jgraph/drawio-desktop
54.4
Adequate · 25 September 2026
5.2k
lines of production code
JavaScript
primary language
4
measurements over time
What this system is
This system is the desktop packaging and runtime layer for the draw.io diagramming application, built on Electron. It manages the build, signing, and distribution of native installers across Windows, macOS, Linux, and Snap platforms. The application provides a secure, hardened desktop environment that integrates the draw.io editor core, supports file preview via Quick Look, and handles diagram editing, export, and automatic updates.
Features
Initial repository structure and build configuration
The repository is initialized with the core Electron build configuration files (electron-builder-win.json, electron-builder-linux-mac.json, electron-builder-snap.json, electron-builder-appx.json, electron-builder-win-arm64.json) that define how the draw.io Desktop application is packaged for Windows, macOS, Linux, and Snap. It includes a .gitmodules file to pull the draw.io editor core as a git submodule, a sync.cjs script to manage versioning, and standard project documentation (README, LICENSE, SECURITY, CODE\_OF\_CONDUCT).
(repo-wide) · high confidence
Behavioural changes
Enhanced macOS build quality and new Quick Look preview support
The macOS installer experience is improved with a new icon generation script that applies Apple's macOS 11 design guidelines (rounded corners and shadows) and a build hook that hides system support files in the DMG to prevent UI clutter. A new Quick Look extension allows users to preview .drawio files directly in Finder using the embedded diagram viewer. Security and stability are also addressed: Electron fuses are enabled to restrict Node.js access and enforce ASAR integrity, a specific entitlement is added to allow the Quick Look extension network access, and a fix prevents crashes on macOS ARM64 by disabling a problematic V8 snapshot option.
build · high confidence
Major desktop application rewrite and security hardening
The desktop application's main process has been rewritten to address multiple security vulnerabilities and improve stability. Key changes include restricting renderer file reads and writes to user-authorised paths, preventing symbolic link following in CLI exports, and starting Windows system tools by absolute path to mitigate path traversal risks. The update mechanism now defaults to silent background updates with a 24-hour cache, and the application supports multiple input files, HTML export, and Mermaid file handling via the CLI. Additionally, the codebase has been migrated to ES Modules, upgraded to Electron 44, and includes improved error handling for CLI exports and print operations.
src/main · high confidence
Test coverage
Added tests for security, CLI, and desktop behavior fixes
Added unit tests in src/test to verify the correctness of several desktop application fixes and features: preventing GUI backup symlink writes ([GHSA redacted]), stopping CLI export from following unauthorized symbolic links ([GHSA redacted]), using absolute paths for Windows system tools ([GHSA redacted]), resetting off-screen or oversized windows to the primary display on start (\#2282), enabling auto-update for Windows arm64 builds (\#2197), watching files for the requesting window (\#2541), using the embedded exe icon for MSI shortcuts (\#2487), and validating CLI argument parsing and configuration path collection.
src/test · high confidence
Dependencies
Upgrade to Electron 44 and Node 22 with new build tooling
The desktop application has been upgraded to Electron 44.2.0 and requires Node.js 22.12.0 or later, reflecting a significant platform shift. This update introduces ES Modules support (via the "type": "module" field) and updates the build toolchain to electron-builder 26.15.7 and @electron/fuses 2.1.3. Runtime dependencies have also been refreshed, including electron-updater 6.8.9 for auto-updates, electron-log 5.4.4 for logging, and @cantoo/pdf-lib 2.7.3 for PDF handling.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 36 → 54 (+18.4)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 49 → 47 (-1.5)
- Architecture 100 (new)
- Maturity 50 → 58 (+8.3)
- Readiness 20 → 52 (+32.2)
- Security 65 → 72 (+7.2)
Resolved (47)
- (anonymous) (cognitive 108) (src/main/electron.js)
- (anonymous) (cognitive 16) (src/main/electron.js)
- (anonymous) (cyclomatic 59) (src/main/electron.js)
- Change coupling: args.js ↔ electron.js (src/main/args.js)
- Dimension evaluation failed
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 27 more
New (78)
- (anonymous) (cognitive 107) (src/main/electron.js)
- (anonymous) (cyclomatic 60) (src/main/electron.js)
- (anonymous)::processOneFile (cognitive 24) (src/main/electron.js)
- (anonymous)::processOneFile (cyclomatic 20) (src/main/electron.js)
- (anonymous)::processOneFile::startExport (cognitive 19) (src/main/electron.js)
- (anonymous)::processOneFile::startExport::reply (cognitive 31) (src/main/electron.js)
- Dependency scanning workflow never runs automatically
- Documentation: no contributor guidance (README.md)
- End-of-life runtime: Node.js 20
- FunctionTooLong: electron.exportDiagram (src/main/electron.js)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 58 more
Changes since last survey
- 72 commits — 66 feature/other, 6 fixes
By area
- (root) — 36 commits
- (repo) — 14 commits
- src/main — 13 commits
- .github/workflows — 7 commits
- doc/RELEASE_PROCESS.md — 2 commits
Notable commits
- fix: Fixes CLI export hanging on invalid Mermaid and layout errors
- fix: Fixes CLI export hanging when the vsdx importer crashes or never replies
- fix: Fixes XML extraction from attachment PDFs, removes dead merge branch
- fix: Fixes empty expression that broke both Windows workflows
- fix: Fixes export hanging when its renderer process crashes
- fix: Signs bundled DLLs, fixes unsigned unfused portable zip [jgraph/drawio-desktop#2509]
- change: Add Flathub release automation workflow
- change: Adds legacy fuse2 AppImage build [jgraph/drawio-desktop#2538]
- change: Adds tests for the configuration paths the renderer may read [jgraph/drawio-desktop#2546]
- change: Allows reading local libraries from the libraries configuration [jgraph/drawio-desktop#2546]
- change: Bumps electron to 44.2.0
- change: Changes licensing to GPL v3
- change: Corrects the release process for the PR-based prepare-release flow
- change: Documents native Windows on Arm support
- change: Documents the AppImageLauncher 3.0 requirement [jgraph/drawio-desktop#2538]
- change: Documents the submodule bump as following the drawio dev tip
- change: Documents why the Flathub release workflow is disabled
- change: Drops files the packaged app never reads from app.asar
- change: Enables auto-update for Windows arm64 builds via a latest-arm64.yml channel [jgraph/drawio-desktop#2197]
- change: Exits the CLI export on an uncaught error instead of showing a dialog
- …and 52 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
jgraph/drawio-desktop was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit f5d4c9a2f8ad7e4a4dfc50c528b72ff27ec62d42 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-dd72cc24c749.