nubjs/nub
55.6
Adequate · 30 September 2026
141.7k
lines of production code
Rust
with JavaScript, TypeScript
2
measurements over time
What this system is
Nub is a high-performance, self-contained Node.js runtime and package manager that embeds a Rust-based engine to replace or augment standard tooling. It provides a unified interface for managing dependencies across npm, pnpm, Yarn, and Bun, while offering native TypeScript transpilation, offline documentation, and the ability to compile applications into standalone executables. The system emphasizes security, deterministic builds, and rapid startup times through features like content-addressable storage, integrity-verified runtime extraction, and adaptive concurrency.
Features
Add schema index page for JSON Schema discovery
A new Schema Index page has been added to the site, which dynamically lists available JSON Schema files for the nub.jsonc configuration. This page allows users to discover and link to specific versioned schemas (e.g., v0.7.0.json) or the rolling latest.json, enabling better editor completion and validation for project configurations.
site/src/app/schema · high confidence
Add support for reading and writing bun lockfiles
The package manager can now parse and generate bun's text-based \bun.lock\ files (lockfileVersion 1 and 2). This includes handling JSONC features like comments and trailing commas, resolving various source types (registry, git, file, workspace, and HTTP tarballs), and preserving integrity hashes and peer dependency metadata. Users can now use bun lockfiles interchangeably with the existing npm lockfile support without losing resolution data or integrity checks.
vendor/aube/crates/aube-lockfile/src/bun · high confidence
Added example to compare filesystem and CAS-indexed phantom scanners
A new example, scan\_both.rs, has been added to demonstrate parity between the filesystem-based and CAS-indexed phantom scanners. Running this example with a directory argument allows users to verify that both scanning methods produce identical results, helping to ensure consistency between the two scanning implementations.
crates/nub-phantom/examples · high confidence
Added libsui binary injection library
Added the \libsui\ crate to vendor dependencies, providing a tool to embed and extract auxiliary data from executable files (ELF, PE, and Mach-O). This library enables the creation of standalone self-extracting executables by injecting resources such as version info, manifests, and icons into PE files, and appending data sections or notes into ELF and Mach-O binaries. It includes platform-specific handling for macOS code signing (including ad-hoc signing for Intel and Apple Silicon) and runtime extraction logic for all supported platforms.
vendor/libsui · high confidence
Added md-toc script to generate markdown heading outlines with line ranges
A new Node.js script at scripts/md-toc/index.mjs has been added to parse markdown files and output a table of contents that includes the exact start and end line numbers for each heading section. This tool uses the mdast-util-from-markdown library to correctly identify headings while ignoring those inside fenced code blocks, enabling targeted reading or processing of specific document sections based on their line ranges.
scripts/md-toc · high confidence
Added shared data format parsing library for YAML, TOML, JSON5, and JSONC
A new \nub-data-formats\ crate has been introduced to provide a unified implementation for parsing YAML, TOML, JSON5, and JSONC data formats. This library is shared between the N-API addon (runtime) and the \nub compile\ command (build time) to ensure that data imports are interpreted consistently in both contexts, preventing divergence between runtime behavior and build-time bundling. The implementation includes specific safeguards such as a 128-level nesting depth limit and YAML alias expansion bounds to prevent stack overflows or excessive memory allocation from malformed inputs.
crates/nub-data-formats · high confidence
Bundled POSIX shell for Windows script execution
The \vendor/busybox-w32\ directory now contains prebuilt BusyBox binaries (version 1.38.0-FRP-6075-g169694ebd) for x64 and ARM64, along with their GPLv2 license and source tarball. This addition provides a native-Win32 POSIX shell that \nub run\ uses to execute \package.json\ script bodies on Windows, replacing the previous behavior where Windows lacked a system POSIX shell like \/bin/sh\ on macOS/Linux.
vendor/busybox-w32 · high confidence
Centralized settings registry with build-time code generation
The \aube-settings\ crate now serves as the single source of truth for all configuration settings, defined in \settings.toml\. A new \build.rs\ script generates Rust metadata and typed accessor functions at compile time, ensuring that every setting is type-safe and consistently resolved from CLI flags, environment variables, \.npmrc\, and workspace YAML. This change introduces a structured settings surface that supports embedder-specific defaults, namespace resolution for directory paths, and an automated audit test to verify that all defined settings are actually wired into the application logic.
vendor/aube/crates/aube-settings · high confidence
Download analytics snapshots and trend reporting
The stats area now includes a daily snapshot system for tracking download counts. A new JSON ledger in stats/download-counts captures cumulative GitHub release asset downloads and npm last-30-day totals, accompanied by a README explaining the data format and limitations. A backfill file restores npm daily history for the period when the automated workflow was broken, while GitHub daily deltas for that window remain unrecoverable. A new Node.js script (stats/download-counts/report.mjs) allows users to compute approximate daily download deltas and view current totals across platforms and tags.
stats · high confidence
Host the setup-node GitHub Action in this repository
The \setup-node\ directory now contains the full source for the \nubjs/nub/setup-node\ GitHub Action, including the \action.yml\ definition, platform-specific install scripts (\install.sh\, \install.ps1\), and ESLint problem matcher configurations. This change enables the repository to host and version the action locally, providing a drop-in replacement for \actions/setup-node\ that integrates with the Nub toolchain to resolve Node versions from project pins and manage package manager shims.
setup-node · high confidence
Initial repository structure and configuration
The repository is initialized with the core configuration files required for the Nub project, including the MIT license, README, and agent guidance files (AGENTS.md, CLAUDE.md, CODEX.md). It establishes the build and development environment through .dockerignore, .gitattributes (enforcing LF line endings for test fixtures to ensure cross-platform consistency), .npmrc (setting a 7-day release age soak window), and .vercelignore. The project adopts a Nix-based build system via flake.nix and flake.lock, and introduces a custom lockfile format (nub.lock) alongside a visibility-lint configuration (hawk.toml). Additionally, it sets up local orchestration and tooling integrations through .mcp.json, .worktreeinclude, and lat.md.
(repo-wide) · high confidence
Introduce \`nub.jsonc\` as the new global and project configuration file
Nub now uses a new \nub.jsonc\ file (JSON with comments) for configuration, replacing the previous \nub.toml\ for global settings and unifying project settings. This file is located at \\~/.config/nub/nub.jsonc\ (or \%APPDATA%\\nub\ on Windows) for global settings and at the project root for project-specific settings. The configuration system now supports a wider range of settings including runtime options (like \preload\, \nodeOptions\, \v8Flags\, \tsconfig\, \jsx\), install options (like \linker\, \minimumReleaseAge\), and execution options (like \dlx\ consent). The \nub config\ command is used to get, set, and delete these settings, with support for both project and global scopes. The \nub init\ command now scaffolds a TypeScript-first project with a \nub.jsonc\ file containing example settings.
crates/nub-cli/src · high confidence
Introduce aube FFI and Node-API bindings for embedding the installer
This change adds two new npm packages to the vendor tree: \@jdxcode/aube-ffi\, which exposes aube's C ABI for use via FFI loaders in Bun, Deno, Node.js, and Python, and \@jdxcode/aube-node\, which provides a native Node-API addon for embedding the installer directly in JavaScript hosts like Node.js, Bun, and Electron. Both packages include platform-specific binaries for macOS, Windows, and Linux (glibc and musl), along with TypeScript definitions, build scripts, and smoke tests to verify functionality such as package installation, event reporting, cancellation, and workspace handling.
vendor/aube/crates/aube-ffi, vendor/aube/crates/aube-node · high confidence
Introduce aube-runtime crate for Node.js version management
Added the \aube-runtime\ crate, which provides the core logic for discovering, resolving, and installing Node.js versions. It scans aube's own runtime directory and mise's installs directory to find existing Node versions, delegates installation to mise when available, and handles downloading, verifying (SHA-256), and extracting Node archives from official or custom mirrors. The crate also manages caching of the Node.js release index and provides typed error handling for runtime resolution failures.
vendor/aube/crates/aube · high confidence
Introduce canonical feature matrix and single-binary runtime integrity
This change establishes a single, auditable feature × Node-version mitigation matrix (\feature\_matrix.rs\) that drives automatic flag injection and polyfill selection across supported Node versions, replacing scattered version checks. It also introduces a single-binary runtime mode that embeds the Node augmentation tree into the executable, extracting it atomically on first run with R1 (secure, per-user base directory validation) and R2 (BLAKE3 integrity verification of entrypoints) hardening, and adds a persistent global \node\ shim (\nub node shim\) that allows nub to act as the default Node runner in the shell.
crates/nub-core/src/node · high confidence
Introduce nub-charts skill for consistent, content-aware chart rendering
Added a new charting skill that generates SVG figures with dynamic sizing based on content, ensuring balanced margins and readable labels. The renderer supports paired, overlap, and ranked chart types, utilizing site-specific color tokens and typography (Encode Sans, Geist Mono) for visual consistency. Key behavioral changes include removing axes from paired charts to rely on inline value labels, enforcing a single direction per chart, and aligning legends to the left.
.claude/skills/nub-charts/scripts · high confidence
Introduce nub-phantom CLI for detecting undeclared npm dependencies
A new \nub-phantom\ tool is available to identify undeclared (phantom) dependencies in npm packages. It fetches the latest published tarball from the npm registry, extracts it, and analyzes the module graph to find imports not covered by declared dependencies, optional peers, or builtins. The CLI supports analyzing specific packages or scanning the top-N most-downloaded packages, with output available in human-readable or JSON formats.
crates/nub-phantom/src · high confidence
Introduce secure package-manager provisioning and shim infrastructure
This change adds the core library components for Nub's package-manager (PM) hypermanager, enabling the tool to provision, resolve, and execute npm, pnpm, and yarn. The new \extract\ module safely unpacks PM tarballs by rejecting symlinks and hardlinks to prevent path-escape attacks ([CVE redacted] class) and capping decompression to prevent bombs. The \provision\ module manages a version-addressed store for PM binaries, supporting exact pins with zero-network cache hits and offline fallbacks for range resolutions. The \resolve\ module implements a unified pin reader that prioritizes \.yarnrc.yml\'s \yarnPath\, \package.json\#packageManager\, and \devEngines.packageManager\, while surfacing structured warnings for disagreements between these fields. The \registry\ module handles registry configuration with strict security controls, specifically disabling environment variable expansion in project-level \.npmrc\ files to prevent credential exfiltration ([GHSA redacted]). Finally, the \shim\ module provides the infrastructure for \nub pm shim\, creating hardlinks in \\~/.nub/shims\ to intercept PM commands and route them through Nub's engine, including an opt-in mode to route install commands.
crates/nub-core/src/pm · high confidence
Introduce structured error and warning codes with bespoke exit codes and generated documentation
The \aube-codes\ crate now provides a centralized, stable registry of error (\ERR\AUBE\\*\) and warning (\WARN\AUBE\\*\) identifiers, each with a category, description, and optional bespoke Unix exit code. This enables CI scripts and shell pipelines to branch on specific exit codes (e.g., lockfile, resolver, or linker failures) rather than parsing stderr text. The crate also includes a \generate-error-codes-docs\ binary that produces \docs/error-codes.data.json\, which feeds the VitePress \\<ErrorCodesTable\>\ component to render a searchable, filterable error-codes reference page. Self-tests in \lib.rs\ and \exit.rs\ enforce naming conventions, uniqueness, and valid exit-code ranges.
vendor/aube/crates/aube-codes · high confidence
Linker vendored with hoisted layout, disk materialization, and macOS performance optimizations
The \aube-linker\ crate has been vendored into the project, introducing a pluggable linker architecture that supports both the default isolated layout (pnpm-style virtual store) and a new \Hoisted\ layout (npm-style flat tree) for legacy toolchain compatibility. This update adds selective disk materialization, allowing specific packages to be forced into project-local directories even when using the global virtual store, and introduces a macOS-specific whole-directory \clonefile(2)\ optimization that significantly speeds up package materialization on APFS volumes. The linker also now supports configurable hoisting limits, public hoist patterns, and progress reporting during installation.
vendor/aube/crates/aube-linker/src · high confidence
New @nubjs/types package provides ambient declarations for the Nub runtime
The new @nubjs/types package adds TypeScript ambient declarations for the Nub runtime, enabling type-checking for Nub-specific surfaces like the browser-shape Worker global, data-format imports (.yaml, .toml, .txt), and polyfilled proposal APIs (Temporal, Iterator methods, Math.sumPrecise, Uint8Array hex/base64, Promise.allKeyed, etc.). It includes a step-aside mechanism to coexist with lib.dom's Worker declaration and provides version-specific entry points for TypeScript 5.9 and 6+.
npm/nub-types · high confidence
New \`nub agent\` command for offline AI coding agent support
The CLI now includes a new \nub agent\ command group designed to help AI coding agents interact with Nub documentation without requiring network access. This feature provides two subcommands: \nub agent skill\, which prints an embedded 'evergreen' agent skill file for agents to install, and \nub agent docs\, which serves the full documentation tree baked into the binary at build time. Users can browse the documentation table of contents or retrieve specific pages using the \--page\ flag with URL-path slugs, ensuring that AI agents can access accurate, up-to-date documentation even in offline environments or from stale binary versions.
crates/nub-cli/src/agent · high confidence
New agent orchestration scripts and settings for v0.1 launch readiness
Added three new files to the .claude directory to guide the AI agent through the v0.1 production readiness audit and implementation. prod-readiness-audit.js defines a structured audit framework with seven dimensions (transpile-loaders, resolution, CLI-spawn-flags, workspace-run, polyfills-globals, exec-watch-upgrade, release-packaging) to identify drift, bugs, and missing features. v0.1-launch-impl.js and worker-and-cli-impl.js provide phased implementation plans for fixing identified blockers, including CLI flag routing, worker lifecycle hangs, signal handling, and workspace script execution. settings.json configures hooks for prompt submission, tool use, and context compaction to support these workflows.
.claude · high confidence
New animated GitHub Star count badge for READMEs
The site now serves a dynamically generated SVG at /stars.svg that replicates GitHub's dark-theme Star button, including the star icon, label, and a rounded count pill. The count pill features a declarative SMIL odometer animation that counts up from zero to the current repository star count over approximately 6.5 seconds, ensuring the animation plays even when the image is embedded in a README (where JavaScript is disabled). The star count is fetched from the GitHub API with a 1-hour server-side cache to balance freshness with API rate limits.
site/src/app/stars.svg · high confidence
New blog posts for Nub 0.1.1–0.1.14 and libuv threadpool sizing
The blog now includes release notes for Nub versions 0.1.1 through 0.1.14, covering features like fresh-project identity, offline installs, and native npm-only verbs, alongside a technical deep-dive on how Nub 0.10 sizes the libuv threadpool to the machine's cores.
site/content/blog · high confidence
New core modules for compiled artifacts, config caching, and platform-specific safeguards
This change introduces several new modules in \nub-core\ that enhance the package manager's reliability and performance. The \compile\ module defines the binary payload container for standalone executables, supporting both embedded and 'smol' (discovery-based) Node.js shapes. A new \config\_cache\ module implements an mtime-validated cache for config file reads, preventing stale values during in-process file rewrites by accounting for OS-level timestamp granularity. Platform-specific improvements include \quarantine\ to clear macOS Gatekeeper flags on self-upgraded artifacts, \windows\_security\ to enforce protected DACLs on cache directories, and \resource\_limits\ to detect and respect cgroup PID/CPU constraints on Linux to prevent install aborts. Additionally, \pnp\ adds detection for Yarn Plug'n'Play contexts, and \lib.rs\ gains utilities to strip UTF-8 BOMs from \package.json\ and correctly resolve executable candidates on Windows via PATHEXT.
crates/nub-core/src · high confidence
New developer tooling and CI scripts for build management, validation, and monitoring
This change introduces a suite of new scripts to the \scripts/\ directory to improve build observability, dependency integrity, and CI reliability. \build-status.sh\ provides a diagnostic view of build slot saturation and rustc semaphore usage to help developers identify machine bottlenecks. \check-lockfiles.sh\ and \check-oxc-lockstep.mjs\ enforce integrity by verifying Cargo.lock staleness and ensuring all oxc consumers remain on a single version to prevent duplicate stacks. \check-docs-links.ts\ validates internal documentation links and anchors, while \check-node-flag-drift.mjs\ monitors Node.js experimental flag changes against a snapshot. Additionally, \ci-watch.ts\ and its test suite replace fragile CI polling with a robust watcher that correctly handles ghost checks and exit codes, and \build-runner-npm.mjs\ automates the staging and packaging of the standalone \@nubjs/runner\ npm package.
scripts · high confidence
New disk-reduction skill for reclaiming Rust build residue
Added a new \.claude/skills/disk-reduction\ skill that provides scripts and documentation to safely reclaim disk space from Rust build artifacts. The skill introduces \clean-shared-buckets.py\ to identify and delete orphaned shared-target buckets in \\~/.cache/nub\ that are no longer referenced by any worktree, while protecting the currently installed \nub-dev\ binary and the newest bucket used as a build seed. It also documents how to clean worktree-private \target/\ directories and merged worktrees, emphasizing the use of \df\ over \du\ for accurate space reporting on APFS due to copy-on-write semantics.
.claude/skills/disk-reduction · high confidence
New guides for Bun migration, NestJS, Turborepo, and Vite+ comparison
The site now includes a \/guides\ section with four new practical walkthroughs: a migration guide from Bun to Nub (covering runtime, scripts, environment files, and a full API replacement map), a guide for running NestJS applications on Nub without a build step, a guide for coexisting with Turborepo in monorepos, and a comparison guide between Nub and Vite+.
site/content/guides · high confidence
New npm lockfile reader and writer with legacy support and hoisting logic
The aube lockfile tool now includes a dedicated module for reading and writing npm package-lock.json (v2/v3) and npm-shrinkwrap.json files. This addition enables aube to parse npm lockfiles, reconstruct the hoisted nested node\_modules layout, and write back a valid lockfile that is compatible with npm ci. The reader supports legacy lockfile formats (lockfileVersion 1 and pre-2017 shrinkwrap) by lifting them into the modern flat structure, and correctly handles edge cases such as workspace links, aliased packages, and install paths generated from different working directories. The writer ensures round-trip fidelity by preserving fields like bundleDependencies, peerDependencies, and engine constraints, and by emitting keys in the exact order npm expects to avoid unnecessary churn.
vendor/aube/crates/aube-lockfile/src/npm · high confidence
New script to safely clean Rust build targets from Nub worktrees
A new Python script, \clean-worktree-targets.py\, has been added to the \.claude/skills/cpu-reduction/scripts\ directory. This tool audits or deletes regenerable Rust build targets owned by clean Nub worktrees. It is designed to handle concurrent execution by using \rm -rf\ to tolerate race conditions where another sweeper might delete a target simultaneously, preventing the script from aborting prematurely. It also checks for live build processes and installed development binaries to avoid deleting targets that are currently in use or required for development.
.claude/skills/cpu-reduction/scripts · high confidence
New site components for documentation, installation, and engagement
This change introduces a suite of new React components to the site's documentation and marketing surfaces. It adds an \AnsiPlayer\ for rendering interactive, non-looping terminal session recordings, and several new tables: \CompatTable\ for vertical package-manager compatibility status, \PmSupportTable\ for a high-level config support summary, and \ExtensionsTable\ for a paginated, filterable view of the package-extensions database. Installation and onboarding are handled by new \GetStarted\ blocks (combining install tabs with a migration prompt) and a \NubIntro\ aside. UI engagement is enhanced with \GitHubStarButton\ and \GitHubStarPill\ for live stargazer counts, a \SectionHeading\ that copies section-specific URLs with \?section=\ params, a \Figure\ component for captioned images with dark-mode support, and a \ShimDemo\ for styled terminal transcripts.
site/src/components · high confidence
New site infrastructure for code rendering, content filtering, and dynamic metadata
The site library now includes several new capabilities: a terminal session replay system with an ANSI screen model and player (\ansi-record.ts\, \ansi-screen.ts\); Shiki transformers that style shell code blocks with a \$ \ prompt (\shiki-console.ts\), render GitHub-style diff blocks (\shiki-diff.ts\), and provide syntax highlighting for the \env-spec\ format (\shiki-env-spec.ts\); a remark plugin to convert GitHub alert blockquotes into styled callouts (\remark-github-alerts.ts\); and a remark plugin to dynamically substitute the latest Node.js and Nub versions into code samples (\remark-node-version.ts\). Content management is enhanced with a \published()\ filter that hides pages marked \unpublished: true\ in production builds, and a new \/guides\ loader is added. The layout now features a GitHub star pill in the navigation and corrected vertical alignment for the wordmark and nav labels. Finally, Open Graph image generation (\og.tsx\) and inline code rendering for titles (\inline-code.tsx\) have been implemented.
site/src/lib · high confidence
New status-tagged todo parser for markdown files
A new \scripts/todo\ tool allows users to parse and filter status-tagged todo items from markdown files. It supports six status markers: pending (\[ \]), in-progress (\[/\]), done (\[x\]), cancelled (\[-\]), deferred (\[\>\]), and question/blocked (\[?\]). Users can filter output by specific statuses, view only actionable items, restrict results to specific sections, or get summary counts. The parser intelligently ignores todo-like syntax inside fenced code blocks.
scripts/todo · high confidence
New visual-review skill for deterministic UI verification
A new \visual-review\ skill has been added to the \.claude/skills\ directory, providing a structured workflow for verifying UI, layout, and styling changes. Instead of relying on flat screenshots, this skill instructs the reviewer to use browser-computed measurements via \evaluate\_script\ to detect occlusion, clipping, and alignment issues that are often missed by the eye. It includes a new \optical-center.js\ utility that calculates the alpha-weighted center of mass of glyph ink, allowing for precise optical alignment of text elements with different font sizes or icon types (such as SVGs or emojis) that standard box-centering fails to handle correctly.
.claude/skills/visual-review · high confidence
Official Docker images for Node 26 (slim and Alpine variants)
Users can now run nub using official Docker images based on Node 26, available in both Debian slim (glibc) and Alpine (musl) variants. The images automatically install the latest nub version, handle platform-specific binary selection, and drop to a non-root user for security. A publish workflow is included to build and push multi-arch images (amd64/arm64) to Docker Hub or GitHub Container Registry on release tags, with support for provenance and SBOM attestations.
docker · high confidence
Runtime support for compiled single-executable artifacts
The runtime now includes the core loader and bootstrap logic required to run applications compiled into standalone single-executable artifacts (SEA) or inline payloads. This change introduces a suite of new modules—such as \compile-bootstrap.cjs\, \compile-inline-loader.cjs\, and \compile-sea-loader.cjs\—that handle the extraction and execution of bundled code from the executable binary itself. It also adds \fetch-serve.cjs\ to enable default-exported \fetch\ handlers to be served as HTTP endpoints, and implements lazy-loading polyfills (e.g., for \Temporal\, \Float16Array\, and \URLPattern\) to minimize startup overhead in compiled artifacts. Additionally, the runtime now manages specific environment variables and process state to ensure correct behavior for child processes and workers spawned from these compiled executables.
runtime · high confidence
Self-contained binary with integrity-verified runtime extraction
The build process now supports generating a single, self-contained executable by embedding the Node.js runtime environment. When the \embed-runtime\ feature is enabled, the build script compresses the runtime tree (including preload scripts, native addons, and vendored dependencies) into a zstd archive and embeds it directly into the binary. At runtime, the system extracts this archive to a cache directory and verifies the integrity of key entrypoints using baked-in BLAKE3 hashes; if the extracted files do not match the expected hashes, the binary automatically re-extracts the trusted version to prevent silent degradation or tampering. This change ensures that users receive a robust, standalone binary that does not rely on external runtime files being present on the host system.
crates/nub-core · high confidence
Soak testing and external tooling validation scripts added
Added a comprehensive suite of scripts and tests under scripts/soak to enforce a 7-day release-age cooldown for dependencies and validate pinned external security tooling. The new soak manager (soak.mts) and constants (constants.mts) ensure that dependency updates across npm, pnpm, Cargo, and Renovate respect a mandatory waiting period, with automated pruning of expired exclusions. The external-tools module (external-tools.mts) manages pinned versions of security tools with SRI integrity checks and platform-specific asset resolution, while supporting a soak-bypass mechanism that expires after the cooldown window. Additional scripts validate git remote configurations (remotes.mts), manage local tool racks (rack.test.mts), and verify dockerignore configurations (dockerignore.test.mts).
scripts/soak · high confidence
Standalone compiled executables with improved Windows and macOS compatibility
The nub-launcher now supports producing standalone, self-contained executables for macOS, Linux, and Windows. On Windows, the launcher statically links the MSVC C runtime to eliminate the silent \STATUS\_DLL\_NOT\_FOUND\ crash on clean systems, and adds a \--hide-console\ flag to suppress the console window flash for GUI apps. On macOS, the build process now strips unused frameworks (Security, Foundation) to reduce startup time and reserves Mach-O header padding to prevent SIGILL crashes during payload injection. The launcher also features a robust, security-hardened cache resolution system that probes for writable, executable directories in constrained environments (like read-only containers) and provides clear error messages with remediation steps.
crates/nub-launcher · high confidence
Support for OpenJS devEngines field and tolerant manifest parsing
The manifest parser now supports the OpenJS \devEngines\ field (specifying runtime and package manager requirements with \onFail\ policies like \download\ or \warn\), preserving unknown slots for forward compatibility. Additionally, parsing for \engines\, \scripts\, and dependency maps (\dependencies\, \devDependencies\, etc.) is now tolerant of legacy non-standard shapes (such as arrays, strings, or null values) that previously caused install failures, ensuring compatibility with older packages. The workspace configuration also gains support for \catalog\ and \catalogs\ fields for dependency version pinning, and \patchedDependencies\ can now be managed in \pnpm-workspace.yaml\.
vendor/aube/crates/aube-manifest · high confidence
Support for verbatim asset embedding and precompiled ESM bytecode caches
The compile tool now supports embedding arbitrary files (e.g., images, JSON) directly into the executable via \--include\ and \--exclude\ flags, preserving the original source-tree directory structure so that relative imports and \\_\_dirname\-based paths resolve correctly at runtime. Additionally, the compiler can now pre-generate V8 ESM bytecode caches during the build process, which are installed into the Node.js compile cache at startup to significantly reduce warm-start times for large applications.
crates/nub-cli/src/compile · high confidence
Vendor aube engine with CI, build, and release infrastructure
The vendored aube engine is updated to upstream v1.35.0 and accompanied by a comprehensive CI and build system. This includes GitHub Actions workflows for continuous integration, API stability checks (Rust semver and C ABI), documentation generation, benchmarking, and COPR package publishing, alongside Buildkite pipeline definitions and Dockerfiles for Linux and macOS agents. The vendor directory also introduces configuration for dependency automation (Dependabot, Renovate), security auditing (cargo-audit), and AI agent integration (Entire, CodeRabbit, Codex).
vendor/aube · high confidence
Yarn lockfile parsing now supports both Classic (v1) and Berry (v2+)
The lockfile reader now handles both Yarn Classic and Yarn Berry (v2+) formats. Berry lockfiles are detected by the presence of the \\_\_metadata:\ header and parsed using a dedicated YAML-based parser that supports workspace members, patches, and various local/remote source protocols (git, file, link, portal). Classic lockfiles continue to be parsed via the existing line-based tokenizer. Both parsers correctly resolve dependencies, handle scoped packages, and preserve integrity hashes and tarball URLs.
vendor/aube/crates/aube-lockfile/src/yarn · high confidence
Security
Dependency lifecycle scripts gain security scanning and sandboxing
The aube-scripts module now enforces a stricter security posture for dependency build scripts. It introduces a content-sniffing layer that scans \preinstall\, \install\, and \postinstall\ bodies for dangerous patterns—such as piping remote downloads to a shell, decoding base64 payloads, or reading credential files—and reports these as warnings before approval. A new \default-trusted-dependencies.txt\ allowlist (sourced from Bun and pnpm) provides a baseline of trusted native packages, working alongside the existing \allowBuilds\ policy. On Linux, scripts are now executed inside a Landlock filesystem jail and a seccomp network filter that blocks most network access, while Windows scripts are wrapped in a Job Object to ensure the entire process tree is terminated on failure. Additionally, a fast-path executor now runs simple, shell-free commands directly to reduce overhead.
vendor/aube/crates/aube-scripts · high confidence
Behavioural changes
Added nesting depth guard for JSON inputs
The \nub-json-guard\ crate now includes a \check\_nesting\_depth\ function that scans raw JSON/JSONC text to enforce a maximum nesting level before parsing. This prevents stack overflow crashes (SIGSEGV) caused by deeply nested structures in recursive-descent parsers, which are particularly vulnerable on Windows due to smaller stack budgets. The guard correctly ignores brackets inside strings and comments, ensuring that only structural nesting is counted.
crates/nub-json-guard · high confidence
Baked-in offline documentation and Windows stack fix in nub-cli
The nub-cli build script now embeds the repository's documentation tree directly into the binary, enabling the \nub agent docs\ command to serve documentation offline with a generated table of contents and page navigation via slugs. Additionally, the build process now reserves an 8 MB stack for the main thread on Windows to prevent stack overflow crashes during CLI argument parsing, and resolves the \CARGO\_MANIFEST\_DIR\ at runtime to ensure correct behavior when sharing build artifacts across different worktrees.
crates/nub-cli · high confidence
Blog index sorting and title rendering improvements
The blog index page now sorts posts by release version as a tie-breaker when multiple posts share the same date, ensuring consistent ordering for same-day releases. Additionally, backtick spans in post titles are now rendered as inline code for better formatting.
site/src/app/(home)/blog · high confidence
Blog posts now feature a persistent right-gutter table of contents on larger screens
The blog post layout has been restructured to replace the previous in-body, collapsible table of contents with a persistent, sticky right-gutter navigation panel on screens 1024px and wider. This new component uses scroll-spying to highlight the active section and includes a scroll area for long posts, while the original in-body TOC remains visible as a fallback on smaller mobile screens. Additionally, the page metadata generation has been consolidated to include proper Open Graph and Twitter card details for social sharing.
site/src/app/(home)/blog/\[slug\] · high confidence
Cache key now includes filename and Node URL-encoding band to prevent source-map collisions
The transpile cache key derivation has been refactored into a standalone \nub-cache-key\ crate and now incorporates the source filename and the host Node.js URL-encoding band into the hash preimage. Including the filename prevents cache collisions when two different files contain identical source code, which previously caused incorrect \//\# sourceURL\ comments and misattributed V8 stack frames. Including the URL-encoding band ensures that cached outputs generated under different Node.js versions (which vary in how they percent-encode characters like brackets and tildes in file URLs) are kept separate, preventing debugger source-mapping errors when switching Node versions.
crates/nub-cache-key · high confidence
Dynamic OG image generation for documentation pages
A new dynamic route at /og has been introduced to generate Open Graph images for documentation pages. This change replaces the previous static file-convention approach, which was incompatible with the site's optional-catch-all routing structure, by allowing per-page cards to be generated via query parameters (title, eyebrow) and explicitly wired through each page's metadata generation.
site/src/app/og · high confidence
Enforce agent tooling integrity and knowledge-graph consistency via new git hooks
New pre-commit and pre-push hooks in .githooks now enforce structural integrity for the repository's agent skill trees and knowledge graph. The pre-push hook validates that .claude/skills is a real directory (not a symlink), ensures no duplicate skill trees exist in other agent directories, verifies that every skill has a valid SKILL.md with required frontmatter, and checks that per-agent hook scripts remain in sync. The pre-commit hook runs a lightweight check to ensure AGENTS.md remains a symlink to wiki/agents.md and, when wiki files are staged, runs a public-content linter and the lat graph checker to catch broken links or internal content leaks before they are committed. A new commit-msg hook automatically strips Co-authored-by trailers for automated agents (e.g., Claude) to prevent unwanted UI attribution in GitHub.
.githooks · high confidence
Enforces terse GitHub comment style via agent guard and integrates local Lat search
The agent configuration now includes a new pre-tool-use hook that blocks GitHub comment and issue creation commands with bodies exceeding 700 characters, ensuring sub-agents produce factual, terse responses instead of verbose essays (with an override available via NUB\_ALLOW\_LONG\_COMMENT=1). Additionally, the agent environment is configured to use the local Lat search tool (lat.md@0.12.2) alongside the Chrome DevTools MCP server, and a hook is added to invoke the Lat prompt script upon user submission.
.codex · high confidence
Guides moved to a top-level /guides route with dedicated layout and social metadata
The documentation guides are now accessible at the top-level /guides path instead of a nested location. This change introduces a dedicated layout that removes the global navigation links and GitHub pill from the sidebar, keeping the guides section visually distinct from the main docs. Each guide page now includes a footer link to the nubjs/nub GitHub repository, self-canonical URLs to avoid inheriting the root layout's canonical tag, and Open Graph/Twitter metadata for social sharing previews.
site/src/app/guides · high confidence
Homepage redesign with new sections and social image support
The homepage has been restructured to feature a new 'Toolkit' section and a 'HypermanagerBand', while the previous 'Pile' and 'NodeVersionBand' sections have been removed. A video walkthrough section has been added but is currently hidden. The hero area now displays updated benchmark claims (e.g., '24× faster pnpm run') and links to the v0.7.0 blog post. Additionally, Open Graph and Twitter image support has been added for the home page to improve social sharing previews.
site/src/app/(home) · high confidence
Improved build reliability and cache invalidation for the native addon
The nub-native addon now builds reliably in cross-compilation environments by including a dedicated Cross.toml that passes RUSTFLAGS into the build container, ensuring musl cdylib builds succeed. Additionally, the build process now stamps a compile-time build ID (derived from the git commit SHA and dirty state) into the addon, replacing the previous runtime executable hash; this ensures the transpile cache correctly invalidates on local development changes while remaining stable for reproducible releases.
crates/nub-native · high confidence
Improved phantom detection precision for Node builtins, host-provided modules, and type surfaces
The phantom detection logic has been refined to reduce false positives. It now correctly recognizes Node builtins (including \node:\ prefixed and subpathed modules) and host-provided modules like \electron\ and \vscode\ as non-phantoms. Additionally, the extractor now captures type-only imports in Single File Components (SFCs) and declaration files (\.d.ts\), ensuring that type dependencies required for resolution under the global virtual store are not incorrectly flagged as missing runtime dependencies.
crates/nub-phantom-core · high confidence
Improved pnpm lockfile parsing performance and compatibility
The pnpm lockfile reader now includes a purpose-built, high-performance subset parser that significantly speeds up reading standard pnpm-lock.yaml files by bypassing the general YAML parser for common structures. This change also adds support for pnpm v11's multi-document lockfile format, ensuring correct parsing of the new bootstrap document structure, and implements precise checksum generation for \packageExtensions\ and \pnpmfile\ contents to maintain compatibility with pnpm's integrity checks.
vendor/aube/crates/aube-lockfile/src/pnpm · high confidence
Improved postinstall reliability with XDG support and self-healing shims
The npm package's postinstall script now ensures the platform binary is executable even when installed by root and run by a non-root user, and it automatically refreshes package-manager shims (npm, pnpm, yarn, etc.) to point to the new binary after an upgrade. It also honors the XDG\_DATA\_HOME environment variable for locating shim directories on fresh installs, improving compatibility with modern Linux standards and containerized environments.
npm/nub · high confidence
Introduce adaptive concurrency and agent-sandbox detection in aube-util
The vendored aube-util library now includes an adaptive concurrency limiter that dynamically adjusts network request parallelism based on observed round-trip times and server throttling responses, replacing static concurrency caps. It also adds detection for coding agent sandboxes (Codex, Claude Code) to provide accurate error messages when network access is blocked by the host environment, and introduces a process-global sink for tracking version resolution decisions affected by release-age gates.
vendor/aube/crates/aube-util · high confidence
Introduces dependency maturity gating via pnpm workspace and taze configuration
The tools directory now includes a pnpm workspace configuration and a taze configuration file to enforce a 7-day maturity period for newly published dependencies. The pnpm workspace file sets a minimum release age of 10080 minutes (7 days) and defines a catalog for the taze tool, while the taze configuration aligns its maturity period with the same 7-day constant. This change ensures that dependency updates are delayed for a week after publication, reducing the risk of adopting unstable or newly released packages.
tools · high confidence
LLMs.txt index now includes guides and respects navigation order
The site's LLMs.txt index has been updated to include a dedicated 'Guides' section sourced from the new guides collection, in addition to the existing Docs and Blog sections. Furthermore, the order of documentation pages in the index now strictly follows the navigation hierarchy defined in meta.json (depth-first traversal), rather than relying on the arbitrary internal order of the source loader, ensuring a more logical and predictable structure for LLM consumers.
site/src/app/llms.txt · high confidence
Lint code line length based on rendered column width
A new script, \lint-code-line-length.mjs\, has been added to the site build process to enforce that fenced code blocks do not exceed the width of their display column, preventing horizontal scrollbars in the documentation. The script calculates the rendered width of each line (accounting for specific font metrics and ANSI escape sequences) and flags any lines that exceed the defined limits: 75 columns for docs and guides, and 99 columns for the blog. Authors can opt out of this check for specific blocks by adding a \wide\ token to the fence (e.g., \\\`console wide), which is useful for verbatim terminal output that cannot be rewrapped.
site/scripts · high confidence
Lockfile detection now respects package manager declarations
The lockfile reader now prioritizes the package manager declared in \package.json\ (via \packageManager\ or \devEngines\) over simple filename precedence. This prevents accidental format switches when stray lockfiles from other tools (like \package-lock.json\ in a pnpm project) are present, ensuring the project continues using its declared manager's format. The system also handles ambiguity by treating undeclared projects with multiple lockfiles as errors, while preserving aube's own canonical lockfile behavior.
vendor/aube/crates/aube-lockfile/src · high confidence
NPM package now ships a single self-contained binary with embedded runtime
The npm package structure has changed to deliver a single, standalone executable (\bin/nub\) that includes the embedded runtime, eliminating the need for a separate \runtime/\ sidecar directory or vendored \node\_modules\ folder within the package. The build process now stages pure-JS dependencies (such as \@oxc-project/runtime\, \urlpattern-polyfill\, and Temporal/Float16 polyfills) into the repository's \runtime/\ directory, which is then embedded into the binary via the \embed-runtime\ feature. Additionally, a platform-specific launcher binary (\nub-launcher-${PLATFORM}-${ARCH}\) is included to handle race-free self-healing and argument passing, allowing the package to be smaller and more portable across macOS, Linux, and Windows without requiring Node.js to be present for the initial execution.
npm · high confidence
Native HTTP benchmark results added
The benchmarks/data/native-http directory now includes a comprehensive set of JSON benchmark result files covering various adapter correctness, static, fetch, and CPU measurement scenarios. These files provide detailed performance metrics for native HTTP implementations, including latency percentiles, requests per second, and resource usage data across different concurrency levels and test configurations.
benchmarks · high confidence
Native in-process transpiler replaces JS oxc-transform/npm parser
The TypeScript and JSX transpilation pipeline has moved from the JavaScript side (relying on the \oxc-transform\ and \oxc-parser\ npm packages) into the native Rust addon. This change introduces an in-process transpiler that mirrors \oxc-transform@0.140.0\ to ensure byte-identical output, while also moving source-shape detection (module format and decorator detection) and the additive TypeScript resolution layer (tsconfig paths, extension probing, and bare subpath resolution) into Rust. The native cache now handles the full transform-on-miss lifecycle, including post-processing steps like stripping empty CJS export markers and appending source maps and sourceURL comments. As a result, the runtime no longer vendors the \oxc-transform\ and \oxc-parser\ npm packages, reducing the JavaScript-side dependency footprint while maintaining compatibility with existing cache formats.
crates/nub-native/src · high confidence
New hooks enforce GitHub comment brevity and improve context compaction quality
Two new hooks in .claude/hooks enhance agent behavior: gh-comment-guard.mjs blocks GitHub issue/PR comments and creations that exceed 700 characters to prevent verbose essays, while precompact-instructions.mjs steers context compaction to produce exhaustive summaries (targeting 15,000 words) that preserve high-level approach, decisions, and verification status rather than just file edits.
.claude/hooks · high confidence
New package manager engine configuration and compatibility layer
The package manager engine now includes a comprehensive configuration and compatibility layer. It introduces a \bunfig.toml\ parser to map Bun-specific settings (like registries, TLS certificates, and release age gates) into the engine's unified model. A new config-scoping policy ensures that dependency overrides (like \resolutions\ or \overrides\) are applied only if the active package manager (npm, pnpm, yarn, or bun) would honor them, preventing lockfile conflicts. Additionally, a bundled \packageExtensions\ database is now used to fix resolution issues for packages that rely on implicit dependencies in flat node\_modules layouts, and version-gated compatibility checks (e.g., for Expo SDK 56+) determine when to eject from the global virtual store.
_crates/nub-cli/src/pm\engine · high confidence
Node provisioning now supports private registry authentication and hardened extraction
The Node provisioning system in \nub-core\ now supports downloading from private registries by attaching \Authorization\ headers (Bearer tokens or Basic auth) to HTTP requests, enabling the use of private Node mirrors. To improve reliability, downloads now include bounded retries for transient network errors. Security and stability are strengthened with strict caps on archive decompression size, entry count, and per-entry size to prevent decompression bombs, alongside a hardened redirect policy that blocks HTTPS-to-HTTP downgrades to prevent credential leakage. Additionally, the version resolution logic now uses a full pin-chain (including \devEngines.runtime\) for \nub node install\ and caches the Node release index per-mirror using a stable hash to avoid collisions.
_crates/nub-core/src/version\management · high confidence
Port TypeScript tsconfig resolution logic to Rust
The \nub-tsconfig\ crate introduces an in-process Rust implementation for discovering, parsing, and resolving \tsconfig.json\ files, mirroring the behavior of the \get-tsconfig\ npm package. This change enables the tool to handle \extends\ chains, \paths\ matching, and \customConditions\ resolution natively, replacing the previous reliance on the external JavaScript library. Users benefit from consistent configuration handling across the CLI and runtime, with specific support for Node export conditions and cache-friendly hashing, although Yarn PnP resolution for package-extended configs is intentionally omitted in favor of standard node\_modules walking.
crates/nub-tsconfig · high confidence
Refactored phantom detection into a modular, provenance-aware scan pipeline
The \nub-phantom-scan\ crate has been restructured into distinct modules (\graph\, \classify\, \manifest\, \lib\) to improve the precision and transparency of phantom dependency detection. The new graph walker tracks provenance bits to distinguish references reached from the main entry surface, \exports\ subpaths, the \.d.ts\ type surface, and speculative legacy deep paths. This allows the classifier to correctly categorize undeclared dependencies as hard phantoms, soft phantoms (guarded by try/catch), or lower-confidence deep-path-only findings. Additionally, a new \scan-verdicts\ binary has been added to dump per-package scan results for corpus alignment spot-checking.
crates/nub-phantom-scan · high confidence
Registry client hardening and pnpm namedRegistries support
The aube-registry crate introduces several reliability and security improvements: it now supports pnpm's namedRegistries routing so packages can be fetched from aliased hosts, enforces body size caps on all registry responses to prevent out-of-memory attacks, and switches packument cache writes to serde\_json to avoid data corruption when other dependencies enable arbitrary\_precision. Additionally, the client honors the NODE\_EXTRA\_CA\_CERTS environment variable for corporate proxy compatibility and uses HTTP/1.1 exclusively for tarball downloads to avoid head-of-line blocking on HTTP/2 connections.
vendor/aube/crates/aube-registry · high confidence
Self-healing launcher and unified runner for faster, more resilient CLI execution
The \nub\ CLI now features a self-healing launcher mechanism that significantly improves cold-start performance and resilience across package managers. On POSIX systems, the first invocation of \nub\, \nubx\, or the new \nubr\ command automatically replaces the package manager's shim (symlink or cmd-shim) with a lightweight shell trampoline, allowing subsequent calls to bypass Node.js entirely and execute the native binary directly. This change also introduces \nubr\ as a unified runner entry point and ensures the native binary is correctly marked as executable even when npm skips lifecycle scripts (e.g., npm v12's default behavior), preventing permission errors in containerized or restricted environments.
npm/nub/bin · high confidence
Site assets and installers updated for nubjs org and canary channel
The site's public assets have been refreshed with new icon variants (icon.svg, icon-border.svg) and a redesigned Twitter install card (twitter-install.source.html) to reflect the nubjs GitHub organization. The shell and PowerShell install scripts (install.sh, install.ps1) now point to the nubjs/nub repository, support a new 'canary' release channel for nightly builds, allow installation to a custom directory via the NUB\_INSTALL\_DIR environment variable, and verify release archive checksums to ensure download integrity.
site/public · high confidence
Site content negotiation, blog variants, and MDX enhancements
The site now supports AI agents requesting raw Markdown via an Accept header rewrite to /llms/\* paths, and Hacker News blog submissions can use a ?hn query parameter to render an alternate headline server-side. MDX rendering gains a neutral info icon for callouts, a full-height opt-out for code blocks, and syntax highlighting for console and ANSI-escaped terminal output. Additionally, guides have moved to a top-level /guides route with corresponding redirects, and the LLM text endpoint now includes guide content.
site · high confidence
Site redesign: new typography, accessibility fixes, and SEO infrastructure
The site now uses Encode Sans for all text and headings (replacing Newsreader) and Geist Mono for code, improving optical balance and readability. Light-mode accent colors and status glyphs have been darkened to meet WCAG AA contrast requirements, and the theme toggle now respects the user's system preference. SEO and accessibility are hardened with a new PWA manifest, robots.txt, sitemap, JSON-LD structured data, and per-page canonicals. The site is now hosted at nubjs.com, and Vercel Web Analytics has been added.
site/src/app · high confidence
Upgrade aube-store to v2.2.5 with performance and security improvements
The vendored aube-store crate is updated to version 2.2.5, bringing several performance and behavioral changes. On Linux and macOS, the content-addressable store (CAS) now uses a direct-write fast path under an install lock, significantly reducing system calls during package installation. The package index serialization has been optimized by switching from serde\_json to sonic\_rs, resulting in faster index reads and writes. Additionally, the store now supports opt-in transparent filesystem compression for native addons via the AUBE\_COMPRESS\_STORE environment variable, allowing users to reduce disk usage. Security is improved by disabling Git terminal credential prompts to prevent interactive hangs in non-interactive environments, and by validating git positional arguments to prevent potential command injection vulnerabilities.
vendor/aube/crates/aube-store · high confidence
Vendor aube test fixtures as in-tree files
The aube test fixtures (import-bun-messy, import-yarn-portal-exec, workspace) are now included directly in the repository as plain JavaScript files, replacing the previous git submodule setup. This change ensures that the test data for package resolution scenarios is always available locally without requiring external submodule initialization.
(repo-wide) · high confidence
Windows nubx/nubr aliases now run reliably without the MSVC C runtime
The \nubx\ and \nubr\ aliases on Windows are now distributed as standalone executables instead of symlinks, ensuring they work on clean Windows installations that lack the Visual C++ runtime. The new stub binary statically links the MSVC C runtime to avoid missing DLL errors and forwards arguments to the main \nub\ binary via the \\_\_NUB\_ARGV0\ environment variable, matching the behavior already used by the npm launcher.
crates/nub-alias · high confidence
Workspace detection performance, environment security, and script execution parity
This update significantly improves performance by memoizing the workspace root detection walk, caching the result per process and invalidating only when relevant filesystem inputs (manifests and pnpm files) change. It hard-gates pnpm-specific file reads (like \pnpm-workspace.yaml\) to only occur when pnpm is the incumbent package manager, preventing accidental reads in non-pnpm projects. Environment loading now mirrors Node and Deno by ignoring runtime-control variables (such as \NODE\_OPTIONS\ and \NODE\_TLS\_REJECT\_UNAUTHORIZED\) when sourced from \.env\ files, and selects \.env\ modes based on \APP\_ENV\ with a clamped \NODE\_ENV\ fallback. Script execution gains pnpm parity through regex-based script selection (\/pattern/\) and role-aware \npm\_config\_user\_agent\ strings, while \nub run\ now correctly echoes forwarded arguments in the command preamble.
crates/nub-core/src/workspace · high confidence
Fixes
Resolver vendored to aube v2.2.5 with performance and compatibility fixes
The vendored aube-resolver crate has been updated to version 2.2.5. This update includes a performance optimization that replaces deep-cloning of the dependency ancestor chain with an atomic reference-counted pointer, reducing memory allocation overhead during resolution. It also adds benchmarks to track the performance of this chain materialization and the new lockfile-reuse index. Additionally, the resolver now matches pnpm importer peer semantics to improve compatibility, and the build system has been updated to use a new embedded metadata primer schema (version 4) with a 100-version cap for faster cold starts.
vendor/aube/crates/aube-resolver · high confidence
Test coverage
Add command×flag conformance test harness; Add framework GVS acceptance matrix tests; Added Criterion benchmarks for cache hashing, body extraction, and workspace filtering; Added Docker and daily-driver smoke test harnesses; Added Node-version matrix smoke tests for augmentation compatibility; Added WPT conformance test harness for Worker APIs; Added Windows dependency lifecycle shell probe; Added Windows dispatch benchmark to measure shim vs. direct binary performance; Added Windows-specific test harnesses and survey scripts; Added Yarn PnP compatibility test harness; Added acceptance tests for GC tuning and startup behavior; Added acceptance tests for Vite symlink-GVS compatibility; Added brand-boundary lint tests to prevent nub from reading AUBE env vars or writing AUBE-branded paths; Added brand-sweep integration tests to verify engine identity isolation; Added compile-corpus and compile-metadata test suites; Added comprehensive test coverage for Worker polyfill behavior; Added cross-format lockfile conversion test harness; Added differential registry and authentication conformance tests; Added differential workspace-filter test suite against pnpm; Added e2e harness for coding-agent sandboxes; Added e2e test harness running aube's bats suite against nub; Added end-to-end probe for bundled busybox shell on Windows; Added end-to-end test for node-gyp header caching; Added end-to-end test harness for store garbage collection; Added end-to-end test harness for the standalone runner package; Added front-door conformance test harness for package-manager compatibility; Added integration tests for compiled augmentation behavior; Added integration tests for global install and remove commands; Added integration tests for lockfile resolution, naming, and write guards; Added integration tests for nub CLI features; Added integration tests for registry stall timeout handling; Added integration tests for the --hide-console flag; Added local VM control runbook and Linux automation script for Apple Silicon; Added lockfile mutation differential test harness; Added native-dependency floor harness tests; Added npm-incumbent corpus tests for real-world npm projects; Added pnpm conformance test harness; Added regression harness for GVS @parcel/core store-dir over-split; Added regression test for preload injection and fixed flaky concurrency fixture; Added regression tests for globalThis brand boundary; Added runtime benchmark suite for threadpool and context-augmentation performance; Added runtime brand-leak guard tests; Added script-runner benchmark harnesses and baseline results; Added startup performance measurement and ablation tests; Added test fixture for async tier hook registration; Added test fixture for broken tsconfig extends; Added test fixture for process.versions.nub self-identification marker; Added test fixture for verifying argument passthrough; Added test fixture for verifying process identity fields; Added test fixture to verify CJS preload execution order; Added test fixture to verify failure of named imports for data modules; Added test fixtures for CJS require-cache handling during dynamic import; Added test fixtures for Import Text feature; Added test fixtures for TypeScript extension resolution edge cases; Added test fixtures for compile augmentation resolution and bootstrap module isolation; Added test fixtures for data-loader require path, JS-to-JSX transpilation, and loader redirections; Added test fixtures for fetch handler and entry URL rewrite behaviors; Added test fixtures for import defer in workers and nested environments; Added test fixtures for module detection and experimental feature loading; Added test fixtures for navigator shim and Web Locks spec compliance; Added test fixtures for non-file URL loader behavior; Added test fixtures for plain JavaScript transpilation and fallback behaviors; Added test fixtures to verify threadpool sizing behavior; Added test harness for POSIX self-heal launcher; Added tests for Node.js built-in module scheme requirements; Added tests for build-slot concurrency and idle-reclaim logic; Added tests for cache eviction and data URL handling; Added tests for compiled code-cache behavior and warm-startup performance; Added tests for config-scoping policy; Added tests for loader source reuse and module sharing; Added tests for outer loader hook ownership and file handling; Added tests for single-executable application compilation and semantic parity; Added tests for the one-binary verb dispatch mechanism; Added tests for the target garbage collector; Automated Node.js compatibility test corpus regeneration and runner updates; Expanded conformance test fixtures for pnpm workspace scenarios; Expanded test fixtures for compiled standalone executables; Installer verification and configuration tests; New benchmark harnesses for local binary dispatch and cold CAS install performance; New bidirectional conformance test harness for package managers; New lockfile conformance harness for package managers; Updated cross-runtime compatibility benchmark to Node 26.7.0 with new scoring lenses; Updated data-loader test fixture to use default exports; Updated flag-parsing tests to support Windows environments; Vendor BATS testing framework and assertion helpers.
Dependencies
Add workspace-descript benchmark fixtures and Rust workspace scaffolding
Added two new benchmark fixtures (\workspace-descript\ and \workspace-descript-b\) under \benchmarks/pm/fixtures\ to test package manager behavior on large, realistic monorepos containing React, Electron, and Express workspaces. Additionally, introduced new Rust crates (\nub-alias\, \nub-cache-key\, \nub-data-formats\, \nub-json-guard\, \nub-phantom-core\, \nub-phantom-scan\) and updated \nub-launcher\ to support isolated workspace builds, cross-compilation, and size-optimized release profiles.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 57 → 56 (-1.8)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 47 → 47 (+0.1)
- Architecture 100 → 98 (-2.1)
- Maturity 66 → 65 (-0.1)
- Readiness 67 → 53 (-13.7)
- Security 59 → 74 (+14.5)
- Accessibility 82 → 82 (+0.0)
- Performance 73 (new)
Resolved (223)
- (anonymous) (cognitive 45) (runtime/compile-sea-loader.cjs)
- (anonymous) (cyclomatic 41) (runtime/compile-sea-loader.cjs)
- Documentation: no architecture or design documentation (README.md)
- Documentation: written for insiders (tests/native-deps/README.md)
- High CVE: [CVE redacted] (site/pnpm-lock.yaml)
- High CVE: [CVE redacted] (site/pnpm-lock.yaml)
- High CVE: [CVE redacted] (site/pnpm-lock.yaml)
- High CVE: [CVE redacted] (site/pnpm-lock.yaml)
- High CVE: [CVE redacted] (site/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (site/pnpm-lock.yaml)
- High: security finding (details withheld)
- Hotspot: crates/nub-cli/src/compile/native.rs (crates/nub-cli/src/compile/native.rs)
- Hotspot: crates/nub-cli/src/pm_engine/info_family.rs (crates/nub-cli/src/pm_engine/info_family.rs)
- Hotspot: crates/nub-cli/src/pm_engine/mod.rs (crates/nub-cli/src/pm_engine/mod.rs)
- Hotspot: crates/nub-core/src/node/runtime_cache.rs (crates/nub-core/src/node/runtime_cache.rs)
- Hotspot: crates/nub-core/src/pm/provision.rs (crates/nub-core/src/pm/provision.rs)
- Hotspot: crates/nub-core/src/pm/registry.rs (crates/nub-core/src/pm/registry.rs)
- Hotspot: crates/nub-core/src/pm/shim.rs (crates/nub-core/src/pm/shim.rs)
- Hotspot: crates/nub-core/src/workspace/env.rs (crates/nub-core/src/workspace/env.rs)
- Hotspot: crates/nub-launcher/src/cache.rs (crates/nub-launcher/src/cache.rs)
- …and 203 more
New (40)
- (anonymous) (cognitive 47) (runtime/compile-sea-loader.cjs)
- (anonymous) (cyclomatic 42) (runtime/compile-sea-loader.cjs)
- Ambiguous overlap between 'discovery/provision' and 'management/install'. discover_or_provision_node seems to handle finding or installing a node version, while install_one and install_from_pin in the manage module also handle installation. It is unclear if discover_or_provision_node is a high-level wrapper that delegates to install_one, or if they are distinct code paths with different side effects (e.g., caching, pinning).
- Documentation: no architecture or design documentation (npm-ci/README.md)
- Duplicate intent for getting shim directories. There are two separate modules (pm.shim and node.shim) with methods that both return a shim directory path. It is unclear if these refer to the same physical directory, different directories for different purposes, or if one is deprecated.
- Duplicate method signatures in the same module. Two methods named clear with identical signatures (one ignoring the argument name).
- Duplicate method signatures with different parameter names (one uses _dir, one uses dir). This suggests a copy-paste error or an unresolved overload/conflict in the API surface. In Rust, this would be a compilation error unless they are in different traits/modules, but here they appear in the same module nub_core.pm.shim.
- Inconsistent encoding API. encode omits the license blob, while encode_with_license includes it. This forces callers to know which variant to call based on whether they have a license blob, rather than passing an Option<&[u8]> for the license. It also creates two entry points for the same core operation.
- Inconsistent error handling and return types for logically similar operations. discover_node returns a Result (implying potential failure), while discover_node_cached returns the value directly (implying it never fails or panics on failure). This forces callers to handle errors differently for cached vs non-cached paths.
- Low cohesion: AugmentationEnv (LCOM4 4) (crates/nub-core/src/node/spawn.rs)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Members sharing a duplicated core (4 members, 50+ identical tokens) (crates/nub-cli/src/compile/bundle.rs)
- Members sharing a duplicated core (4 members, 50+ identical tokens) (crates/nub-cli/src/pm_engine/info_family.rs)
- Off the main sequence: nub-core
- Off the main sequence: nub-phantom-core
- Outdated: blake3
- …and 20 more
Changes since last survey
- 39 commits — 37 feature/other, 2 fixes
By area
- site/content — 9 commits
- (root) — 4 commits
- vendor/aube — 4 commits
- .claude/skills — 3 commits
- .github/workflows — 3 commits
- crates/nub-cli — 2 commits
- npm/nub — 2 commits
- site/src — 2 commits
- wiki/research — 2 commits
- .github/scripts — 1 commit
- crates/nub-core — 1 commit
- crates/nub-native — 1 commit
- tests/action-smoke — 1 commit
- tests/compile-corpus — 1 commit
- tests/fixtures — 1 commit
- tests/framework-matrix — 1 commit
- winget/manifests — 1 commit
Notable commits
- fix: Fix bugs and improve performance
- fix: wiki: cold-start — the generator fix is per process, not per isolate; four-way re-measurement
- change: Cleanup bad commits (#972)
- change: Serve a default-exported fetch handler (#938)
- change: action-smoke: note that the smoke runs the released Nub, so an unshipped engine change is gated by the corpus and the shim tests
- change: actions: host the setup-node and install GitHub Actions in this repo (#961)
- change: actions: npm-ci, the npm ci step on Nub's engine (#967)
- change: aube-resolver: raise the tarball manifest-scan cap to the store's 1 GiB (#959)
- change: babysit skill: check for an existing CI run before adding the label
- change: blog: hide extension rules the package's current release has outgrown (#950)
- change: blog: keep each extension rule's version range in the table (#949)
- change: blog: replace the extensions table's labels with a hover explanation (#948)
- change: blog: the Nub 0.9.3 release post
- change: blog: the Nub 0.9.5 release post
- change: build: verify Cargo.locks correctly; docs: say what actually bounds the threadpool (#945)
- change: chore: update npm/nub package
- change: disk-reduction: include vendor/libsui in the bucket key, matching rust-build.sh
- change: docs: mise puts nubr on PATH alongside nub and nubx
- change: docs: provision-node on the GitHub Action page; add nubjs/action/setup-node
- change: docs: stop naming the retired loader package
- …and 19 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
nubjs/nub was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit a67ed6c0bd3f1884089f4a03f38b9e1d4dea69d3 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-cb25ca4feafa.