Skip to content
CAI
Software that uses CAICheck a score

remy/nodemon

61.6

Adequate · 25 September 2026

2.8k

lines of production code

JavaScript

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is nodemon, a utility that monitors changes in source files and automatically restarts Node.js applications. It provides a command-line interface and a programmatic API for managing file watching, process execution, and event handling. The system supports flexible configuration via JSON files and CLI arguments, allowing users to define custom ignore rules, execution commands, and environment variables.

How it got here

2010–2013 — Modular architecture and API expansion

21 changes.

This period focused on restructuring nodemon's internal codebase into modular components for configuration, monitoring, and CLI parsing to improve maintainability and testability. The project introduced a public programmatic API, allowing nodemon to be used as a library, while simultaneously expanding CLI capabilities with new flags and a dynamic help system. Comprehensive test suites were added to cover the new modular architecture, ensuring robust behavior for file watching, process execution, and configuration loading.

2014–2022 — test coverage and website updates

7 changes.

This period focused on expanding test coverage for nodemon's event handling, watch/ignore logic, and package resolution through new fixtures and suites. It also involved launching a new static website with automated sponsor rendering capabilities.

Features

New help system with color support and input sanitization

A new help module has been introduced in lib/help/index.js that dynamically loads CLI documentation from text files in the doc/cli directory. The implementation sanitizes user input to prevent path traversal or invalid file access by stripping non-alphabetic characters, and it integrates with the supports-color library to ensure ANSI color codes in the documentation are rendered correctly only when the terminal supports color.

lib/help · high confidence

New static website with automated sponsor rendering

The website now uses a new static \index.html\ and \style.css\ to display the nodemon landing page, including a dedicated sponsor section. This section is automatically populated by a new Node.js script (\oc.js\) and a jq filter (\oc.jq\) that fetches OpenCollective member data and injects sponsor logos and links into the HTML and README. The site also includes a new \nodemon.svg\ logo and a \sparkpost.svg\ asset.

website · high confidence

Nodemon is now usable as a programmable library

The library now exposes a \nodemon()\ function that accepts settings or a CLI string, allowing developers to start and control the watcher programmatically rather than only via the command line. This change introduces a public API for embedding nodemon in other tools, including support for programmatic configuration, event handling via an internal bus, and proper cleanup of file watchers on exit.

lib · high confidence

Architecture

Introduce dedicated monitor module for file watching and process execution

The file monitoring and child process management logic has been reorganized into a new \lib/monitor\ directory, containing \index.js\, \match.js\, \run.js\, \signals.js\, and \watch.js\. This change consolidates the core functionality for watching file changes (using Chokidar), matching files against ignore/watch rules, and spawning/restarting the user's application script. Users benefit from more robust handling of file patterns, improved cross-platform compatibility (particularly for Windows path normalization and signal handling), and better process tree management during restarts.

lib/monitor · high confidence

Refactored file watch/ignore rules into modular components

The file watching and ignoring logic has been restructured into three distinct modules (add, index, parse) to improve testability and maintainability. The new \parse\ module now handles loading nodemon configuration files, supporting both the legacy plain-text format and the JSON format. The \add\ module manages the conversion of file patterns into internal rules, while the \index\ module exposes a unified API for loading, resetting, and managing watch/ignore rules. This change isolates the rule parsing and management logic, making it easier to test and extend.

lib/rules · high confidence

Behavioural changes

New modular CLI argument parser with expanded option support

The CLI entry point has been refactored into a new modular structure (lib/cli/index.js and lib/cli/parse.js) that replaces the previous argument handling logic. This change introduces support for several new command-line flags, including --spawn, --config, --polling-interval, --on-change-only, --signal, and --no-colours, while also correcting the handling of existing options like --legacy-watch and --no-update-notifier. Users will now experience more precise control over nodemon's behavior through these additional configuration options and a more robust argument parsing mechanism that correctly handles quoted strings and script positioning.

lib/cli · high confidence

Project infrastructure and configuration overhaul

The repository has been restructured with new configuration files to standardize development workflows and improve maintainability. A new ESLint configuration (.eslintrc.json) replaces the previous JSHint setup (.jshintrc), and Prettier is introduced via .prettierrc.json for code formatting. The legacy 'ignore' file has been removed in favor of a comprehensive .gitignore. Additionally, the project now includes a Dockerfile for containerized environments, a Code of Conduct, and updated CI/CD settings via .travis.yml and .releaserc to support automated releases on the main branch.

(repo-wide) · high confidence

Refactored configuration loading and execution logic

The configuration system has been restructured into modular components (command, defaults, exec, load, index) to improve maintainability and fix several behavioral issues. Key changes include: 1) The command construction logic is now isolated in \command.js\, correctly handling the ordering of execArgs, script, and user args. 2) Default options are centralized in \defaults.js\, including the \execMap\ and \ignoreRoot\. 3) The \exec.js\ module now handles script discovery from \package.json\ (prioritizing \main\ then \start\), automatic extension detection (defaulting to \js,mjs,cjs,json\ for JS files), and \execMap\ lookups. 4) The \load.js\ module manages the config file loading order (global -\> local -\> CLI), merges ignore rules with defaults, and handles legacy config support. 5) The main \index.js\ config module now orchestrates the loading process and exposes the final command string. This refactoring fixes issues with script argument ordering, extension watching defaults, and config file priority.

lib/config · high confidence

Refactored internal utilities and logging infrastructure

The lib/utils module has been restructured to improve modularity and reliability. A new event bus (lib/utils/bus.js) now centralizes event handling and supports inter-process communication for forked instances. Logging (lib/utils/log.js) has been rewritten to route messages through this bus, enabling better testability and consistent output. Utility functions for deep cloning (lib/utils/clone.js), object merging (lib/utils/merge.js), and color handling (lib/utils/colour.js) have been extracted into dedicated modules. Additionally, the main utils index (lib/utils/index.js) now exposes platform detection, version checking, and argument stringification helpers.

lib/utils · high confidence

Replace update-notifier with simple-update-notifier

The nodemon executable now uses the simplified 'simple-update-notifier' package instead of the previous 'update-notifier' to check for available updates. This change resolves breaking changes and issues associated with the previous library while maintaining the functionality to notify users of new versions when running non-development versions of nodemon.

bin · high confidence

Test coverage

Added fork-mode integration tests; Added test coverage for CLI argument parsing and execution configuration; Added test coverage for file monitoring and restart behavior; Added test fixture for main and start package handling; Added test fixture for watch count functionality; Added test fixtures and help tests; Added test fixtures for legacy nodemon ignore file formats; Added test fixtures for nodemon event handling; Added test fixtures for package.main preference; Added test fixtures for watch and ignore relative functionality; Added test infrastructure and utilities; Added tests for configuration loading and environment variable passing; Added tests for listener cleanup and SIGINT signal handling; Added tests for nodemon event handling and API behavior; Added tests for nodemon rules configuration loading; Added unit tests for nodemon library API and event handling; Added unit tests for utility functions.

Dependencies

Nodemon dependency and lockfile update

The project's dependency manifest and lockfile have been updated to align with the current dependency tree. Key production dependencies include chokidar (^3.5.2), debug (^4), minimatch (^10.2.1), semver (^7.5.3), and simple-update-notifier (^2.0.0). Dev dependencies such as eslint (^7.32.0), mocha (^2.5.3), and semantic-release (^25.0.0) are also present in the updated package.json and package-lock.json.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 40 → 62 (+21.7)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 61 → 59 (-2.0)
  • Architecture 92 (new)
  • Maturity 61 → 61 (+0.0)
  • Readiness 24 → 59 (+35.5)
  • Security 52 → 72 (+20.7)

Resolved (92)

  • (anonymous) (cognitive 20) (lib/config/load.js)
  • (anonymous) (cognitive 20) (lib/monitor/match.js)
  • (anonymous) (cognitive 23) (lib/monitor/match.js)
  • (anonymous) (cognitive 24) (lib/monitor/run.js)
  • (anonymous) (cognitive 25) (lib/nodemon.js)
  • (anonymous) (cyclomatic 17) (lib/monitor/match.js)
  • (anonymous) (cyclomatic 18) (lib/monitor/run.js)
  • (anonymous) (cyclomatic 21) (lib/nodemon.js)
  • Boundary-crossing change coupling: index.js ↔ bus.js (lib/config/index.js)
  • Boundary-crossing change coupling: index.js ↔ run.js (lib/cli/index.js)
  • Boundary-crossing change coupling: load.js ↔ log.js (lib/config/load.js)
  • Boundary-crossing change coupling: run.js ↔ bus.js (lib/monitor/run.js)
  • Boundary-crossing change coupling: run.js ↔ index.js (lib/monitor/run.js)
  • Boundary-crossing change coupling: run.js ↔ index.js (lib/monitor/run.js)
  • Boundary-crossing change coupling: run.js ↔ log.js (lib/monitor/run.js)
  • Boundary-crossing change coupling: watch.js ↔ add.js (lib/monitor/watch.js)
  • Boundary-crossing change coupling: watch.js ↔ bus.js (lib/monitor/watch.js)
  • Boundary-crossing change coupling: watch.js ↔ index.js (lib/monitor/watch.js)
  • Coverage not measured — test suite did not build
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • …and 72 more

New (85)

  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • FunctionTooLong: nodemon.nodemon (lib/nodemon.js)
  • FunctionTooLong: run.run (lib/monitor/run.js)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • …and 65 more

Changes since last survey

  • 4 commits — 4 feature/other, 0 fixes

By area

  • (root) — 4 commits

Notable commits

  • change: chore: website
  • change: chore: website
  • change: chore: website
  • change: chore: website

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

remy/nodemon was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit bc5990cc615253adbf13544da73fce4ff8d2220b — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-dd72cc24c749.