Skip to content
CAI
Software that uses CAICheck a score

lovell/sharp

54.5

Adequate · 25 September 2026

6.4k

lines of production code

JavaScript

with C++, C

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a high-performance image processing library that wraps the libvips C++ library to provide efficient image manipulation capabilities. It supports a wide range of platforms and architectures, including native binaries for various operating systems and WebAssembly targets for browser-like environments. The library offers comprehensive tooling for developers, including dual ESM/CommonJS module support, TypeScript definitions, and extensive testing suites for performance, memory safety, and type correctness.

How it got here

2013–2014 — Modernization and testing infrastructure

6 changes.

The project upgraded its native dependencies to require C++17 and modern N-API, rewriting core bindings to support newer libvips versions and broader platform binaries including WebAssembly. Concurrently, the testing infrastructure was significantly enhanced by migrating to the Node.js native test runner, adding Docker-based performance benchmarks, and implementing automated memory leak detection and robust visual similarity assertions.

2015–2023 — ESM modularization and WebAssembly support

4 changes.

The library was refactored from a monolithic structure into modular ESM source files, with corresponding updates to TypeScript definitions. Concurrently, build infrastructure was added to support WebAssembly (wasm32) via Emscripten, including dedicated export stubs for CommonJS and ES Module consumers on specific platforms.

2025–2026 — Build system modernization and ESM support

4 changes.

The project overhauled its build process to generate dual ESM and CommonJS packages with TypeScript definitions, while making native source builds an opt-in step. Concurrently, it fixed WebAssembly memory handling issues and added comprehensive type tests to ensure robustness across different module systems and environments.

Features

Add ESM and CommonJS export stubs for WebAssembly platforms

The npm package now includes dedicated export files for the freebsd-wasm32 and webcontainers-wasm32 platforms, providing both CommonJS (\.cjs\) and ES Module (\.mjs\) entry points. These stubs re-export package metadata, version information, and the prebuilt WebAssembly binary from the \@img/sharp-wasm32\ package, ensuring that consumers using either module system can correctly resolve the WebAssembly support.

npm · high confidence

Add Emscripten build infrastructure for WebAssembly (wasm32)

This change introduces the necessary build configuration and runtime initialization code to support building the project as a WebAssembly module (wasm32 target). A new \common.gypi\ file defines the Emscripten-specific compiler and linker flags, including thread support and specific exports for VIPS and libuv shutdown functions. Additionally, a \pre.js\ script is added to handle module initialization, setting up the concurrency environment via \VIPS\_CONCURRENCY\, initializing the EMNAPI runtime context, and ensuring proper cleanup of native resources when the process exits.

src/emscripten · high confidence

Architecture

Library refactored into modular ESM source files

The library's internal structure has been reorganized from a single monolithic file into distinct, modular ESM source files (e.g., \lib/channel.mjs\, \lib/colour.mjs\, \lib/composite.mjs\, \lib/constructor.mjs\, \lib/input.mjs\, \lib/operation.mjs\, \lib/output.mjs\, \lib/utility.mjs\). These modules are now aggregated and exported via a new \lib/index.mjs\ entry point, and the TypeScript definitions in \lib/index.d.ts\ have been updated to reflect this new module structure.

lib · high confidence

Behavioural changes

Build script now generates dual ESM/CJS packages and type definitions

The build process has been updated to automatically produce both ES Module (.mjs) and CommonJS (.cjs) output files, along with corresponding TypeScript declaration files (.d.mts and .d.cts). This ensures the library is compatible with both modern ESM-based runtimes and legacy CommonJS environments, resolving previous issues with dual-module support.

scripts · high confidence

Building from source is now opt-in

The installation process no longer attempts to build the native libvips addon from source by default. A new \install/build.js\ script has been introduced to handle source builds, meaning users must now explicitly opt-in to building from source (e.g., by ensuring dependencies like \node-addon-api\ and \node-gyp\ are present) rather than having it happen automatically during installation.

install · high confidence

Sharp v0.33.0: C++17 requirement and libvips 8.18.6 minimum

The native binding now requires a C++17 compiler and libvips 8.18.6 or later, enforced at compile time. The build configuration (binding.gyp) sets the C++17 standard for Windows and uses N-API version 9, while the C++ source files (common.h, common.cc, metadata.cc, operations.cc) are rewritten to use the modern Napi API and the libvips C++ bindings. This change drops support for older Node.js versions and libvips releases, and may require users to update their build toolchains and system dependencies.

src · high confidence

Fixes

Fix wasm32 build by handling shared/resizable memory views in emnapi

The emnapi library patch now correctly handles SharedArrayBuffer and resizable memory buffers when decoding UTF-8 and UTF-16 strings in the wasm32 target. Previously, the code used a helper that likely failed or produced incorrect results with these memory types; the fix introduces a getHeapViewOrCopy function that slices the heap for shared/resizable buffers and uses subarray otherwise, ensuring string decoding works correctly in WebAssembly environments that utilize these advanced memory features.

patches · high confidence

Test coverage

123 commits adding/updating tests in test/fixtures/expected; Add SVG test fixtures and fingerprint-based test helpers; Added Docker-based performance benchmarking suite; Added TypeScript type tests for Sharp; Added automated memory leak detection tests; Migrate unit tests to Node.js native test runner.

Dependencies

Sharp v0.35.5-rc.0 prebuilt binaries and documentation tooling

This release introduces prebuilt native binaries for Sharp v0.35.5-rc.0 across a wide range of platforms, including macOS (arm64, x64), Linux (glibc and musl variants for arm, arm64, ppc64, riscv64, s390x, x64), Windows (arm64, ia32, x64), and FreeBSD (wasm32). The package also adds WebAssembly support via the \@img/sharp-wasm32\ and \@img/sharp-webcontainers-wasm32\ packages, enabling image processing in browser-like environments. Additionally, the documentation site has been updated to use Astro 7 and Starlight 0.42.2 for improved generation and navigation.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 38 → 55 (+16.4)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 33 → 43 (+10.0)
  • Architecture 100 (new)
  • Maturity 57 → 57 (+0.0)
  • Readiness 29 → 64 (+34.2)
  • Security 75 → 76 (+1.1)

Resolved (61)

  • (anonymous) (cognitive 33) (lib/composite.mjs)
  • (anonymous) (cyclomatic 21) (lib/composite.mjs)
  • A robots.txt directive restricts indexing of the site but does not itself provide useful documentation value. (docs/public/robots.txt)
  • Dimension evaluation failed
  • FileTooLong: lib/input.mjs (lib/input.mjs)
  • FileTooLong: lib/operation.mjs (lib/operation.mjs)
  • FileTooLong: lib/resize.mjs (lib/resize.mjs)
  • FileTooLong: unit/metadata.js (test/unit/metadata.js)
  • FileTooLong: unit/tile.js (test/unit/tile.js)
  • High IaC: DS-0002 (test/bench/Dockerfile)
  • High IaC: DS-0029 (test/bench/Dockerfile)
  • High IaC: DS-0029 (test/bench/Dockerfile)
  • High IaC: DS-0029 (test/bench/Dockerfile)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Hotspot: lib/composite.mjs (lib/composite.mjs)
  • Hotspot: lib/input.mjs (lib/input.mjs)
  • Low IaC: DS-0026 (test/bench/Dockerfile)
  • …and 41 more

New (61)

  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no committed lockfile, so no resolved version to grade)
  • Documentation: no installation or build instructions
  • Documentation: no project overview
  • FunctionTooLong: input._createInputDescriptor (lib/input.mjs)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Job-level write token spans steps that do not need it
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • …and 41 more

Changes since last survey

  • 26 commits — 25 feature/other, 1 fixes

By area

  • (root) — 8 commits
  • docs/src — 6 commits
  • .github/workflows — 3 commits
  • lib/sharp.mjs — 2 commits
  • src/common.cc — 2 commits
  • .github/SECURITY.md — 1 commit
  • lib/constructor.mjs — 1 commit
  • lib/index.d.ts — 1 commit
  • test/types — 1 commit
  • test/unit — 1 commit

Notable commits

  • fix: CI: Fix wasm32 build (#4589)
  • change: Add upper bounds check on length of linear and GIF delay arrays
  • change: Bound resize dimensions to coordinate limit
  • change: Bump pnpm/action-setup from 6.0.10 to 6.1.0 (#4598)
  • change: Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (#4588)
  • change: Create image on demand, reduces memory consumption
  • change: Docs: Add (refreshed) contributing page to website
  • change: Docs: Add (refreshed) security page to website
  • change: Docs: autoOrient handles only EXIF Orientation (#4587)
  • change: Docs: changelog entries for #4578 #4584
  • change: Ensure info.pages is correct when limiting input page range (#4578)
  • change: Improve gain map support for extract operation #4606
  • change: Improve runtime error messaging for missing libstdc++ #4610
  • change: Improve support for input Streams finishing before output is requested (#4584)
  • change: Increase accepted dimensions when extending #4605
  • change: Prerelease v0.35.4-rc.0
  • change: Prerelease v0.35.5-rc.0
  • change: Prevent TypeError when module load error has no code (#4593)
  • change: Release v0.35.4
  • change: Tests: ensure composite tests pass on big endian platforms #4609
  • …and 6 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

lovell/sharp was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit cef3b8c467c21f7e84bd51d5e53f2d115669f8d8 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-dd72cc24c749.