Skip to content
CAI
Software that uses CAICheck a score

jenkinsci/jenkins

61.6

Weak · 29 July 2026

474

lines of production code

JavaScript

with Python

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 57 → 62 (+4.7)
  • Rubric changed (rubric-2026.08.17 → rubric-2026.08.18) — scores are not directly comparable.

Lenses

  • Architecture 100 → 100 (+0.0)
  • Maturity 55 → 55 (+0.0)
  • Readiness 48 → 56 (+7.9)
  • Security 70 → 84 (+14.2)
  • Domain Modelling 100 → 100 (+0.0)
  • Accessibility 62 → 62 (+0.0)

Resolved (42)

  • Dependency hygiene not measured — no supported dependency manifest was read
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • …and 22 more

New (3)

  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)

Changes since last survey

  • 28 commits — 25 feature/other, 3 fixes

By area

  • (root) — 16 commits
  • test/pom.xml — 3 commits
  • .github/workflows — 2 commits
  • core/src — 2 commits
  • test/src — 2 commits
  • core/pom.xml — 1 commit
  • src/checkstyle — 1 commit
  • src/main — 1 commit

Notable commits

  • fix: Fix PackedMap.values() returning keys instead of values (#27110)
  • fix: Fix missing shadow and blur on the global search results dropdown (#27113)
  • fix: Fix self-referential Javadoc links in InMemorySecurityRealm test class (#27119)
  • change: Add expression examples to "Restrict where builds can run" help (#27117)
  • change: Align GenericWhitespace ws.illegalFollow message with Checkstyle default (#27120)
  • change: Lock file maintenance (#27149)
  • change: Remove comments from properties and jelly files in shipped war (#27100)
  • change: Remove pre 2.0 detached plugins (#27098)
  • change: Update actions/checkout action to v7.0.1 (#27123)
  • change: Update dependency eslint to v10.8.0 (#27148)
  • change: Update dependency io.jenkins.plugins:font-awesome-api to v7.3.1-1013.v0835a_879ec6d (#27124)
  • change: Update dependency org.jenkins-ci.main:jenkins-test-harness to v2578 (#27125)
  • change: Update dependency org.jenkins-ci.main:remoting to v3384 (#27114)
  • change: Update dependency org.jenkins-ci.plugins:junit to v1416 (#27131)
  • change: Update dependency postcss to v8.5.21 (#27130)
  • change: Update dependency postcss to v8.5.22 (#27147)
  • change: Update dependency prettier to v3.9.6 (#27137)
  • change: Update dependency sass to v1.101.3 (#27138)
  • change: Update dependency sass to v1.101.7 (#27144)
  • change: Update dependency sass to v1.102.0 (#27150)
  • …and 8 more

Architecture

  • Unchanged — 0 containers · 1 contexts · 0 edges

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

jenkinsci/jenkins was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 29 July 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 78ba741250ab4f0b2bc21046f59354f28d1fd253 — the exact code this score is about.
  • Scored under rubric-2026.08.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer latest.