Skip to content
CAI
Software that uses CAICheck a score

marimo-team/marimo

45.8

Weak · 4 October 2026

376.5k

lines of production code

Python

with TypeScript

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is an interactive Python notebook environment that emphasizes secure data handling and robust frontend interactions. Recent activity focuses on hardening security by sanitizing password outputs and improving null handling in data filters, while simultaneously enhancing the user experience through better table export options and file navigation. The codebase is also undergoing maintenance to resolve performance issues, fix encoding bugs, and update core dependencies like SQLAlchemy and Storybook.

Narrated so far: 2026-09-30 – 2026-10-03; history before 2026-09-30 not narrated yet.

This week

  • Added tests for cell name validation, getpass output sanitization, and Hungarian algorithm correctness — Added tests to verify that cell names are validated against Python identifier rules and reserved keywords, that getpass responses are excluded from saved console output and HTML exports, and that the Hungarian algorithm for cell matching produces optimal assignments. (tests)
  • Fixes for cell name validation, password output handling, and cell-matching performance — This update addresses three distinct issues: it now rejects invalid cell names in code mode by enforcing NFKC normalization and valid Python identifier rules; it prevents password prompts from being saved in console output by filtering out 'text/password' mimetypes during session deserialization and ensuring they are not concatenated with stdin data during replay; and it improves performance for large cell-matching operations by switching from the exact O(n^3) Hungarian algorithm to a faster approximate assignment heuristic when the number of cells exceeds 50. (marimo)
  • Password inputs are no longer saved in console history — The frontend now prevents password responses (identified by the 'text/password' MIME type) from being stored in the console input history. When a user submits a password, the value is sent to the backend but the history entry is saved as an empty string, ensuring that secrets do not persist in the UI's up/down arrow navigation or in the serialized cell state. This change also includes tests to verify that password prompts are handled correctly and that subsequent history navigation does not reveal the secret. (frontend)
  • Added tests for dataframe/table download options and string filter null handling — Added tests verifying that CSV and JSON download options (such as separator, encoding, and ensure\_ascii) are correctly applied via request parameters, and that string filter code generation handles null values consistently across pandas, Polars, and Ibis backends. _(tests/\plugins/ui)
  • Improved null handling in generated filter code and configurable table export options — The table UI now generates more robust filter code for Pandas, Polars, and Ibis backends by filling null values with empty strings before string operations (contains, starts\_with, ends\_with) and explicitly excluding nulls in negated filters, preventing errors when filtering columns with missing data. Additionally, the table export dialog now supports per-request configuration for CSV separators, encodings, and JSON ASCII escaping, allowing users to customize export settings directly from the UI rather than relying solely on widget defaults. _(marimo/\plugins/ui)
  • Enhanced table export options and static notebook publishing via molab — Users can now configure CSV, TSV, and JSON export formats with specific options (such as delimiter, encoding, and ASCII escaping) through a new shared export dialog in the data table, replacing the previous simple menu. Additionally, the static notebook sharing feature has been updated to publish HTML exports to the web via molab, handling the upload staging and providing a claim URL for completion, while ensuring assets are correctly sourced from the CDN in production or the dev server locally. (frontend)
  • Fixes for pair-agent instructions and DuckDB discovery settings — Updates the pair-agent CLI documentation and logic to clarify that code mode is the only write path and to provide correct fallback instructions for starting a server when no session exists. Additionally, fixes the DuckDB SQL engine to respect user-provided discovery settings (schemas, tables, columns) instead of always fetching all metadata, improving performance and control over data exploration. (marimo)
  • Test suite updates for DuckDB isolation and CLI pair help text — Added tests to verify that DuckDB dataframes created via mocks use isolated in-memory connections to prevent state leaks, and updated runtime tests to clean up DuckDB schemas after SQL execution. Updated CLI pair tests to assert that the help text now instructs users to start a server via 'marimo edit' when no session exists, and adjusted SQL discovery tests to reflect the inclusion of the 'temp' database and deferred schema resolution. (tests)
  • Exclude broken SQLAlchemy 2.1.0 release — The dependency specification for SQLAlchemy has been updated to explicitly exclude version 2.1.0, which is a known broken release, while maintaining the minimum version requirement of 2.0.40. This change applies to both the optional test dependencies and the type-checking dependencies in the project configuration. ((dependencies))
  • Add actions to expand or clamp all cell outputs — Users can now expand or clamp (collapse) the output of all cells in the notebook at once. This is available via new toolbar buttons labeled "Expand all outputs" and "Clamp all outputs" in edit mode, as well as through new global hotkeys (currently unassigned but discoverable via keywords like "show full output" or "collapse outputs"). The feature intelligently skips cells that have no output or are already in the desired state, updating the \expand\_output\ configuration for affected cells. (frontend)
  • File browser navigation now uses breadcrumbs instead of a dropdown — The file browser's directory selection control has been replaced with a breadcrumb navigation trail. Users can now click on any ancestor directory in the breadcrumb trail to navigate directly to that location, rather than selecting from a dropdown list. The current directory is visually distinguished, and clicking it does not trigger a reload. This change improves navigation clarity and accessibility by providing a clear path of the current location within the file system hierarchy. (frontend/src/plugins/impl)
  • Update Storybook, Oxc, and SQLAlchemy dependencies — This release updates several development and test dependencies. Storybook packages (including @storybook/addon-docs, @storybook/addon-links, @storybook/react-vite, and storybook) are upgraded from version 10.5.10 to 10.6.0. Oxc tooling dependencies (oxfmt and oxlint) are updated to versions 0.68.0 and 1.83.0 respectively. Additionally, the SQLAlchemy dependency in test and typecheck environments is modified to include the \[asyncio\] extra and the version constraint excluding 2.1.0 is removed. ((dependencies))
  • Expanded test coverage for CLI, reload, and screenshot subsystems — Added and updated tests to verify CLI check output formatting (JSON/strict), CLI echo fallback behavior for non-encodable characters, screenshot session URL construction and credential passing, screenshot attachment to live notebook sessions, autoreload generation tracking and cell-run recording, module watcher mtime handling and self-import cycle race conditions, execution endpoint screenshot metadata injection, and scratchpad listener stderr ordering and child-cell error diagnostics. (tests)
  • Fixes for CLI output encoding, code-mode screenshots, and autoreload staleness — This release resolves several issues affecting the CLI, code-mode, and autoreload system. The CLI \check\ command no longer raises an UnboundLocalError when using the \--strict --format json\ flags. Terminal output is now more robust: the \echo\ function handles arbitrary non-encodable characters (not just a fixed set of symbols) by falling back to backslash-escaping, preventing crashes on non-UTF-8 terminals. In code-mode, screenshots are now correctly attached to the active notebook session by passing the file key, and the documentation for \NotebookCell.output\ is updated to clarify that fresh outputs require a new code-mode invocation. Finally, the autoreload mechanism is fixed to prevent cells that have already rerun after a reload from being incorrectly marked as stale, ensuring that the notebook state remains consistent during file changes. (marimo)
  • Fix cache hashing for PyArrow tables with non-numeric columns — The runtime now correctly handles PyArrow tables and arrays containing non-numeric columns in the cache system. Previously, these values might have been hashed incorrectly or caused errors because PyArrow objects expose \\_\array\\_\ without a \dtype\. The fix ensures that only PyArrow data with integer or floating-point types are considered hashable primitives, preventing cache inconsistencies for mixed-type Arrow data. (marimo)
  • Added tests for PyArrow data handling and hashing — Added test coverage for PyArrow integration, including validation of numeric and non-numeric column classification in the runtime primitives and verification of persistent caching behavior for PyArrow string tables. (tests)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 46.

Lenses

  • Code Health 71
  • Architecture 63
  • Maturity 75
  • Readiness 32
  • Security 65
  • Accessibility 49
  • Performance 69

Changes since last survey

  • 300 commits — 181 feature/other, 119 fixes

By area

  • frontend/src — 98 commits
  • (root) — 39 commits
  • marimo/_runtime — 18 commits
  • marimo/_server — 13 commits
  • marimo/_cli — 10 commits
  • marimo/_plugins — 10 commits
  • docs/guides — 9 commits
  • tests/_plugins — 8 commits
  • tests/_server — 7 commits
  • .github/workflows — 6 commits
  • frontend/.oxlintrc.json — 5 commits
  • packages/llm-info — 5 commits
  • frontend/e2e-tests — 4 commits
  • marimo/_config — 4 commits
  • marimo/_save — 4 commits
  • marimo/_utils — 4 commits
  • marimo/_ast — 3 commits
  • marimo/_code_mode — 3 commits
  • marimo/_convert — 3 commits
  • marimo/_output — 3 commits

Notable commits

  • fix: Fix code lens tooltip jitter (#10591)
  • fix: Fix dependency installation in island payloads (#10832)
  • fix: Fix image_compare expand output bug (#10907)
  • fix: Fix plotly hover text rendering issue (#10988)
  • fix: Fix suboptimal assignment in cell-matching Hungarian algorithm (#10654)
  • fix: Keep sandbox package managers fixed in install alerts (#10983)
  • fix: Revert "fix: stop nested scroll regions from chaining to the notebook" (#10968)
  • fix: Supply startup in dotenv session regression test (#10970)
  • fix: UI fix for SFTP (and a fsspec plugin for ssh) (#10977)
  • fix: ci: restore current JAX coverage after Flax compatibility fix (#10669)
  • fix: fix editor: use Ctrl for AI shortcuts on Windows (#10751)
  • fix: fix(a11y): preserve cell-toolbar keyboard activation (#10827)
  • fix: fix(acp): wait for initialization before starting sessions (#10927)
  • fix: fix(agent-panel): recover prompt submits failures (#10818)
  • fix: fix(ai): keep custom SSL clients type-safe on openai 3 (#10587)
  • fix: fix(ai): pass real JSON schema through for MCP/backend tools (#10573)
  • fix: fix(ai): preserve child-cell traceback context (#11035)
  • fix: fix(ai): send stable conversation headers to OpenCode Go (#10895)
  • fix: fix(anywidget): preserve virtual ESM URLs (#10687)
  • fix: fix(cache): hash pyarrow values with non-numeric columns by execution path (#11084)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

marimo-team/marimo was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 4 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 82b936f910b644c6b8052b22e4083b77a1b716b7 — the exact code this score is about.
  • Scored under rubric-2026.10.1 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b94e107d0cec.