Skip to content
CAI
Software that uses CAICheck a score

GoogleChrome/workbox

54.5

Adequate · 1 October 2026

19.7k

lines of production code

TypeScript

with JavaScript

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is Workbox, a library for building and managing service workers to enable offline capabilities and caching strategies in web applications. It provides a modular toolkit for precaching assets, routing network requests, handling background synchronization, and managing cache expiration, along with build tooling to integrate these features into modern JavaScript projects. The codebase includes comprehensive test infrastructure and CLI utilities to validate service worker behavior and streamline configuration.

How it got here

2016–2018 — TypeScript migration and build modernization

34 changes.

This period focused on migrating the Workbox codebase from JavaScript to TypeScript and modernizing the build pipeline with Lerna, Rollup, and Gulp. The work included refactoring core packages like workbox-build and workbox-sw, implementing lazy-loading module proxies, and enforcing strict bundle size budgets. A comprehensive testing infrastructure was also established, featuring new utilities for service worker validation, integration tests, and automated PR checks.

2019 — TypeScript migration and test expansion

44 changes.

This period focused on migrating core Workbox packages to TypeScript and introducing comprehensive test suites for service worker integration. The work included rewriting key modules like routing, strategies, and precaching in TypeScript while adding robust infrastructure for testing iframe management, background sync, and Webpack plugin compatibility.

2020–2022 — TypeScript migration and tooling modernization

10 changes.

This period focused on migrating core Workbox packages, including the CLI, build system, and Webpack plugin, from JavaScript to TypeScript to improve type safety and developer experience. The work also introduced the workbox-recipes package for simplified caching strategies, expanded interactive demos, and enforced automated code quality checks through Husky and linting.

Features

Added TypeScript utility modules for plugin filtering and development logging

The workbox-core package now includes new TypeScript source files for utility functions. The pluginUtils module provides a filter function to select plugins based on the presence of specific callback methods, while the welcome module outputs a development-only console message guiding users to documentation and support resources when the application is not in production mode.

packages/workbox-core/src/utils · high confidence

Initial release of workbox-window v7.4.1

This change introduces the initial TypeScript implementation of the workbox-window package (v7.4.1), providing the Workbox class for managing service worker registration and lifecycle events, along with the messageSW utility for communicating with service workers. The package exports Workbox, messageSW, and WorkboxEvent types, replacing previous JavaScript sources with a fully typed codebase.

packages/workbox-window/src · high confidence

Introduction of workbox-recipes package with pre-built caching strategies

The new workbox-recipes package provides a set of pre-configured caching strategies to simplify service worker setup. It includes recipes for caching Google Fonts (using Stale-While-Revalidate for stylesheets and Cache-First for webfonts), images (Cache-First with optional cache warming), static resources like CSS and JavaScript (Stale-While-Revalidate), and pages (Network-First with a configurable network timeout). Additionally, it offers an offline fallback mechanism to serve cached versions of pages, images, and fonts when the network is unavailable, and a utility to warm strategy caches during the service worker install event.

packages/workbox-recipes · high confidence

Introduction of workbox-routing v7.4.1 with TypeScript and new route types

The workbox-routing package has been rewritten in TypeScript (v7.4.1) and introduces new route types to simplify service worker configuration. Users can now use \NavigationRoute\ to easily handle browser navigation requests with optional allow/deny lists, and \RegExpRoute\ for regular expression-based URL matching that supports capture groups. The core \Route\ class now supports per-route catch handlers via \setCatchHandler\, and the \Router\ class provides a singleton pattern with automatic fetch and cache listeners. The \registerRoute\ helper now accepts strings, RegExps, functions, or Route objects, normalizing them into the appropriate route types.

packages/workbox-routing/src · high confidence

New CacheTimestampsModel for IndexedDB-based cache expiration

A new CacheTimestampsModel class has been introduced in the workbox-expiration package to manage cache entry timestamps using IndexedDB. This model normalizes URLs, stores cache entries with timestamps, and supports expiration logic based on minimum timestamps or maximum entry counts. It handles database schema upgrades and cleans up deprecated databases, providing a robust backend for cache expiration strategies.

packages/workbox-expiration/src/models · high confidence

New JSDoc reference documentation templates

The reference documentation generation now uses a new set of Handlebars templates and localization files in \infra/templates/reference-docs/jsdoc\. This includes a custom \PublishJob\ for generating table-of-contents YAML and index pages, a \publish.js\ entry point that configures the JSDoc baseline, and a suite of view templates (e.g., \symbol-detail\, \details-table\, \layout\) that define the structure and styling of the generated API docs. A new English localization file (\lang/en.yaml\) provides the text strings used in the documentation output.

infra/templates · high confidence

New Workbox module demos added to Glitch

Added a comprehensive set of interactive demos for Workbox modules (including background-sync, broadcast-update, cacheable-response, core, expiration, google-analytics, navigation-preload, precaching, range-requests, routing, and strategies) hosted on Glitch. These examples demonstrate specific Workbox features, such as offline request retrying, cache expiration policies, and navigation preload, using Workbox version 6.1.5.

demos · high confidence

New build utility modules for bundling, publishing, and CDN management

The \gulp-tasks/utils\ directory now includes a suite of new helper modules that support the build and release pipeline. \rollup-helper.js\ configures the Rollup bundler with Babel and Terser, targeting IE11 for ES5 builds and modern browsers otherwise, while \cdn-helper.js\ manages uploading release assets to Google Cloud Storage with gzip and cache-control headers. \github-helper.js\ handles GitHub release creation and asset uploads, and \publish-helpers.js\ orchestrates downloading source code, building commits, and grouping files for release. Additional utilities include \analyse-properties.js\ for bundle size analysis, \package-runner.js\ for executing tasks across packages, and \version-module.js\ for injecting version strings into source files.

gulp-tasks/utils · high confidence

New utility modules for async debouncing and structured logging

The infra/utils area now includes two new modules: AsyncDebounce, which provides a class to manage asynchronous function execution with debouncing logic, and log-helper, which offers structured logging functions (debug, log, warn, error) with consistent formatting and color-coded output using chalk. These utilities support internal infrastructure operations by standardizing how asynchronous tasks are debounced and how log messages are formatted and displayed.

infra/utils · high confidence

PR Bot now enforces a gzip bundle size budget for Workbox packages

The PR Bot infrastructure now includes a new Aggregate Size Plugin that monitors the combined gzip size of core Workbox packages (such as workbox-core, workbox-routing, and workbox-sw). If the total gzip size exceeds 15 KB, the bot will post a warning in the PR comments; if it exceeds 100% of the budget, the PR will be automatically failed. This helps maintain strict bundle size limits for the library.

infra/pr-bot · high confidence

Workbox Range Requests plugin now supports HTTP Range headers for partial content

The workbox-range-requests package now includes a RangeRequestsPlugin that intercepts cached responses to handle requests containing a 'Range' header. When a request includes this header, the plugin slices the cached response body to return only the requested byte range with a 206 Partial Content status, rather than serving the full cached response. This enables efficient streaming and seeking for media or large files served from the cache, while preserving the original response headers and handling invalid range requests with a 416 Range Not Satisfiable response.

packages/workbox-range-requests/src · high confidence

Behavioural changes

Added TypeScript type overrides for browser APIs

The infrastructure now includes a new \type-overrides.d.ts\ file that provides TypeScript definitions for \IDBIndex\, \IDBObjectStore\, \CacheStorage\, \Headers\, and \URLSearchParams\. These overrides address known TypeScript library generator issues and bugs (tracked via linked GitHub issues) by explicitly defining iterator methods and cursor operations, ensuring stricter type checking for IndexedDB, Cache API, and Fetch API usage within the project.

infra · high confidence

Automated code formatting and linting on commit and push

The development workflow now automatically runs lint-staged before each commit and the full linter before each push. This ensures that code style and quality checks are enforced consistently, reducing manual effort and preventing unformatted or linting-violating code from entering the repository.

.husky · high confidence

Background Sync plugin and queue now support forced sync fallback

The \Queue\ class in \workbox-background-sync\ now accepts a \forceSyncFallback\ option. When enabled, the queue bypasses the browser's background sync API and instead replays queued requests immediately at service worker startup, which is useful for environments (like Electron) that expose the sync interfaces but do not implement them correctly.

packages/workbox-background-sync/src · high confidence

Background sync queue storage now uses a dedicated IndexedDB schema with relaxed durability

The background sync library replaces its previous database wrapper with a new \QueueDb\ class that manages a dedicated IndexedDB database (\workbox-background-sync\, version 3) for storing queued requests. This change introduces a specific schema with a \requests\ object store indexed by queue name, allowing for more efficient retrieval and counting of entries. Additionally, database transactions now use \durability: 'relaxed'\ to optimize write performance, and the \QueueStore\ exposes a \size()\ method to let users check the number of pending requests in a queue.

packages/workbox-background-sync/src/lib · high confidence

Core private utilities migrated to TypeScript

The internal helper modules in \packages/workbox-core/src/\_private\ (including \Deferred\, \WorkboxError\, \assert\, \cacheNames\, \logger\, and others) have been converted from JavaScript to TypeScript. This migration adds strict type definitions and improves code safety for these foundational components without changing their public API or runtime behavior.

_packages/workbox-core/src/\private · high confidence

Expiration plugin now supports custom CacheQueryOptions for deletion

The \workbox-expiration\ plugin now accepts a \matchOptions\ configuration property, allowing users to specify \CacheQueryOptions\ (such as \ignoreMethod\ or \ignoreVary\) when deleting expired cache entries. This change is implemented in the \CacheExpiration\ and \ExpirationPlugin\ classes, where the new \matchOptions\ are passed through to the underlying \cache.delete()\ calls, giving developers finer control over how stale responses are removed from the cache.

packages/workbox-expiration/src · high confidence

Introduction of TypeScript event handling utilities

The workbox-window package now includes TypeScript definitions and implementations for its internal event system. This change introduces a minimal EventTarget shim (WorkboxEventTarget) and a typed WorkboxEvent class to ensure compatibility with browsers that do not support constructable EventTarget. It also adds specific type interfaces for lifecycle events (such as installing, waiting, and activating) and message events, including the ports property for message events, while providing a utility function for URL matching.

packages/workbox-window/src/utils · high confidence

Introduction of TypeScript source files for core model constants and state

The workbox-core package now includes TypeScript source files (pluginEvents.ts and quotaErrorCallbacks.ts) that define plugin event constants and manage the set of quota error callbacks. These files replace the previous JavaScript implementations, providing native type definitions for the plugin event names and the callback registry, which improves type safety and developer experience for consumers of the library.

packages/workbox-core/src/models · medium confidence

Introduction of structured, parameterized error messages in Workbox Core

The workbox-core package now uses a centralized message generation system for runtime errors. Instead of inline string literals, errors are defined in a new \messages.ts\ map with specific codes (e.g., \invalid-value\, \not-an-array\, \incorrect-type\) and generated via \messageGenerator.ts\. This system supports parameterized details (like parameter names, expected types, and module context) in development mode, while falling back to a simpler format in production, providing more consistent and informative error reporting for developers using Workbox.

packages/workbox-core/src/models/messages · high confidence

Migrate workbox-webpack-plugin to TypeScript

The workbox-webpack-plugin source code has been rewritten in TypeScript, introducing strict type definitions for plugin configurations (GenerateSWConfig, WebpackInjectManifestOptions) and internal logic. This migration ensures better type safety for users configuring the plugin in their webpack setups and provides improved IDE autocomplete and error checking for options like exclude patterns, runtime caching rules, and service worker source paths.

packages/workbox-webpack-plugin/src · high confidence

Migration of workbox-build to TypeScript

The workbox-build package has been migrated from JavaScript to TypeScript. This change introduces a new tsconfig.json configuration file that sets the compilation target to ES2018, enables composite builds, and establishes references to internal Workbox packages such as workbox-core, workbox-precaching, and workbox-routing. Additionally, the service worker generation logic has been moved into a new TypeScript template file (sw-template.ts), and a configuration file for dependency checking (.ncurc.js) has been added to manage version updates.

packages/workbox-build · high confidence

Modernized build and release pipeline with TypeScript and Rollup

The gulp build system has been completely rewritten to support a modernized development workflow. TypeScript source files are now transpiled using a single top-level \tsc --build\ command, which also generates \.mjs\ stub files for Node.js compatibility. Browser packages are bundled using Rollup, producing ESM, legacy ESM (ES5), and UMD formats, while Node packages are built using Babel. The pipeline now includes dedicated tasks for generating JSON schemas for \workbox-build\ options, publishing to the CDN and GitHub releases, and updating Glitch demos. Additionally, the test suite has been refactored to run integration tests against stable Chrome and Firefox versions using Selenium, and a \--skipTests\ flag has been added to bypass the test suite during builds.

gulp-tasks · high confidence

Precaching utility functions rewritten in TypeScript

The utility functions in the workbox-precaching package (including cache key generation, URL variation handling, and install/cleanup logging) have been rewritten in TypeScript. This change improves type safety and maintainability of the internal precaching logic without altering the external API or user-facing behavior.

packages/workbox-precaching/src/utils · high confidence

Workbox Build migrated to TypeScript

The workbox-build package source code has been converted from JavaScript to TypeScript. This migration introduces strict type definitions for all public APIs (generateSW, getManifest, injectManifest) and internal configuration options, providing better IDE autocomplete and compile-time safety for build configurations. The change also includes updated type declarations for external dependencies and a new CDN details configuration file reflecting the latest release version.

packages/workbox-build/src · high confidence

Workbox CLI rewritten in TypeScript with new CLI architecture

The Workbox CLI source code has been converted from JavaScript to TypeScript, introducing a new entry point structure with dedicated \app.ts\ and \bin.ts\ modules. This change implements a command-driven architecture supporting \generateSW\, \injectManifest\, \wizard\, \copyLibraries\, and \help\ commands, and integrates \chokidar\ for file watching capabilities during builds. The CLI now uses \meow\ for argument parsing and includes an update notifier, while error handling has been refined to display full stack traces only when the \--debug\ flag is active.

packages/workbox-cli/src · high confidence

Workbox CLI rewritten in TypeScript with new wizard and configuration handling

The Workbox CLI core library has been migrated from JavaScript to TypeScript, introducing new internal modules for stack trace cleanup, error messaging, and logging. The configuration wizard now prompts users for the 'ignoreURLParametersMatching' setting, allowing them to specify URL search parameters to exclude from caching, and generates a CommonJS configuration file (defaulting to workbox-config.js) that can be used with generateSW or injectManifest commands.

packages/workbox-cli/src/lib · high confidence

Workbox CLI wizard prompts for service worker configuration

The Workbox CLI wizard now interactively prompts users for key configuration options, including the web app root directory, file extensions to precache, service worker source and destination paths, configuration file location, and URL query parameters to ignore. This replaces the previous behavior where these values were likely required upfront or defaulted without guidance, streamlining the setup process for new users.

packages/workbox-cli/src/lib/questions · high confidence

Workbox SW v7.4.1 global API initialization

The workbox-sw package has been updated to version 7.4.1, introducing a new global API entry point. The library now exposes a \workbox\ object on the global scope (e.g., \self.workbox\) via \index.mjs\, which instantiates the \WorkboxSW\ controller. This change simplifies integration by providing a single global namespace for Workbox modules, replacing previous import patterns, and includes updated type definitions and version metadata to support this new initialization method.

packages/workbox-sw · high confidence

Workbox Streams v7.4.1 TypeScript Refactor

The workbox-streams module has been rewritten in TypeScript (v7.4.1), introducing a new internal type definition for StreamSource and refactoring the core logic into dedicated modules (concatenate, concatenateToResponse, strategy). This change improves type safety and code organization for developers using the streaming response strategy, while maintaining the existing behavior of concatenating multiple source streams into a single Response.

packages/workbox-streams/src · high confidence

Workbox Webpack Plugin internals migrated to TypeScript

The internal library files for the workbox-webpack-plugin (located in src/lib) have been rewritten in TypeScript. This migration introduces strict typing for Webpack compilation objects and assets, ensuring more robust handling of asset hashing, manifest entry generation, and URL resolution. Users benefit from improved type safety and better integration with modern Webpack 5 features, such as the 'auto' publicPath mode, without changing the plugin's external API.

packages/workbox-webpack-plugin/src/lib · high confidence

Workbox build system migrated to TypeScript

The \workbox-build\ library source code in \src/lib\ has been converted from JavaScript to TypeScript. This migration introduces static typing for core build operations—including manifest generation, file hashing, and service worker bundling—and updates the build pipeline to use modern Rollup v4 plugins (such as \@rollup/plugin-terser\ and \@trickfilm400/rollup-plugin-off-main-thread\). For users, this ensures stricter validation of configuration inputs and improves the reliability of the generated service worker scripts through enhanced type safety.

packages/workbox-build/src/lib · high confidence

Workbox core library updated to v7.4.1 with TypeScript migration and API refinements

The workbox-core package has been updated to version 7.4.1, migrating the source code to TypeScript and restructuring internal modules. This release introduces a new \copyResponse()\ utility that allows developers to clone and modify response headers, status, or status text, while explicitly blocking cross-origin copies for security. The \skipWaiting()\ wrapper is now deprecated in favor of the native \self.skipWaiting()\, emitting a warning in non-production environments. Additionally, the public API exports refined TypeScript type definitions for route matching and handler callbacks, including the new \RouteHandlerCallbackOptions\ and \RouteHandlerObject\ interfaces, to improve type safety for service worker routing logic.

packages/workbox-core/src · high confidence

Workbox precaching restructured around a new Strategy-based architecture

The workbox-precaching module has been refactored to use a modern Strategy and Route pattern. The core \PrecacheController\ now manages the cache list and delegates asset fetching to a \PrecacheStrategy\, which enforces stricter cacheability rules (e.g., rejecting bad responses) and supports Subresource Integrity (SRI) for cache repair. A new \PrecacheRoute\ handles request matching, while a \PrecacheFallbackPlugin\ allows developers to specify an offline fallback response when a precache miss occurs. Convenience functions like \precacheAndRoute\ remain, but the internal wiring now relies on these composable strategy components.

packages/workbox-precaching/src · high confidence

Workbox strategies rewritten in TypeScript

The \workbox-strategies\ package has been rewritten in TypeScript, introducing full type definitions for all strategy classes (CacheFirst, CacheOnly, NetworkFirst, NetworkOnly, StaleWhileRevalidate) and the base Strategy class. This migration includes the addition of a dedicated StrategyHandler class to manage plugin callbacks and request lifecycle events, and exports new TypeScript interfaces such as StrategyOptions, NetworkFirstOptions, and NetworkOnlyOptions to provide stricter type checking for strategy configuration.

packages/workbox-cacheable-response/src, packages/workbox-strategies/src · high confidence

Workbox v7.4.1 release and project maintenance updates

This entry covers the v7.4.1 release of the Workbox library, which includes a change of the project license from Apache 2.0 to MIT. The update also introduces a new monorepo build configuration using Lerna (v5.6.2) and TypeScript (targeting ES2017), alongside new tooling configurations for ESLint, Prettier, and Gulp to support the migration to TypeScript. Documentation is updated to reflect that the Chrome Aurora team now maintains the project.

(repo-wide) · high confidence

WorkboxSW controller introduces lazy-loading module proxy

The WorkboxSW controller now uses a Proxy-based architecture to lazily load Workbox modules on demand. Instead of bundling all functionality upfront, accessing a namespace like workbox.routing or workbox.precaching triggers the dynamic import of the corresponding module (e.g., workbox-routing). This change supports configuration via setConfig for debug modes and custom module paths, and includes mappings for modules such as backgroundSync, navigationPreload, and recipes, optimizing initial load performance by only loading what is actually used.

packages/workbox-sw/controllers · high confidence

workbox-broadcast-update v7.4.1 release

This update releases version 7.4.1 of the workbox-broadcast-update package, which provides the BroadcastCacheUpdate class and BroadcastUpdatePlugin. These components allow developers to notify open browser tabs and windows when a cached response has been updated by comparing specific response headers (such as etag, content-length, and last-modified) and broadcasting a message via postMessage. The implementation includes logic to wait for the resulting client to exist for navigation requests and handles Safari-specific postMessage buffering behaviors.

packages/workbox-broadcast-update/src · high confidence

Fixes

Fix range request boundary calculation when start is zero

The \calculateEffectiveBoundaries\ utility in the \workbox-range-requests\ package has been corrected to properly handle cases where the range start offset is 0. Previously, the logic failed to distinguish between an undefined start and a start value of 0, leading to incorrect boundary calculations for range requests beginning at the start of the resource. This fix ensures that range requests starting at byte 0 are processed correctly, while also introducing TypeScript type definitions for the utility functions.

packages/workbox-range-requests/src/utils · high confidence

Test coverage

Added Comlink-based test infrastructure for Service Worker integration tests; Added Node.js test suite for workbox-build; Added Node.js tests for workbox-cli app logic and dependency validation; Added basic background sync test fixture; Added comprehensive test suite for package structure, exports, and build integrity; Added dependency validation tests for workbox-webpack-plugin; Added integration and unit tests for workbox-routing; Added integration test fixtures for BroadcastUpdatePlugin; Added integration tests for CacheableResponse and RangeRequests plugins; Added integration tests for Workbox caching strategies; Added integration tests for Workbox window registration and lifecycle events; Added integration tests for workbox-core service worker loading; Added service worker environment tests for CacheableResponse; Added service worker environment tests for workbox-expiration; Added service worker runtime validator for testing; Added service worker test runner templates; Added service worker tests for Workbox Google Analytics initialization; Added service worker tests for workbox-precaching; Added static test assets for Workbox service worker integration; Added static test assets for workbox-precaching; Added static test fixtures for Workbox Webpack Plugin; Added static test fixtures for the Workbox Expiration Plugin; Added static test fixtures for workbox-google-analytics integration; Added static test fixtures for workbox-routing scenarios; Added test coverage for workbox-core private utilities; Added test coverage for workbox-core service worker utilities; Added test coverage for workbox-streams; Added test fixtures for Web Worker with WASM module loading; Added test fixtures for navigation preload configuration; Added test fixtures for precaching and cache cleanup scenarios; Added test fixtures for precaching functionality; Added test fixtures for workbox-core cache names and logger; Added test helper utilities for service worker testing; Added test infrastructure for workbox-window integration tests; Added tests for WorkboxSW configuration and integration; Added tests for cacheOkAndOpaquePlugin; Added tests for service worker registration, update handling, and messaging in workbox-window; Added tests for workbox-webpack-plugin with webpack v5; Added unit and integration tests for the RangeRequestsPlugin; Added unit and integration tests for the background-sync service worker; Added unit tests for Workbox CLI wizard prompts; Added unit tests for range-request utility functions; Added unit tests for workbox-cli lib modules; New WebDriver test utilities for iframe management and service worker cleanup; New test infrastructure server components; New test server routes for service worker and window test execution; New testing infrastructure utilities for service worker and build validation.

Dependencies

Workbox 7.4.1 release with Node 20 requirement and dependency updates

This release updates the Workbox library to version 7.4.1 across all packages, including the build tooling (workbox-build) and CLI (workbox-cli). The minimum supported Node.js version has been raised to 20.0.0, requiring users to upgrade their runtime environment. Key dependency updates include bumping idb to 7.1.1 for IndexedDB support, updating @babel/runtime to 7.27.1, and migrating the rollup off-main-thread plugin to @trickfilm400/rollup-plugin-off-main-thread version 3.0.0-pre1. The workbox-build package now uses the eta templating engine and ajv 8.6.0 for schema validation, while the CLI adds update-notifier for version checks.

(dependencies) · high confidence

Workbox Google Analytics module updated to v7.4.1

The workbox-google-analytics package has been updated to version 7.4.1. This release includes the standard version identifier update and maintains the existing functionality for initializing Google Analytics tracking with service workers, including support for background sync, hit filtering, and parameter overrides.

packages/workbox-google-analytics/src · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 52 → 55 (+2.4)
  • Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 76 → 76 (+0.0)
  • Architecture 47 → 52 (+4.9)
  • Maturity 60 → 60 (+0.0)
  • Readiness 63 → 54 (-8.9)
  • Security 50 → 52 (+1.9)
  • Accessibility 59 → 59 (+0.0)
  • Performance 100 (new)

Resolved (6)

  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no project overview (README.md)
  • High CVE: [GHSA redacted] (package-lock.json)
  • Medium CVE: [GHSA redacted] (package-lock.json)
  • Off-boarding risk: anonymized user #1

New (38)

  • End-of-life runtime: Node.js 20
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • Medium CVE: [GHSA redacted] (package-lock.json)
  • Medium vulnerability: [GHSA redacted] (package-lock.json)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Off the main sequence: workbox-routing (packages/workbox-routing)
  • Off-boarding risk: anonymized user #1
  • Outdated (npm): @babel/core
  • Outdated (npm): @babel/preset-env
  • Outdated (npm): @babel/runtime
  • Outdated (npm): chalk
  • Outdated (npm): chokidar
  • Outdated (npm): common-tags
  • Outdated (npm): fs-extra
  • …and 18 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

GoogleChrome/workbox was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 4ea3138a120fd2c87389b54130e25f47e0fd7089 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.