Skip to content
CAI
Software that uses CAICheck a score

decaporg/decap-cms

61.3

Adequate · 1 October 2026

65.7k

lines of production code

JavaScript

with TypeScript

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the Decap CMS monorepo, an open-source content management platform designed for static site generators. It provides a web-based interface for managing content stored in Git repositories, featuring a flexible widget-based editor and support for various version control backends. The codebase is structured into backend, widget, library, and UI packages, with recent updates focusing on infrastructure modernization and dependency management.

How it got here

2016–2023 — Decap CMS migration and modernization

109 changes.

The project was rebranded from Netlify CMS to Decap CMS, undergoing a comprehensive architectural overhaul that included migrating the codebase to TypeScript, adopting pnpm workspaces, and updating to React 19. This period involved rewriting core components, replacing legacy Redux and routing systems, and implementing a new Slate-based markdown editor alongside extensive Cypress end-to-end testing infrastructure.

2024–2026 — Rich text rewrite and backend expansion

16 changes.

The project significantly upgraded the rich text widget by rewriting it with the Plate.js framework, introducing a modern visual editor with improved paste handling and serialization. Concurrently, new backend integrations for AWS Cognito and Forgejo were added to expand authentication and hosting options, while collaborative notes and UUID widgets enhanced core editor functionality.

Features

Add Azure DevOps backend configuration and demo files

Added a new Azure DevOps backend configuration (\config.yml\) and a corresponding demo HTML page (\index.html\) to the \dev-test/backends/azure\ directory. The configuration defines the backend settings for connecting to an Azure repository, including placeholders for tenant and app IDs, and sets up collections for posts and pages with specific field widgets. The HTML file provides a preview template implementation for these collections, allowing users to test the Azure backend integration within the Decap CMS development environment.

dev-test/backends/azure · high confidence

Add GitHub backend development test site

Added a new development test configuration for the GitHub backend, including a \config.yml\ that sets up the \github\ backend with the \editorial\_workflow\ publish mode and an \index.html\ that loads the CMS and registers preview templates for 'posts' and 'pages'.

dev-test/backends/github · high confidence

Add Gitea backend configuration for development testing

A new Gitea backend configuration has been added to the development test environment. This includes a \config.yml\ file that sets up Gitea as the backend provider with specific repository and branch settings, defines collections for posts and pages with their respective fields and widgets, and an \index.html\ file that registers preview templates for these collections to allow visual verification of content in the CMS interface.

dev-test/backends/gitea · high confidence

Add Gitea backend support

Users can now connect Decap CMS to Gitea repositories. This change introduces a new backend implementation that handles authentication via PKCE, manages file persistence (create, update, delete) through the Gitea API, and supports media uploads. It includes a dedicated authentication UI component and comprehensive test coverage for the API and implementation logic.

packages/decap-cms-backend-gitea/src · high confidence

Add TypeScript type definitions for CMS core modules

This change introduces TypeScript declaration files and type definitions for the Decap CMS core package, improving type safety and developer experience. The new files define types for the global window object (CMS\_CONFIG, CMS\_ENV), provide type guards and interfaces for Immutable.js structures (StaticallyTypedRecord), declare modules for external dependencies (diacritics, tomlify-j0.4), and establish comprehensive type definitions for the CMS configuration, backend types (including gitea and forgejo), and field widgets.

packages/decap-cms-core/src/types · high confidence

Add UUID widget for Decap CMS

A new 'uuid' widget is now available, allowing users to automatically generate and manage UUID values within their content. The widget supports configuration options including a text prefix, read-only mode (defaulting to true), and optional Base32 encoding. It intelligently handles internationalization by generating a UUID only on the default locale or for translatable fields, and includes a preview component for displaying the value.

packages/decap-cms-widget-uuid · high confidence

Add boolean widget control component and entry point

The boolean widget now includes a dedicated BooleanControl component that renders a toggle switch using the decap-cms-ui-default library, with custom styling for active and inactive states. The widget entry point exports the widget definition and control component, enabling the boolean widget to be used within the CMS interface.

packages/decap-cms-widget-boolean/src · high confidence

Add collaborative notes pane to the Editor screen

A new Notes pane is now available in the Editor, allowing editors to add, edit, resolve, and delete notes attached to the current entry. Notes are sorted with unresolved items first, display the author and timestamp, and include a link back to the source issue (supporting GitHub and GitLab hosts). Editors can only modify their own notes, and the pane shows a count of unresolved items to highlight pending work.

packages/decap-cms-core/src/components/Editor/EditorNotesPane · high confidence

Add editorial workflow test configurations for Bitbucket and GitLab backends

Added new \config.yml\ and \index.html\ files to the \dev-test/backends/bitbucket\ and \dev-test/backends/gitlab\ directories. These files provide development test setups for the Bitbucket and GitLab backends, specifically enabling the \editorial\_workflow\ publish mode. The configurations define 'posts' and 'pages' collections with standard fields (title, date, body, etc.) and include corresponding preview templates in the HTML files to allow testing of the editorial workflow UI for these backends.

dev-test/backends/bitbucket, dev-test/backends/gitlab · high confidence

Add image editor component with alt and title support

The image editor component now supports alt text and title attributes in addition to the image path. Users can define these properties in the CMS configuration, and the component will correctly generate Markdown syntax including these attributes (e.g., \!\[alt\](path "title")\) and render them in the preview.

packages/decap-cms-editor-component-image/src · high confidence

Add proxy backend development test environment

A new development test setup for the proxy backend has been added, including a configuration file that defines GitHub as the backend with editorial workflow support and an HTML entry point that registers preview templates for posts and pages.

dev-test/backends/proxy · high confidence

Added Forgejo backend configuration and demo UI

A new Forgejo backend configuration has been added to the development test environment, enabling users to connect Decap CMS to a Forgejo instance. The update includes a config file defining the backend settings (app ID, API root, branch, and repository) and two content collections (posts and pages) with their respective fields and widgets. An accompanying index.html file provides a demo interface with registered preview templates for these collections, allowing developers to test the integration locally.

dev-test/backends/forgejo · high confidence

Backend packages receive new documentation and build configuration

The Azure, Bitbucket, GitHub, GitLab, and Proxy backend packages now include dedicated README files that document their code structure, API wrappers, and authentication flows, alongside standardized webpack configuration files that delegate to a shared script.

packages/decap-cms · high confidence

Bitbucket backend implementation added

This change introduces the source code for the Bitbucket backend integration, including the main API client, authentication page, Git LFS client, and backend implementation wrapper. It enables users to connect Decap CMS to Bitbucket repositories for content management, handling authentication (both implicit and Netlify proxy), file operations, and pull request workflows.

packages/decap-cms-backend-bitbucket/src · high confidence

Decap CMS core package restructured with new entry points and integrations

The \decap-cms-core\ package has been reorganized to provide a cleaner public API and support new integration capabilities. The main entry point is now \DecapCmsCore\, which exposes the \init\ function for bootstrapping the application, along with the registry for widgets and media libraries. A new \backend.ts\ module centralizes backend logic, including entry creation, search expansion, and i18n handling. New integrations for Algolia search and a generic Asset Store have been added, allowing users to configure external search providers and custom asset upload flows. The bootstrap process now uses React 18's \createRoot\ for rendering, and routing is handled by a dedicated \history\ module with helper functions for navigation. Additionally, an 'unknown' editor widget is now registered to handle unsupported widget types gracefully.

packages/decap-cms-core/src · high confidence

Decap server now supports secure configuration and custom environment variables

The decap-server package now allows for more secure and flexible local development setups. Users can configure the server via environment variables (documented in the new .env.example and README), including setting a custom port, specifying the Git repository directory, and adjusting the log level. Crucially, the server now supports binding to a specific host (e.g., 127.0.0.1) and restricting API requests to a specific origin, enhancing security for local development. The package has also been refactored to use TypeScript with a new build configuration (tsconfig.json, webpack.config.js) and includes a Jest configuration for testing.

packages/decap-server · high confidence

Entries view now displays unpublished workflow entries alongside published ones

The Entries component in the Collection view now supports showing unpublished entries (from the editorial workflow) in addition to published ones. The new EntriesCollection and EntryListing components handle loading and rendering these unpublished entries, displaying workflow status badges (draft, in review, ready) on entry cards. Users can now see both published and unpublished content in the same collection view, with proper filtering and sorting applied to the combined list.

packages/decap-cms-core/src/components/Collection/Entries · high confidence

Git Gateway backend now supports OAuth2 PKCE authentication

The Git Gateway backend now supports OAuth2 PKCE authentication, allowing users to configure the backend with \auth\_type: pkce\ and provide a \base\_url\ for custom OAuth2 providers (such as AWS Cognito) instead of relying solely on Netlify Identity. This change introduces a \PKCEAuthenticationPage\ implementation that handles the OAuth2 flow and sends the access token for all requests, enabling integration with non-Netlify Git Gateway implementations.

packages/decap-cms-backend-git-gateway · high confidence

Initial Storybook configuration for component documentation

A new Storybook configuration has been added to the project, enabling the visualization of UI components. The setup targets story files located within the \decap-cms-core\ and \decap-cms-ui-default\ packages and includes the Storybook links addon to facilitate navigation between components.

.storybook · high confidence

Initial implementation of the Uploadcare media library integration

This change introduces the core Uploadcare media library integration for Decap CMS. The new \index.js\ module initializes the Uploadcare widget, registers the effects tab, and handles file selection (single or multiple) by opening the widget dialog and passing the resulting CDN URLs back to the CMS editor. A corresponding test suite (\index.spec.js\) validates the initialization, configuration merging, and file insertion logic.

packages/decap-cms-media-library-uploadcare/src · high confidence

Initial package scaffolding for string and text widgets

The \decap-cms-widget-string\ and \decap-cms-widget-text\ packages are now structured as independent modules within the monorepo. This change introduces standard build configurations using a shared webpack setup, generates comprehensive changelogs documenting the version history of these widgets, and adds placeholder README files to guide users to the main documentation and community support channels.

packages/decap-cms-widget-string, packages/decap-cms-widget-text · high confidence

Initial release of decap-cms-backend-test package

The \decap-cms-backend-test\ package is introduced as a new component of the Decap CMS monorepo. It provides a test backend implementation for the File Management System API, designed specifically for demo purposes (such as the demo.decapcms.org site). The package includes a simple JavaScript-based file system simulation using \window.repoFiles\ and \window.repoFilesUnpublished\, along with a custom authentication component that bypasses the login screen for easier testing. It is built using a standard webpack configuration and follows the project's conventional commit and changelog standards.

packages/decap-cms-backend-test, packages/decap-cms-lib-util, packages/decap-cms-widget-richtext · high confidence

Introduce AWS Cognito Proxy backend for GitHub integration

This change adds a new \AwsCognitoGitHubProxyBackend\ implementation that allows Decap CMS to authenticate against GitHub via an AWS Cognito proxy. The backend leverages PKCE (Proof Key for Code Exchange) for secure OAuth2 authentication, handling the login flow through a dedicated \AuthenticationPage\ component. It extends the standard GitHub backend to bypass write access checks for app tokens and retrieves user information from the Cognito \/oauth2/userInfo\ endpoint, ensuring correct user identity resolution during the proxy-mediated auth process.

packages/decap-cms-backend-aws-cognito-github-proxy/src · high confidence

Introduce AWS Cognito Proxy for GitHub backend

Adds a new backend package that acts as an abstraction layer between the CMS and a proxied version of GitHub, enabling authentication via AWS Cognito. This component wraps the existing GitHub backend and utilizes lib-auth to provide a generic authentication page supporting PKCE, allowing users to authenticate through an AWS Cognito identity provider instead of direct GitHub OAuth.

packages/decap-cms-backend-aws-cognito-github-proxy · high confidence

Introduce decap-cms-app package for extension-based usage

A new \decap-cms-app\ package has been added to provide a variant of the CMS designed for use with extensions. Unlike the standard package, this version does not automatically initialize, requires React and React DOM as peer dependencies, and excludes specific media library extensions (Cloudinary and Uploadcare). It exposes a \DecapCmsApp\ object with an \init\ method, allowing developers to manually bootstrap the CMS via script tags or npm imports.

packages/decap-cms-app · high confidence

Introduce new richtext widget with blob URL preview support

A new richtext widget is added to the CMS, providing both a visual editor and a raw Markdown mode. A key behavioral change in the preview component is the preservation of local 'blob:' image URLs during HTML sanitization; previously, these temporary preview images were stripped by DOMPurify, but the new implementation specifically allows same-origin blob URLs on image sources while maintaining strict security for other attributes.

packages/decap-cms-widget-richtext/src · high confidence

Introduction of core value objects and Cloudinary media library integration

This change introduces new core value objects in \decap-cms-core\ to handle specific data structures: \AssetProxy\ for managing asset URLs and file objects, \EditorComponent\ for creating and configuring editor components with default behaviors, and \Entry\ for standardizing entry creation with consistent field initialization. Additionally, it adds the \decap-cms-media-library-cloudinary\ package, which provides a media library integration for Cloudinary. This integration loads the Cloudinary script, enforces specific configuration settings (like z-index and button class) that cannot be overridden, and handles asset insertion by supporting secure URLs, transformations, and filename-only output modes based on user configuration.

packages/decap-cms-core/src/valueObjects, packages/decap-cms-media-library-cloudinary/src · high confidence

List widget now supports drag-and-drop reordering and configurable add/remove/reorder flags

The list widget in the Decap CMS now allows users to reorder list items via drag-and-drop, powered by the dnd-kit library. Additionally, the widget schema now exposes \allow\_add\, \allow\_remove\, and \allow\_reorder\ boolean flags, giving content editors and developers fine-grained control over whether users can add new items, delete existing ones, or change their order within the list interface.

packages/decap-cms-widget-list/src · high confidence

Map widget now supports Point, LineString, and Polygon geometries

The map widget now allows users to create and edit not just single points, but also LineStrings and Polygons. This is enabled by a new schema definition that exposes a \type\ field with options for 'Point', 'LineString', and 'Polygon', and a control component that initializes the OpenLayers draw interaction based on this selected type. The widget also includes a preview component that displays the stored GeoJSON value.

packages/decap-cms-widget-map/src · high confidence

New Cypress E2E test runner and documentation

This change introduces a new Node.js-based runner script (cypress/run.mjs) that manages Cypress execution, including manual sharding for parallel local runs and integration with Cypress Cloud parallelization for CI environments. It also adds a new README (cypress/Readme.md) documenting how to run, debug, and record test data for various backends, along with unit tests (cypress/run.spec.mjs) verifying the sharding and argument generation logic.

cypress · high confidence

New Cypress test infrastructure for Git backends and proxy server

The \cypress/plugins\ directory has been restructured to introduce dedicated setup and teardown logic for GitHub, GitLab, Bitbucket, and the proxy server backends. This change adds new plugin files (\github.js\, \gitlab.js\, \bitbucket.js\, \proxy.js\, \gitGateway.js\) that manage test environment preparation, including creating temporary repositories, configuring authentication, and handling LFS support where applicable. A shared \common.js\ module provides utilities for Git client initialization and HTTP request transformation. The main \index.js\ plugin orchestrates these backends, allowing tests to dynamically switch between providers and manage their respective lifecycles, thereby improving the reliability and isolation of end-to-end tests for the CMS's content management workflows.

cypress/plugins · high confidence

New Forgejo backend with editorial workflow and open authoring support

This release introduces a new Forgejo backend for Decap CMS, enabling users to manage content hosted on Forgejo (or Codeberg) instances. The backend supports the editorial workflow, allowing draft reviews via pull requests, and includes open authoring support which automatically handles forking and collaboration workflows. It also includes a fix to correctly support Forgejo editorial workflow PR heads.

packages/decap-cms-backend-forgejo · high confidence

New Slack slash command function to trigger GitHub Actions

A new \publish.js\ function has been added to handle Slack slash commands. It verifies Slack request signatures and timestamps, checks if the invoking user is in the allowed list (case-insensitive, trimmed), and dispatches an on-demand GitHub Action to the configured repository if the command matches the expected value. The function logs event details and environment variables for debugging and returns a 401 Unauthorized response for invalid signatures, unauthorized users, or incorrect commands.

functions · high confidence

New UI component library and error reporting enhancements

This change introduces a new set of core UI components within the CMS core package, including a drag-and-drop system (DragDrop), a file upload button, a modal wrapper, and a settings dropdown for the app header. It also adds an ErrorBoundary component that now supports configurable issue report URLs, allowing administrators to direct bug reports to custom endpoints, and includes a test suite for these new components.

packages/decap-cms-core/src/components/UI · high confidence

New authentication library with PKCE, Implicit, and Netlify providers

The \decap-cms-lib-auth\ package has been introduced, providing a modular authentication system with three distinct strategies: PKCE OAuth (supporting OIDC auto-discovery and refresh tokens), Implicit OAuth, and Netlify's hosted auth. The implementation uses the native \crypto.randomUUID()\ for nonce generation and enforces secure protocols. Comprehensive test coverage has been added for the PKCE flow (including error handling and token refresh), the Netlify authenticator, and the utility functions.

packages/decap-cms-lib-auth/src · high confidence

New build, publishing, and integrity verification tooling

The repository now includes a suite of new scripts to manage the build and release process. The \scripts/externals.js\ and \scripts/webpack.js\ files define the UMD and CommonJS build configurations, mapping package names to global exports and handling browser polyfills. A new \scripts/pack-and-install.sh\ script allows developers to locally pack and install all workspace packages into a test project. To ensure release stability, \scripts/publish-packages.mjs\ provides a resumable publishing mechanism that handles registry lag and prevents partial failures, while \scripts/test-package-integrity.mjs\ and \scripts/verify-published-packages.mjs\ act as pre- and post-publish gates to detect issues like unresolved pnpm protocols or browser-incompatible dependencies. Additional utility scripts include \scripts/cache.js\ for CI caching, \scripts/revert\_publish.sh\ for rolling back releases, and \scripts/shims/fileURLToPath.js\ for browser compatibility.

scripts · high confidence

New development test environment with comprehensive widget coverage

A new development test site has been added to the \dev-test\ directory, providing a local environment for validating CMS features. The configuration (\config.yml\) defines multiple collections including posts, restaurants, FAQs, and settings, utilizing a wide range of widgets such as relation, map, uuid, color, and select (with multiple selection support). The setup includes i18n support with English and German locales, visual editing capabilities, and specific collection filters and view groups. Sample data is embedded in \index.html\ to test various front matter formats (YAML, JSON, TOML) and content structures, while \example.css\ provides basic styling for the test interface.

dev-test · high confidence

New package for centralized default library exports

A new entry point at packages/decap-cms-default-exports/src/index.js has been added to bundle and re-export common dependencies used across the CMS. This module exposes a DecapCmsDefaultExports object containing EmotionCore (css, withEmotionCache, CacheProvider, ThemeContext, jsx, Global, keyframes, ClassNames), EmotionStyled, Immutable, ImmutablePropTypes, Lodash, PropTypes, React, and ReactDOM, providing a single location for these shared utilities.

packages/decap-cms-default-exports/src · high confidence

New test backend package with in-memory implementation and React 19 compatibility

A new \decap-cms-backend-test\ package has been added, providing a test backend that stores entries and assets in memory via the browser's \window\ object, allowing developers to run the CMS editor without a real Git repository. The package includes an \AuthenticationPage\ component that supports a new \login: false\ configuration option to skip the login screen for demo purposes, and it explicitly handles React 19's removal of automatic PropTypes validation by calling \PropTypes.checkPropTypes\ manually. The implementation covers core CMS operations such as retrieving, persisting, and moving entries (including nested paths and subfolder handling), as well as cursor-based pagination for folder listings, accompanied by comprehensive unit tests for these behaviors.

packages/decap-cms-backend-test/src · high confidence

New visual editing and preview pane components

The EditorPreviewPane now includes new components (EditorPreview, EditorPreviewContent, PreviewHOC) that enable visual editing (click-to-edit) via Vercel Stega decoding and improve preview performance with conditional updates. EditorPreviewContent handles click interactions to trigger field editing when visual editing is enabled, while PreviewHOC optimizes re-renders by only updating on value changes for non-container widgets.

packages/decap-cms-core/src/components/Editor/EditorPreviewPane · high confidence

Rewrite of datetime widget with dayjs and custom format support

The datetime widget has been rewritten to replace Moment.js with dayjs, enabling more efficient date handling and supporting custom date and time formats via the new \date\_format\ and \time\_format\ schema properties. The \DateTimeControl\ component now intelligently selects the appropriate HTML input type (date, time, or datetime-local) based on the configured formats, and correctly handles UTC mode by escaping literal 'Z' characters. Additionally, the widget now triggers a change event when the default value is set to \{{now}}\, ensuring the field is populated with the current time upon initialization.

packages/decap-cms-widget-datetime/src · high confidence

Support for custom inline shortcode components in the markdown widget

The markdown widget now allows custom inline shortcodes to be inserted via a plugin system. When a user inserts an inline shortcode, the editor calls a provided \onInsert\ callback with the currently selected text and CMS context; the callback can return data to populate the shortcode or return null to cancel the insertion. The implementation ensures these inline shortcodes are treated as void elements and includes logic to prevent the editor from becoming empty if a shortcode is deleted.

packages/decap-cms-widget-markdown/src/MarkdownControl/plugins/shortcodes · high confidence

Support for inline custom editor components in markdown widget

The markdown widget now allows users to define and use custom inline components (shortcodes) within the editor. This change introduces new UI components (\InlineShortcode\, \Shortcode\, \VoidBlock\) that render custom shortcodes as interactive elements, supporting both inline previews and full block-level editing via custom plugins. Users can now extend the editor with custom logic for handling specific shortcode types, enhancing the flexibility of content creation.

packages/decap-cms-widget-markdown/src/MarkdownControl/components · high confidence

decap-cms-core now exposes its version at runtime

The core package now injects its own version number into the built application via a webpack DefinePlugin. This allows the CMS UI and any extensions to programmatically detect which version of decap-cms-core is currently running, which is useful for displaying version information in the interface or for conditional logic based on the CMS version.

packages/decap-cms-core · high confidence

Removals

Removal of example project configuration and entry point

The example project's configuration file (config.yml) and entry point (index.html) have been removed. This eliminates the default test-repo setup, including the posts, FAQ, and settings collections, as well as the basic HTML scaffold used to load the CMS in the example directory.

example · high confidence

Removal of legacy collections and config reducers

The legacy reducer files for managing collections and configuration have been removed from the codebase. This eliminates the specific state management logic that previously handled the loading and storage of collection definitions and general configuration settings via Immutable.js structures.

src/reducers · high confidence

Removal of legacy config loading actions

The file src/actions/config.js, which previously handled fetching and parsing the CMS configuration from config.yml or window.CMS\_CONFIG, has been removed. This change eliminates the legacy mechanism for loading and validating the site configuration, indicating a shift in how configuration data is managed within the application.

src/actions · high confidence

Removed legacy App and DashboardPage container components

The \App\ and \DashboardPage\ container components in \src/containers\ have been deleted. This removes the Redux-connected logic that previously handled configuration loading states (showing loading or error messages) and the dashboard view that listed collections with links to their respective paths. Users will no longer see these specific UI elements or the associated Redux state management for config loading and collection listing within this location.

src/containers · high confidence

Security

Decap CMS Proxy Server introduces strict path validation to prevent traversal attacks

The Decap CMS Proxy Server now enforces strict path validation on all file system and Git operations, blocking path traversal and symlink-based attacks that could allow access to files outside the configured repository. This change introduces a new \pathTraversal\ Joi validator and utility functions (\resolveExistingRepoPath\, \resolveNewRepoPath\) that verify every requested path resolves within the repository root, even when symlinks are involved. The validation applies to all actions including \getEntry\, \persistEntry\, \getMedia\, \deleteFile\, and others, ensuring that users cannot read, write, or delete files outside the intended scope. Tests confirm that both sibling-prefix traversals (e.g., \../secret.txt\) and symlink-based escapes are rejected with a clear error message.

packages/decap-server/src · high confidence

Sanitize pasted HTML to block dangerous protocols

The Markdown widget now sanitizes HTML content pasted from external sources (e.g., web browsers, other editors) before converting it to Markdown. This change blocks potentially dangerous protocols such as \javascript:\, \vbscript:\, and \file:\ in links and images, ensuring that malicious scripts or unauthorized local file accesses are not executed or loaded when users paste rich text into the editor.

packages/decap-cms-widget-markdown/src/MarkdownControl/plugins/html · high confidence

Behavioural changes

Add internal utilities and deprecation shims

This change introduces several internal components and compatibility shims. It adds a Redux middleware (\waitUntilAction\) to \decap-cms-core\ that allows actions to block until a specific condition is met, and a script in \decap-cms-backend-github\ to extract GraphQL fragment types. In \decap-cms-widget-markdown\, new Slate.js matchers (\lowestMatchedAncestor\, \matchLink\, \matchedAncestors\) and a hyperscript test helper (\h\) are added to support editor logic. Finally, \decap-cms\ includes a blank \cms.css\ shim to prevent build breaks for sites expecting the old static CSS file, and a JavaScript shim that warns users when loading the deprecated \dist/cms.js\ CDN file, directing them to use \dist/decap-cms.js\ instead.

(repo-wide) · high confidence

App component restructured for React 19 compatibility and responsive UI

The App, Header, and NotFoundPage components in the core package have been rewritten to support React 19 and improve the user interface. The App component now includes manual PropTypes validation in componentDidMount to address React 19 breaking changes, ensuring stable runtime checks. The Header component has been redesigned to be responsive, featuring a sticky layout on taller screens and flexible navigation buttons that adapt to screen width, while also supporting a configurable logo. These changes provide a more robust and visually consistent experience across different device sizes.

packages/decap-cms-core/src/components/App · high confidence

Automatic initialization and global extension hooks for Decap CMS

The main entry point now automatically initializes the CMS if the \window.CMS\_MANUAL\_INIT\ flag is not set, while still allowing manual initialization when the flag is present. Additionally, the CMS instance and helper functions (\initCMS\, \createClass\, \h\) are exposed on the global \window\ object, and two media libraries (Uploadcare and Cloudinary) are registered by default via a new extensions module.

packages/decap-cms/src · high confidence

Azure backend refactored for React 19 compatibility and improved authentication

The Azure backend implementation has been refactored to support React 19, addressing breaking changes in PropTypes validation by adding manual checks in the authentication component. The authentication flow now explicitly handles potential null labels during pull request filtering to prevent errors. Additionally, the backend UI now supports a configurable logo in the header, allowing users to customize the login page appearance via the \logo\ configuration option.

packages/decap-cms-backend-azure/src · medium confidence

Centralized configuration constants and schema definitions

The CMS now organizes its core configuration logic into a dedicated constants directory, introducing explicit definitions for collection types (file-based vs. folder-based), view styles (list vs. grid), and publish modes (simple vs. editorial workflow). A comprehensive AJV-based config schema is provided to validate settings, including support for internationalization structures, media processing options, and field patterns. Additionally, the system defines standard sortable and identifier fields (such as title, date, and author) with associated synonyms and default preview behaviors, while also establishing specific validation error types to improve error handling clarity.

packages/decap-cms-core/src/constants · high confidence

Centralized registration of backends, widgets, and locales in decap-cms-app

The \decap-cms-app\ package now explicitly registers all supported backends (including Gitea, Forgejo, and AWS Cognito GitHub Proxy), widgets (including the new UUID widget and Richtext widget, with the Date widget removed), editor components, and locales in a single \extensions.js\ entry point. This change consolidates the CMS configuration, ensuring that importing \decap-cms-app\ automatically makes all these features available without manual setup.

packages/decap-cms-app/src · high confidence

Code widget now supports dynamic language mode loading and fixes hidden-content visibility

The Code widget in Decap CMS has been refactored to dynamically load CodeMirror language modes on demand via \languageLoaders.js\, replacing static imports to improve performance. Additionally, the widget now correctly refreshes the CodeMirror instance when it is initially hidden and then shown, ensuring content is visible in collapsed lists. The widget also ignores the initial language change to prevent false unsaved-change states upon first load.

packages/decap-cms-widget-code/src · high confidence

Collection views are now responsive with a redesigned sidebar and controls

The Collection component and its sub-components (Sidebar, CollectionTop, CollectionControls, etc.) have been refactored to support responsive layouts. The sidebar now adapts to smaller screens by removing the fixed positioning and adjusting widths, while the main content area and controls reflow using flexbox and media queries. This ensures the collection interface is usable on mobile devices and varying viewport sizes, addressing the need for responsive collection and workflow views.

packages/decap-cms-core/src/components/Collection · high confidence

Color string widget now supports clearable values and input toggles

The color string widget has been rewritten to use a new \ColorControl\ component that adds a clear button (allowing users to reset the field to an empty value) and an optional text input field controlled by the \allowInput\ option. It also respects the \enableAlpha\ option to show or hide the alpha channel in the color picker, and uses \tinycolor2\ to validate and display color swatches with a checkerboard background for transparency.

packages/decap-cms-widget-colorstring/src · high confidence

Commit message validation via Husky v7

The project now enforces commit message standards using Husky v7. A new \.husky/commit-msg\ hook has been added to automatically lint commit messages using \commitlint\ before they are accepted, ensuring consistent commit history formatting.

.husky · high confidence

Core Redux actions restructured into modular TypeScript files

The Redux action logic in \packages/decap-cms-core/src/actions\ has been reorganized from a monolithic structure into distinct, modular TypeScript files (e.g., \auth.ts\, \collections.ts\, \config.ts\, \entries.ts\, \media.ts\). This change introduces specific capabilities for the editor, including a collaborative notes pane (with actions for loading, adding, and polling notes in \entries.ts\), support for browser-based image transformations (via \mediaLibrary.ts\), and a \default\_sort\ option for sortable fields (handled in \config.ts\). It also includes architectural improvements such as cancelable deploy preview polling in \deploys.ts\ and a new \waitUntil\ utility for managing asynchronous state dependencies.

packages/decap-cms-core/src/actions · high confidence

Core library refactoring and new capabilities for i18n, image processing, and visual editing

The core library has been reorganized into dedicated modules, introducing several new capabilities and fixes. A new \imageTransformations.ts\ module enables browser-side image processing, allowing users to configure format, quality, and dimension constraints for uploaded images. The \i18n.ts\ module centralizes internationalization logic, supporting multiple folder and file structures for locale management. Visual editing is enhanced via \stega.ts\, which embeds hidden metadata into entry values to support precise field targeting. Additionally, \formatters.ts\ now handles commit message formatting with support for signed-off-by trailers, and \urlHelper.ts\ provides robust slug sanitization that preserves Unicode characters (IRI support) and slashes. The \registry.js\ module has been updated to fix event invocation, ensuring the full entry object is returned rather than just data.

packages/decap-cms-core/src/lib · high confidence

Default UI icon set updated with new assets and structure

The default CMS UI icon library has been restructured and expanded. A new centralized configuration module (\icons.js\) now manages icon definitions, allowing for specific properties like direction to be applied to directional icons. The icon set itself has been updated with new SVG assets, including support for Gitea and Forgejo version control providers, a strikethrough formatting icon for the markdown editor, and a new 'add-with' icon variant.

packages/decap-cms-ui-default/src/Icon · high confidence

Dynamic CodeMirror language mode loading

The code widget now dynamically loads CodeMirror language modes on demand rather than bundling them statically. A new build script processes language definitions to generate a loader module that imports specific mode files only when needed, reducing initial bundle size and improving performance for users editing code in various languages.

packages/decap-cms-widget-code/scripts · high confidence

Editor component restructure and notes pane integration

The Editor screen components have been reorganized into a new modular structure within the Editor directory. The main Editor component now handles core lifecycle logic, including local backup retrieval, draft creation, and navigation blocking. A new EditorInterface component manages the layout, introducing a split-pane view that supports a new Notes pane alongside the existing Control and Preview panes, with logic to resolve the active pane based on availability. The EditorToolbar has been updated with new styling for buttons and dropdowns, and a withWorkflow higher-order component now explicitly handles editorial workflow logic by overriding entry loading and persistence actions.

packages/decap-cms-core/src/components/Editor · high confidence

Editor control pane refactored with React 19 compatibility and performance improvements

The editor control pane components (EditorControl, EditorControlPane, and Widget) have been refactored to support React 19, including manual PropTypes validation in componentDidMount to handle breaking changes. The Widget component now implements a custom shouldComponentUpdate to avoid unnecessary re-renders while loading assets and respects widget-specific update logic. Field errors are now cleared immediately when a field value changes, and the label component now wraps the optional indicator in a span for better customization. The control pane also includes improved focus handling with smooth scrolling to labels and better error positioning.

packages/decap-cms-core/src/components/Editor/EditorControlPane · high confidence

File widget control now supports drag-and-drop sorting for multiple files

The file widget's control component has been updated to use the dnd-kit library, enabling users to drag and drop files to reorder them when the 'allow\_multiple' option is enabled. This replaces the previous react-sortable-hoc implementation, providing a modern, touch-friendly sorting experience within the media manager.

packages/decap-cms-widget-file/src · high confidence

The Markdown widget now prevents empty links from persisting in the document when the linked text is deleted, resolving an issue where hidden link nodes remained after content removal. This fix is implemented within the new \withInlines\ plugin via a normalization step that removes link elements with no text content. Additionally, the inline editing logic has been reorganized into a modular structure under \plugins/inlines\, introducing dedicated handlers for keyboard shortcuts (bold, italic, underline, code, links, and line breaks) and utility functions for toggling marks and managing link wrapping/unwrapping.

packages/decap-cms-widget-markdown/src/MarkdownControl/plugins/inlines · high confidence

Git Gateway backend refactored to support OAuth2 PKCE and multiple Git providers

The Git Gateway backend has been restructured to support OAuth2 PKCE authentication, allowing users to restore sessions on page reload without re-authenticating. The implementation now abstracts Git provider logic, introducing dedicated API classes for GitHub and GitLab (and supporting Bitbucket) that handle provider-specific authentication headers and error handling. This change also improves large media handling by correctly identifying binary files via the isLargeMedia check and ensures user metadata, including avatar URLs, is passed through correctly from the identity provider.

packages/decap-cms-backend-git-gateway/src · high confidence

GitHub backend refactored to TypeScript with new GraphQL API support

The GitHub backend implementation has been rewritten in TypeScript, introducing a new GraphQL-based API layer (GraphQLAPI) alongside the existing REST API. This change adds support for optional GraphQL usage via the \use\_graphql\ configuration option, enabling more efficient data fetching for repositories. The refactoring also includes updated authentication handling in the AuthenticationPage component to support React 19's stricter PropTypes validation and improves the editorial workflow by ensuring correct base branch names are used when creating pull requests.

packages/decap-cms-backend-github/src · high confidence

GitLab backend rewritten with PKCE authentication, GraphQL support, and notes via issues

The GitLab backend has been completely rewritten to improve reliability and add new capabilities. Authentication now uses the PKCE flow by default, which automatically refreshes expired access tokens for both REST and GraphQL requests, preventing login interruptions. The backend supports an optional GraphQL API for fetching files and metadata, and uses Bearer authentication for those requests. It also introduces a Notes feature that stores entry comments as GitLab issues, handling pagination and filtering to ensure notes are correctly associated with entries. Additionally, the implementation now correctly loads GitLab LFS media content when requested and ensures the correct branch is used when not explicitly specified in the configuration.

packages/decap-cms-backend-gitlab/src · high confidence

Improved format resolution and custom format registration

The CMS now supports registering custom file formats via a new registry API, allowing users to define custom \fromFile\ and \toFile\ logic for specific extensions (e.g., \txt-querystring\) and override existing formatters (e.g., replacing the default YAML parser). The format resolution logic in \formats.ts\ has been updated to check this registry when resolving formats by name or extension. Additionally, the frontmatter parser now supports custom delimiters for YAML, TOML, and JSON frontmatter, and duplicate key detection has been improved to throw specific errors during parsing.

packages/decap-cms-core/src/formats · high confidence

Improved list editing behavior in the Markdown widget

The Markdown widget now features a comprehensive rewrite of its list handling logic, introducing precise support for nested lists and refined keyboard interactions. Users can now create nested lists by pressing Enter within a list item, indent or outdent list items using Tab and Shift+Tab, and merge or unwrap list items with Backspace. The update also adds the ability to toggle between different list types (e.g., bulleted to numbered) and correctly handles conversions between paragraphs and list items, ensuring that list structures remain consistent and intuitive during editing.

packages/decap-cms-widget-markdown/src/MarkdownControl/plugins/lists · high confidence

Markdown widget editor rewritten with Slate and new visual/raw modes

The Markdown widget's editing interface has been completely rewritten to use the Slate editor library, replacing the previous implementation. This introduces a dual-mode editing experience: a 'rich\_text' (visual) mode that renders Markdown as formatted HTML with a toolbar for headings, lists, links, and formatting, and a 'raw' mode that displays the underlying Markdown source in a monospaced text area. The visual editor now supports strikethrough, custom editor components (shortcodes), and improved handling of code blocks and media libraries. The toolbar buttons are now sorted alphabetically, and the editor state is persisted in localStorage to remember the user's preferred mode. This change also includes fixes for initial value handling and accessibility labels.

packages/decap-cms-widget-markdown/src/MarkdownControl · high confidence

Markdown widget serialization engine refactored to Unified ecosystem

The Markdown widget's internal serialization logic has been rewritten to use the Unified ecosystem (Remark and Rehype) instead of previous regex-based parsing. This change introduces a robust pipeline for converting between Markdown, MDAST, HAST, HTML, and Slate formats, enabling support for custom editor components (shortcodes) and improving stability. Key behavioral improvements include stricter adherence to Remark's tokenizer rules, automatic removal of HTML comments from pasted content, proper handling of Dropbox Paper emoji images, and fixes for invalid MDAST nesting and link padding issues that previously caused rendering artifacts.

packages/decap-cms-widget-markdown/src/serializers · high confidence

Media library UI is now responsive and supports virtualized scrolling

The media library modal now adapts its layout to different screen sizes, adjusting the modal width and button text visibility based on breakpoints (e.g., hiding button labels on screens under 600px). For large media collections, the library uses virtualized rendering via \react-window\ to improve performance, while smaller sets fall back to a paginated grid with infinite scroll. Additionally, a new 'Copy to Clipboard' button allows users to copy file paths or URLs, and the interface now distinguishes between viewable images and other file types with appropriate icons.

packages/decap-cms-core/src/components/MediaLibrary · high confidence

New API client with Bearer token authentication and backoff retry logic

The \packages/decap-cms-lib-util\ package introduces a new \API\ module that standardizes HTTP requests across backends. API requests now use the \Bearer\ prefix for the Authorization header instead of the previous \token\ format. The module includes built-in rate-limit handling with exponential backoff for 429 (GitLab/Bitbucket) and 403 (GitHub) responses, and supports custom API roots for each backend (GitHub, GitLab, Bitbucket). It also provides utilities for cursor-based pagination, content key generation, and editorial workflow error handling.

packages/decap-cms-lib-util/src · high confidence

New PKCE authentication UI and refactored Netlify login page

The \decap-cms-ui-auth\ package now includes a \PKCEAuthenticationPage\ component that supports OAuth2 PKCE flows with optional OIDC auto-configuration, extracting user details like email and avatar from token claims. The existing \NetlifyAuthenticationPage\ has been moved from the Git Gateway backend into this shared UI package, updated to support the new \logo\ prop alongside the deprecated \logoUrl\, and adjusted for React 19 compatibility.

packages/decap-cms-ui-auth · high confidence

New image widget with local file preview support

The image widget now includes a dedicated preview component that correctly displays images uploaded from the local device. By using \URL.createObjectURL\ for File objects, the preview pane shows the selected image immediately, resolving previous issues where local uploads were not visible in the preview.

packages/decap-cms-widget-image/src · high confidence

Number, String, and Text widgets updated for React 19 compatibility

The Number, String, and Text widget control components have been updated to address a breaking change in React 19 regarding PropTypes validation. Since React 19 no longer automatically validates PropTypes in development, these widgets now explicitly call \PropTypes.checkPropTypes\ within \componentDidMount\ to ensure prop types are still checked. This change ensures that developers receive proper warnings for invalid prop usage in these specific widgets when running in development mode.

packages/decap-cms-widget-number/src, packages/decap-cms-widget-string/src, packages/decap-cms-widget-text/src · high confidence

Object widget control and preview components restructured

The object widget's implementation in the \decap-cms-widget-object\ package has been reorganized into distinct \ObjectControl\ and \ObjectPreview\ components, replacing the previous monolithic structure. The new \ObjectControl\ component manages nested field rendering, validation propagation, and collapse state, while \ObjectPreview\ handles the display of object fields in read-only contexts. The widget entry point (\index.js\) now explicitly exports these components along with a schema defining \collapsed\ and \i18n\ properties, ensuring consistent behavior for nested object editing and previewing within the CMS interface.

packages/decap-cms-widget-object/src · high confidence

Preserve local image previews in markdown preview and add strikethrough support

The markdown widget now correctly displays images selected from the local file system in the preview pane by allowing same-origin blob URLs during HTML sanitization, preventing them from being stripped by DOMPurify. Additionally, the widget's schema has been updated to include 'strikethrough' as a supported button option, enabling users to apply strikethrough formatting via the editor toolbar.

packages/decap-cms-widget-markdown/src · high confidence

Project rebranded to Decap CMS with modernized build tooling

The project has been rebranded from Netlify CMS to Decap CMS, reflected in the README, license, and configuration files. The build system has been modernized by replacing the legacy .babelrc and webpack.config.js with a new babel.config.js and pnpm workspaces, enabling the use of React's automatic JSX runtime and TypeScript support. Configuration files such as .eslintrc, tsconfig.json, and jest.config.js have been updated to align with these changes, and the repository structure now uses pnpm for package management.

(repo-wide) · high confidence

Proxy backend now validates and sanitizes proxy URLs

The proxy backend implementation now enforces stricter validation on the \proxy\_url\ configuration. It rejects unsafe schemes (such as \javascript:\ or \file:\) and protocol-relative URLs, allowing only \http\, \https\, or root-relative paths. Additionally, surrounding whitespace in the URL is automatically trimmed to prevent connection errors.

packages/decap-cms-backend-proxy/src · high confidence

Redesign of the Redux state management architecture

The core state management logic in \packages/decap-cms-core/src/reducers\ has been completely rewritten to improve reliability and maintainability. The new implementation replaces the previous reducer structure with a modular set of TypeScript files (e.g., \auth.ts\, \config.ts\, \entries.ts\) that utilize the \immer\ library for immutable state updates. This change introduces a more robust handling of authentication, configuration, editorial workflows, and media libraries, while also standardizing the root reducer setup and selector exports.

packages/decap-cms-core/src/reducers · high confidence

Redux store configuration removed

The file configuring the Redux store in src/store has been deleted. This file previously defined the store setup, including the combination of config, collections, and router reducers, and applied middleware such as redux-thunk and react-router-redux sync.

src/store · high confidence

Refactored Markdown block editing logic for improved stability

The Markdown widget's block editing behavior has been refactored to improve stability and fix focus-loss issues. This change introduces a new modular structure in the \blocks\ plugin directory, separating location checks (e.g., cursor position relative to headings, lists, or breaks), transforms (e.g., splitting nodes, unwrapping blocks), and event handlers (e.g., keyDown for Enter/Backspace). Specifically, it adds logic to handle backspace actions after soft breaks, prevents focus loss when deleting content, and refines how block types (like headings and quotes) are toggled and merged. This restructuring ensures more predictable editing experiences when manipulating block structures in the markdown editor.

packages/decap-cms-widget-markdown/src/MarkdownControl/plugins/blocks · high confidence

Relation widget gains sorting, caching, and filtering capabilities

The relation widget now supports reordering of selected items in multi-select mode using dnd-kit, replacing the previous react-sortable-hoc implementation. A new client-side cache (RelationCache) stores successful query results to improve performance and reduce redundant network requests, while invalidating entries when collections change. Additionally, the widget now supports filtering relation options via a new 'filters' schema property, allowing users to narrow down available choices based on specific field values.

packages/decap-cms-widget-relation/src · high confidence

Removal of default application entry point

The default entry point file (src/index.js) has been removed, eliminating the automatic DOM setup and React rendering logic that previously initialized the application. This change supports the shift toward manual initialization and custom root element configuration, allowing users to integrate the library into their own existing applications without the framework imposing its own bootstrap structure.

src · high confidence

Removal of legacy react-router configuration

The file src/routes/routes.js, which previously defined the application's routing structure using the deprecated react-router v3 API (including browserHistory and IndexRoute), has been removed. This change eliminates the old routing setup, likely as a prerequisite for migrating to a newer router version or a different routing strategy.

src/routes · high confidence

Rich text widget rewritten with Plate.js editor

The rich text widget in the Decap CMS has been completely rewritten to use the Plate.js editor framework, replacing the previous implementation. This change introduces a new visual editing mode with support for headings, bold, italic, strikethrough, code, lists, blockquotes, links, images, tables, and shortcodes, alongside a raw Markdown mode. The update also improves paste handling from external sources, adds support for linked images, and allows for custom inline editor components and media library configuration merging.

packages/decap-cms-widget-richtext/src/RichtextControl · high confidence

Rich text widget serialization engine refactored for shortcode and paste handling

The rich text widget's serialization logic has been rewritten to use a modular Unified/Remark/Rehype pipeline, replacing the previous implementation. This change introduces support for rendering nested shortcodes in the preview pane, improves paste handling by stripping HTML comments and normalizing link spacing (particularly for Google Docs content), and ensures stricter adherence to Markdown tokenizer rules to prevent invalid AST nesting. Users will see more accurate previews of custom editor components and cleaner Markdown output when pasting content.

packages/decap-cms-widget-richtext/src/serializers · high confidence

Richtext widget UI components rewritten for Plate.js editor

The richtext widget's user interface components (Editor, Toolbar, and element renderers) have been completely rewritten to integrate with the Plate.js rich-text editor library. This change introduces new React components for rendering content elements (such as headings, blockquotes, lists, images, links, tables, and shortcodes) and toolbar buttons (for bold, italic, headings, lists, links, and editor components), replacing the previous implementation to provide a modern, plugin-based editing experience.

packages/decap-cms-widget-richtext/src/RichtextControl/components · high confidence

Richtext widget plugin architecture and behavior updates

The richtext widget's plugin system has been refactored to use Plate.js, introducing new plugins for handling breaks (Shift+Enter creates break nodes), blockquotes (exiting empty blockquotes or backspacing at the start removes the blockquote), images, shortcodes, and tables. The list plugin now explicitly allows shortcodes as valid list item children, and the blockquote plugin has extended behavior to unwrap the blockquote when pressing Enter in an empty block or Backspace at the start of a collapsed block within a blockquote.

packages/decap-cms-widget-richtext/src/RichtextControl/plugins · high confidence

Select widget now supports numeric option values and fixes selection of zero

The select widget now correctly handles options with numeric values, including the value 0, which was previously failing to select. The widget's schema and control component have been updated to accept both string and number types for option values, ensuring that numeric selections are properly passed through to the content model. Additionally, the widget now includes a preview component for displaying selected values in the editor.

packages/decap-cms-widget-select/src · high confidence

String template engine now supports filters and improved date handling

The string template engine in the widgets library has been updated to support value filters (such as \upper\, \lower\, \date\, \default\, \ternary\, and \truncate\) within template variables, allowing users to transform slug and field values directly in template strings. Additionally, the underlying date library has been switched from Moment.js to Day.js, and the \slugFormatter\ logic now correctly populates date template variables using the date from the entry if it exists, ensuring consistent slug generation.

packages/decap-cms-lib-widgets/src · high confidence

UI components rewritten for React 19 compatibility and responsive dropdown positioning

The default UI components have been refactored to support React 19, including manual PropTypes validation in class components and handling of SVG prop changes in the Icon component. Dropdown positioning is now calculated dynamically using a custom hook and ResizeObserver to ensure menus stay within the viewport, and the authentication page now supports custom logos via a new logo prop.

packages/decap-cms-ui-default/src · high confidence

Updated locale files with new languages and UI string standardization

The locale package now includes new translations for Bulgarian (bg), Catalan (ca), and Danish (da), alongside updates to existing locales such as Czech, German, and English. The English locale has been expanded to support new UI features, including a collaborative notes pane and strikethrough formatting in the markdown editor. Additionally, the 'New entry' button label has been standardized across all locales to '+ %{collectionLabel}', and backend authentication options for Gitea and Forgejo have been added to the relevant language files.

packages/decap-cms-locales/src · high confidence

Workflow UI restructured with responsive layout and React 19 compatibility

The editorial workflow interface has been rebuilt to support responsive design, adapting the card grid and column layouts for mobile and desktop viewports. The implementation now uses dayjs for date handling and includes explicit PropTypes validation in componentDidMount to ensure compatibility with React 19's stricter runtime checks. Users will see a more flexible layout for managing unpublished entries, with improved spacing and visual hierarchy across screen sizes.

packages/decap-cms-core/src/components/Workflow · high confidence

Fixes

GitLab PKCE access token refresh fix

The authentication library now automatically refreshes expired PKCE access tokens for GitLab, preventing authentication failures when tokens lapse during use.

packages/decap-cms-lib-auth · high confidence

Test coverage

Added Jest mocks for stack cleaning, files, and styles; Added Jest snapshot tests for Collection, NestedCollection, and Sidebar components; Added Jest snapshot tests for Editor and EditorToolbar components; Added Jest snapshot tests for the ListControl widget; Added common Cypress test suites for editorial workflows, media library, and i18n; Added comprehensive test coverage for richtext widget serializers; Added comprehensive test coverage for the markdown widget serializer; Added test backend configuration and demo data; Added test coverage for core CMS utilities; Added test coverage for the Editor component suite; Added tests for CMS configuration schema validation; Added tests for ListControl widget behavior; Added tests for Markdown preview rendering and sanitization; Added tests for MarkdownControl visual editor and parser; Added tests for RichtextPreview rendering; Added tests for backend entry filtering and i18n processing; Added tests for relation widget filtering and nested field support; Added tests for richtext widget parsing, visual editing, and paste handling; Added unit tests for Collection UI components; Added unit tests for core CMS reducers; Expanded end-to-end test coverage for editorial workflow, media library, and markdown widget; New Cypress e2e test infrastructure with custom commands and API stubbing; New Cypress test utilities for configuration, workflow, and mocking; Removed legacy test files and setup configuration.

Dependencies

Decap CMS packages adopt pnpm catalog dependency management

The Decap CMS monorepo has migrated its dependency management from standard npm/yarn versioning to pnpm catalogs. This change updates package.json files across all backend, widget, library, and UI packages to reference dependencies via the \catalog:\ protocol, centralizing version control. Additionally, the Forgejo backend package now explicitly specifies peer dependency versions for React 19, Emotion, and other core libraries, reflecting the project's alignment with these newer versions.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 60 → 61 (+1.5)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 59 → 59 (+0.1)
  • Architecture 65 → 59 (-6.0)
  • Maturity 68 → 68 (+0.2)
  • Readiness 62 → 60 (-1.7)
  • Security 58 → 67 (+9.6)
  • Performance 100 (new)

Resolved (16)

  • ETagPollingManager.checkCurrentIssue (cognitive 17) (packages/decap-cms-backend-github/src/polling.ts)
  • EditorInterface.render (cyclomatic 17) (packages/decap-cms-core/src/components/Editor/EditorInterface.js)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Hotspot: packages/decap-cms-backend-forgejo/src/API.ts (packages/decap-cms-backend-forgejo/src/API.ts)
  • Hotspot: packages/decap-cms-backend-forgejo/src/implementation.tsx (packages/decap-cms-backend-forgejo/src/implementation.tsx)
  • Hotspot: packages/decap-cms-backend-github/src/implementation.tsx (packages/decap-cms-backend-github/src/implementation.tsx)
  • Hotspot: packages/decap-cms-core/src/actions/config.ts (packages/decap-cms-core/src/actions/config.ts)
  • Hotspot: packages/decap-cms-core/src/backend.ts (packages/decap-cms-core/src/backend.ts)
  • Hotspot: packages/decap-cms-core/src/components/Editor/EditorInterface.js (packages/decap-cms-core/src/components/Editor/EditorInterface.js)
  • Hotspot: packages/decap-cms-core/src/reducers/entries.ts (packages/decap-cms-core/src/reducers/entries.ts)
  • Hotspot: packages/decap-cms-core/src/reducers/entryDraft.js (packages/decap-cms-core/src/reducers/entryDraft.js)
  • Hotspot: packages/decap-cms-widget-markdown/src/MarkdownControl/renderers.js (packages/decap-cms-widget-markdown/src/MarkdownControl/renderers.js)
  • Medium CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Medium: security finding (details withheld)
  • Off-boarding risk: anonymized user #1

New (28)

  • ClassTooLong: GitLab (packages/decap-cms-backend-gitlab/src/implementation.ts)
  • Documentation: no installation or build instructions (packages/decap-cms-widget-code/README.md)
  • FileTooLong: src/implementation.ts (packages/decap-cms-backend-gitlab/src/implementation.ts)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Low cohesion: API (LCOM4 5) (packages/decap-cms-backend-git-gateway/src/GitHubAPI.ts)
  • Low cohesion: ControlPane (LCOM4 4) (packages/decap-cms-core/src/components/Editor/EditorControlPane/EditorControlPane.js)
  • Low cohesion: TestBackend (LCOM4 15) (packages/decap-cms-backend-test/src/implementation.ts)
  • Low vulnerability: [GHSA redacted] (pnpm-lock.yaml)
  • Medium CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Medium CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • MethodTooLong: Widget.render (packages/decap-cms-core/src/components/Editor/EditorControlPane/Widget.js)
  • NotesPollingManager.checkCurrentIssue (cognitive 23) (packages/decap-cms-lib-util/src/notesPolling.ts)
  • …and 8 more

Changes since last survey

  • 3 commits — 3 feature/other, 0 fixes

By area

  • packages/decap-cms-core — 2 commits
  • packages/decap-cms — 1 commit

Notable commits

  • change: Feature/optimize editor performance (#7793)
  • change: Notes pane improvements, GitLab support (#7994)
  • change: chore(release): publish

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

decaporg/decap-cms was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 1d5868347d3d8648d7d5f7f59fc1b46595881b29 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.