GoogleChrome/workbox
54.5
Adequate · 1 October 2026
19.7k
lines of production code
TypeScript
with JavaScript
2
measurements over time
What this system is
This system is Workbox, a library for building and managing service workers to enable offline capabilities and caching strategies in web applications. It provides a modular toolkit for precaching assets, routing network requests, handling background synchronization, and managing cache expiration, along with build tooling to integrate these features into modern JavaScript projects. The codebase includes comprehensive test infrastructure and CLI utilities to validate service worker behavior and streamline configuration.
How it got here
2016–2018 — TypeScript migration and build modernization
34 changes.
This period focused on migrating the Workbox codebase from JavaScript to TypeScript and modernizing the build pipeline with Lerna, Rollup, and Gulp. The work included refactoring core packages like workbox-build and workbox-sw, implementing lazy-loading module proxies, and enforcing strict bundle size budgets. A comprehensive testing infrastructure was also established, featuring new utilities for service worker validation, integration tests, and automated PR checks.
2019 — TypeScript migration and test expansion
44 changes.
This period focused on migrating core Workbox packages to TypeScript and introducing comprehensive test suites for service worker integration. The work included rewriting key modules like routing, strategies, and precaching in TypeScript while adding robust infrastructure for testing iframe management, background sync, and Webpack plugin compatibility.
2020–2022 — TypeScript migration and tooling modernization
10 changes.
This period focused on migrating core Workbox packages, including the CLI, build system, and Webpack plugin, from JavaScript to TypeScript to improve type safety and developer experience. The work also introduced the workbox-recipes package for simplified caching strategies, expanded interactive demos, and enforced automated code quality checks through Husky and linting.
Features
Added TypeScript utility modules for plugin filtering and development logging
The workbox-core package now includes new TypeScript source files for utility functions. The pluginUtils module provides a filter function to select plugins based on the presence of specific callback methods, while the welcome module outputs a development-only console message guiding users to documentation and support resources when the application is not in production mode.
packages/workbox-core/src/utils · high confidence
Initial release of workbox-window v7.4.1
This change introduces the initial TypeScript implementation of the workbox-window package (v7.4.1), providing the Workbox class for managing service worker registration and lifecycle events, along with the messageSW utility for communicating with service workers. The package exports Workbox, messageSW, and WorkboxEvent types, replacing previous JavaScript sources with a fully typed codebase.
packages/workbox-window/src · high confidence
Introduction of workbox-recipes package with pre-built caching strategies
The new workbox-recipes package provides a set of pre-configured caching strategies to simplify service worker setup. It includes recipes for caching Google Fonts (using Stale-While-Revalidate for stylesheets and Cache-First for webfonts), images (Cache-First with optional cache warming), static resources like CSS and JavaScript (Stale-While-Revalidate), and pages (Network-First with a configurable network timeout). Additionally, it offers an offline fallback mechanism to serve cached versions of pages, images, and fonts when the network is unavailable, and a utility to warm strategy caches during the service worker install event.
packages/workbox-recipes · high confidence
Introduction of workbox-routing v7.4.1 with TypeScript and new route types
The workbox-routing package has been rewritten in TypeScript (v7.4.1) and introduces new route types to simplify service worker configuration. Users can now use \NavigationRoute\ to easily handle browser navigation requests with optional allow/deny lists, and \RegExpRoute\ for regular expression-based URL matching that supports capture groups. The core \Route\ class now supports per-route catch handlers via \setCatchHandler\, and the \Router\ class provides a singleton pattern with automatic fetch and cache listeners. The \registerRoute\ helper now accepts strings, RegExps, functions, or Route objects, normalizing them into the appropriate route types.
packages/workbox-routing/src · high confidence
New CacheTimestampsModel for IndexedDB-based cache expiration
A new CacheTimestampsModel class has been introduced in the workbox-expiration package to manage cache entry timestamps using IndexedDB. This model normalizes URLs, stores cache entries with timestamps, and supports expiration logic based on minimum timestamps or maximum entry counts. It handles database schema upgrades and cleans up deprecated databases, providing a robust backend for cache expiration strategies.
packages/workbox-expiration/src/models · high confidence
New JSDoc reference documentation templates
The reference documentation generation now uses a new set of Handlebars templates and localization files in \infra/templates/reference-docs/jsdoc\. This includes a custom \PublishJob\ for generating table-of-contents YAML and index pages, a \publish.js\ entry point that configures the JSDoc baseline, and a suite of view templates (e.g., \symbol-detail\, \details-table\, \layout\) that define the structure and styling of the generated API docs. A new English localization file (\lang/en.yaml\) provides the text strings used in the documentation output.
infra/templates · high confidence
New Workbox module demos added to Glitch
Added a comprehensive set of interactive demos for Workbox modules (including background-sync, broadcast-update, cacheable-response, core, expiration, google-analytics, navigation-preload, precaching, range-requests, routing, and strategies) hosted on Glitch. These examples demonstrate specific Workbox features, such as offline request retrying, cache expiration policies, and navigation preload, using Workbox version 6.1.5.
demos · high confidence
New build utility modules for bundling, publishing, and CDN management
The \gulp-tasks/utils\ directory now includes a suite of new helper modules that support the build and release pipeline. \rollup-helper.js\ configures the Rollup bundler with Babel and Terser, targeting IE11 for ES5 builds and modern browsers otherwise, while \cdn-helper.js\ manages uploading release assets to Google Cloud Storage with gzip and cache-control headers. \github-helper.js\ handles GitHub release creation and asset uploads, and \publish-helpers.js\ orchestrates downloading source code, building commits, and grouping files for release. Additional utilities include \analyse-properties.js\ for bundle size analysis, \package-runner.js\ for executing tasks across packages, and \version-module.js\ for injecting version strings into source files.
gulp-tasks/utils · high confidence
New utility modules for async debouncing and structured logging
The infra/utils area now includes two new modules: AsyncDebounce, which provides a class to manage asynchronous function execution with debouncing logic, and log-helper, which offers structured logging functions (debug, log, warn, error) with consistent formatting and color-coded output using chalk. These utilities support internal infrastructure operations by standardizing how asynchronous tasks are debounced and how log messages are formatted and displayed.
infra/utils · high confidence
PR Bot now enforces a gzip bundle size budget for Workbox packages
The PR Bot infrastructure now includes a new Aggregate Size Plugin that monitors the combined gzip size of core Workbox packages (such as workbox-core, workbox-routing, and workbox-sw). If the total gzip size exceeds 15 KB, the bot will post a warning in the PR comments; if it exceeds 100% of the budget, the PR will be automatically failed. This helps maintain strict bundle size limits for the library.
infra/pr-bot · high confidence
Workbox Range Requests plugin now supports HTTP Range headers for partial content
The workbox-range-requests package now includes a RangeRequestsPlugin that intercepts cached responses to handle requests containing a 'Range' header. When a request includes this header, the plugin slices the cached response body to return only the requested byte range with a 206 Partial Content status, rather than serving the full cached response. This enables efficient streaming and seeking for media or large files served from the cache, while preserving the original response headers and handling invalid range requests with a 416 Range Not Satisfiable response.
packages/workbox-range-requests/src · high confidence
Behavioural changes
Added TypeScript type overrides for browser APIs
The infrastructure now includes a new \type-overrides.d.ts\ file that provides TypeScript definitions for \IDBIndex\, \IDBObjectStore\, \CacheStorage\, \Headers\, and \URLSearchParams\. These overrides address known TypeScript library generator issues and bugs (tracked via linked GitHub issues) by explicitly defining iterator methods and cursor operations, ensuring stricter type checking for IndexedDB, Cache API, and Fetch API usage within the project.
infra · high confidence
Automated code formatting and linting on commit and push
The development workflow now automatically runs lint-staged before each commit and the full linter before each push. This ensures that code style and quality checks are enforced consistently, reducing manual effort and preventing unformatted or linting-violating code from entering the repository.
.husky · high confidence
Background Sync plugin and queue now support forced sync fallback
The \Queue\ class in \workbox-background-sync\ now accepts a \forceSyncFallback\ option. When enabled, the queue bypasses the browser's background sync API and instead replays queued requests immediately at service worker startup, which is useful for environments (like Electron) that expose the sync interfaces but do not implement them correctly.
packages/workbox-background-sync/src · high confidence
Background sync queue storage now uses a dedicated IndexedDB schema with relaxed durability
The background sync library replaces its previous database wrapper with a new \QueueDb\ class that manages a dedicated IndexedDB database (\workbox-background-sync\, version 3) for storing queued requests. This change introduces a specific schema with a \requests\ object store indexed by queue name, allowing for more efficient retrieval and counting of entries. Additionally, database transactions now use \durability: 'relaxed'\ to optimize write performance, and the \QueueStore\ exposes a \size()\ method to let users check the number of pending requests in a queue.
packages/workbox-background-sync/src/lib · high confidence
Core private utilities migrated to TypeScript
The internal helper modules in \packages/workbox-core/src/\_private\ (including \Deferred\, \WorkboxError\, \assert\, \cacheNames\, \logger\, and others) have been converted from JavaScript to TypeScript. This migration adds strict type definitions and improves code safety for these foundational components without changing their public API or runtime behavior.
_packages/workbox-core/src/\private · high confidence
Expiration plugin now supports custom CacheQueryOptions for deletion
The \workbox-expiration\ plugin now accepts a \matchOptions\ configuration property, allowing users to specify \CacheQueryOptions\ (such as \ignoreMethod\ or \ignoreVary\) when deleting expired cache entries. This change is implemented in the \CacheExpiration\ and \ExpirationPlugin\ classes, where the new \matchOptions\ are passed through to the underlying \cache.delete()\ calls, giving developers finer control over how stale responses are removed from the cache.
packages/workbox-expiration/src · high confidence
Introduction of TypeScript event handling utilities
The workbox-window package now includes TypeScript definitions and implementations for its internal event system. This change introduces a minimal EventTarget shim (WorkboxEventTarget) and a typed WorkboxEvent class to ensure compatibility with browsers that do not support constructable EventTarget. It also adds specific type interfaces for lifecycle events (such as installing, waiting, and activating) and message events, including the ports property for message events, while providing a utility function for URL matching.
packages/workbox-window/src/utils · high confidence
Introduction of TypeScript source files for core model constants and state
The workbox-core package now includes TypeScript source files (pluginEvents.ts and quotaErrorCallbacks.ts) that define plugin event constants and manage the set of quota error callbacks. These files replace the previous JavaScript implementations, providing native type definitions for the plugin event names and the callback registry, which improves type safety and developer experience for consumers of the library.
packages/workbox-core/src/models · medium confidence
Introduction of structured, parameterized error messages in Workbox Core
The workbox-core package now uses a centralized message generation system for runtime errors. Instead of inline string literals, errors are defined in a new \messages.ts\ map with specific codes (e.g., \invalid-value\, \not-an-array\, \incorrect-type\) and generated via \messageGenerator.ts\. This system supports parameterized details (like parameter names, expected types, and module context) in development mode, while falling back to a simpler format in production, providing more consistent and informative error reporting for developers using Workbox.
packages/workbox-core/src/models/messages · high confidence
Migrate workbox-webpack-plugin to TypeScript
The workbox-webpack-plugin source code has been rewritten in TypeScript, introducing strict type definitions for plugin configurations (GenerateSWConfig, WebpackInjectManifestOptions) and internal logic. This migration ensures better type safety for users configuring the plugin in their webpack setups and provides improved IDE autocomplete and error checking for options like exclude patterns, runtime caching rules, and service worker source paths.
packages/workbox-webpack-plugin/src · high confidence
Migration of workbox-build to TypeScript
The workbox-build package has been migrated from JavaScript to TypeScript. This change introduces a new tsconfig.json configuration file that sets the compilation target to ES2018, enables composite builds, and establishes references to internal Workbox packages such as workbox-core, workbox-precaching, and workbox-routing. Additionally, the service worker generation logic has been moved into a new TypeScript template file (sw-template.ts), and a configuration file for dependency checking (.ncurc.js) has been added to manage version updates.
packages/workbox-build · high confidence
Modernized build and release pipeline with TypeScript and Rollup
The gulp build system has been completely rewritten to support a modernized development workflow. TypeScript source files are now transpiled using a single top-level \tsc --build\ command, which also generates \.mjs\ stub files for Node.js compatibility. Browser packages are bundled using Rollup, producing ESM, legacy ESM (ES5), and UMD formats, while Node packages are built using Babel. The pipeline now includes dedicated tasks for generating JSON schemas for \workbox-build\ options, publishing to the CDN and GitHub releases, and updating Glitch demos. Additionally, the test suite has been refactored to run integration tests against stable Chrome and Firefox versions using Selenium, and a \--skipTests\ flag has been added to bypass the test suite during builds.
gulp-tasks · high confidence
Precaching utility functions rewritten in TypeScript
The utility functions in the workbox-precaching package (including cache key generation, URL variation handling, and install/cleanup logging) have been rewritten in TypeScript. This change improves type safety and maintainability of the internal precaching logic without altering the external API or user-facing behavior.
packages/workbox-precaching/src/utils · high confidence
Workbox Build migrated to TypeScript
The workbox-build package source code has been converted from JavaScript to TypeScript. This migration introduces strict type definitions for all public APIs (generateSW, getManifest, injectManifest) and internal configuration options, providing better IDE autocomplete and compile-time safety for build configurations. The change also includes updated type declarations for external dependencies and a new CDN details configuration file reflecting the latest release version.
packages/workbox-build/src · high confidence
Workbox CLI rewritten in TypeScript with new CLI architecture
The Workbox CLI source code has been converted from JavaScript to TypeScript, introducing a new entry point structure with dedicated \app.ts\ and \bin.ts\ modules. This change implements a command-driven architecture supporting \generateSW\, \injectManifest\, \wizard\, \copyLibraries\, and \help\ commands, and integrates \chokidar\ for file watching capabilities during builds. The CLI now uses \meow\ for argument parsing and includes an update notifier, while error handling has been refined to display full stack traces only when the \--debug\ flag is active.
packages/workbox-cli/src · high confidence
Workbox CLI rewritten in TypeScript with new wizard and configuration handling
The Workbox CLI core library has been migrated from JavaScript to TypeScript, introducing new internal modules for stack trace cleanup, error messaging, and logging. The configuration wizard now prompts users for the 'ignoreURLParametersMatching' setting, allowing them to specify URL search parameters to exclude from caching, and generates a CommonJS configuration file (defaulting to workbox-config.js) that can be used with generateSW or injectManifest commands.
packages/workbox-cli/src/lib · high confidence
Workbox CLI wizard prompts for service worker configuration
The Workbox CLI wizard now interactively prompts users for key configuration options, including the web app root directory, file extensions to precache, service worker source and destination paths, configuration file location, and URL query parameters to ignore. This replaces the previous behavior where these values were likely required upfront or defaulted without guidance, streamlining the setup process for new users.
packages/workbox-cli/src/lib/questions · high confidence
Workbox SW v7.4.1 global API initialization
The workbox-sw package has been updated to version 7.4.1, introducing a new global API entry point. The library now exposes a \workbox\ object on the global scope (e.g., \self.workbox\) via \index.mjs\, which instantiates the \WorkboxSW\ controller. This change simplifies integration by providing a single global namespace for Workbox modules, replacing previous import patterns, and includes updated type definitions and version metadata to support this new initialization method.
packages/workbox-sw · high confidence
Workbox Streams v7.4.1 TypeScript Refactor
The workbox-streams module has been rewritten in TypeScript (v7.4.1), introducing a new internal type definition for StreamSource and refactoring the core logic into dedicated modules (concatenate, concatenateToResponse, strategy). This change improves type safety and code organization for developers using the streaming response strategy, while maintaining the existing behavior of concatenating multiple source streams into a single Response.
packages/workbox-streams/src · high confidence
Workbox Webpack Plugin internals migrated to TypeScript
The internal library files for the workbox-webpack-plugin (located in src/lib) have been rewritten in TypeScript. This migration introduces strict typing for Webpack compilation objects and assets, ensuring more robust handling of asset hashing, manifest entry generation, and URL resolution. Users benefit from improved type safety and better integration with modern Webpack 5 features, such as the 'auto' publicPath mode, without changing the plugin's external API.
packages/workbox-webpack-plugin/src/lib · high confidence
Workbox build system migrated to TypeScript
The \workbox-build\ library source code in \src/lib\ has been converted from JavaScript to TypeScript. This migration introduces static typing for core build operations—including manifest generation, file hashing, and service worker bundling—and updates the build pipeline to use modern Rollup v4 plugins (such as \@rollup/plugin-terser\ and \@trickfilm400/rollup-plugin-off-main-thread\). For users, this ensures stricter validation of configuration inputs and improves the reliability of the generated service worker scripts through enhanced type safety.
packages/workbox-build/src/lib · high confidence
Workbox core library updated to v7.4.1 with TypeScript migration and API refinements
The workbox-core package has been updated to version 7.4.1, migrating the source code to TypeScript and restructuring internal modules. This release introduces a new \copyResponse()\ utility that allows developers to clone and modify response headers, status, or status text, while explicitly blocking cross-origin copies for security. The \skipWaiting()\ wrapper is now deprecated in favor of the native \self.skipWaiting()\, emitting a warning in non-production environments. Additionally, the public API exports refined TypeScript type definitions for route matching and handler callbacks, including the new \RouteHandlerCallbackOptions\ and \RouteHandlerObject\ interfaces, to improve type safety for service worker routing logic.
packages/workbox-core/src · high confidence
Workbox precaching restructured around a new Strategy-based architecture
The workbox-precaching module has been refactored to use a modern Strategy and Route pattern. The core \PrecacheController\ now manages the cache list and delegates asset fetching to a \PrecacheStrategy\, which enforces stricter cacheability rules (e.g., rejecting bad responses) and supports Subresource Integrity (SRI) for cache repair. A new \PrecacheRoute\ handles request matching, while a \PrecacheFallbackPlugin\ allows developers to specify an offline fallback response when a precache miss occurs. Convenience functions like \precacheAndRoute\ remain, but the internal wiring now relies on these composable strategy components.
packages/workbox-precaching/src · high confidence
Workbox strategies rewritten in TypeScript
The \workbox-strategies\ package has been rewritten in TypeScript, introducing full type definitions for all strategy classes (CacheFirst, CacheOnly, NetworkFirst, NetworkOnly, StaleWhileRevalidate) and the base Strategy class. This migration includes the addition of a dedicated StrategyHandler class to manage plugin callbacks and request lifecycle events, and exports new TypeScript interfaces such as StrategyOptions, NetworkFirstOptions, and NetworkOnlyOptions to provide stricter type checking for strategy configuration.
packages/workbox-cacheable-response/src, packages/workbox-strategies/src · high confidence
Workbox v7.4.1 release and project maintenance updates
This entry covers the v7.4.1 release of the Workbox library, which includes a change of the project license from Apache 2.0 to MIT. The update also introduces a new monorepo build configuration using Lerna (v5.6.2) and TypeScript (targeting ES2017), alongside new tooling configurations for ESLint, Prettier, and Gulp to support the migration to TypeScript. Documentation is updated to reflect that the Chrome Aurora team now maintains the project.
(repo-wide) · high confidence
WorkboxSW controller introduces lazy-loading module proxy
The WorkboxSW controller now uses a Proxy-based architecture to lazily load Workbox modules on demand. Instead of bundling all functionality upfront, accessing a namespace like workbox.routing or workbox.precaching triggers the dynamic import of the corresponding module (e.g., workbox-routing). This change supports configuration via setConfig for debug modes and custom module paths, and includes mappings for modules such as backgroundSync, navigationPreload, and recipes, optimizing initial load performance by only loading what is actually used.
packages/workbox-sw/controllers · high confidence
workbox-broadcast-update v7.4.1 release
This update releases version 7.4.1 of the workbox-broadcast-update package, which provides the BroadcastCacheUpdate class and BroadcastUpdatePlugin. These components allow developers to notify open browser tabs and windows when a cached response has been updated by comparing specific response headers (such as etag, content-length, and last-modified) and broadcasting a message via postMessage. The implementation includes logic to wait for the resulting client to exist for navigation requests and handles Safari-specific postMessage buffering behaviors.
packages/workbox-broadcast-update/src · high confidence
Fixes
Fix range request boundary calculation when start is zero
The \calculateEffectiveBoundaries\ utility in the \workbox-range-requests\ package has been corrected to properly handle cases where the range start offset is 0. Previously, the logic failed to distinguish between an undefined start and a start value of 0, leading to incorrect boundary calculations for range requests beginning at the start of the resource. This fix ensures that range requests starting at byte 0 are processed correctly, while also introducing TypeScript type definitions for the utility functions.
packages/workbox-range-requests/src/utils · high confidence
Test coverage
Added Comlink-based test infrastructure for Service Worker integration tests; Added Node.js test suite for workbox-build; Added Node.js tests for workbox-cli app logic and dependency validation; Added basic background sync test fixture; Added comprehensive test suite for package structure, exports, and build integrity; Added dependency validation tests for workbox-webpack-plugin; Added integration and unit tests for workbox-routing; Added integration test fixtures for BroadcastUpdatePlugin; Added integration tests for CacheableResponse and RangeRequests plugins; Added integration tests for Workbox caching strategies; Added integration tests for Workbox window registration and lifecycle events; Added integration tests for workbox-core service worker loading; Added service worker environment tests for CacheableResponse; Added service worker environment tests for workbox-expiration; Added service worker runtime validator for testing; Added service worker test runner templates; Added service worker tests for Workbox Google Analytics initialization; Added service worker tests for workbox-precaching; Added static test assets for Workbox service worker integration; Added static test assets for workbox-precaching; Added static test fixtures for Workbox Webpack Plugin; Added static test fixtures for the Workbox Expiration Plugin; Added static test fixtures for workbox-google-analytics integration; Added static test fixtures for workbox-routing scenarios; Added test coverage for workbox-core private utilities; Added test coverage for workbox-core service worker utilities; Added test coverage for workbox-streams; Added test fixtures for Web Worker with WASM module loading; Added test fixtures for navigation preload configuration; Added test fixtures for precaching and cache cleanup scenarios; Added test fixtures for precaching functionality; Added test fixtures for workbox-core cache names and logger; Added test helper utilities for service worker testing; Added test infrastructure for workbox-window integration tests; Added tests for WorkboxSW configuration and integration; Added tests for cacheOkAndOpaquePlugin; Added tests for service worker registration, update handling, and messaging in workbox-window; Added tests for workbox-webpack-plugin with webpack v5; Added unit and integration tests for the RangeRequestsPlugin; Added unit and integration tests for the background-sync service worker; Added unit tests for Workbox CLI wizard prompts; Added unit tests for range-request utility functions; Added unit tests for workbox-cli lib modules; New WebDriver test utilities for iframe management and service worker cleanup; New test infrastructure server components; New test server routes for service worker and window test execution; New testing infrastructure utilities for service worker and build validation.
Dependencies
Workbox 7.4.1 release with Node 20 requirement and dependency updates
This release updates the Workbox library to version 7.4.1 across all packages, including the build tooling (workbox-build) and CLI (workbox-cli). The minimum supported Node.js version has been raised to 20.0.0, requiring users to upgrade their runtime environment. Key dependency updates include bumping idb to 7.1.1 for IndexedDB support, updating @babel/runtime to 7.27.1, and migrating the rollup off-main-thread plugin to @trickfilm400/rollup-plugin-off-main-thread version 3.0.0-pre1. The workbox-build package now uses the eta templating engine and ajv 8.6.0 for schema validation, while the CLI adds update-notifier for version checks.
(dependencies) · high confidence
Workbox Google Analytics module updated to v7.4.1
The workbox-google-analytics package has been updated to version 7.4.1. This release includes the standard version identifier update and maintains the existing functionality for initializing Google Analytics tracking with service workers, including support for background sync, hit filtering, and parameter overrides.
packages/workbox-google-analytics/src · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 52 → 55 (+2.4)
- Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 76 → 76 (+0.0)
- Architecture 47 → 52 (+4.9)
- Maturity 60 → 60 (+0.0)
- Readiness 63 → 54 (-8.9)
- Security 50 → 52 (+1.9)
- Accessibility 59 → 59 (+0.0)
- Performance 100 (new)
Resolved (6)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no installation or build instructions (README.md)
- Documentation: no project overview (README.md)
- High CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Off-boarding risk: anonymized user #1
New (38)
- End-of-life runtime: Node.js 20
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium vulnerability: [GHSA redacted] (package-lock.json)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Off the main sequence: workbox-routing (packages/workbox-routing)
- Off-boarding risk: anonymized user #1
- Outdated (npm): @babel/core
- Outdated (npm): @babel/preset-env
- Outdated (npm): @babel/runtime
- Outdated (npm): chalk
- Outdated (npm): chokidar
- Outdated (npm): common-tags
- Outdated (npm): fs-extra
- …and 18 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
GoogleChrome/workbox was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 4ea3138a120fd2c87389b54130e25f47e0fd7089 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.