jashkenas/underscore
60.6
Adequate · 25 September 2026
10.5k
lines of production code
JavaScript
primary language
4
measurements over time
What this system is
This system is the Underscore.js utility library, providing a collection of functional programming helpers for JavaScript arrays, collections, and objects. It has been modernized to support native ES modules alongside CommonJS and UMD formats, enabling tree-shaking and selective imports. The codebase includes a comprehensive QUnit-based test suite and utilizes Rollup for bundling to ensure compatibility and performance across various environments.
Security
Security advisory for Underscore.js template injection
The documentation and code comments for \\_.template\ now explicitly warn about the risk of code injection, directing users to the project's security policy for safe usage guidelines.
(repo-wide) · high confidence
Behavioural changes
Underscore.js modularized into ES modules with IE11 and security fixes
The library has been split into individual ES modules, enabling tree-shaking and selective imports. This release includes a fix for [CVE redacted] by making the internal flatten function iterative to prevent stack overflows, and adds a fingerprinting heuristic to correctly identify Map, WeakMap, and Set objects in IE 11.
modules · high confidence
Workaround for docco build issue via patch-package
A patch has been added to resolve a build problem in the docco documentation generator by modifying how the 'marked' library is imported within the node\_modules directory, ensuring the correct function is accessed.
patches · high confidence
Test coverage
Initial test suite for Underscore.js; Modularized test-treeshake entry points for tree-shaking evaluation; Updated QUnit test framework to version 2.10.1.
Dependencies
Add ESM support and modern build tooling
Underscore now supports native ES modules alongside its existing CommonJS and UMD formats. A new \modules/package.json\ declares the module type, and the main \package.json\ exports are configured to serve the appropriate bundle (ESM, CJS, or UMD) based on the consumer's environment. The build system has been upgraded to use Rollup for bundling and Terser for minification, replacing previous tools, and a \package-lock.json\ has been added to ensure deterministic dependency resolution.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 43 → 61 (+17.6)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 52 → 65 (+12.7)
- Architecture 100 (new)
- Maturity 54 → 51 (-2.7)
- Readiness 30 → 68 (+38.4)
- Security 70 → 80 (+10.0)
- Accessibility 68 (new)
Resolved (97)
- (anonymous) (cognitive 22) (modules/_createIndexFinder.js)
- (anonymous) (cognitive 22) (underscore-esm.js)
- (anonymous) (cognitive 22) (underscore-node-f.cjs)
- (anonymous) (cognitive 22) (underscore-umd.js)
- (anonymous) (cognitive 22) (underscore.js)
- (anonymous) (cognitive 23) (underscore-umd.js)
- (anonymous) (cognitive 23) (underscore.js)
- (anonymous) (cyclomatic 24) (underscore-umd.js)
- (anonymous) (cyclomatic 24) (underscore.js)
- Change coupling: index.js ↔ underscore-node.cjs (modules/index.js)
- Change coupling: underscore-esm-min.js ↔ underscore-umd-min.js (underscore-esm-min.js)
- Change coupling: underscore-esm.js ↔ underscore-node-f.cjs (underscore-esm.js)
- Change coupling: underscore-esm.js ↔ underscore-node.mjs (underscore-esm.js)
- Change coupling: underscore-esm.js ↔ underscore-umd.js (underscore-esm.js)
- Change coupling: underscore-node-f.cjs ↔ underscore-node.cjs (underscore-node-f.cjs)
- Change coupling: underscore-node-f.cjs ↔ underscore-node.mjs (underscore-node-f.cjs)
- Change coupling: underscore-node-f.cjs ↔ underscore-umd.js (underscore-node-f.cjs)
- Change coupling: underscore-node.cjs ↔ underscore-node.mjs (underscore-node.cjs)
- Change coupling: underscore-node.mjs ↔ underscore-umd.js (underscore-node.mjs)
- Critical CVE: [GHSA redacted] (package-lock.json)
- …and 77 more
New (87)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (the committed lockfile resolved no direct production dependency)
- Documentation: no contributor guidance
- Documentation: no installation or build instructions
- Documentation: no installation or build instructions
- Documentation: no installation or build instructions (README.md)
- Documentation: no project overview
- Documentation: no project overview
- Documentation: no usage examples
- Documentation: no usage examples
- Documentation: no usage examples (README.md)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 67 more
Changes since last survey
- 8 commits — 5 feature/other, 3 fixes
By area
- (repo) — 4 commits
- (root) — 4 commits
Notable commits
- fix: Fix isEqual symmetry for NaN and its number wrapper
- fix: Merge pull request #3018 from dkempner/fix-max-min-null-numeric-iteratee
- fix: Merge remote-tracking branch 'origin/master' into fix-max-min-null-numeric-iteratee
- change: Avoid clash with the 'delete' keyword in ES3
- change: Merge pull request #3022 from jgonggrijp/faster-isequal
- change: Merge pull request #3024 from Hugohong258/work/round-five
- change: Return early from .max/.min when the collection is nullish
- change: isEqual: avoid costly loop in cleanup per review comment by @colingm in #3022
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
jashkenas/underscore was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit db2025c3c55b3e0cac2b46dd01ee103d4c9e7b1a — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-dd72cc24c749.