Skip to content
CAI
Software that uses CAICheck a score

coreybutler/nvm-windows

52.2

Weak · 6 August 2026

4.6k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Windows-native Node.js version manager implemented in Go. It provides core functionality for detecting system architecture, managing Node.js installations, and handling semantic versioning. The application includes a Windows installer, background update mechanisms, and secure file operations, all supported by a Go module-based dependency structure.

Features

Add architecture detection logic

Introduced a new Go module in src/arch that provides functions to detect the system architecture. The Bit function identifies the architecture (arm64, 64, or 32) by searching for specific byte sequences in files, while the Validate function normalizes architecture strings by checking the PROCESSOR\_ARCHITECTURE environment variable.

src/arch · high confidence

Added Semver package for version parsing and comparison

A new Go package named 'semver' has been added to the codebase, providing functionality to parse, validate, and compare semantic versions. This includes support for major, minor, and patch versioning, as well as pre-release and build metadata, allowing users to perform version comparisons and validations within the application.

src/semver · high confidence

Added Windows installation and environment configuration scripts

Added new assets to support Windows-based installation and configuration. This includes Inno Setup localization and preprocessor files (Default.isl, ISPPBuiltins.iss) for building installers, along with batch scripts (install.cmd, run.cmd, elevate.cmd) and VBScript helpers (setuserenv.vbs, unsetuserenv.vbs) that manage environment variables and system paths for nvm-windows.

assets · high confidence

Added background update checking and upgrade commands

The \src/upgrade\ directory now includes new files (\check.go\, \notification.go\, \register.go\, \upgrade.go\) that implement automatic background checks for Node.js and NVM for Windows updates. The \register.go\ file sets up Windows Scheduled Tasks to run update checks hourly, while \check.go\ handles fetching release data and displaying toast notifications for new versions. The \upgrade.go\ file provides the core logic for downloading and installing updates, including a progress UI and signal handling for cancellation. This introduces a new mechanism for users to receive timely notifications about available updates without manual intervention.

src/upgrade · high confidence

Introduce Go-based Node.js version management

Added a new Go implementation for managing Node.js versions, including functions to detect the current version, check if specific versions are installed or available, and list all installed versions. The code uses the 'github.com/blang/semver' library for semantic versioning support and implements logic to identify LTS, current, stable, and unstable versions from the Node.js registry.

src/node · high confidence

Introduce author bridge and encoding support for Windows

Added a new 'author' package that provides a bridge to a separate executable (author-nvm.exe) for handling elevated tasks, notifications, and console management on Windows. Additionally, introduced an 'encoding' package that detects character sets and converts content to UTF-8, improving handling of non-ASCII characters and settings file parsing.

src · high confidence

NVM for Windows installer and build tooling

The repository now includes a complete installer package for NVM for Windows, defined in \nvm.iss\ (Inno Setup script) and built via \build.js\ (Deno script). The installer configures the application, registers the 'nvm' URL protocol, and handles the migration of existing Node.js installations. Additionally, \.gitattributes\ and \.gitignore\ are added to manage binary files and build artifacts, while \SUPPORT.md\ and \CONTRIBUTING.md\ provide user and contributor guidance.

(repo-wide) · high confidence

Behavioural changes

Add secure ZIP extraction and file utility functions

Introduces a new 'file' package containing an Unzip function that safely extracts archives by validating file paths to prevent directory traversal attacks, alongside helper functions for reading lines and checking file existence.

src/file · medium confidence

Cross-volume file renaming and verbose debug logging

The utility package now supports renaming files and directories across different disk volumes (e.g., C: to D:), falling back to a copy-and-delete strategy when the source and destination are on different drives. Additionally, a new verbose debugging mode has been introduced, allowing users to enable detailed, color-coded debug logs that include file paths, line numbers, and formatted output for troubleshooting.

src/utility · high confidence

Improved HTTP error handling and download interruption management

The web download and request functions now include robust error handling for failed HTTP requests and specific handling for server status code 300 (multiple choices), including a targeted fix for npm v6.14.17. Additionally, the download process now safely handles user interruptions (Ctrl+C) by rolling back partial downloads, and the User-Agent header is set to identify the NVM for Windows version.

src/web · medium confidence

Dependencies

Migrate to Go modules

The project has been converted to use Go modules, introducing a go.mod and go.sum file to manage dependencies. This change standardizes how the application's Go packages are versioned and resolved, ensuring consistent builds across different environments.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 52 → 52 (+0.0)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.08.19) — scores are not directly comparable.

Lenses

  • Code Health 57 → 57 (+0.0)
  • Architecture 100 → 100 (+0.0)
  • Maturity 55 → 55 (+0.0)
  • Readiness 43 → 43 (+0.0)
  • Security 61 → 61 (+0.0)

Findings

  • No change — the same findings as the prior survey.

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

coreybutler/nvm-windows was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 6 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 5b18223ca19ff50d707f35410dbc6bd440a9f74d — the exact code this score is about.
  • Scored under rubric-2026.08.19 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer latest.