Skip to content
CAI
Software that uses CAICheck a score

gulpjs/gulp

61.8

Adequate · 25 September 2026

61

lines of production code

JavaScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Behavioural changes

Gulp 5.0.1 hotfix and Gulp 5.0.0 major release

Gulp 5.0.1 hotfixes a globbing race condition where the read stream was opened before globbing, and resolves Node.js deprecation warnings for \fs.Stats\. The major Gulp 5.0.0 release introduces a new ESM export, supports \gulpfile.mjs\ and \gulpile.cjs\, and standardizes globbing using the \anymatch\ library. It also drops support for Node.js versions older than 10.13, removes legacy task and CLI flags, and upgrades to \chokidar\ v3 for file watching.

(repo-wide) · high confidence

Refactored CLI entry point to use gulp-cli package

The bin/gulp.js entry point has been refactored to delegate to the external gulp-cli package instead of requiring a local cli module and loading CoffeeScript. This change updates the executable to use the standardized CLI implementation, ensuring consistent command-line behavior and removing the direct dependency on the local cli module.

bin · high confidence

Refactored lib structure by removing main entry point and stream modules

The library's internal structure has been reorganized. The main entry point (lib/main.coffee) and the file stream creation module (lib/createFilesStream.coffee) have been removed. This suggests a shift away from the previous task-based or stream-based API in favor of a simpler, flatter file structure, likely aligning with the 'simple file struct' and 'flat files' changes noted in the commit history.

lib · medium confidence

Test coverage

Added comprehensive test suite for core Gulp APIs; Added test fixtures for various file types.

Dependencies

Update Gulp to version 5.0.1 with modernized dependencies

Gulp has been updated to version 5.0.1, introducing a modernized dependency stack including glob-watcher ^6.0.0, gulp-cli ^3.1.0, undertaker ^2.0.0, and vinyl-fs ^4.0.2. The package now supports ESM via index.mjs, enforces a minimum Node.js version of 10.13.0, and includes updated dev dependencies for testing and linting.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 45 → 62 (+16.6)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 58 → 70 (+11.5)
  • Architecture 69 (new)
  • Maturity 57 → 63 (+6.6)
  • Readiness 29 → 55 (+26.0)
  • Security 81 → 89 (+7.8)

Resolved (13)

  • Dimension evaluation failed
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No automated tests
  • No exposed public API
  • No tests found
  • Scanner failed to run — not a clean result
  • Test reliability not included
  • Excuse our dust! All other docs will be behind until we get everything updated. (README.md)

New (26)

  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no committed lockfile, so no resolved version to grade)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No ADRs found
  • No assertions: should call the function when file changes at a path with japanese characters (test/watch.js)
  • No assertions: should call the function when file changes: no options (test/watch.js)
  • No assertions: should call the function when file changes: w/ options (test/watch.js)
  • No assertions: should execute the gulp.parallel tasks (test/watch.js)
  • No assertions: should not call the function when ignored file changes (test/watch.js)
  • No assertions: should not call the function when no file changes: no options (test/watch.js)
  • No assertions: should work with destructuring (test/watch.js)
  • …and 6 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

gulpjs/gulp was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 61f22dc11bb14234b555253095fa1d224ce0eab1 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-dd72cc24c749.