Skip to content
CAI
Software that uses CAICheck a score

parse-community/parse-server

40.9

Weak · 1 October 2026

47.3k

lines of production code

JavaScript

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is Parse Server, a backend framework that provides a flexible, adapter-based architecture for managing data, authentication, and real-time communication. It supports multiple storage backends including MongoDB and PostgreSQL, and offers extensible modules for caching, file storage, push notifications, and analytics. The platform includes a GraphQL API, LiveQuery for real-time subscriptions, and robust security features such as account lockout, schema enforcement, and configuration auditing.

How it got here

2016 — TypeScript migration and adapter architecture

26 changes.

The codebase underwent a major migration to TypeScript, introducing asynchronous initialization and standardized route syntax. This period focused on restructuring the server around a modular adapter pattern, adding support for PostgreSQL, LiveQuery, and various new services like analytics and push notifications. Significant enhancements included security hardening, CLI improvements, and extensive test infrastructure updates.

2017–2021 — Schema management and security hardening

18 changes.

This period focused on introducing declarative schema management with user-defined definitions and migrations, while significantly hardening the GraphQL API against security vulnerabilities like introspection leaks and DoS attacks. The work also expanded the platform's capabilities with localized push notifications, real-time WebSocket support, and automated configuration generation, alongside comprehensive security auditing tools.

2025 — TypeScript adoption and benchmarking infrastructure

5 changes.

This period focused on introducing comprehensive TypeScript type definitions for Parse Server, its options, and adapters to improve type safety and developer experience. Concurrently, a new benchmarking suite was implemented to monitor performance and detect regressions in continuous integration.

Features

Account lockout policy and security hardening

This release introduces an account lockout policy that automatically locks user accounts after a configurable number of failed login attempts, with an optional automatic unlock on password reset. It also adds a new \enableSanitizedErrorResponse\ configuration option to hide detailed error messages from clients while logging them server-side, and enforces validation of file upload URLs against a configurable list of allowed domains to prevent SSRF attacks.

src · high confidence

Add AnalyticsAdapter base class for analytics integrations

Introduces a new AnalyticsAdapter class in src/Adapters/Analytics that serves as a base implementation for analytics adapters. The class provides default no-op implementations for appOpened and trackEvent methods, allowing derived classes to override specific behaviors while ensuring a consistent interface for analytics data collection.

src/Adapters/Analytics · high confidence

Add TypeScript definitions for Parse Server options

This change introduces the \types/Options/index.d.ts\ file, providing TypeScript type definitions for the \ParseServerOptions\ interface and related configuration structures (such as \SchemaOptions\, \PagesOptions\, \SecurityOptions\, and \RateLimitOptions\). This enables developers using TypeScript to receive compile-time type checking and autocompletion for Parse Server configuration, ensuring that options like \publicServerURL\, \verifyServerUrl\, and \fileUpload\ adhere to the expected types defined in the source code.

types/Options · high confidence

Add TypeScript type definitions and validation tooling

This change introduces TypeScript support by adding \.d.ts\ definition files for the main \ParseServer\ class, options, logger, and various adapters (such as \FileSystemAdapter\, cache adapters, and \AuthAdapter\), along with an \index.d.ts\ to expose these types. It also includes an ESLint configuration (\eslint.config.mjs\) using \typescript-eslint\ to enforce type checking and a \tsconfig.json\ with a test file (\tests.ts\) to validate the correctness of the type definitions.

types · high confidence

Added TypeScript definitions for Parse LiveQuery and external adapters

This change introduces TypeScript declaration files to improve type safety and developer experience. It adds definitions for the \ParseLiveQueryServer\ class, exposing its constructor, lifecycle methods (\connect\, \shutdown\), and internal handling logic for subscriptions and authentication. Additionally, it includes type stubs for the \@parse/fs-files-adapter\ and \deepcopy\ libraries to resolve missing type errors for these dependencies.

types/@types, types/LiveQuery · high confidence

Added localized email verification and password reset pages

Added new HTML templates for email verification and password reset flows in English and German (including Austrian German), allowing users to see these system messages in their preferred language. The update also includes example files demonstrating how to implement custom pages and JSON-based localization for these public-facing routes.

public · high confidence

Added release notes templates for automated changelog generation

The release automation now includes Handlebars templates (header, commit, footer, and template) to structure the generated changelog. These templates define how version headers, commit subjects, linked references, and note groups are formatted in the final release notes.

.releaserc · high confidence

Added vendorized MongoDB URL parser to support special hostname characters

A fork of Node's \url\ module has been added to \src/vendor\ as \mongodbUrl.js\ to handle \mongodb://\ URIs. This vendorized parser allows commas and colons in hostnames, enabling the application to correctly parse and escape the authentication portion of MongoDB connection strings that contain replica set arrays, which standard URL parsers might reject or misinterpret.

src/vendor · high confidence

Automated generation of server configuration definitions

A new build script, \resources/buildConfigDefinitions.js\, has been added to automatically generate the server configuration definitions file (\src/Options/Definitions.js\) from the source option interfaces. This script parses the TypeScript/Flow interfaces to extract property names, types, default values, and environment variable mappings, ensuring that the CLI help text and configuration parsing logic remain synchronized with the defined server options.

resources · high confidence

CLI definitions for Parse Server and Live Query Server

The CLI now exposes command-line argument definitions for the Parse Server and the Live Query Server. New files in src/cli/definitions import and export the corresponding option schemas (ParseServerOptions and LiveQueryServerOptions) from the core Options module, enabling the CLI to parse and validate configuration settings for both server components.

src/cli/definitions · high confidence

Cloud Code validators now support rate limiting and granular role-based access control

Cloud Code function validators can now enforce rate limits and restrict access based on user roles. The \Parse.Cloud.define\ API accepts a validator object that supports \rateLimit\ configuration (with zones for \global\, \session\, \user\, and \ip\ via \ParseServer.RateLimitZone\) to throttle requests, as well as \requireAnyUserRoles\ and \requireAllUserRoles\ to enforce specific role requirements before the function executes. Additionally, the validator schema now explicitly supports \skipWithMasterKey\ to allow master key bypasses for specific validation rules.

src/cloud-code · high confidence

Initial PostgreSQL storage adapter implementation

Introduces the PostgreSQL storage adapter, enabling Parse Server to use PostgreSQL as a backend database. This change adds the core adapter logic in PostgresStorageAdapter, a client factory in PostgresClient for managing database connections and SSL configuration, and a configuration parser in PostgresConfigParser. It also includes a suite of SQL functions for handling JSONB array operations (add, remove, contains) and nested JSON key manipulation, providing the necessary data persistence capabilities for PostgreSQL.

src/Adapters/Storage/Postgres · high confidence

Initial implementation of the LiveQuery server subsystem

This change introduces the core LiveQuery server infrastructure, including the WebSocket server adapter, client connection management, and pub/sub messaging via Redis or in-memory adapters. It adds the subscription lifecycle logic, query matching engine, and request validation schemas, establishing the foundation for real-time data synchronization between clients and the Parse server.

src/LiveQuery · high confidence

Introduce WebSocketServer adapter for real-time connections

Added the WebSocketServer adapter implementation (WSAdapter and WSSAdapter) in src/Adapters/WebSocketServer, providing the underlying infrastructure for handling WebSocket connections, including server initialization, connection lifecycle management, and error handling.

src/Adapters/WebSocketServer · high confidence

Introduce new cache adapter implementations and interface

The cache subsystem in src/Adapters/Cache has been restructured with a new CacheAdapter interface and several concrete implementations. A NullCacheAdapter provides a no-op caching option, while InMemoryCache offers a simple TTL-based in-memory store. The InMemoryCacheAdapter wraps an LRU cache (from the lru-cache library) to handle caching with size and time limits, and the RedisCacheAdapter provides distributed caching with support for per-entry TTLs, connection management, and safe flushing. Additionally, a SchemaCache module manages caching of schema definitions.

src/Adapters/Cache · high confidence

Introduce user-defined schema definitions and migrations

Parse Server now supports defining the database schema via the new \schema.definitions\ configuration option, allowing administrators to enforce a specific schema structure. This change introduces schema migration capabilities with \beforeMigration\ and \afterMigration\ callbacks, along with options to control schema enforcement such as \strict\ mode, \lockSchemas\ to prevent runtime modifications, and \deleteExtraFields\ to automatically remove undefined fields during development.

src/Options · high confidence

Introduces MailAdapter base class for email sending

A new MailAdapter base class has been added to the email adapter module, providing a standard interface for sending emails. This class defines a sendMail method that accepts recipient, text, and subject parameters, serving as the foundation for implementing specific email delivery mechanisms.

src/Adapters/Email · high confidence

Introduction of PushAdapter interface for custom push notification mechanisms

A new PushAdapter class has been added to src/Adapters/Push, providing a standard interface for customizing push notification delivery. This adapter defines the required send method, which accepts notification body, installation targets, and push status, along with a getValidPushTypes method to declare supported platforms. Users can now extend this class to implement alternative push providers beyond the default FCM and APNS configuration.

src/Adapters/Push · high confidence

New CLI argument parsing and configuration loading utilities

The CLI now uses a new utility module in src/cli/utils to handle command-line argument parsing and configuration loading. The commander.js file extends the Commander library to support loading options from definitions, environment variables, and JSON config files, with a specific priority order: environment variables are loaded first, then overridden by config file values, and finally defaults are applied. It also includes deprecation scanning for Parse Server options. The runner.js file provides a standardized entry point that loads definitions, parses arguments, and logs startup options with sensitive data redaction (e.g., databaseURI, masterKey) when verbose mode is enabled.

src/cli/utils · high confidence

New CLI entry points for Parse Server and Live Query Server

This change introduces dedicated CLI scripts (\parse-server\ and \parse-live-query-server\) that wrap the core library for easier command-line usage. The \parse-server\ script now handles argument validation (requiring \appId\ and \masterKey\), normalizes legacy options like \liveQuery.classNames\ into the proper structure, and supports cluster mode for multi-process deployment. The \parse-live-query-server\ script provides a direct interface to start the live query server using the same runner infrastructure.

bin, src/cli · high confidence

New GraphQL API for Global Config and Schema Management

The GraphQL API now exposes new queries and mutations for managing server configuration and schema definitions. Users can retrieve and update Global Config parameters via the \cloudConfig\ query and \updateCloudConfig\ mutation, which require master key authentication. Additionally, the API provides \class\ and \classes\ queries, along with \createClass\, \updateClass\, and \deleteClass\ mutations, allowing administrators to inspect and modify the database schema directly through GraphQL.

src/GraphQL/loaders · high confidence

New PubSub adapter implementations for LiveQuery

The LiveQuery server now supports configurable pub/sub backends via new adapter files in src/Adapters/PubSub. A PubSubAdapter interface defines the contract, while EventEmitterPubSub provides an in-memory implementation that resets listener counts to prevent warnings, and RedisPubSub provides a Redis-based implementation using the redis client for distributed messaging.

src/Adapters/PubSub · high confidence

New aggregate, analytics, audience, and global config routers added

The server now exposes dedicated routers for several new capabilities: the AggregateRouter enables native MongoDB-style aggregation pipelines on classes (with support for rawValues/rawFieldNames and a new allowAggregationForReadOnlyMasterKey config option); the AnalyticsRouter adds endpoints for app-opened and custom event tracking; the AudiencesRouter provides CRUD operations for push audiences under /push\_audiences; and the GlobalConfigRouter allows reading and updating server configuration via /config, including masterKeyOnly field masking and beforeSave/afterSave hooks. Additionally, the FeaturesRouter now reports these capabilities (globalConfig, pushAudiences, etc.) in the /serverInfo endpoint, and the ClassesRouter enforces idempotency on user creation to prevent role-privilege acquisition via crafted objectIds.

src/Routers · high confidence

New benchmarking infrastructure for performance regression detection

Added a new benchmarking suite in the \benchmark/\ directory to measure Parse Server performance and detect regressions in CI. This includes \performance.js\ for running benchmarks with configurable iterations and optional artificial MongoDB latency (via \MongoLatencyWrapper.js\), and \compare.js\ for comparing PR results against a baseline, flagging regressions, and performing retests to rule out CI runner noise.

benchmark · high confidence

New modular authentication adapter interface and base classes

The authentication system now uses a new \AuthAdapter\ base class and \BaseCodeAuthAdapter\ helper, providing a structured interface with distinct lifecycle methods (\validateSetUp\, \validateLogin\, \validateUpdate\, \challenge\, \afterFind\) and usage policies (\default\, \additional\, \solo\). This change introduces a more powerful and extensible framework for custom authentication adapters, allowing developers to implement specific validation logic for different user states and support multi-factor authentication flows.

src/Adapters/Auth · high confidence

New security check system for detecting weak configurations

Added a new security check framework in src/Security that allows Parse Server to detect and report weak security settings. The system includes a Check class for individual validations, a CheckGroup class for organizing checks, and a CheckRunner that executes these checks and generates a JSON report. Users can enable this feature via configuration options to receive warnings about potential security issues along with suggested solutions.

src/Security · high confidence

New security configuration checks for database and server settings

This change introduces a new security auditing module in src/Security/CheckGroups that automatically validates Parse Server configuration against common security best practices. The 'Database' check group verifies that the database password meets complexity requirements (length ≥14, mixed case, numbers, special characters). The 'Parse Server Configuration' check group enforces secure defaults by checking for a strong master key, disabled client class creation, enforced private users, disabled insecure auth adapters, disabled GraphQL public introspection and playground, restricted public database explain, restricted read-only master key IP ranges, enabled request complexity limits, mitigated user enumeration in password reset and email verification endpoints, and enabled LiveQuery regex timeouts. These checks help administrators identify and remediate misconfigurations that could lead to brute-force attacks, data exposure, or denial-of-service vulnerabilities.

src/Security/CheckGroups · high confidence

Support for user-defined schema migrations

Users can now define and enforce their application's data schema using a new \DefinedSchemas\ class and migration framework. By providing schema definitions via \schemaOptions.definitions\, the system automatically creates or updates classes in the database to match the specified fields, indexes, and class-level permissions. The framework supports a \strict\ mode to warn about schemas present in the database but not defined in code, and includes hooks for \beforeMigration\ and \afterMigration\ execution. This allows for version-controlled, declarative schema management rather than relying solely on automatic schema generation.

src/SchemaMigrations · high confidence

Removals

Removal of default cloud code functions

The default cloud code file (cloud/main.js) containing sample functions like 'hello', 'foo', and 'bar', as well as various beforeSave/afterSave triggers, has been removed from the server. Users relying on these default definitions will need to provide their own cloud code configuration.

cloud · high confidence

Security

Security hardening of GraphQL API against schema disclosure and DoS

This update addresses multiple security vulnerabilities in the GraphQL API by implementing strict introspection controls and input sanitization. It prevents schema disclosure to unauthenticated users by blocking introspection queries (including via inline fragments and automatic persisted queries) and stripping 'Did you mean' validation suggestions and input-coercion error messages that previously leaked class, field, and type names. Additionally, it introduces query complexity validation to mitigate denial-of-service risks from unbounded queries and ensures that CORS and WebSocket security middleware are correctly enforced.

src/GraphQL · high confidence

Architecture

Introduces AdaptableController base class for adapter-based controllers

A new AdaptableController base class has been added to the Controllers directory to standardize how controllers interact with external adapters. This base class manages the adapter instance via private setters and getters, and enforces that the provided adapter implements the expected interface by validating that the adapter's prototype matches the required methods. Controllers such as AnalyticsController, CacheController, FilesController, LoggerController, and UserController now extend this base class, ensuring consistent adapter validation and injection across the server.

src/Controllers · high confidence

Behavioural changes

Defines the StorageAdapter interface with Flow types and extended query options

The storage adapter layer now exposes a formalized interface (StorageAdapter.js) using Flow types, which standardizes the contract for storage implementations. This interface introduces support for advanced query options such as \hint\, \comment\, \rawValues\, and \rawFieldNames\ in aggregation and count operations, and updates the \updateObjectsByQuery\ method to optionally return \matchedCount\ and \modifiedCount\ for better update visibility. It also includes properties for schema caching (\schemaCacheTtl\, \enableSchemaHooks\) and transactional session management, providing a more robust and typed foundation for storage operations.

src/Adapters/Storage · high confidence

GraphQL query complexity validation and helper refactoring

The GraphQL helpers have been refactored to introduce explicit query complexity validation and restructure core data access logic. A new queryComplexity module now enforces configurable limits on query depth and field count via a validation plugin, protecting the API from denial-of-service attacks caused by unbounded query complexity. Additionally, object mutations (create, update, delete) and queries have been moved into dedicated helper files (objectsMutations.js and objectsQueries.js), centralizing the logic for interacting with the REST layer and handling context propagation.

src/GraphQL/helpers · high confidence

GraphQL schema transformation logic is restructured into modular transformer files

The GraphQL schema generation logic in \src/GraphQL/transformers\ has been refactored into distinct, modular files (\className.js\, \constraintType.js\, \inputType.js\, \mutation.js\, \outputType.js\, \query.js\, \schemaFields.js\). This change separates concerns by extracting specific transformation responsibilities—such as mapping Parse types to GraphQL input/output types, handling query constraints, and processing mutations—into their own modules. For users, this ensures that GraphQL schema generation is more maintainable and robust, particularly regarding how complex types like Pointers, Relations, and Files are transformed between the Parse and GraphQL domains.

src/GraphQL/transformers · high confidence

Introduce MongoCollection and MongoSchemaCollection abstractions for MongoDB storage

The MongoDB storage adapter now uses dedicated \MongoCollection\ and \MongoSchemaCollection\ wrapper classes to manage database interactions. \MongoCollection\ implements 'smart indexing' for geospatial queries, automatically creating missing \2d\ indexes when queries use operators like \$nearSphere\ or \$geoNear\, and includes logic to identify the specific field requiring the index to support MongoDB 8.3+ error messages. \MongoSchemaCollection\ centralizes schema management, handling the conversion between MongoDB internal schema formats and Parse schema objects, including class-level permissions and indexes. These changes isolate MongoDB-specific logic within the adapter, removing direct dependencies on the \schemaController\ and raw MongoDB access from higher-level components like \SchemaRouter\ and \DatabaseController\.

src/Adapters/Storage/Mongo · high confidence

Introduce extensible Winston-based logging adapter

The logger adapter in src/Adapters/Logger has been replaced with a new implementation based on Winston 3, providing structured JSON logging, configurable log levels, and support for daily log rotation. Users can now customize the logging mechanism via options such as logsFolder, jsonLogs, logLevel, and maxLogFiles, and can dynamically add or remove log transports at runtime through the new addTransport and removeTransport methods.

src/Adapters/Logger · high confidence

New AdapterLoader module for flexible adapter instantiation

A new \AdapterLoader\ module has been introduced in \src/Adapters\ to standardize how adapters are loaded and instantiated. The \loadAdapter\ function now handles various input formats, including direct adapter classes, constructor functions, string module paths, and configuration objects specifying \module\, \class\, or \adapter\ properties. This change centralizes the logic for resolving and initializing adapters, allowing for more flexible configuration options and fallback to default adapters when none are explicitly provided.

src/Adapters · high confidence

New CI checks for dependency versions and definitions integrity

The CI pipeline now includes automated checks to ensure compatibility and consistency. A new version check script validates that the CI matrix tests against the latest supported versions of Node.js and MongoDB, ignoring end-of-life or unsupported rapid-release versions. Additionally, a node engine check verifies that all dependencies in node\_modules do not require a higher Node.js version than the one specified in the project's package.json, preventing runtime incompatibilities. Finally, a definitions check ensures that the generated Options definitions and documentation files are not manually edited but are instead regenerated via the build script, maintaining consistency between source code and documentation.

ci · high confidence

New dedicated scripts for Postgres test environment setup and configuration

Added two new shell scripts, \before\_script\_postgres.sh\ and \before\_script\_postgres\_conf.sh\, to the \scripts\ directory. The first script initializes the test database by creating the \parse\_server\_postgres\_adapter\_test\_database\ and enabling the \pgcrypto\, \postgis\, and \postgis\_topology\ extensions. The second script applies specific PostgreSQL configuration settings (such as connection limits, memory buffers, and WAL settings) to optimize the database environment for testing.

scripts · high confidence

Parse Server 9.0.0: TypeScript migration, async initialization, and route syntax update

Parse Server 9.0.0 introduces several significant changes. The codebase has been migrated to TypeScript, requiring Node.js 18+ and changing the import syntax to \const { ParseServer } = require('parse-server')\. Initialization is now asynchronous, requiring \await server.start()\ before mounting the app. Route path syntax has been standardized to use path-to-regexp v8, with old wildcard syntax deprecated. The email verification process no longer uses the username field, and automatic indexes are created for \\_email\_verify\_token\ and \\_perishable\_token\ fields.

(repo-wide) · high confidence

Password reset page now requires password confirmation

The password reset view has been updated to include a 'Confirm New Password' input field alongside the original password field. This change enforces a confirmation step during the password reset flow, requiring users to enter their new password twice to prevent typos, with client-side validation provided via JavaScript to indicate if the entries match before submission.

views · high confidence

Refactored file storage adapters with encryption and streaming support

The file storage adapters in src/Adapters/Files have been restructured to introduce a base FilesAdapter interface and a new GridFSBucketAdapter that replaces the deprecated GridStoreAdapter. This change adds support for AES-256-GCM file encryption via an optional encryption key, enables streaming file uploads for better performance, and allows custom client metadata to be sent to the MongoDB driver for logging and debugging purposes. The old GridStoreAdapter is now removed and throws an error directing users to migrate to GridFSBucketAdapter.

src/Adapters/Files · high confidence

Refactored push notification processing to support localized payloads and badge increments

The push notification system in src/Push has been refactored to introduce new components (PushQueue, PushWorker, utils) that enhance payload handling. Users can now send localized push notifications by specifying locale-specific keys (e.g., alert-en, title-fr) in the push body, which are automatically routed to the correct installations based on their localeIdentifier. Additionally, the system now supports incrementing badge counts on installations using the 'increment' operation, allowing for more dynamic badge management. The refactoring also includes improved handling of push status and device token validation.

src/Push · high confidence

Runtime deprecation warnings for configuration options

Parse Server now logs warnings at startup for configuration options that will change their default values or be removed in future versions. This includes tightening defaults for security and complexity limits (such as \fileUpload.allowedFileUrlDomains\, \readOnlyMasterKeyIps\, and various \requestComplexity\ settings), removing legacy features (like \mountPlayground\, \playgroundPath\, \enableProductPurchaseLegacyApi\, and \allowExpiredAuthDataToken\), and adjusting behavior for \protectedFields\ and \installation\ deduplication. Users are advised to explicitly set these options to the new desired values to suppress warnings and ensure stable behavior.

src/Deprecator · high confidence

Test coverage

1556 commits adding/updating tests in spec; Added mock adapters for testing file and mail operations; Added test coverage for authentication adapters; Enhanced test infrastructure with spec reporting and mock adapters.

Dependencies

2690 commits updating dependencies (4 manifests)

A dependency / build maintenance change in (dependencies) — 2690 commits (350 fixs), 4 files.

(dependencies) · high confidence · unverified

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 39 → 41 (+1.6)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 40 → 40 (-0.3)
  • Architecture 75 → 75 (-0.3)
  • Maturity 55 → 56 (+0.3)
  • Readiness 40 → 44 (+3.2)
  • Security 46 → 54 (+7.9)
  • Accessibility 35 → 35 (+0.0)
  • Performance 85 (new)

Resolved (71)

  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • FilesController.expandFilesInObject (cognitive 19) (src/Controllers/FilesController.js)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • …and 51 more

New (84)

  • Critical CVE: [GHSA redacted] (package-lock.json)
  • End-of-life runtime: Node.js 20
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Hotspot: src/GraphQL/ParseGraphQLServer.js (src/GraphQL/ParseGraphQLServer.js)
  • Low CVE: [GHSA redacted] (package-lock.json)
  • Low cohesion: Config (LCOM4 6) (src/Config.js)
  • Medium CVE: [GHSA redacted] (package-lock.json)
  • Medium CVE: [GHSA redacted] (package-lock.json)
  • Medium CVE: [GHSA redacted] (package-lock.json)
  • Medium CVE: [GHSA redacted] (package-lock.json)
  • Medium vulnerability: [GHSA redacted] (package-lock.json)
  • Medium: security finding (details withheld)
  • …and 64 more

Changes since last survey

  • 57 commits — 41 feature/other, 16 fixes

By area

  • (root) — 39 commits
  • spec/vulnerabilities.spec.js — 4 commits
  • (repo) — 2 commits
  • .github/workflows — 2 commits
  • spec/ParseGraphQLServer.spec.js — 2 commits
  • spec/AuthenticationAdapters.spec.js — 1 commit
  • spec/EmailVerificationToken.spec.js — 1 commit
  • spec/MongoStorageAdapter.spec.js — 1 commit
  • spec/ParseLiveQuery.spec.js — 1 commit
  • spec/ParseLiveQueryServer.spec.js — 1 commit
  • spec/index.spec.js — 1 commit
  • src/GraphQL — 1 commit
  • src/Options — 1 commit

Notable commits

  • fix: fix: Bump @parse/push-adapter from 8.4.0 to 8.5.3 (#10676)
  • fix: fix: Bump body-parser from 2.2.2 to 2.3.0 (#10600)
  • fix: fix: Bump express-rate-limit from 8.3.1 to 8.7.0 (#10672)
  • fix: fix: Bump parse from 8.6.0 to 8.6.2, @parse/push-adapter from 8.5.3 to 8.5.5 and ws from 8.21.0 to 8.21.3 (#10688)
  • fix: fix: Bump qs from 6.15.2 to 6.16.0 (#10651)
  • fix: fix: Bump undici from 7.28.0 to 7.29.1 (#10674)
  • fix: fix: GraphQL argument and enum validation errors disclose target class names when public introspection is disabled ([[GHSA redacted]](https://github.com/parse-community/parse-server/security/advisories/[GHSA redacted])) (#10665)
  • fix: fix: GraphQL schema is disclosed by replaying an automatic persisted query when public introspection is disabled ([[GHSA redacted]](https://github.com/parse-community/parse-server/security/advisories/[GHSA redacted])) (#10669)
  • fix: fix: LiveQuery evaluates class-level permissions against an incomplete caller identity (#10675)
  • fix: fix: LiveQuery ignores userField protectedFields groups and over-redacts fields the REST path returns (#10690)
  • fix: fix: Parse Server option graphQLPublicIntrospection has no effect (#10696)
  • fix: fix: Per-entry cache TTL is ignored by the in-memory cache adapter (#10671)
  • fix: fix: Relation count query bypasses protectedFields for identity-scoped groups ([[GHSA redacted]](https://github.com/parse-community/parse-server/security/advisories/[GHSA redacted])) (#10667)
  • fix: fix: Server crash via file pointer without URL in an object write ([[GHSA redacted]](https://github.com/parse-community/parse-server/security/advisories/[GHSA redacted])) (#10694)
  • fix: fix: Server crash via unhandled error when sending verification or password reset email (([[GHSA redacted]](https://github.com/parse-community/parse-server/security/advisories/[GHSA redacted]))) (#10730)
  • fix: fix: Transactional batch request can roll back or block writes of other clients ([[GHSA redacted]](https://github.com/parse-community/parse-server/security/advisories/[GHSA redacted])) (#10713)
  • change: build: Release (#10689)
  • change: chore(release): 9.10.1 [skip ci]
  • change: chore(release): 9.10.1-alpha.12 [skip ci]
  • change: chore(release): 9.10.1-alpha.13 [skip ci]
  • …and 37 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

parse-community/parse-server was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit f4c5f31032dfe5955ce39a58be055f5be9d5a60d — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.