highlightjs/highlight.js
46.9
Weak · 1 October 2026
57.5k
lines of production code
JavaScript
primary language
2
measurements over time
What this system is
This system is a syntax highlighting library that parses source code and renders it with semantic CSS classes for visual styling. It provides a modular architecture with a modern API, supporting multiple programming languages through reusable definition libraries and a robust auto-detection mechanism. The project includes a comprehensive build system for generating browser and Node.js bundles, along with extensive test coverage to ensure parser accuracy and security against regex vulnerabilities.
How it got here
2007–2014 — Modular architecture and modernization
9 changes.
The project underwent a significant structural overhaul, introducing a modular source layout, a robust build system, and strict development tooling to support modern JavaScript standards. This period focused on updating the public API, expanding language and theme support, and enhancing test coverage to ensure reliability across the new architecture.
2015–2019 — comprehensive test suite expansion
7 changes.
This period focused on establishing a robust and comprehensive testing infrastructure for the syntax highlighting engine. The work involved adding extensive API, markup, auto-detection, and parser regression tests to verify core logic and edge cases. Additionally, browser-based tests for plugins and web workers, along with build integration tests for ESM and CommonJS outputs, were implemented to ensure broad coverage and correct module consumption.
2020–2021 — modular architecture and type safety
8 changes.
The project restructured its internal codebase into a modular architecture with shared language libraries and introduced comprehensive TypeScript type definitions. This period also focused on enhancing syntax highlighting capabilities through multi-class scope matching and expanded test coverage for regex security and language-specific constructs.
Features
Add new Base16 syntax highlighting themes
The codebase now includes a wider selection of Base16 syntax highlighting themes for code blocks, such as 3024, Apathy, Apprentice, Ashes, and various Atelier variants. These new CSS styles allow users to choose from additional color palettes to customize the appearance of highlighted code snippets.
src/styles/base16 · high confidence
Initial TypeScript type definitions for highlight.js
This release introduces the \types/index.d.ts\ file, providing comprehensive TypeScript definitions for the highlight.js library. This allows TypeScript consumers to get full type safety and IntelliSense support when using the public API, including methods like \highlight\, \registerLanguage\, and \newInstance\, as well as configuration interfaces like \HLJSOptions\ and \HighlightOptions\. It also exposes internal types such as \HLJSPlugin\ for plugin development and \HLJSApi\ for creating isolated highlighter instances, ensuring that both standard usage and advanced extension scenarios are properly typed.
types · high confidence
New guide for creating third-party language definitions
Added a new 'Language Contribution Guide' in the extra directory to help users create and share their own language definitions for Highlight.js. The guide outlines the recommended workflow, which involves using a grammar template to develop grammars in independent repositories rather than within the core highlight.js project. It details the required directory structure, testing procedures using npm, and the process for publishing packages to NPM and submitting them to the supported languages list.
extra · high confidence
New interactive demo page with category and theme switching
The demo application now features a new interactive interface that allows users to filter code samples by language category and switch between syntax highlighting themes. The new \demo/index.html\ template, \demo/demo.js\ logic, and \demo/style.css\ styles implement a sidebar with category and style selectors. Clicking a category dynamically shows or hides corresponding code samples, while selecting a theme toggles the active CSS stylesheet. The page also automatically scrolls to the top when a new category is selected.
demo · high confidence
New modular build system with dedicated tooling scripts
The project introduces a new, structured build system located in the \tools/\ directory, replacing previous ad-hoc build processes. This includes a main entry point (\build.js\) that orchestrates builds for three distinct targets: \browser\ (bundling core and languages for client-side use), \cdn\ (generating optimized assets for content delivery networks, including Subresource Integrity digests), and \node\ (producing CommonJS and ESM modules with dual-package exports). Supporting this infrastructure are specialized scripts for generating size reports (\buildSizeReport.js\), validating auto-detection accuracy (\checkAutoDetect.js\), and auditing theme CSS compliance (\checkTheme.js\). The system also adds a developer tool (\developer.html\) for interactive syntax highlighting testing and theme previewing, along with library modules for dependency resolution, language metadata parsing, and Rollup-based bundling.
tools · high confidence
New shared language definition libraries for CSS, ECMAScript, Java, Swift, and Mathematica
This change introduces a new \src/languages/lib\ directory containing shared, reusable language definition modules. These libraries extract common syntax rules, keywords, and constants from existing language modes to reduce duplication and improve consistency. Specifically, \css-shared.js\ provides shared CSS modes (such as hex colors, unicode ranges, and variable detection) and tag lists; \ecmascript.js\ defines core JavaScript/TypeScript keywords (including \using\), literals, and built-in types (like \BigInt64Array\); \java.js\ standardizes numeric literal patterns; \kws\_swift.js\ consolidates Swift keywords (including \actor\, \async/await\, and \isolated\); and \mathematica.js\ exports a comprehensive list of system symbols. These modules are intended to be imported by their respective language modes to ensure uniform highlighting behavior across the library.
src/languages/lib · high confidence
New syntax highlighting themes and styles
Added a large set of new syntax highlighting themes to the styles directory, including 1c-light, a11y-dark, a11y-light, agate, an-old-hope, androidstudio, arduino-light, arta, ascetic, atom-one-dark, atom-one-dark-reasonable, atom-one-light, brown-paper, codepen-embed, color-brewer, cybertopia-cherry, cybertopia-dimmer, cybertopia-icecap, cybertopia-saturated, dark, default, devibeans, docco, equinox, far, felipec, foundation, github, github-adaptive, github-dark, github-dark-dimmed, gml, googlecode, gradient-dark, gradient-light, grayscale, hybrid, ice, and many others. These files provide CSS definitions for various visual styles for code highlighting.
src/styles · high confidence
Support for multi-class scope matching in syntax modes
The library now supports defining multiple scope classes within a single begin or end pattern for syntax highlighting modes. This change introduces a new \multi\_class.js\ extension that processes mode definitions to remap labeled scope names, ensuring that inner capture groups do not break the alignment of output scopes. Users can now use array-based \begin\ and \end\ patterns with corresponding \beginScope\ and \endScope\ objects to assign different CSS classes to different parts of a matched token, enabling more granular and accurate syntax highlighting for complex language structures.
src/lib/ext · high confidence
Architecture
New modular internal library architecture for syntax highlighting
The internal \src/lib\ codebase has been restructured into a modular architecture, replacing the previous monolithic implementation with distinct files for specific concerns. This change introduces a new \TokenTree\ and \HTMLRenderer\ system for building and rendering output, a dedicated \compile\_keywords\ module for processing language keywords, and a \compiler\_extensions\ system that allows grammars to use syntactic sugar (like \match\ or \beforeMatch\) without modifying core compiler logic. Additionally, the library now includes a \logger\ for managing deprecation warnings, an \HTMLInjectionError\ class for security handling, and a \regex\ utility module for safer pattern construction.
src/lib · high confidence
Behavioural changes
New modular source structure and API deprecations
The library source has been reorganized into a modular structure with new entry points (src/highlight.js, src/core.d.ts, src/stub.js) and internal libraries for response handling, token trees, and regex utilities. The public API has shifted to a new signature where highlight() accepts code and an options object, deprecating the legacy highlight(lang, code) signature. Additionally, the internal emitter is now a configurable beta option, and several legacy features like useBR, tabReplace, and HTML merging have been moved to internal plugins or deprecated.
src · high confidence
Standardized development environment and code quality tooling
The project now enforces consistent coding standards and build environments through the addition of several configuration files. An \.editorconfig\ ensures consistent line endings (LF) and indentation (2 spaces) across editors, while a \.gitattributes\ file guarantees JavaScript files are checked out with Unix line endings to prevent build script failures. A comprehensive \.eslintrc.js\ configuration introduces strict linting rules, enforcing ES6+ syntax, module usage, and specific style guidelines, with overrides for TypeScript and test files. Additionally, a \.dockerignore\ file and a \.readthedocs.yaml\ configuration streamline the Docker build process by excluding unnecessary files and define the environment for building documentation on Read the Docs.
(repo-wide) · high confidence
Syntax highlighting updates for multiple languages
The language definitions in src/languages have been updated to improve syntax highlighting accuracy and support for modern language features. Notable changes include adding support for Rust built-in macros (macro\_rules!, union, move, safe, r\# raw identifiers), C\# contextual keywords (scoped, record, required, file, args, dynamic), and Python 3.15 lazy import syntax. Other updates include fixing false positives in JavaScript/TypeScript (lambda parameters, template literals), improving CSS variable and pseudo-element handling, and adding new languages such as GML, GAMS, and ArcGIS Arcade.
src/languages · high confidence
Test coverage
Added API test suite for syntax highlighting core features; Added auto-detection test suite for language grammars; Added browser test suite for plugin callbacks and web workers; Added build integration tests for ESM and CommonJS outputs; Added parser regression tests for syntax highlighting edge cases; Added regex backtracking vulnerability tests; Added syntax highlighting tests for R language constructs; Added test coverage for special highlighting cases; Added test fixtures for syntax highlighting edge cases; Asynchronous markup test suite with third-party language support; Restructured test suite with new entry point and utility modules.
Dependencies
Upgrade to highlight.js 11.12.0 with Node 20+ requirement and updated build tooling
The project has been updated to version 11.12.0, introducing a minimum Node.js engine requirement of 20.0.0. Build and development dependencies have been upgraded, including Mocha to 11.0.1, Commander to 14.0.3, Rollup to 4.0.2, and jsdom to 30.0.1. Additionally, the documentation build system now uses Sphinx 9.1.0 with the Shibuya theme.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 47 → 47 (-0.6)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 48 → 48 (+0.0)
- Architecture 98 → 89 (-8.6)
- Maturity 58 → 58 (-0.0)
- Readiness 52 → 53 (+0.7)
- Security 75 → 72 (-2.1)
- Accessibility 39 → 39 (+0.0)
- Performance 60 (new)
Resolved (6)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no installation or build instructions (README.md)
- Documentation: no installation or build instructions (docs/index.rst)
- Documentation: no project overview (README.md)
- Documentation: no usage examples (docs/index.rst)
- Off-boarding risk: anonymized user #1
New (13)
- Dependency hygiene PARTLY measured — Python dependencies read, no exact pin to grade for currency
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Off-boarding risk: anonymized user #1
- Projects may be oversized for their cohesion
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
highlightjs/highlight.js was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit fc3f06392f189354eed922973635ab9e9268b983 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.