pahen/madge
59.3
Adequate · 2 October 2026
985
lines of production code
JavaScript
primary language
2
measurements over time
What this system is
Madge is a command-line tool and library for analyzing JavaScript and TypeScript module dependency graphs. It detects circular dependencies, identifies orphan and leaf modules, and supports various module formats including AMD, CommonJS, ES6, and Vue components. The system provides programmatic and CLI interfaces for generating dependency trees and visualizing graph structures.
Behavioural changes
API refactored to use Promises and ES6 classes with new analysis methods
The library's core API has been rewritten to use ES6 classes and return Promises instead of callbacks, making it easier to integrate into modern asynchronous workflows. The \Madge\ constructor now accepts a path or a predefined tree and returns a Promise. New methods have been added to the API: \orphan()\ to find modules with no dependents, \leaf()\ to find modules with no dependencies, and \circularGraph()\ to get a graph object of only circular dependencies. The internal tree generation has been moved to \tree.js\ and now uses \dependency-tree\ for more robust path resolution. Output formatting has been consolidated into \output.js\, replacing the old \print.js\ and \color.js\ modules, and now supports JSON output and colored text via \chalk\. The circular dependency detection logic in \cyclic.js\ (renamed from \circular.js\) has been updated to return an array of dependency paths instead of an object.
lib · high confidence
CLI interface overhaul with new options and configuration support
The command-line interface has been completely rewritten, replacing the previous \bin/madge\ script with a new \bin/cli.js\. This change introduces a significantly expanded set of CLI options, including support for TypeScript (\--ts-config\), RequireJS (\--require-config\), and Webpack (\--webpack-config\) configurations, as well as new flags for showing orphans (\--orphans\), leaves (\--leaves\), and custom graph layout directions (\--rankdir\). The CLI now supports reading configuration from \package.json\ and \.madgerc\ files, allows disabling the progress spinner (\--no-spinner\) and colors (\--no-color\), and enables reading predefined dependency trees from standard input (\--stdin\). Output formats have been standardized, with JSON output now triggered by \--json\ instead of \--output json\, and the tool now uses \chalk\ for colored output and \ora\ for the spinner.
bin · high confidence
Removal of internal AMD, CJS, and base parsing modules
The internal implementation files for parsing AMD, CommonJS, and base module structures (lib/parse/amd.js, lib/parse/cjs.js, lib/parse/base.js, and lib/parse/parse.js) have been removed. This change eliminates the legacy code responsible for traversing source files and extracting dependency trees for these module formats, likely as part of a broader refactoring to replace these parsers with an external dependency-tree module.
lib/parse · high confidence
Test coverage
Expanded test coverage for AMD, ES6, TypeScript, and Vue dependency analysis
The test suite has been significantly expanded to validate dependency detection across multiple module systems and frameworks. New tests verify AMD support for ES6 syntax, circular dependencies with path aliases, nested dependencies, and RequireJS shim configurations. ES6 and ES7 support is tested via re-export syntax and async functions, while TypeScript tests cover custom tsconfig paths, the 'extends' field, and mixed CommonJS/ES6 imports. Additionally, new tests ensure correct dependency resolution in Vue Single File Components (both standard and TypeScript variants) and JSX files, alongside API-level tests for features like dependency filtering and RegExp-based exclusions.
test · high confidence
Dependencies
Madge 8.0.0: Major dependency overhaul and Node.js 18 requirement
This release updates the madge package to version 8.0.0, requiring Node.js 18 or later. The dependency tree has been significantly modernized: the core graphing library has switched from the legacy 'graphviz' package to 'ts-graphviz' (v2.1.2), and the module resolution logic now relies on 'dependency-tree' (v11.0.0) instead of the older 'detective' and 'resolve' modules. CLI output styling has moved from 'colors' to 'chalk' (v4.1.2), and the spinner library is now 'ora' (v5.4.1). TypeScript is no longer a direct dependency but is listed as an optional peer dependency (v5.4.4).
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 59 → 59 (+0.5)
- Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 74 → 74 (+0.0)
- Architecture 69 → 69 (+0.0)
- Maturity 51 → 51 (+0.0)
- Readiness 60 → 59 (-1.2)
- Security 75 → 72 (-3.0)
- Performance 100 (new)
Resolved (5)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
New (10)
- End-of-life runtime: Node.js 20
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Outdated (npm): chalk
- Outdated (npm): commander
- Outdated (npm): debug
- Outdated (npm): dependency-tree
- Outdated (npm): ora
- Outdated (npm): pretty-ms
- Outdated (npm): ts-graphviz
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
pahen/madge was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 456057b85c2d063dad9c10147d7686ded4fc5ce5 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.