linuxserver/Heimdall
52.3
Adequate · 26 September 2026
40.8k
lines of production code
PHP
primary language
4
measurements over time
What this system is
Heimdall is a dashboard application designed to organize and launch third-party services, featuring a centralized interface for managing pinned items, tags, and user accounts. It supports a plugin-like ecosystem where users can install and configure external applications, with robust search capabilities and customizable settings. The system provides comprehensive administration tools, including role-based access control, user impersonation, and data import/export, all secured against common web vulnerabilities.
How it got here
2018 — Laravel 13 migration and security hardening
33 changes.
The project migrated its bootstrap and configuration to Laravel 11 and later upgraded to Laravel 13 with PHP 8.4, while introducing structured controller layers and background job processing. Significant security hardening was implemented to mitigate host header injection and open redirects, alongside comprehensive updates to authentication, user management, and application integration features.
2022–2024 — Dependency modernization and internationalization
16 changes.
This period focused on modernizing the project's dependency stack, upgrading core libraries like Laravel UI to support Bootstrap 5 and Vite, and integrating PSR standards for event dispatching and HTTP clients. Concurrently, the team expanded internationalization support by adding seven new language packs and implemented database seeders to automate initial system configuration. The work was complemented by significant improvements in developer experience through IDE helper integration and comprehensive test coverage for security, helpers, and language consistency.
2025–2026 — Docker environment and form service enhancements
7 changes.
This period focused on establishing a local Docker development environment and introducing a new CustomFormBuilder service with a corresponding facade to standardize form generation. It also included significant infrastructure updates, such as adding SSRF protection, implementing TrueNAS WebSocket support, and upgrading the Doctrine Inflector library for multi-language capabilities.
Features
AWS SDK for PHP updated with new service clients and core infrastructure
The AWS SDK for PHP has been upgraded to include new client wrappers and exception classes for AWS services such as ACM Private CA, AI Ops, ARC Region Switch, ARC Zonal Shift, Access Analyzer, AWS Account, AWS Certificate Manager, Amplify, Amplify Backend, and Amplify UI Builder. Additionally, the update introduces core infrastructure components including the AbstractConfigurationProvider for managing configuration caching and chaining, and the AbstractModel and ApiProvider classes for handling API shape definitions and data resolution.
vendor/aws/aws-sdk-php · high confidence
Add public entry point and web server configuration files
The application now includes the standard public-facing assets required for deployment: an .htaccess file for Apache URL rewriting and authorization header handling, an index.php entry point bootstrapping the Laravel framework, a manifest.json for PWA support, a browserconfig.xml for Windows tiles, a robots.txt, and a mix-manifest.json for asset versioning.
public · high confidence
Added Azerbaijani, Brazilian Portuguese, Czech, Danish, German, Greek, and Spanish translations
Users can now access the application interface in Azerbaijani, Brazilian Portuguese, Czech, Danish, German, Greek, and Spanish. These new language packs cover all core application strings, authentication messages, password reset notifications, pagination controls, and validation error messages, allowing non-English speakers to navigate settings, manage applications, and handle user accounts in their preferred language.
lang · high confidence
Added Form facade for custom form service
A new Form facade has been introduced in the application, providing a static interface to the 'custom-form' service bound in the container. This allows developers to access custom form functionality via the standard Facade pattern (e.g., Form::method()) rather than resolving the service directly.
app/Facades · high confidence
Added Laravel IDE Helper for improved code autocompletion
The project now includes the \barryvdh/laravel-ide-helper\ package, which adds artisan commands (\ide-helper:generate\, \ide-helper:models\, \ide-helper:meta\, \ide-helper:eloquent\) to generate PHPDoc helper files. These files provide IDEs with accurate autocomplete and type hinting for Laravel facades, Eloquent models, and service container bindings, significantly improving the developer experience when writing code.
vendor/barryvdh/laravel-ide-helper, vendor/barryvdh/reflection-docblock, vendor/composer/pcre · high confidence
Added database factories for seeding test data
New factory classes have been introduced for the User, Item, and ItemTag models to facilitate database seeding and testing. The User factory generates users with hashed passwords and optional unverified states, while the Item factory provides unique titles and URLs. These additions support the application's testing infrastructure by allowing developers to easily create realistic mock data for these entities.
database/factories · high confidence
Added local Docker development environment
Introduced a new Docker Compose setup for local development, featuring an Nginx web server and a PHP 8.4-FPM application container. The configuration exposes port 8080 for web access, mounts the project root to serve files, and enables Xdebug for PHP debugging with remote configuration pointing to the host machine.
docker · high confidence
Added normalize.css base styles
The application now includes normalize.css v3.0.3 to standardize HTML element rendering across browsers. This adds consistent default styles for typography, form controls, and block-level elements, ensuring a uniform baseline appearance for all users.
css · high confidence
Authentication system now supports username-based login and autologin via UUID
The application's authentication controllers have been implemented to allow users to log in using their username instead of an email address. Additionally, a new autologin feature has been added, enabling users to bypass the login form by clicking a secure link containing a unique UUID, which automatically authenticates them and redirects to the dashboard. The system also includes standard registration and password reset flows.
app/Http/Controllers/Auth · high confidence
Initial Sass styling foundation for the application
The application's styling has been established through a new set of Sass source files. This includes a reset via normalize.css, a set of custom color and layout variables, and specific styles for the app layout, a marquee title animation, a color picker (Huebee), and Select2 dropdowns. These styles are compiled into the main app.scss entry point to define the visual appearance of the interface.
resources/assets/sass · high confidence
Initial application setup and authentication logic in service providers
The application now initializes its environment and database on startup via AppServiceProvider, including creating the .env file if missing, generating the application key, and handling SQLite database file creation. It also implements basic and REMOTE\_USER authentication mechanisms within a view composer, allowing users to be automatically logged in based on HTTP headers or server variables. Additionally, the RouteServiceProvider has been added to define web and API route groups, supporting the adoption of class-based routing.
app/Providers · high confidence
Initial release of dashboard view templates
This change introduces the core Blade view templates that render the application's user interface, including the main dashboard (welcome.blade.php), the item display component (item.blade.php), and the sorting logic (sortable.blade.php). It adds a dedicated view for adding pinned items (add.blade.php) with admin-only gating, a user selection screen (userselect.blade.php) that respects role-based configuration, and a basic authenticated dashboard (home.blade.php). These files collectively establish the frontend structure for displaying apps, categories, and search functionality.
resources/views · high confidence
Initial route definition for web, API, console, and broadcasting endpoints
The application now includes its first set of route definitions across four files: web, API, console, and broadcasting. The web routes establish the core user interface, including authentication (login, autologin, user selection), item management (CRUD, pinning, ordering, restoration), tag handling, search with autocomplete, settings management, and user administration. It also exposes a health check endpoint and an import feature. The API routes file is created but currently empty, awaiting future API endpoint definitions. Console and broadcasting route files are also initialized with default Laravel structures.
routes · high confidence
Initialize database seeders for settings, users, and language support
The application now includes database seeders to automatically configure initial system state. The SettingsSeeder populates setting groups (system, appearance, miscellaneous, advanced) and default settings, including a new Trianglify toggle and a search provider selector. It also dynamically detects available languages from the filesystem to populate the language selection options, falling back to English if the PHP Intl extension is missing. The UsersSeeder creates a default admin user, and the main DatabaseSeeder orchestrates the execution of these components.
database/seeders · high confidence
Introduce structured controller layer with health check and search capabilities
The application now uses a dedicated \Controller\ base class to centralize user authentication and authorization middleware, ensuring consistent access control across all endpoints. A new \HealthController\ provides a rate-limited \/health\ endpoint that reports the count of active users and dashboard items, enabling external monitoring. \SearchController\ adds support for external search providers with autocomplete suggestions for Google, Bing, and DuckDuckGo, while \ItemRestController\ exposes a JSON API for managing items and tags. Additionally, \UserController\ now supports user impersonation via a \selectUser\ action and enforces strict ownership rules when deleting users to prevent orphaned data.
app/Http/Controllers · high confidence
New authentication views for login, registration, and password recovery
The application now includes dedicated Blade templates for the core authentication flows: login, registration, and password reset. The login view supports a simplified single-user mode (when role-based authentication is disabled) that auto-fills the password field, as well as a standard multi-user form. The registration form collects name, email, and password, while the password reset flow includes both the email request and the token-based reset pages with standard validation feedback.
resources/views/auth · high confidence
New item import/export and enhanced drag-and-drop sorting
Users can now export their items to a JSON file and import them back, with the import process resolving app details and handling missing apps gracefully. The interface also features a new drag-and-drop sorting system using SortableJS, which supports nested categories and includes specific fixes for Firefox browser compatibility. Additionally, the search bar now offers autocomplete suggestions, and the password field in edit mode is masked to prevent accidental submission of unchanged passwords.
resources/assets/js · high confidence
New item management interface with import, trash, and enhanced editing
The application now provides a comprehensive set of views for managing items (applications). Users can create and edit items via a new form that includes a live preview, color picker, and support for pinned status and tags. A new import screen allows bulk adding of items via file upload. The main list view displays items with clickable URLs and tags, and includes a link to a trash view for managing soft-deleted items, where users can restore or permanently delete them. An enable toggle is also available for managing item activation status.
resources/views/items · high confidence
New register:app command with removal and bulk support
A new console command, register:app, has been added to manage local app registrations. Users can now register a specific app by providing its folder name, or register all apps at once by passing 'all' as the argument. The command also supports a --remove option to unregister an existing app, and includes logic to handle icon storage during the registration process.
app/Console · high confidence
New search interface and configurable tag filtering
The application now includes a new search form partial that renders the search UI via the App\\Search service. Additionally, a new tag list partial has been added to the dashboard, which conditionally displays tags based on the 'treat\_tags\_as' setting. When enabled, this feature allows users to filter content by tags, with support for a configurable default tag and dynamic styling based on tag colors.
resources/views/partials · high confidence
New settings management interface with import/export and access controls
The application now includes a dedicated settings management area, featuring a list view (list.blade.php) that displays settings grouped by category, with options to import and export items. The edit view (edit.blade.php) and shared form (form.blade.php) allow users to modify settings, including support for image uploads with displayed size limits and textarea formatting. Access to these settings is restricted based on user roles, with non-admin users seeing unauthorized messages for forms and limited editing capabilities for system settings.
resources/views/settings · high confidence
New tag management interface with trash and access controls
Users can now create, edit, and manage tags via a new set of views (create, edit, list, trash) that include a color picker, pinned status toggle, and icon upload. The interface enforces role-based access, displaying an unauthorized message for non-admin users, and provides a trash view to restore or permanently delete removed tags.
resources/views/tags · high confidence
New user management interface with role-based access and autologin controls
This change introduces a complete set of views for managing users, including a list view (index), creation form (create), editing form (edit), and a trash/recycle bin view (trash). The user list displays usernames, password status, and autologin URLs, while the forms allow administrators to configure user details, upload avatars, and toggle specific permissions such as 'public\_front' and 'autologin\_allow'. Access to these user management features is restricted by an \$enable\_auth\_admin\_controls\ flag; non-admin users or those without this control will see an 'unauthorized' message instead of the forms. The implementation also includes a script for autocomplete functionality on application names within the form context.
resources/views/users · high confidence
SSRF protection for URL fetching and WebSocket support for TrueNAS
The application now includes a SafeUrlFetcher helper that prevents Server-Side Request Forgery by validating that URLs use HTTP/HTTPS and resolve only to public IP addresses, re-checking this guard on every redirect hop. Additionally, a new TrueNASWebSocketClient helper enables communication with TrueNAS 25.04+ via the JSON-RPC 2.0 WebSocket API, replacing the deprecated REST API.
app/Helpers · high confidence
Security
Hardened host and proxy trust configuration
The application now enforces the TRUSTED\_HOSTS allow-list in all environments (not just non-local) to prevent host header injection, and updates the trusted proxies middleware to exclude the X-Forwarded-Host header, mitigating open redirect vulnerabilities ([CVE redacted]). Additionally, private subnets are added to the default trusted proxies to support reverse proxy setups, and the deprecated HEADER\_X\_FORWARDED\_ALL constant is replaced with specific header flags.
app/Http/Middleware · high confidence
Hardening against host header injection and open redirects
Heimdall now includes configuration options in .env.example to mitigate host header injection and open redirect vulnerabilities. Users can set TRUSTED\PROXIES to define which reverse proxies are allowed to set X-Forwarded-\ headers, and TRUSTED\_HOSTS to restrict the application to specific domain names, ensuring that requests are only served for intended hosts.
(repo-wide) · high confidence
Behavioural changes
App update and processing moved to background jobs with stricter retry and uniqueness controls
App update and processing logic has been moved from synchronous execution to background queue jobs (UpdateApps and ProcessApps). These jobs are configured to run only once per attempt ($tries = 1) and enforce uniqueness with a 10-minute lock expiration ($uniqueFor = 600) to prevent duplicate processing while allowing recovery from crashed workers. The UpdateApps job now includes a 1-second delay between individual app updates to throttle requests, and both jobs provide enhanced failure logging that includes the exception class, message, and file location.
app/Jobs · high confidence
Bootstrap configuration migrated to Laravel 11 Application Configuration
The application bootstrap process has been updated to use the new Laravel 11 application configuration structure. The traditional \bootstrap/app.php\ file now uses the fluent \Application::configure\ API to register service providers (including Spatie Html), define routing paths, and configure middleware (such as CSRF exceptions, API throttling, and custom trust hosts/proxies). Additionally, a new \bootstrap/providers.php\ file has been introduced to explicitly list application service providers, replacing the previous provider registration mechanism.
bootstrap · high confidence
Doctrine Inflector updated to v2 with multi-language support and caching
The Doctrine Inflector library has been upgraded to version 2, introducing a redesigned architecture that includes a new \CachedWordInflector\ for improved performance and support for multiple languages (English, French, Italian, Spanish, Portuguese, Turkish, Norwegian Bokmal, and Esperanto). This update changes the internal behavior of word inflection (singularization and pluralization) and may affect applications relying on the previous v1 API or specific inflection rules.
vendor/doctrine/inflector, vendor/staabm/side-effects-detector · high confidence
Introduction of Supported Apps and enhanced search provider management
The application now supports a new 'Supported Apps' ecosystem, allowing users to install and manage third-party applications (such as Plex, Nextcloud, and Gitea) via a centralized list and class-based integration. This change introduces a new \Application\ model and \SupportedApps\ service to handle app metadata, file downloads, and API testing. Additionally, the search functionality has been updated to allow users to configure custom search providers via a YAML file, with the UI automatically hiding the provider selection dropdown when only a single provider is available. The system also now validates uploaded SVG icons to prevent malicious content and supports a configurable setting to skip TLS verification for API connections.
app · high confidence
Introduction of new application and user layout templates
The application now uses newly created \app.blade.php\ and \users.blade.php\ layout files to structure the main interface and user-specific views. The main app layout integrates custom CSS and JavaScript injection points, allowing users to apply personalized styling and scripts via the settings panel. It also includes logic to conditionally display administrative controls, such as the pin list and user switching, based on role configurations. The user layout provides a streamlined structure for user-related pages, ensuring consistent asset loading and error handling.
resources/views/layouts · high confidence
Laravel UI scaffolding updated for Bootstrap 5 and Vite
The \laravel/ui\ package has been upgraded to provide authentication scaffolding and frontend presets compatible with modern tooling. The Bootstrap preset now targets Bootstrap 5.2.3 and uses Vite for asset compilation instead of Mix, while the Vue preset has been updated to use Vue 3.5.13 and the React preset to use React 18.2.0. The authentication views (login, register, password reset, etc.) have been rewritten to use Bootstrap 5 classes and the new Vite-based layout stubs. Additionally, the \league/commonmark\ package has been updated, introducing the \CommonMarkConverter\ class and \ConverterInterface\ for Markdown processing.
vendor/laravel/ui, vendor/league/commonmark · high confidence
New CustomFormBuilder service for enhanced form field support
A new CustomFormBuilder service has been introduced in the application's service layer, providing a dedicated wrapper around the Spatie Html library for generating form elements. This service adds explicit support for password fields via a new password() method, addressing previous gaps in form builder capabilities. It also standardizes the generation of text, hidden, checkbox, select, textarea, and generic input fields, ensuring consistent HTML attribute handling across the application's forms.
app/Services · high confidence
PHPUnit vendor directory updated to a new event-driven architecture
The PHPUnit library in the vendor directory has been upgraded to a version that replaces the previous event system with a new, structured event-dispatching architecture. This change introduces new core components such as \CollectingDispatcher\, \DeferringDispatcher\, and \DirectDispatcher\ to manage event flow, alongside a comprehensive set of immutable event classes (e.g., \Application\\Started\, \Test\\HookMethod\\AfterTestMethodCalled\) and their corresponding subscriber interfaces. For users, this represents a significant internal refactor of how PHPUnit reports test execution and lifecycle events, which may require updates to any custom plugins or listeners that relied on the previous event implementation.
vendor/phpunit/phpunit · high confidence
Pin session cookie name and introduce default configuration files
The application now pins the session cookie name to 'heimdall\_session' (configurable via SESSION\_COOKIE) instead of deriving it from APP\_NAME, preventing session desynchronization and 419 errors when APP\_NAME contains characters like dots or spaces. Additionally, the config directory now includes default configuration files for the application, authentication, database (defaulting to SQLite), filesystems, GitHub integration, mail, services, and sessions, providing a structured baseline for environment-specific overrides.
config · high confidence
Reassign orphaned items to prevent silent tile disappearance
A new data migration automatically reassigns items that reference deleted users to a surviving user (preferring user ID 1, or the lowest existing ID), ensuring that previously orphaned tiles and tags become visible again. The migration also includes a cache table setup and renames the password\_resets table to password\_reset\_tokens to align with framework standards.
database/migrations · high confidence
Updated CSS assets with Font Awesome Pro and Normalize.css
The public CSS assets have been updated to include Font Awesome Pro 5.15.4 (all.min.css) and Normalize.css v3.0.3 (app.css). This introduces the Pro icon set for the interface and ensures consistent cross-browser styling for HTML elements.
public/css · high confidence
Updated vendor dependencies for Laravel 7 compatibility
The project has updated several vendor packages to support Laravel 7. This includes a new version of graham-campbell/manager with updated type declarations and interfaces, and updates to php-http/httplug and php-http/promise which now include PSR-18 exception interfaces and promise implementations compatible with the new framework requirements.
vendor/graham-campbell/manager, vendor/php-http/httplug, vendor/php-http/promise · medium confidence
Updated vendor dependencies for php-invoker and cli-parser
The vendor packages phpunit/php-invoker and sebastian/cli-parser have been updated to new versions. The php-invoker update introduces a new Invoker class that uses the PCNTL extension to enforce execution timeouts, throwing a TimeoutException when exceeded, and includes specific exception classes for missing extensions. The cli-parser update replaces the command-line argument parser with a new readonly Parser class that supports both short and long options, providing detailed exceptions for ambiguous, unknown, or malformed arguments.
vendor/phpunit/php-invoker, vendor/sebastian/cli-parser · medium confidence
Updated vendor dependencies for result handling and configuration
The \graham-campbell/result-type\ and \league/config\ libraries have been updated to new versions. The result-type update introduces a new Result abstraction with distinct Success and Error classes, while the league/config update replaces the underlying configuration implementation with a new structure-based schema system, adding interfaces for configuration building, reading, and mutation.
vendor/graham-campbell/result-type, vendor/league/config · medium confidence
Fixes
Vendor phrity/websocket dependency and fix v3 exception namespace
The \phrity/websocket\ library has been vendored into the project, bringing in its core HTTP and comparison utilities (such as \phrity/http\ and \phrity/comparison\). This update resolves a v3 exception namespace issue, ensuring that exception classes are correctly located and instantiated, which prevents runtime errors when the library handles WebSocket connections and HTTP interactions.
(repo-wide) · high confidence
Test coverage
Add test infrastructure with in-memory SQLite enforcement; Added test fixtures for FakeHomePath ruleset expansion; Added unit test for language key consistency; Added unit tests for helper functions; Added unit tests for the SettingsSeeder and default tag configuration; Expanded feature test coverage for dashboard, security, and import/export functionality.
Dependencies
Added PSR-14 Event Dispatcher and PSR-18 HTTP Client interfaces
The vendor directory now includes the PSR-14 (Event Dispatcher) and PSR-18 (HTTP Client) standard interfaces. This adds \EventDispatcherInterface\, \ListenerProviderInterface\, and \StoppableEventInterface\ for event handling, alongside \ClientInterface\, \ClientExceptionInterface\, \NetworkExceptionInterface\, and \RequestExceptionInterface\ for HTTP client implementations. These interfaces provide the contracts required for applications to interact with event systems and HTTP clients in a standardized way.
vendor/psr/event-dispatcher, vendor/psr/http-client · high confidence
Updated CORS handling and URI template libraries
The application updated the fruitcake/php-cors library to a new version that introduces a dedicated InvalidOptionException and refines how CORS options (such as origins, headers, and methods) are normalized and validated, ensuring stricter configuration handling. Additionally, the guzzlehttp/uri-template library was updated to a new version providing a userland implementation of RFC 6570 URI template expansion, which may affect how dynamic URLs are constructed if the application relies on this functionality.
vendor/fruitcake/php-cors, vendor/guzzlehttp/uri-template · medium confidence
Updated Composer and Laravel Prompts vendor dependencies
The project's vendor dependencies have been updated, including a new version of Composer's class-map generator (introducing classes like ClassMap, ClassMapGenerator, FileList, PhpFileCleaner, and PhpFileParser for improved autoloading and PSR violation handling) and Laravel Prompts (adding new prompt types such as AutoCompletePrompt, Callout, and Clear, along with updated UI concerns for colors, cursor, scrolling, and theming).
(repo-wide) · high confidence
Updated email validation library to version 2.x
The \egulias/email-validator\ package has been upgraded to version 2.x. This update introduces a new validation architecture that returns structured result objects (ValidEmail/InvalidEmail) with specific reasons and warnings, replacing the previous boolean-based validation. Users may need to update their code to handle the new return types and access validation details via the result object rather than simple true/false checks.
(repo-wide) · high confidence
Updated frontend JavaScript libraries
The frontend JavaScript dependencies have been updated: jQuery has been upgraded to version 3.6.3, and the Sortable library has been updated to version 1.15.6. These changes are reflected in the compiled \public/js/app.js\ and \public/js/jquery.min.js\ files.
public/js · high confidence
Updated sebastian/complexity, sebastian/lines-of-code, and sebastian/type libraries
The vendored copies of sebastian/complexity, sebastian/lines-of-code, and sebastian/type have been replaced with newer versions. These updates modernize the underlying code analysis and type-reflection utilities used by the project's testing tooling, ensuring compatibility with current PHP versions and providing improved accuracy in cyclomatic complexity calculations, line-of-code counting, and reflection-based type mapping.
vendor/sebastian/complexity, vendor/sebastian/lines-of-code, vendor/sebastian/type · high confidence
Updated sebastian/diff, sebastian/environment, and sebastian/global-state vendor packages
The vendor copies of sebastian/diff, sebastian/environment, and sebastian/global-state have been upgraded to newer versions. This brings updated implementations for diff generation and parsing, improved console and runtime environment detection (including better support for modern PHP features and coverage drivers), and refined global state snapshotting and exclusion logic. These changes ensure compatibility with the current PHP runtime and testing infrastructure.
vendor/sebastian/diff, vendor/sebastian/environment, vendor/sebastian/global-state · high confidence
Updated vendor dependencies for Laravel Serializable Closure, Nette Utils, and Nunomaduro Collision
The project has updated several vendor dependencies, introducing new source files for laravel/serializable-closure (including contracts, serializers, and signers), nette/utils (including new classes like ArrayList, ArrayHash, and updated iterators), and nunomaduro/collision. These updates bring in new interfaces, utility classes, and internal implementations that may affect how closures are serialized, how arrays and iterators are handled, and how errors are reported, potentially requiring adjustments if your code relies on specific internal structures or deprecated methods from these libraries.
(repo-wide) · high confidence
Upgrade to Laravel 13 and PHP 8.4 with updated dependencies
The application has been upgraded to Laravel 13 and requires PHP 8.4, bringing in the latest framework features and security improvements. This change also updates core dependencies including Guzzle, AWS SDK, and various development tools like PHPUnit and ESLint, ensuring compatibility with the new PHP version and maintaining a secure, up-to-date dependency tree.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 41 → 52 (+10.9)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 94 (-5.5)
- Architecture 95 (new)
- Maturity 62 → 63 (+0.7)
- Readiness 20 → 62 (+42.6)
- Security 52 → 71 (+19.6)
- Accessibility 34 (new)
Resolved (48)
- Boundary-crossing change coupling: app.js ↔ app.js (public/js/app.js)
- Change coupling: app.js ↔ webpack.mix.js (public/js/app.js)
- Coverage not measured — test suite did not build
- Critical CVE: [GHSA redacted] (package-lock.json)
- Dimension evaluation failed
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (composer.lock)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (composer.lock)
- High CVE: [GHSA redacted] (composer.lock)
- High CVE: [GHSA redacted] (composer.lock)
- High CVE: [GHSA redacted] (composer.lock)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (composer.lock)
- High IaC: DS-0002 (docker/php/Dockerfile)
- High: security finding (details withheld)
- …and 28 more
New (102)
- (anonymous) (cognitive 58) (resources/assets/js/app.js)
- (anonymous) (cyclomatic 40) (resources/assets/js/app.js)
- AppServiceProvider.boot (cognitive 23) (app/Providers/AppServiceProvider.php)
- AppServiceProvider.boot (cyclomatic 20) (app/Providers/AppServiceProvider.php)
- Boundary-crossing change coupling: AppServiceProvider.php ↔ list.blade.php (app/Providers/AppServiceProvider.php)
- Boundary-crossing change coupling: ItemController.php ↔ list.blade.php (app/Http/Controllers/ItemController.php)
- Boundary-crossing change coupling: ItemController.php ↔ scripts.blade.php (app/Http/Controllers/ItemController.php)
- Boundary-crossing change coupling: ItemController.php ↔ welcome.blade.php (app/Http/Controllers/ItemController.php)
- Change coupling: ItemController.php ↔ TagController.php (app/Http/Controllers/ItemController.php)
- Change coupling: app.php ↔ app.php (lang/de/app.php)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Documentation: no installation or build instructions (README.md)
- Documentation: no licence statement (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (10–11 lines × 4) (database/seeders/SettingsSeeder.php)
- Duplicated block (11 lines × 2) (app/Http/Controllers/ItemController.php)
- Duplicated block (11 lines × 2) (database/seeders/SettingsSeeder.php)
- Duplicated block (11 lines × 3) (database/seeders/SettingsSeeder.php)
- Duplicated block (13 lines × 2) (app/Http/Controllers/ItemController.php)
- Duplicated block (13 lines × 4) (database/seeders/SettingsSeeder.php)
- …and 82 more
Changes since last survey
- 32 commits — 24 feature/other, 8 fixes
By area
- (repo) — 12 commits
- tests/Feature — 6 commits
- public/js — 3 commits
- app/Http — 2 commits
- config/app.php — 2 commits
- (root) — 1 commit
- app/Setting.php — 1 commit
- config/session.php — 1 commit
- docker/compose.yaml — 1 commit
- lang/az — 1 commit
- resources/views — 1 commit
- tests/Unit — 1 commit
Notable commits
- fix: Fix reordering when tags are treated as categories
- fix: Merge pull request #1585 from pilotso11/fix/session-cookie-appname-dot
- fix: Merge pull request #1594 from linuxserver/fix/reorder-categories
- fix: Merge pull request #1599 from linuxserver/fix/ssrf-redirect-and-icon
- fix: Merge pull request #1603 from azuretek/fix/roles-mode-sidenav-leak
- fix: Merge pull request #1605 from azuretek/fix/roles-header-missing-500
- fix: fix(roles): degrade instead of 500 when the roles header is absent
- fix: fix(roles): gate the sidenav pin list and #add-item on the admin role
- change: Add Azerbaijani translation
- change: Add pinned & order to import/export
- change: Bump version to 2.8.2
- change: Bump version to 2.8.3
- change: Make category drag work in Firefox and harden /order
- change: Merge pull request #1587 from linuxserver/release/v2.8.2
- change: Merge pull request #1592 from kushagharahi/add-order-pinned-import-export
- change: Merge pull request #1595 from linuxserver/feat/default-tag-home-dashboard
- change: Merge pull request #1597 from schnillerman/patch-1
- change: Merge pull request #1598 from jamalkamaladdin/feat/az-locale
- change: Merge pull request #1600 from linuxserver/release/v2.8.3
- change: Merge remote-tracking branch 'origin/2.x' into feat/default-tag-home-dashboard
- …and 12 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
linuxserver/Heimdall was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 9ad5864a80d7025db1e6eab8eb2981c165b0ddff — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.