class and HttpCode enum allow endpoints to return structured HTTP responses with specific status codes and optional details. Additionally, utility functions for normalizing URLs (removing extra slashes), generating UUIDs, and pluralizing strings have been added to support consistent data handling across the application.

src/common · high confidence

New development and CI tooling scripts

The repository now includes a suite of shell scripts and a TypeScript watcher in the \ci/dev\ directory to streamline local development and continuous integration. These scripts automate documentation generation (\doctoc.sh\), icon creation with dark-mode support (\gen\_icons.sh\), and shell script linting (\lint-scripts.sh\). Installation is handled by \postinstall.sh\ and \preinstall.js\, which enforces npm usage and manages submodule dependencies. Testing is separated into dedicated scripts for unit (\test-unit.sh\), integration (\test-integration.sh\), native (\test-native.sh\), end-to-end (\test-e2e.sh\), and script (\test-scripts.sh\) tests. Additionally, \watch.ts\ provides a unified development environment that monitors source changes for code-server, VS Code, and plugins, automatically restarting the web server upon compilation.

ci/dev · high confidence

New multi-distro release Docker images with user customization and startup scripts

The release pipeline now builds and publishes code-server images based on Debian 13 (trixie), Debian 12 (bookworm), Ubuntu Focal, Ubuntu Noble, Ubuntu Resolute, Fedora 39, and openSUSE Tumbleweed, supporting both linux/amd64 and linux/arm64 architectures. These images include a pre-configured 'coder' user (UID 1000) with the fixuid tool to handle UID/GID remapping, allowing containers to run with custom user IDs via the DOCKER\_USER environment variable. Additionally, users can now place executable scripts in the \~/entrypoint.d directory to run automatically at container startup for workspace preparation.

ci/release-image · high confidence

Node-side internationalization (i18n) infrastructure introduced

The build tooling now includes a dedicated i18n module for the Node environment, initializing i18next with built-in translations for English, Chinese (Simplified), Japanese, Thai, and Urdu. This module also exposes a function to load and apply custom translation strings from a user-provided JSON file, allowing users to override or extend the default translations across all supported locales.

src/node/i18n · high confidence

Support for reverse proxy base paths and custom application names

Users can now host code-server behind a reverse proxy using a custom path (e.g., domain.tld/my/base/path) and customize the application name displayed in browser tabs. The base path patch modifies the web client server and browser resources to correctly resolve static assets, icons, and WebSocket connections relative to the proxy's path prefix, ensuring the interface loads properly when not served at the root. Additionally, the app-name patch allows the \--app-name\ CLI argument to set the \nameShort\ and \nameLong\ product configuration, which updates the title shown in the browser tab to match the user's custom identifier.

patches · high confidence

Behavioural changes

Complete architectural rewrite of the Node.js server core

The server implementation has been completely rewritten from scratch, replacing the previous codebase with a new modular structure. This change introduces a new Express-based HTTP server with separate routers for standard requests and WebSockets, a new CLI argument parser that supports YAML configuration files, and a new authentication system using Argon2 for password hashing. The update also adds a new entry point that manages parent-child process wrapping, a new heartbeat mechanism for idle timeouts, and a new editor session manager for handling file opening in existing instances.

src/node · high confidence

Redesigned login and error pages with dark mode support

The login and error pages have been completely restyled to provide a modern, consistent user interface that supports both light and dark color schemes. The new login page features a centered card layout with improved form styling, responsive design for mobile devices, and accessibility enhancements such as hidden username fields. The error page now displays a clean, centered error message with a link to return to the home page. Both pages utilize a shared global stylesheet for consistent typography and spacing, and include proper meta tags for mobile viewport and color scheme preferences.

src/browser/pages · high confidence

Refactored build and release infrastructure

The CI build process has been restructured into a modular set of scripts under ci/build. This includes dedicated scripts for compiling code-server and VS Code, bundling them into a release package with shrinkwraps for deterministic dependencies, and generating platform-specific packages (deb, rpm, tarball) via nfpm. The release now includes systemd service files for Linux, a Windows launcher, and a robust post-install script that handles Node.js version checks and dependency installation. Additionally, helper scripts for updating the VS Code submodule and Helm charts have been added.

ci/build · high confidence

Repository restructured with new development tooling and configuration files

The repository has been reorganized to support modern development workflows, introducing a Nix flake for reproducible development environments, a new ESLint flat configuration, and a Prettier configuration with specific formatting rules. A dedicated install script (install.sh) is now provided for automated installation across various operating systems, including support for remote installation via SSH. The project also standardizes Node.js version management via .node-version and .nvmrc, integrates Renovate for automated dependency updates, and establishes a formal changelog (CHANGELOG.md) and license (LICENSE) file. Additionally, the VS Code source is now managed as a Git submodule, and various ignore files (.gitignore, .dockerignore, .prettierignore) have been updated to reflect the new directory structure and build artifacts.

(repo-wide) · high confidence

Rewrite of routing architecture to Express 5

The routing layer has been completely refactored to use Express 5, replacing the previous implementation with a modular structure. This change introduces dedicated route modules for domain proxying, path proxying, health checks, login, logout, and VS Code integration, all registered through a central index. Key behavioral updates include the addition of a domain proxy feature that supports dynamic port matching via {{host}} and {{port}} placeholders, the implementation of a dedicated WebSocket error handler, and the migration of authentication and rate-limiting logic to be fully asynchronous. The login flow now correctly applies rate limiting only after failed attempts, and the system now supports skipping authentication for preflight OPTIONS requests when the skip-auth-preflight flag is enabled.

src/node/routes · high confidence

VS Code integration moved to a submodule

The VS Code codebase is now managed as a Git submodule (commit 04c0d99) within the lib directory, replacing the previous inline inclusion. This change simplifies dependency management by allowing the project to track specific VS Code versions independently.

lib · high confidence

Test coverage

Added CodeServer test model for e2e testing; Added Playwright e2e test configuration; Added integration tests for CLI help and extension installation; Added test extension for e2e proxy URI and asExternalUri validation; Added unit tests for common utilities; Added unit tests for core node modules; Added unit tests for installer and build scripts; Added unit tests for node routes; New end-to-end test suite for code-server features; New test utility library for helpers, server mocking, and environment setup.

Dependencies

Initial dependency manifests and lockfiles for code-server and test environments

This change introduces the foundational dependency management files for the project, including the root package.json, the test suite's package.json, and a test extension package definition, along with their corresponding package-lock.json lockfiles. The root manifest establishes the runtime dependencies (such as Express 5, argon2, and i18next) and development tools (like ESLint 9 and TypeScript 5), while the test manifest adds Jest, Playwright, and jsdom for testing. These files define the environment required to build, lint, and test the code-server application.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 50 → 58 (+7.4)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 86 → 88 (+2.6)
  • Architecture 80 (new)
  • Maturity 54 → 65 (+10.4)
  • Readiness 35 → 63 (+28.3)
  • Security 74 → 66 (-7.8)
  • Accessibility 47 (new)

Resolved (49)

  • Dimension evaluation failed
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (test/package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High IaC: DS-0019 (ci/release-image/Dockerfile.fedora)
  • High IaC: DS-0020 (ci/release-image/Dockerfile.opensuse)
  • High IaC: KSV-0014 (ci/helm-chart/templates/deployment.yaml)
  • High IaC: KSV-0014 (ci/helm-chart/templates/deployment.yaml)
  • High: security finding (details withheld)
  • Low CVE: [GHSA redacted] (test/package-lock.json)
  • Low CVE: [GHSA redacted] (test/package-lock.json)
  • Low CVE: [GHSA redacted] (test/package-lock.json)
  • Low IaC: KSV-0003 (ci/helm-chart/templates/deployment.yaml)
  • Low IaC: KSV-0004 (ci/helm-chart/templates/deployment.yaml)
  • Low IaC: KSV-0004 (ci/helm-chart/templates/deployment.yaml)
  • Low IaC: KSV-0011 (ci/helm-chart/templates/deployment.yaml)
  • Low IaC: KSV-0011 (ci/helm-chart/templates/deployment.yaml)
  • Low IaC: KSV-0015 (ci/helm-chart/templates/deployment.yaml)
  • …and 29 more

New (82)

  • CI installs an unverified third-party binary (.github/workflows/release.yaml)
  • Coverage not measured — JavaScript/TypeScript suite
  • FileTooLong: node/cli.ts (src/node/cli.ts)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High IaC: KSV-0014 (ci/helm-chart/templates/deployment.yaml)
  • High IaC: KSV-0014 (ci/helm-chart/templates/deployment.yaml)
  • High IaC: WD-DOCKER-0001 (ci/release-image/Dockerfile)
  • High IaC: WD-DOCKER-0001 (ci/release-image/Dockerfile.fedora)
  • High IaC: WD-DOCKER-0001 (ci/release-image/Dockerfile.opensuse)
  • High IaC: WD-DOCKER-0013 (ci/release-image/Dockerfile.fedora)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Hotspot: src/node/cli.ts (src/node/cli.ts)
  • Low IaC: KSV-0011 (ci/helm-chart/templates/deployment.yaml)
  • Low IaC: KSV-0011 (ci/helm-chart/templates/deployment.yaml)
  • Low IaC: KSV-0015 (ci/helm-chart/templates/deployment.yaml)
  • Low IaC: KSV-0015 (ci/helm-chart/templates/deployment.yaml)
  • …and 62 more

Changes since last survey

  • 63 commits — 60 feature/other, 3 fixes

By area

  • (root) — 20 commits
  • .github/workflows — 19 commits
  • ci/helm-chart — 8 commits
  • ci/build — 5 commits
  • src/node — 3 commits
  • test/package-lock.json — 3 commits
  • (repo) — 1 commit
  • .github/dependabot.yaml — 1 commit
  • ci/lib.sh — 1 commit
  • docs/helm.md — 1 commit
  • test/e2e — 1 commit

Notable commits

  • fix: Fix --idle-timeout-seconds validation being skipped (#8009)
  • fix: Fix incorrect data path being used (#7991)
  • fix: Fix the windows arms of the release build scripts (#7986)
  • change: Add --socket-fd CLI option (#7940)
  • change: Add VSCODE_OPTIONS and --vscode-option for Code flags (#1528) (#7952)
  • change: Add a windows launcher to the standalone release (#7984)
  • change: Add a windows package job to the release workflow (#7987)
  • change: Add local settings test (#7992)
  • change: Bump @humanfs/node from 0.16.7 to 0.16.8 (#7979)
  • change: Bump aquasecurity/trivy-action to latest (#7966)
  • change: Bump brace-expansion (#7958)
  • change: Bump brace-expansion from 1.1.11 to 1.1.18 in /test (#7957)
  • change: Bump browserslist from 4.24.0 to 4.28.9 in /test (#7988)
  • change: Bump docker/setup-buildx-action from 4.1.0 to 4.3.0 (#7995)
  • change: Bump docker/setup-qemu-action from 4.1.0 to 4.3.0 (#7969)
  • change: Bump docker/setup-qemu-action from 4.1.0 to 4.3.0 (#7994)
  • change: Bump dorny/paths-filter from 4.0.1 to 4.0.3 (#8000)
  • change: Bump github/codeql-action/analyze from 4.37.6 to 4.37.9 (#8001)
  • change: Bump github/codeql-action/autobuild from 4.37.6 to 4.37.8 (#7974)
  • change: Bump github/codeql-action/init from 4.37.8 to 4.37.9 (#7999)
  • …and 43 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

coder/code-server was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 53c2f3253bcf32886706fc023e794bbeb253c90f — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d00c643c3f66.