gulpjs/gulp
61.8
Adequate · 25 September 2026
61
lines of production code
JavaScript
primary language
4
measurements over time
What this system is
Behavioural changes
Gulp 5.0.1 hotfix and Gulp 5.0.0 major release
Gulp 5.0.1 hotfixes a globbing race condition where the read stream was opened before globbing, and resolves Node.js deprecation warnings for \fs.Stats\. The major Gulp 5.0.0 release introduces a new ESM export, supports \gulpfile.mjs\ and \gulpile.cjs\, and standardizes globbing using the \anymatch\ library. It also drops support for Node.js versions older than 10.13, removes legacy task and CLI flags, and upgrades to \chokidar\ v3 for file watching.
(repo-wide) · high confidence
Refactored CLI entry point to use gulp-cli package
The bin/gulp.js entry point has been refactored to delegate to the external gulp-cli package instead of requiring a local cli module and loading CoffeeScript. This change updates the executable to use the standardized CLI implementation, ensuring consistent command-line behavior and removing the direct dependency on the local cli module.
bin · high confidence
Refactored lib structure by removing main entry point and stream modules
The library's internal structure has been reorganized. The main entry point (lib/main.coffee) and the file stream creation module (lib/createFilesStream.coffee) have been removed. This suggests a shift away from the previous task-based or stream-based API in favor of a simpler, flatter file structure, likely aligning with the 'simple file struct' and 'flat files' changes noted in the commit history.
lib · medium confidence
Test coverage
Added comprehensive test suite for core Gulp APIs; Added test fixtures for various file types.
Dependencies
Update Gulp to version 5.0.1 with modernized dependencies
Gulp has been updated to version 5.0.1, introducing a modernized dependency stack including glob-watcher ^6.0.0, gulp-cli ^3.1.0, undertaker ^2.0.0, and vinyl-fs ^4.0.2. The package now supports ESM via index.mjs, enforces a minimum Node.js version of 10.13.0, and includes updated dev dependencies for testing and linting.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 45 → 62 (+16.6)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 58 → 70 (+11.5)
- Architecture 69 (new)
- Maturity 57 → 63 (+6.6)
- Readiness 29 → 55 (+26.0)
- Security 81 → 89 (+7.8)
Resolved (13)
- Dimension evaluation failed
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- No automated tests
- No exposed public API
- No tests found
- Scanner failed to run — not a clean result
- Test reliability not included
- Excuse our dust! All other docs will be behind until we get everything updated. (README.md)
New (26)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no committed lockfile, so no resolved version to grade)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- No ADRs found
- No assertions: should call the function when file changes at a path with japanese characters (test/watch.js)
- No assertions: should call the function when file changes: no options (test/watch.js)
- No assertions: should call the function when file changes: w/ options (test/watch.js)
- No assertions: should execute the gulp.parallel tasks (test/watch.js)
- No assertions: should not call the function when ignored file changes (test/watch.js)
- No assertions: should not call the function when no file changes: no options (test/watch.js)
- No assertions: should work with destructuring (test/watch.js)
- …and 6 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
gulpjs/gulp was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 61f22dc11bb14234b555253095fa1d224ce0eab1 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-dd72cc24c749.