google/zx
68.6
Adequate · 25 September 2026
4.1k
lines of production code
TypeScript
with JavaScript
4
measurements over time
What this system is
This system is zx, a shell scripting tool for Node.js that has been migrated to TypeScript to provide a robust API for executing shell commands and managing processes. It supports multiple runtimes including Node.js, Deno, and Bun, and offers features like environment file loading, interactive REPL mode, and automatic dependency installation. The project includes comprehensive tooling for building, testing, and releasing across various platforms and module systems.
How it got here
2021–2022 — TypeScript migration and v8.9.0 release
8 changes.
This period focused on migrating the zx codebase to TypeScript and restructuring the build system to support ESM and CJS bundles. The work included implementing new CLI features such as environment file loading and an interactive REPL, alongside comprehensive test coverage for the new architecture and type definitions.
2024–2025 — Build automation and cross-platform testing
6 changes.
The project established a comprehensive Node.js-based build and release automation system, introducing dedicated scripts for bundling, packaging, and security auditing. To ensure reliability across diverse environments, extensive smoke and integration tests were added for Bun, Deno, Node.js, and Windows, alongside benchmarks for performance optimization. The period also included the addition of standard Unix man page documentation and updates to build artifacts for version 8.9.0.
Features
Add zx man page documentation
A new man page (man/zx.1) has been added to the project, providing users with a standard Unix manual entry for the zx CLI. This documentation covers the tool's synopsis, lists all available command-line options (such as --cwd, --shell, --prefer-local, --ext, --install, --registry, and --env), and includes usage examples, allowing users to access help via the 'man' command.
man · high confidence
New and updated example scripts for weather fetching, interactive input, and npm OIDC publishing
The examples directory now includes new scripts: fetch-weather.mjs demonstrates fetching weather data from wttr.in with a colored table output; hello.mjs shows a simple verbose command execution; interactive.mjs illustrates piping stdin to an interactive process (npm init); and npm-oidc-enable.mjs provides a bulk setup script for npm OIDC trusted publishing (requiring npm \>= 11.10.0). Additionally, background-process.mjs (renamed from basics.mjs) now demonstrates running a background server, waiting for it to be ready, and killing it. The backup-github.mjs example has been updated to fetch more repositories (per\_page=1000), use SSH clone URLs, and clone repositories sequentially instead of in parallel. The parallel.mjs example now uses the spinner utility to run tests found via glob.
examples · high confidence
New build and release automation scripts
The project now includes a suite of new Node.js scripts to manage the build pipeline and release process. The build system has been restructured with dedicated scripts for generating JavaScript bundles (build-js.mjs), TypeScript declaration files (build-dts.mjs), and cleaning up redundant build artifacts (build-clean.mjs). Release preparation is handled by scripts that generate optimized package.json files for the main and lite distributions (build-pkgjson-main.mjs, build-pkgjson-lite.mjs), as well as a JSR configuration file (build-jsr.mjs). Additional tooling includes scripts for generating export tests (build-tests.mjs), tracking dependency versions (build-versions.mjs), enforcing bundle size limits (build-size-limit.mjs), and performing security audits with configurable vulnerability allowances (npm-audit.js). Polyfills for Deno compatibility (deno.polyfill.js, import-meta-url.polyfill.js) are also provided to ensure runtime support across environments.
scripts · high confidence
Repository initialization with TypeScript build and CI configuration
The repository is initialized with a TypeScript build pipeline (tsconfig.json) and a suite of development tooling including commitlint, prettier, and lefthook for pre-commit and pre-push checks. Build size limits are defined in .size-limit.json, and the project is configured to target Node.js 24. Legacy entry points (index.mjs, zx.mjs, index.d.ts) are removed in favor of the new build structure.
(repo-wide) · high confidence
Behavioural changes
Build artifacts updated to version 8.9.0 with new dependency versions
The build output in the \build/\ directory has been regenerated for version 8.9.0. This update includes a new \3rd-party-licenses\ file listing dependencies such as \globby@16.2.0\, \chalk@5.6.2\, \yaml@2.9.0\, and \@webpod/ps@1.2.1\. The compiled CLI and core modules now reflect these dependency versions and internal changes, including the addition of the \Fail\ class and \ProcessPromise.cwd\ getter.
build · high confidence
zx v8.9.0 release with TypeScript migration and new CLI features
This release introduces zx version 8.9.0, migrating the source code to TypeScript and restructuring the internal architecture with a new internal API bus for dependency wrapping. The CLI now supports environment file loading via the --env flag, allows setting the current working directory with --cwd, and provides a new --repl flag to start an interactive Read-Eval-Print Loop. Additionally, the tooling now includes a Markdown script transformer, a dependency parser for automatic installation, and a new Fail error class with detailed exit code and signal information.
src · high confidence
Test coverage
Added TypeScript project fixture for testing; Added benchmark for buffer-to-string join strategies; Added integration tests for build artifacts and Docker container; Added smoke tests for Bun, Deno, Node.js (CJS/ESM), TypeScript, and Windows; Added test fixtures for CLI argument parsing and file handling; Added type-definition tests for core, globals, and goods modules; Comprehensive test suite for CLI, core, and utilities.
Dependencies
zx v8.9.0 release with modernized build and test fixtures
The package has been updated to version 8.9.0, introducing a comprehensive build system that generates ESM and CJS bundles in the \build/\ directory, replacing the previous single-file entry points. This change includes a migration to TypeScript, updated dev dependencies (such as TypeScript 5.9.3, esbuild 0.28.1, and globby 16.2.0), and a new lockfile format (v3). Additionally, new test fixtures (\test/fixtures/js-project\ and \test/fixtures/ts-project\) have been added to validate the package's compatibility with both JavaScript and TypeScript project setups.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 49 → 69 (+20.0)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 76 → 80 (+3.7)
- Architecture 99 (new)
- Maturity 64 → 63 (-0.5)
- Readiness 30 → 62 (+32.1)
- Security 67 → 87 (+20.3)
Resolved (78)
- Change coupling: cli.ts ↔ deps.ts (src/cli.ts)
- Change coupling: cli.ts ↔ repl.ts (src/cli.ts)
- Change coupling: core.ts ↔ vendor-core.ts (src/core.ts)
- Change coupling: goods.ts ↔ index.ts (src/goods.ts)
- Change coupling: goods.ts ↔ repl.ts (src/goods.ts)
- Change coupling: util.ts ↔ vendor-core.ts (src/util.ts)
- Dimension evaluation failed
- FileTooLong: test/core.test.js (test/core.test.js)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 58 more
New (98)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (the committed lockfile resolved no direct production dependency)
- Documentation: no installation or build instructions (README.md)
- Documentation: no licence statement (README.md)
- Documentation: no usage examples (README.md)
- FileTooLong: src/core.ts (src/core.ts)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 78 more
Changes since last survey
- 1 commits — 1 feature/other, 0 fixes
By area
- (root) — 1 commit
Notable commits
- change: Clarify shell requirement and add MAML reference (#1500)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
google/zx was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 65fc542d88baac578967e22bea28cb610976578c — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-dd72cc24c749.