node-red/node-red
50.4
Adequate · 1 October 2026
1.1k
lines of production code
JavaScript
primary language
2
measurements over time
What this system is
This system is the core runtime and editor infrastructure for Node-RED, structured as a monorepo of scoped npm packages. It provides the foundational engine for managing flows, nodes, and credentials, alongside the web-based user interface for visual programming. The codebase handles the server-side logic, API endpoints, and client-side UI components necessary to build and execute data-processing workflows.
How it got here
2013 — Monorepo restructuring and legacy cleanup
13 changes.
The project was restructured into a monorepo using scoped npm packages, replacing the legacy flat architecture and monolithic entry points. This period involved removing deprecated core, analysis, I/O, and social nodes, as well as deleting outdated frontend assets like Bootstrap v2.3.2 and legacy jQuery versions to support the new modular design.
2014–2018 — test infrastructure and coverage expansion
24 changes.
This period focused on establishing a robust testing framework for Node-RED, introducing WebdriverIO-based UI automation for the editor alongside comprehensive unit tests for core parsers, the registry, and the runtime. The work also included developing new development and release automation scripts to streamline the build process and enhance the developer experience.
2019–2026 — test coverage expansion and build migration
15 changes.
This period focused on significantly expanding unit and UI test coverage across core runtime modules, editor nodes, and storage components. Concurrently, the build system for the editor client was refactored from Grunt to custom npm scripts to streamline the development workflow.
Features
New development and release automation scripts
The project introduces a suite of new scripts to streamline the developer experience and release process. For local development, \scripts/dev.js\ replaces the previous Grunt-based workflow with a custom Node.js watcher that monitors source changes and rebuilds assets, while \scripts/build-custom-theme.js\ allows users to generate custom CSS themes from SCSS files. For releases, \scripts/release/index.js\ orchestrates the build, dependency verification, compression, and packaging of modules, supported by \scripts/generate-publish-script.js\ to create the appropriate npm publish commands and \scripts/set-package-version.js\ to update version numbers across all packages.
scripts · high confidence
Removals
Removal of analysis nodes from this repository
The sentiment, wordpos, and xml2js analysis nodes have been deleted from the nodes/analysis directory. These nodes are no longer available in this package and have been moved to the node-red-nodes repository.
nodes/analysis · high confidence
Removal of core editor modules
The \history.js\, \main.js\, and \nodes.js\ files have been deleted from the \public/red\ directory. This removes the previous implementations of the undo/redo history system, the main application initialization and deployment logic, and the core node management registry from the client-side editor.
public/red · high confidence
Removal of core node definitions
The core Inject, Debug, Exec, Function, Template, and Comment node definitions have been removed from the nodes/core directory. This change eliminates the legacy implementations of these nodes, including their UI templates, server-side logic, and WebSocket handling, from this location.
nodes/core · high confidence
Removal of deprecated I/O nodes
The MQTT, Serial, Socket, TCP, Multicast, and HTTP GET nodes have been removed from the nodes/io directory. These nodes are no longer available for use in flows.
nodes/io · high confidence
Removal of legacy jQuery and jQuery UI assets
The \public/jquery\ directory no longer includes the jQuery 1.9.1 library, the jQuery UI 1.10.3 custom build (JavaScript and CSS), or the associated Smoothness theme assets. These files have been deleted, meaning any pages or components that previously relied on these specific local versions for DOM manipulation or UI widgets (such as accordions, datepickers, or draggable elements) will lose that functionality unless the dependencies are provided elsewhere.
public/jquery · high confidence
Removal of legacy red module components
The \red/library.js\, \red/nodes.js\, and \red/server.js\ files have been deleted from the codebase. This removes the previous implementation of the flow library storage, the core node registry and runtime engine, and the initial HTTP server setup, indicating a structural shift in how the application manages nodes, storage, and server initialization.
red · high confidence
Removal of legacy social and notification nodes
The social and notification nodes located in the nodes/social directory have been removed. This includes the Twitter input/output and credentials nodes, the Feedparse RSS/Atom monitor, the Growl and Prowl desktop notification nodes, the PushBullet mobile notification node, the Email send and IMAP receive nodes, the IRC input/output and server configuration nodes, and the XMPP messaging node. Users will no longer have access to these specific integrations within this package.
nodes/social · high confidence
Removal of legacy storage nodes
The legacy file, tail, Redis output, and MongoDB storage nodes have been removed from the nodes/storage directory. This eliminates the ability to write to local files, tail log files, write to Redis, or save data to MongoDB directly from these specific node types.
nodes/hardware, nodes/storage · high confidence
Architecture
Repository restructured into scoped npm packages with updated developer tooling
The repository has been reorganized from a flat structure into a monorepo using scoped \@node-red\ npm packages (e.g., \@node-red/editor-api\, \@node-red/runtime\), replacing the previous \red.js\ entry point and \settings.js\ configuration file. This change introduces new configuration files for the build and test environment, including \.mocharc.json\ for Mocha, \.nycrc.json\ for code coverage, \eslint.config.js\ for linting, and \nodemon.json\ for development, while removing legacy files like \INSTALL\ and \.nodemonignore\.
(repo-wide) · high confidence
Behavioural changes
Build system migrated from Grunt to custom npm scripts
The build process for the Node-RED editor client has been refactored from the Grunt task runner to a set of standalone Node.js scripts (clean, concat, copy, minify, sass, jsonlint, attach-copyright) orchestrated by scripts/build/index.js. This change replaces the previous Grunt-based workflow with direct CLI usage and native Node.js file system operations, including the use of esbuild for minification and sass for CSS compilation. The new system supports a development mode that skips minification and copyright attachment, and includes specific handling for Windows path normalization and UTF-8 BOM removal during copyright attachment.
scripts/build · high confidence
Editor UI modules refactored and removed
The \public/red/ui\ directory has been restructured by deleting the monolithic editor modules (\editor.js\, \keyboard.js\, \library.js\, \notifications.js\, \palette.js\, \sidebar.js\, and \view.js\). This change removes the previous implementation of the node editing dialog, keyboard shortcuts, library management, notifications, palette rendering, sidebar, and canvas view, indicating a move toward a new modular architecture for these core interface components.
public/red/ui · high confidence
Removal of Bootstrap v2.3.2 CSS framework
The public-facing Bootstrap v2.3.2 stylesheet has been removed from the application. This eliminates the dependency on this specific version of the Twitter Bootstrap CSS library, which will likely require the UI to rely on alternative styling or a newer framework version to maintain its visual layout and component behavior.
public · high confidence
Removal of bundled Orion editor assets
The pre-built Orion editor styles (\built-editor.css\) and minified JavaScript (\built-editor.min.js\) have been removed from the \public/orion\ directory. This change eliminates the locally bundled editor assets, likely shifting the application to load the Orion editor from an external source or a different build process.
public/orion · high confidence
Test coverage
Added HTML test resource for node parsing; Added SSL test resources for certificate validation; Added UI test coverage for Node-RED cookbook scenarios; Added comprehensive test suites for core parser nodes; Added page object abstractions for Sequence nodes; Added page object abstractions for editor UI testing; Added page object abstractions for editor node testing; Added page object definitions for core editor nodes; Added page object tests for core parser nodes; Added page object wrappers for core function nodes; Added placeholder test suite for multiplayer module; Added test coverage for core common nodes; Added test coverage for file and watch storage nodes; Added test fixtures for plugin registration and library source plugins; Added test resources for subflow package modules; Added test utilities for UI automation and shortcut key handling; Added unit tests for Node, credentials, and index modules; Added unit tests for Node-RED context storage mechanisms; Added unit tests for Node-RED runtime initialization and version reporting; Added unit tests for Node-RED runtime initialization, settings, and plugin modules; Added unit tests for Split, Sort, and Batch sequence nodes; Added unit tests for core function nodes; Added unit tests for editor API authentication modules; Added unit tests for editor API modules; Added unit tests for editor-api initialization and utility functions; Added unit tests for local filesystem project storage components; Added unit tests for local filesystem storage components; Added unit tests for search dialog casing preservation; Added unit tests for subflow data flow and environment variable access; Added unit tests for telemetry initialization and metrics collection; Added unit tests for the admin API module; Added unit tests for the flows runtime library; Added unit tests for the runtime API layer; Added workspace UI integration tests; Expanded test coverage for network nodes; Expanded unit test coverage for the Node-RED registry module; New UI test infrastructure for the editor.
Dependencies
Node-RED 5.0.7 dependency and manifest update
This release updates the Node-RED project to version 5.0.7, introducing a comprehensive set of dependency upgrades across the core packages (@node-red/editor-api, @node-red/nodes, @node-red/registry, @node-red/runtime, and @node-red/util). Key library updates include Express to 4.22.2, MQTT to 5.15.2, Multer to 2.3.0, and JSONata to 2.2.2 (via the util package). The minimum supported Node.js engine version has been raised to 22.9. Additionally, the project structure now includes a package-lock.json file to ensure reproducible dependency chains, and several test resource packages have been updated to reflect the new module layout.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 48 → 50 (+2.6)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 69 → 69 (+0.0)
- Architecture 69 → 69 (+0.0)
- Maturity 55 → 55 (+0.0)
- Readiness 36 → 37 (+0.7)
- Security 55 → 62 (+7.1)
- Performance 100 (new)
Resolved (4)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no contributor guidance (README.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
New (35)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Low vulnerability: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Outdated (npm): basic-auth
- Outdated (npm): body-parser
- Outdated (npm): chalk
- Outdated (npm): cheerio
- Outdated (npm): content-type
- Outdated (npm): cookie
- Outdated (npm): express
- Outdated (npm): fs-extra
- Outdated (npm): got
- …and 15 more
Changes since last survey
- 1 commits — 0 feature/other, 1 fixes
By area
- packages/node_modules — 1 commit
Notable commits
- fix: Fix legacy CSV parsing of leading empty columns (#5961)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
node-red/node-red was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 1e85f1efbc8875ad960400905038154a4e4dd76e — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.