Skip to content
CAI
Software that uses CAICheck a score

editorconfig-checker/editorconfig-checker.javascript

67.8

Adequate · 21 September 2026

177

lines of production code

TypeScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a TypeScript-based utility that downloads and executes the editorconfig-checker binary from GitHub releases. It handles platform-specific asset resolution, archive extraction, and proxy configuration using modern Node.js features. The project has been fully modernized with strict runtime requirements and automated release tooling.

Architecture

Repository restructured for TypeScript and automated releases

The project has been converted to TypeScript, introducing a new build configuration (tsconfig.json) and ESLint setup, while the legacy Node 6 runtime support has been dropped in favor of modern Node versions. To streamline development and publishing, the repository now includes configuration for Semantic Release (automated versioning and changelog generation), Conventional Commits, and Prettier, alongside updated documentation and CI badges.

(repo-wide) · high confidence

Behavioural changes

Rewritten binary download and execution logic using Node.js built-ins

The \src\ directory has been rewritten in TypeScript to handle downloading and executing the editorconfig-checker binary. The new implementation uses the Octokit library to fetch release assets from GitHub, supporting both \.tar.gz\ and \.zip\ archives, and respects \http\_proxy\ environment variables via Node.js's built-in \http.setGlobalProxyFromEnv\. It intelligently locates the correct binary for the current platform (including legacy \ec-\ naming fallbacks) and executes it, replacing the previous download mechanism.

src · high confidence

Dependencies

Major dependency overhaul and Node.js 24 requirement

The project has been significantly modernized by updating its development dependencies to their latest major versions, including TypeScript 6, ESLint 10, Prettier 3, and @types/node 26. This shift is accompanied by a strict runtime requirement for Node.js 24.14.0 or higher, reflecting the adoption of newer JavaScript features and tooling standards.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 57 → 68 (+10.5)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 96 (new)
  • Architecture 69 → 69 (+0.0)
  • Maturity 55 → 59 (+3.7)
  • Readiness 64 → 79 (+14.6)
  • Security 54 → 80 (+26.0)

Resolved (46)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • …and 26 more

New (18)

  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (the committed lockfile resolved no direct production dependency)
  • Documentation: no usage examples (README.md)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: [GHSA redacted] (package-lock.json)
  • No ADRs found
  • No dependency advisory monitoring

Changes since last survey

  • 4 commits — 4 feature/other, 0 fixes

By area

  • (root) — 2 commits
  • .github/workflows — 1 commit
  • src/index.ts — 1 commit

Notable commits

  • change: chore(release): pin conventional-changelog-conventionalcommits@9 for semantic-release compatibility
  • change: ci: trusted npm package publishing (OIDC)
  • change: feat: support editorconfig-checker binary name for v4 with legacy ec fallback (#435)
  • change: perf!: reduce package size by replacing undici with Node.js built-in proxy support (#436)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

editorconfig-checker/editorconfig-checker.javascript was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 683d5e588f1e77217a544fccac39593db320d02a — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.