microsoft/sudo
73.6
Strong · 29 September 2026
2.5k
lines of production code
Rust
primary language
2
measurements over time
What this system is
Sudo for Windows is an open-source utility that enables users to run commands with elevated administrator privileges on Windows systems. It implements a secure client-server architecture using local RPC to communicate between unprivileged callers and an elevated helper process, incorporating nonce-based security measures to prevent ALPC spoofing. The system provides comprehensive auditing through Windows Event Tracing and supports configuration via group policy and system settings.
Features
Initial OneBranch CI/CD pipeline setup for sudo
This change introduces the initial OneBranch pipeline infrastructure for the sudo project, enabling automated builds on Windows and Linux. The configuration includes PR and standard pipelines that build the Rust-based sudo binary for x64, x86, and ARM64 targets, with support for multiple brandings (Inbox, Stable, Dev). It integrates static analysis via PREfast and Sarif output, imports results into Guardian, and handles localization by fetching resources from Touchdown. The standard pipeline also generates a vPack for distribution and signs the resulting executables.
.pipelines · high confidence
Initial release of Sudo for Windows
This change introduces the initial source code for Sudo for Windows, a tool that allows users to run commands with elevated administrator privileges. The implementation includes a CLI interface for running commands with options such as preserving environment variables, forcing a new window, or disabling input, as well as a hidden 'elevate' subcommand for internal use. The system uses a local RPC mechanism to communicate between the unprivileged caller and the elevated helper process, featuring security measures like nonce-based endpoint generation to discourage ALPC spoofing and strict security descriptors for the RPC server. It also includes comprehensive logging to the Windows Event Log for auditing purposes and supports configuration via system settings and group policy.
sudo · high confidence
Initial release of Windows-specific logging, RPC, and resource utilities
This change introduces the foundational Windows-specific components for the sudo application. It adds C++ code and Event Tracing for Windows (ETW) manifests to enable logging to the Windows Event Viewer, including specific events for sudo command execution. It also implements a C wrapper for the local RPC interface to handle Structured Exception Handling (SEH) on the client side, which Rust cannot easily manage, and provides Rust libraries for generating ETW events and accessing Win32 string resources.
_cpp, sudo\events, win32resources · high confidence
Initial release of sudo for Windows
This change introduces the initial release of the sudo tool for Windows, including the core executable logic, a PowerShell script to generate language codes for localization, a test notebook for manual verification of elevation scenarios, and a TVPP configuration file for viewing sudo events.
tools · high confidence
Sudo for Windows is now open source with community contribution guidelines
The repository has transitioned from a closed/internal project to an open-source initiative, allowing the community to submit issues, feature requests, and pull requests. The README and CONTRIBUTING documents have been updated to reflect this change, removing previous statements that the project was not open source. New contributors are guided through a process involving feature flags (Inbox, Stable, Dev) to manage code integration, and specific instructions for building the Rust-based project using Cargo are provided in the new Building.md file.
(repo-wide) · high confidence
Fixes
Fixes PowerShell script logic errors in sudo.ps1
The sudo.ps1 script now correctly handles null checks for the PowerShell process path and fixes a typo in the variable name 'sudoOffset' that previously caused a runtime error when parsing command lines.
scripts · high confidence
Dependencies
Initial release of the sudo source and workspace structure
This change introduces the initial source code for the \sudo\ utility, establishing a Cargo workspace with three members: \sudo\, \sudo\_events\, and \win32resources\. The \sudo\ crate is configured as a binary with a build script, utilizing the \windows\ crate (version 0.57) for Windows API access and \clap\ for command-line parsing. The workspace defines shared dependencies in the root \Cargo.toml\, including \cc\ for C++ compilation, \embed-manifest\ for resource embedding, and \winres\ for Windows resource handling. The \sudo\ crate also depends on local path dependencies \sudo\_events\ and \win32resources\, and includes feature flags for branding (Inbox, Stable, Dev) and compliance.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 74 → 74 (-0.9)
- Rubric changed (rubric-2026.09.10 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 98 → 98 (+0.0)
- Architecture 100 → 97 (-2.8)
- Maturity 57 → 57 (+0.0)
- Readiness 87 → 84 (-3.0)
- Security 85 → 88 (+2.5)
Resolved (2)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
New (1)
- Off the main sequence: win32resources
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
microsoft/sudo was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 29 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit feadab8d32f06d7f6e87e5370b071103b175a595 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-5ff527f25b99.