Skip to content
CAI
Software that uses CAICheck a score

IceWhaleTech/CasaOS

51.9

Adequate · 24 September 2026

10.9k

lines of production code

Go

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

CasaOS is a self-hosted personal cloud and file management system that provides a unified interface for managing local storage, cloud storage providers, and remote file systems. It exposes a RESTful API (v1 and v2) for file operations, system health monitoring, and network configuration, while handling background tasks like USB mounting and service management via systemd. The system supports multi-architecture builds and includes migration tools for version upgrades.

How it got here

2021 — CasaOS v0.4.3 release and build system overhaul

14 changes.

This period centered on the CasaOS v0.4.3 release, which introduced USB disk merging, improved file installation and sharing permissions, and fixed several system and file-related bugs. The build system was significantly restructured to support multiple architectures and include a migration tool, while the repository was rebranded from 'Oasis' to 'CasaOS' with updated documentation and code of conduct.

2022 — CasaOS migration and setup infrastructure

10 changes.

This period focused on establishing the foundational infrastructure for CasaOS, introducing a comprehensive migration framework to handle version upgrades and service management. The work included adding setup and cleanup scripts for various Linux distributions, defining systemd service units, and updating storage mount paths to standardize the installation and maintenance processes.

2023 — v2 API and cloud storage integration

6 changes.

This period focused on expanding the application's capabilities by introducing a new v2 API for file uploads, health checks, and system diagnostics. Concurrently, the codebase was enhanced with support for major cloud storage providers and an internal driver architecture for dynamic backend registration. Additionally, a message bus system was implemented to handle system and file events, accompanied by documentation generation tools.

Features

Add CasaOS migration script for version upgrades

A new migration script (03-migrate-casaos.sh) has been added to handle CasaOS version upgrades. The script detects the current and target versions, determines the appropriate migration path from a list, downloads the necessary migration tools from region-specific repositories (using Aliyun for China, GitHub otherwise), and executes them to perform the upgrade.

build/scripts/migration/script.d · high confidence

Add CasaOS setup script for Linux

A new setup script (03-setup-casaos.sh) has been added to the build system. This script dynamically locates and executes the appropriate OS-specific setup script for CasaOS, supporting various Linux distributions and versions by checking /etc/os-release.

build/scripts/setup/script.d · high confidence

Add message-bus-docgen CLI tool for generating event type documentation

A new command-line tool, message-bus-docgen, has been added to the codebase. This utility scans the application's event types and generates a Markdown document containing details about each event type, including its name, source ID, and property types with their descriptions and examples. This tool automates the creation of documentation for the message bus events.

cmd/message-bus-docgen · high confidence

Add support for Dropbox, Google Drive, and OneDrive cloud storage

Users can now connect to Dropbox, Google Drive, and OneDrive storage services. This change introduces new driver implementations for each provider, enabling file listing, authentication, and data synchronization with these cloud platforms through the application's storage interface.

drivers · high confidence

Added Arch Linux support for CasaOS service setup

A new setup script for Arch Linux has been added to the CasaOS installation process. This script handles copying configuration files, removing old service files, and enabling the service via systemd. Additionally, Debian and Ubuntu distributions now use shared or linked setup scripts to ensure consistent behavior across different Linux environments.

build/scripts/setup/service.d · high confidence

Added CasaOS cleanup scripts for Arch, Debian, and Ubuntu

New cleanup scripts have been added to the build system for Arch, Debian, and Ubuntu distributions. These scripts handle the removal of CasaOS services, configuration files, and associated Docker containers and images, ensuring a complete uninstallation of the software.

build/sysroot/usr/share/casaos/cleanup · high confidence

Added migration tool interface

A new \MigrationTool\ interface has been introduced in the \interfaces\ package, defining the contract for migration operations with methods to check if a migration is needed, and to execute pre-migration, migration, and post-migration steps.

interfaces · high confidence

Added systemd service definitions for CasaOS and rclone

New systemd unit files have been added to the system root, defining how the main CasaOS application and the rclone daemon are started and managed. The CasaOS service is configured to start after the message bus and rclone, while the rclone service is set up to manage the rclone daemon process with automatic restarts.

build/sysroot/usr · high confidence

Introduce system and file event types for message bus integration

The common package now defines specific event types for the message bus, including system utilization, file recovery, and file operations. These events are registered in the \EventTypes\ slice, enabling the application to publish and subscribe to these specific system and file-related notifications.

common · high confidence

Introduce the migration tool framework

A new migration tool is introduced to handle version upgrades. The tool includes a logging utility (log.go), a main entry point (main.go) that checks for required privileges and service status, and a dummy migration implementation (migration\_dummy.go) that serves as a placeholder for future migration logic.

cmd/migration-tool · high confidence

Introduced internal configuration and driver architecture

Added internal configuration structures for database, logging, and application settings, alongside a new driver interface and registration system that allows external storage backends to be dynamically registered and configured.

internal · high confidence

Introduces new utility packages for caching, synchronization, and file handling

The \pkg\ directory now includes several new utility packages: a thread-safe \cache\ implementation, a generic \generic\_sync\ map for concurrent map access, a \singleflight\ package to suppress duplicate function calls, and various \utils\ helpers for path manipulation, time handling, and HTTP interactions with services like Rclone and ZeroTier. Additionally, the \samba\ package provides functions to connect to and list Samba shares, while the \sign\ package implements HMAC-based signature verification. These additions support file management, network detection, and system interactions.

pkg · high confidence

New v2 API endpoints for file upload, health checks, and ZeroTier status

The v2 API surface is expanded with new endpoints: a file upload implementation allowing chunked uploads and chunk verification, health check endpoints to retrieve running/not-running services, active TCP/UDP ports, and a compressed archive of CasaOS logs, plus a ZeroTier info endpoint that reports network status. These additions provide programmatic access to file management, system health diagnostics, and network configuration.

route/v2 · high confidence

New v2 API endpoints for health checks, logs, and file uploads

The CasaOS API now exposes a new v2 specification (openapi.yaml) and a Redoc-based documentation page (index.html). The API adds health check endpoints to retrieve the status of \casaos-\*\ services, the ports currently in use, and system logs. Additionally, it introduces file-related endpoints, including a test endpoint and a chunked file upload mechanism that accepts multipart form data with parameters for path, filename, and chunk details.

api · high confidence

Removals

Removal of the legacy CasaOS UI frontend

The entire UI directory has been deleted, removing the Vue.js-based frontend application. This includes all source code (App.vue, components, assets), configuration files (.eslintrc.js, babel.config.js, .browserslistrc), environment files (.env.dev, .env.production), and public assets (icons, animations, HTML template). This change eliminates the previous web interface from the codebase.

UI · high confidence

Removed legacy webpack-bundled JavaScript assets

The pre-compiled, webpack-bundled JavaScript files (\app.js\ and \chunk-vendors.js\) have been removed from the \web/js\ directory. This change eliminates the monolithic, minified bundles that previously served the Vue.js application and its vendor dependencies (such as \axios\ and \@babel/runtime\ helpers) as single files, likely shifting the build or serving strategy for these assets.

web/js · high confidence

Behavioural changes

Added default configuration template for CasaOS

A new sample configuration file (casaos.conf.sample) has been added to the build sysroot, providing default settings for application paths, logging, database storage, and server endpoints. This establishes the baseline configuration structure for the CasaOS application.

build/sysroot/etc · high confidence

The migration script now includes download links for the CasaOS migration tool versions 0.3.5, 0.3.5.1, and a legacy version, all pointing to the v0.3.6 release assets. This enables the migration process to locate and download the appropriate tool version for older CasaOS installations.

build/scripts/migration/service.d · high confidence

CasaOS v0.4.3 release and build system overhaul

The release introduces version 0.4.3, which adds USB disk merging, improves file installation and sharing permissions, and fixes several system and file-related bugs. The build system has been significantly restructured: the project now uses GoReleaser configuration files (.goreleaser.yaml and .goreleaser.debug.yaml) to build binaries for multiple architectures (amd64, arm64, arm-7, riscv64) and includes a migration tool. The build process now embeds OpenAPI documentation, utilizes UPX for binary compression, and integrates with a message bus for status updates. Additionally, the repository has been rebranded from 'Oasis' to 'CasaOS', with updated documentation, a new code of conduct, and a contributor list.

(repo-wide) · high confidence

Major service layer refactoring and feature expansion

The service package underwent a significant structural overhaul, introducing new service modules for managing peer connections, file operations, storage mounts, and system health checks, while simultaneously removing the legacy application, DDNS, disk, and Docker management services. This change introduces new capabilities for handling SMB connections, file uploads, and remote version checks, alongside the removal of outdated Docker and DDNS implementations.

service · high confidence

Migrated API routes from Gin to Echo and added cloud storage and Samba management endpoints

The API layer in the route/v1 directory has been migrated from the Gin web framework to Echo, as evidenced by the removal of all previous Gin-based route files (app.go, ddns.go, disk.go, docker.go, share\_directory.go, shortcuts.go) and the introduction of new route handlers. New endpoints have been added to manage cloud storage services (Google Drive, Dropbox, OneDrive) for listing, mounting, and recovering storage configurations. Additionally, new routes have been introduced to manage Samba shares and remote SMB connections, including status checks, share creation/deletion, and connection management. A WebSocket-based SSH terminal interface has also been added to the route/v1 package.

route/v1 · high confidence

Migrated routing from Gin to Echo and restructured API endpoints

The application's HTTP routing layer has been migrated from the Gin framework to Echo, introducing a new modular route structure. The legacy \route/route.go\ and \route/doc.go\ files (Gin-based) have been removed and replaced with \route/init.go\, \route/periodical.go\, \route/v1.go\, and \route/v2.go\ (Echo-based). This change reorganizes the API into distinct v1 and v2 router groups, implementing new initialization logic for network mounts and system information, while maintaining backward compatibility for existing v1 endpoints and introducing new v2 endpoints for file and system management.

route · high confidence

Model layer refactored with new data structures and removed legacy app models

The model package has been significantly restructured. New data structures were added to support file operations, storage management, notifications, and system information, including \FileOperate\, \StorageA\, \NotifyModel\, and \BaseInfo\. Conversely, the legacy \app.go\ and \category.go\ models were removed, and the \net.go\ model was simplified by removing the \DateTime\ field from \IOCountersStat\.

model · high confidence

New type definitions for person, search, and notifications

The \types\ package now includes new files defining constants for friend states, person-related operations (such as add, agree, download, and upload), download states, and search application types. Additionally, the \system.go\ file containing the \CURRENTVERSION\ constant has been removed, and new notification types for person friendship status and health checks have been added to \notify.go\.

types · high confidence

Removal of USB mount rules and shell update tool

The system no longer automatically mounts USB storage devices via udev rules, and the shell script used to manage background processes (Watchmen, Oasis) and perform updates has been removed.

shell · high confidence

Removal of legacy web static assets and Go embeds

The web directory no longer includes the legacy HTML entry point (index.html), browser configuration (browserconfig.xml), and site manifest (site.webmanifest) files. Additionally, the Go source file (static.go) that embedded these static assets into the application has been removed, indicating a shift away from serving these specific legacy web resources.

web · high confidence

Removal of the Gin-based CORS middleware

The \middleware/gin.go\ file, which previously provided a CORS (Cross-Origin Resource Sharing) handler for the Gin web framework, has been removed from the codebase. This eliminates the automatic setting of headers such as \Access-Control-Allow-Origin\ and \Access-Control-Allow-Headers\ for every request processed by this middleware.

middleware · high confidence

Replaced INI configuration with a new sample configuration file

The legacy \conf/conf.ini\ file, which contained hardcoded credentials, API endpoints, and feature toggles, has been removed. It is replaced by \conf/conf.conf.sample\, a new configuration file that defines application paths, logging settings, and server modes, providing a cleaner, more secure default configuration template for users.

conf · high confidence

Updated USB storage mount paths and scripts

The shell scripts for managing USB storage have been updated. The primary change is the mount point path for USB drives, which has been changed from /media/USB\Storage\ to /DATA/USB\Storage\. The systemd service unit has been updated to reflect the new script location. Additionally, the helper script now includes a function to retrieve the system time zone, and the disk partitioning logic has been modified to use GPT partition tables and specific mkfs.ext4 options.

build/sysroot/usr/share/casaos/shell · high confidence

Dependencies

Migrated frontend SDK to TypeScript and updated Go dependencies

The project introduced a new TypeScript/Node.js SDK for the CasaOS OpenAPI, adding \package.json\ with \axios\ and OpenAPI generator tools, while removing the previous \UI/package.json\ and \UI/yarn.lock\ files. In the Go backend, the module path was updated to \github.com/IceWhaleTech/CasaOS\, the Go version was bumped to 1.21, and numerous dependencies were upgraded or replaced, including \github.com/labstack/echo/v4\, \gorm.io/gorm\, and \google/uuid\.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 47 → 52 (+5.2)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 82 → 87 (+5.7)
  • Architecture 97 → 95 (-1.8)
  • Maturity 56 → 57 (+1.2)
  • Readiness 49 → 60 (+10.9)
  • Security 41 → 45 (+4.1)
  • Domain Modelling 43 → 50 (+6.8)

Resolved (79)

  • Boundary-crossing change coupling: sys_common.go ↔ v1.go (model/sys_common.go)
  • Boundary-crossing change coupling: v1.go ↔ notify.go (route/v1.go)
  • Boundary-crossing change coupling: v1.go ↔ service.go (route/v1.go)
  • Change coupling: init.go ↔ v1.go (route/init.go)
  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical vulnerability: [GHSA redacted] (go.mod)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (drivers/dropbox/util.go)
  • Duplicated block (10 lines × 2) (drivers/onedrive/util.go)
  • Duplicated block (10 lines × 2) (pkg/utils/httper/httper.go)
  • Duplicated block (10 lines × 3) (route/v1/recover.go)
  • Duplicated block (12 lines × 2) (route/v1/file.go)
  • Duplicated block (13 lines × 2) (drivers/dropbox/util.go)
  • Duplicated block (13 lines × 2) (pkg/utils/httper/httper.go)
  • Duplicated block (13 lines × 2) (pkg/utils/httper/zerotier.go)
  • Duplicated block (15 lines × 2) (pkg/utils/file/file.go)
  • Duplicated block (16 lines × 2) (service/notify.go)
  • Duplicated block (6 lines × 2) (route/periodical.go)
  • Duplicated block (6 lines × 2) (route/v1.go)
  • …and 59 more

New (170)

  • Base-context workflow trigger runs with an unscoped token
  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency pinned to a stale untagged commit: github.com/Curtis-Milo/nat-type-identifier-go
  • Dependency pinned to a stale untagged commit: github.com/coreos/go-systemd
  • Deprecated module: github.com/deepmap/oapi-codegen
  • Duplicated block (10 lines × 2) (drivers/dropbox/util.go)
  • Duplicated block (10 lines × 2) (pkg/utils/httper/httper.go)
  • Duplicated block (11 lines × 2) (service/system.go)
  • Duplicated block (12–13 lines × 3) (route/v1/recover.go)
  • Duplicated block (14 lines × 2) (drivers/onedrive/util.go)
  • Duplicated block (15 lines × 2) (route/v2.go)
  • Duplicated block (16–17 lines × 2) (route/v1.go)
  • Duplicated block (20 lines × 2) (pkg/utils/httper/httper.go)
  • Duplicated block (24 lines × 2) (drivers/dropbox/util.go)
  • Duplicated block (24 lines × 2) (pkg/utils/httper/zerotier.go)
  • Duplicated block (26 lines × 2) (pkg/utils/file/file.go)
  • Duplicated block (48–49 lines × 2) (service/notify.go)
  • Duplicated block (5 lines × 2) (route/periodical.go)
  • Duplicated block (5 lines × 2) (route/v1.go)
  • …and 150 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

IceWhaleTech/CasaOS was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 0d3b2f444ec0193193cf03eef6d43c6e35b0183e — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-5f8d0eb43fd7.