editorconfig-checker/editorconfig-checker.javascript
67.8
Adequate · 21 September 2026
177
lines of production code
TypeScript
primary language
4
measurements over time
What this system is
This system is a TypeScript-based utility that downloads and executes the editorconfig-checker binary from GitHub releases. It handles platform-specific asset resolution, archive extraction, and proxy configuration using modern Node.js features. The project has been fully modernized with strict runtime requirements and automated release tooling.
Architecture
Repository restructured for TypeScript and automated releases
The project has been converted to TypeScript, introducing a new build configuration (tsconfig.json) and ESLint setup, while the legacy Node 6 runtime support has been dropped in favor of modern Node versions. To streamline development and publishing, the repository now includes configuration for Semantic Release (automated versioning and changelog generation), Conventional Commits, and Prettier, alongside updated documentation and CI badges.
(repo-wide) · high confidence
Behavioural changes
Rewritten binary download and execution logic using Node.js built-ins
The \src\ directory has been rewritten in TypeScript to handle downloading and executing the editorconfig-checker binary. The new implementation uses the Octokit library to fetch release assets from GitHub, supporting both \.tar.gz\ and \.zip\ archives, and respects \http\_proxy\ environment variables via Node.js's built-in \http.setGlobalProxyFromEnv\. It intelligently locates the correct binary for the current platform (including legacy \ec-\ naming fallbacks) and executes it, replacing the previous download mechanism.
src · high confidence
Dependencies
Major dependency overhaul and Node.js 24 requirement
The project has been significantly modernized by updating its development dependencies to their latest major versions, including TypeScript 6, ESLint 10, Prettier 3, and @types/node 26. This shift is accompanied by a strict runtime requirement for Node.js 24.14.0 or higher, reflecting the adoption of newer JavaScript features and tooling standards.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 57 → 68 (+10.5)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 96 (new)
- Architecture 69 → 69 (+0.0)
- Maturity 55 → 59 (+3.7)
- Readiness 64 → 79 (+14.6)
- Security 54 → 80 (+26.0)
Resolved (46)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 26 more
New (18)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (the committed lockfile resolved no direct production dependency)
- Documentation: no usage examples (README.md)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: [GHSA redacted] (package-lock.json)
- No ADRs found
- No dependency advisory monitoring
Changes since last survey
- 4 commits — 4 feature/other, 0 fixes
By area
- (root) — 2 commits
- .github/workflows — 1 commit
- src/index.ts — 1 commit
Notable commits
- change: chore(release): pin conventional-changelog-conventionalcommits@9 for semantic-release compatibility
- change: ci: trusted npm package publishing (OIDC)
- change: feat: support editorconfig-checker binary name for v4 with legacy ec fallback (#435)
- change: perf!: reduce package size by replacing undici with Node.js built-in proxy support (#436)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
editorconfig-checker/editorconfig-checker.javascript was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 683d5e588f1e77217a544fccac39593db320d02a — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.