Skip to content
CAI
Software that uses CAICheck a score

trunk-rs/trunk

61.2

Adequate · 30 September 2026

9.9k

lines of production code

Rust

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Trunk is a build tool and development server for WebAssembly-based web applications, primarily targeting Rust projects. It manages the compilation of Rust code to WASM, integrates with frontend assets like CSS and JavaScript, and provides a local server with live-reloading capabilities. The system supports complex build pipelines, including proxying, custom hooks, and integration with popular Rust web frameworks.

How it got here

2020–2021 — Configuration system and CLI expansion

13 changes.

This period focused on introducing a declarative Trunk.toml configuration file and a robust proxy system, alongside restructuring the configuration subsystem for better modularity. The CLI was expanded with dedicated subcommands for build, watch, and tool management, while new asset pipelines and a build failure overlay enhanced the developer experience. The release also included several new example applications demonstrating integration with frameworks like Yew and Seed, as well as vanilla Rust and Tailwind CSS.

2022–2023 — WebWorker examples and processing enhancements

10 changes.

This period focused on expanding the example suite to cover Web Workers, vanilla WASM, and non-Rust workflows, while introducing a Trunk-only static asset example. Internally, the project implemented dedicated modules for integrity hash generation and asset minification, alongside progress tracking for WASM loading.

2024–2026 — Configuration overhaul and example expansion

15 changes.

The project underwent a significant restructuring of its configuration system, introducing modular models, migration support for legacy fields, and flexible file format options. Concurrently, the codebase expanded its example suite to demonstrate advanced capabilities such as WebAssembly threading, Node.js package integration, and reverse proxy deployment, while adding new pipelines for node module handling.

Features

Add Gloo web worker example

The examples/webworker-gloo directory now contains a complete example demonstrating how to use Gloo workers in a Rust web application. This includes a Trunk build configuration, an HTML entry point that loads both the main application and worker binaries, and Rust source code defining a 'Multiplier' worker that performs calculations and communicates results back to the main thread via callbacks.

examples/webworker-gloo · high confidence

Add Leptos WASM example application

A new example application demonstrating how to build a WebAssembly application using the Leptos framework. The example includes the necessary HTML entry point, Rust source code, and JavaScript module, allowing users to run and view the app locally by executing \trunk serve --open\ from the \examples/leptos\ directory.

examples/leptos · high confidence

Add Node Module example using PatternFly

A new example in the examples/node-module directory demonstrates integrating the @patternfly/patternfly npm package (version 6.4.0) with Trunk. The setup includes a Trunk.toml configuration to declare the dependency, an index.html that links the PatternFly SCSS styles and assets, and a Rust source file that dynamically creates a styled button using PatternFly CSS classes.

examples/node-module · high confidence

Add Seed-based TodoMVC example application

Introduces a new example application in the \examples/seed\ directory that demonstrates building a WebAssembly web app using the Seed framework and Trunk. The example implements a full TodoMVC interface, including creating, editing, toggling, and removing todos, with state persistence via browser LocalStorage and URL-based filtering (All, Active, Completed).

examples/seed · high confidence

Add Vanilla Rust example using web-sys

Added a new example demonstrating how to build a vanilla Rust WebAssembly application using the web-sys crate. The example includes a Trunk configuration, an HTML entry point that loads Rust, SCSS, CSS, and JavaScript assets, and Rust source code that interacts with the DOM and JavaScript via FFI. It also demonstrates the new startup event for ensuring WebAssembly bindings are ready and shows how to disable CSS minification for specific files.

examples/vanilla · high confidence

Add WebWorker example demonstrating WASM-based background threads

The examples/webworker directory now includes a complete example showing how to use Web Workers with Rust/WASM. It features an HTML entry point that loads both a main application binary and a worker binary, along with Rust source files for the main app (app.rs) and the worker (worker.rs). The example demonstrates spawning a dedicated worker via a Blob URL, handling message passing between the main thread and the worker, and properly synchronizing to ensure the worker is ready before sending messages.

examples/webworker · high confidence

Add Yew + Tailwind CSS example application

A new example application has been added to demonstrate building a WebAssembly web app using Trunk, the Yew framework, and Tailwind CSS. The example includes a Trunk configuration, an HTML entry point that links the Tailwind CSS source, and a Rust component that renders a styled navigation bar and informational cards using Tailwind utility classes.

examples/yew-tailwindcss · high confidence

Add Yew and YBC example application

A new example application demonstrating how to build a WebAssembly web app using Trunk, the Yew framework, and the YBC component library. The example includes a Trunk configuration, an HTML entry point that links SCSS and Rust sources, and a Rust source file that renders a UI using YBC components and demonstrates enabling Cargo features via the \data-cargo-features\ attribute.

examples/yew · high confidence

Add blog section with RSS feed and custom styling

The site now includes a dedicated blog section. Users can view a list of blog posts on the new blog page, which also provides an RSS/Atom feed subscription link. Individual blog posts display the author and date, and the layout includes specific styling for the author metadata and fixes for code block indentation and background colors within the Juice theme.

site/templates · high confidence

Add cdylib example demonstrating vanilla Rust WASM with web-sys

A new example application has been added to the examples/cdylib directory, showcasing how to build a vanilla Rust WebAssembly application using the web-sys library without any frameworks. The example includes a Trunk configuration, an HTML entry point that links the Rust crate and a JavaScript helper, and source files for styling and logic, allowing users to run and view the rendered output via \trunk serve\.

examples/cdylib · high confidence

Add examples for Cargo.toml and YAML configuration modes

Two new example applications are added to demonstrate Trunk's configuration system: one using a \Cargo.toml\ file for configuration and another using a \Trunk.yaml\ file. These examples provide ready-to-run templates showing how to structure a vanilla Rust WASM web application under each configuration approach, including the necessary HTML, CSS, and Rust source files.

examples/cargo-manifest, examples/yaml-config · high confidence

Add hooks example demonstrating build-time code generation

A new example in the \examples/hooks\ directory demonstrates how to use Trunk's hook system to run custom code during the build process. It showcases two approaches: an \xtask\-based hook defined in \Trunk.toml\ that generates JavaScript via a separate Rust crate, and a standard Cargo \build.rs\ script that conditionally generates code based on enabled features. The example includes the necessary configuration, source files, and documentation to help users understand how to integrate custom build steps into their Trunk projects.

examples/hooks, examples/hooks/xtask · high confidence

Add node package download pipeline

Introduces a new pipeline component that downloads and extracts Node.js packages from npm-compatible registries. The system spawns asynchronous tasks to fetch package metadata, download the corresponding tarballs, and unpack them into the target directory, with support for custom registry URLs and proper error handling for network or not-found issues.

_src/pipelines/node\packages · high confidence

Add wasm\_threads example demonstrating shared-memory Web Workers

Introduces a new example in examples/wasm\_threads that showcases multi-threading in WebAssembly using the wasm\_thread crate. This example enables shared memory between threads via SharedArrayBuffer, requiring specific HTTP headers (Cross-Origin-Embedder-Policy, Cross-Origin-Opener-Policy) configured in Trunk.toml and served via assets/\_headers. It relies on a nightly Rust toolchain (rust-toolchain.toml) to rebuild the standard library with atomic and bulk-memory features, and includes VS Code settings to ensure rust-analyzer compatibility with the build-std flag.

_examples/wasm\threads · high confidence

Added WebWorker module example

A new example demonstrating how to use Web Workers with Rust/WASM modules via Trunk. It includes a main application binary that spawns a module-based worker and a worker binary that performs a multiplication task, illustrating the correct message-passing lifecycle for asynchronous WASM workers.

examples/webworker-module · high confidence

Added example demonstrating Trunk without Rust/WASM

A new example project located at examples/no-rust has been added to demonstrate building static web assets using Trunk without requiring Rust or WASM compilation. This example includes a Trunk configuration file, an HTML entry point that links an SCSS stylesheet, and the corresponding SCSS file, providing a reference for users who want to use Trunk for standard web development.

examples/no-rust · high confidence

Added page-specific table of contents (pagetoc)

The guide theme now includes a fixed, scrollable table of contents on the right side of the page that highlights the current section as the user scrolls. This feature is implemented via new CSS and JavaScript files in the theme directory, which dynamically generate the TOC from page headers and handle active state updates and scrolling behavior.

guide/theme · high confidence

Introduction of Trunk.toml configuration and proxy system

Trunk now supports a declarative configuration file, Trunk.toml, allowing users to define build, serve, watch, and tool settings (such as sass and wasm-bindgen versions) without relying solely on CLI flags. This change introduces a robust proxy system for the development server, enabling HTTP and WebSocket proxying with features like path rewriting, insecure certificate handling, and system proxy bypass. Additionally, the configuration system supports build hooks (pre\_build, build, post\_build) with OS-specific command overrides, giving users greater control over the build pipeline.

(repo-wide) · high confidence

New CLI commands for build, clean, watch, and tool management

The CLI now includes dedicated subcommands for managing the build lifecycle and environment. Users can run \trunk build\ to compile assets with granular control over output, minification, and Cargo profiles; \trunk clean\ to remove build artifacts, run \cargo clean\, or clear the tools cache; and \trunk watch\ to automatically rebuild on file changes with options for polling and screen clearing. Additionally, \trunk tools\ allows users to inspect installed tool versions, while \trunk config\ provides utilities to view the current configuration or generate a JSON schema.

src/cmd · high confidence

New Trunk Proxy example with configurable request headers

Added a new example demonstrating the Trunk proxy system for HTTP and WebSocket endpoints. The example includes a \Trunk.toml\ configuration showing how to set up WebSocket proxies, rewrite URLs, and inject custom request headers (such as \x-api-key\) into proxied requests. It also provides a \docker-compose.yaml\ file to spin up a local echo server for testing and a minimal Rust/WASM frontend.

examples/proxy · high confidence

New Yew TLS example with self-signed certificates

Added a new example application in \examples/yew-tls\ that demonstrates serving a Yew web application over HTTPS using Trunk. The example includes a \Trunk.toml\ configuration pointing to self-signed TLS certificates (valid until 2033) located in \self\_signed\_certs/\, along with instructions in the README for generating new certificates. The application itself uses Yew 0.20 and YBC 0.4 to display the current browser location, leveraging \web\_sys\ instead of the deprecated \stdweb\.

examples/yew-tls · high confidence

New asset pipelines for copying files and directories

The build system now supports copying arbitrary files and directories into the distribution output via new \copy-file\ and \copy-dir\ asset pipelines. Users can include these in their HTML using \\<link data-trunk rel="copy-file" href="..."/\>\ and \\<link data-trunk rel="copy-dir" href="..."/\>\ respectively. Both pipelines support an optional \data-target-path\ attribute to specify a custom destination directory within the output folder, allowing for organized asset management without requiring manual file copying steps.

src/pipelines · high confidence

New build failure overlay and auto-reload WebSocket client

A new \src/autoreload.js\ client is injected into served pages to establish a WebSocket connection for live-reloading. It now handles a new \buildFailure\ message type, displaying an in-page overlay with the error reason when a build fails, in addition to triggering a full page reload on successful changes. This client-side logic is supported by new server-side WebSocket handling in \src/ws.rs\ (which now sends \BuildFailure\ messages and responds to Ping frames) and the \WatchSystem\ in \src/watch.rs\ (which reports build errors to the WebSocket state).

src · high confidence

New example demonstrating custom target paths for build assets

Adds a new example application that shows how to organize build outputs into a specific directory structure. The example uses the \data-target-path="static"\ attribute on Trunk links (for SCSS, CSS, Rust/WASM, copy-dir, copy-file, icon, and scripts) to place all generated assets into a \static\ subfolder within the distribution directory, rather than the default root.

examples/target-path · high confidence

New example for running Trunk behind a reverse proxy

Added a new example demonstrating how to run Trunk behind an NGINX reverse proxy, including configuration for WebSocket upgrades and correct URL generation via the Host header. This allows users to test or deploy Trunk in environments where it is served under a specific sub-path (e.g., /my-app) by a reverse proxy, rather than using Trunk's built-in proxy feature.

examples/behind-reverse-proxy · high confidence

New initializer example demonstrating custom WebAssembly loading hooks

Added a new example application that demonstrates how to use a custom JavaScript initializer to track the WebAssembly loading process. The example includes an \initializer.mjs\ file that hooks into the build lifecycle via \onStart\, \onProgress\, \onComplete\, \onSuccess\, and \onFailure\ callbacks, allowing users to display loading progress and debug information. The \index.html\ file configures this initializer via the \data-initializer\ attribute on the Rust link and listens for the \TrunkApplicationStarted\ event to confirm when bindings are ready.

examples/initializer · high confidence

New progress tracking and custom initialization for Rust/WASM applications

The Rust pipeline now supports tracking the loading progress of WebAssembly modules and allows users to provide a custom JavaScript initializer function. A new \initializer.js\ module implements a streaming fetch that reports progress via \onProgress\ callbacks, enabling UI indicators during WASM download. The pipeline passes the total WASM size and the custom initializer to the generated script, and the \RustAppOutput\ structure exposes these capabilities. This change also includes the introduction of \SriBuilder\ for managing Subresource Integrity hashes and \WasmBindgenFeatures\ to handle version-specific initialization arguments (object vs. string) for wasm-bindgen \>= 0.2.93.

src/pipelines/rust · high confidence

Behavioural changes

Adopts Convco for changelog generation with custom formatting

The project has switched to using Convco to generate changelogs, replacing the previous manual or alternative method. This change introduces a set of Handlebars templates (header, commit, footer, and main template) that define the structure and styling of the output. Users will now see changelogs formatted with specific headers for versions, links to commits and issues, and grouped sections for commits and breaking changes, improving the readability and consistency of release notes.

.convco · high confidence

HTML rewriting module with strict self-closing script tag validation

A new \html\_rewrite\ module has been added to the common library, providing utilities to modify HTML documents using \lol\_html\. This module introduces strict validation for \\<script\>\ elements: by default, self-closing script tags (e.g., \\<script .../\>\) are now rejected with a clear error message directing users to close them properly (e.g., \\<script ...\>\</script\>\). Users can opt out of this strictness by setting \allow\_self\_closing\_script\ in \DocumentOptions\, which will instead log a warning. The module also exposes methods for selecting, appending, replacing, and removing HTML content via CSS selectors.

src/common · high confidence

Improved server binding resilience and new proxy configuration options

The serve module now handles address binding more robustly by attempting to bind to all requested addresses and continuing to serve on those that succeed, rather than failing entirely if one address is unavailable. It also supports serving via DNS-resolved aliases. Additionally, the proxy subsystem introduces a \no\_redirect\ option to control HTTP redirect behavior and allows injecting custom request headers into proxied requests.

src/serve · high confidence

New integrity and minification processing modules

The src/processing module now includes dedicated integrity and minification logic. The integrity module generates Subresource Integrity (SRI) hashes using SHA-256, SHA-384, or SHA-512 with standard Base64 encoding, allowing users to disable SRI via configuration. The minification module handles JavaScript using SWC (supporting both global and module script modes), CSS using LighteningCSS, and HTML using the minify-html crate, with graceful fallbacks to original content if parsing or minification fails.

src/processing · high confidence

Restructured configuration system with new module organization

The configuration subsystem has been reorganized into distinct modules (\manifest\, \models\, \rt\, \types\) to support a layered approach involving command-line arguments, serialization from config files, and runtime options. A new \CargoMetadata\ wrapper has been introduced to asynchronously parse Cargo project metadata, enabling the system to load configuration from \Cargo.toml\ metadata. This change establishes the structural foundation for the new configuration loading pipeline, exposing \Configuration\, \Hooks\, and other model structs for use by commands.

src/config · medium confidence

Reworked configuration system with new model structure and migration support

The configuration system has been restructured into a modular model located in \src/config/models\, introducing dedicated structs for build, serve, proxy, hooks, and other settings. This change introduces several new configuration capabilities: build options now support cargo profiles (\cargo\_profile\), HTML output customization (\html\_output\), and nonce creation (\create\_nonce\); the serve module adds Content Security Policy controls (\disable\_csp\, \csp\) and address aliases (\aliases\); and the proxy system now supports multiple proxies (\Proxies\), request header injection (\request\_headers\), and system proxy bypass (\no\_system\_proxy\). To ensure backward compatibility, the system includes automatic migration logic that handles deprecated fields like \clean.dist\ (migrating to global \dist\), single proxy settings (migrating to the \proxies\ list), and the legacy \address\ field (migrating to \addresses\). The configuration loader now supports multiple file formats (TOML, YAML, JSON) and can also read configuration from the Cargo manifest metadata.

src/config/models · high confidence

Reworked configuration system with new runtime modules

The configuration system has been restructured into dedicated runtime modules (build, clean, core, serve, watch) under src/config/rt, introducing new configuration options such as cargo profiles, node package support, HTML output filename control, and nonce creation. The serve module now supports aliases, explicit CSP configuration, and DNS-based address resolution, while the watch module adds glob-based ignore patterns, screen clearing, and polling mode. Path handling has been improved with canonicalization using the dunce crate and stricter relative path enforcement for dist and watch directories.

src/config/rt · high confidence

Updated Juice theme submodule to latest commit

The Juice theme submodule has been updated to a new commit (c6ad1fb), bringing in the latest changes from the upstream theme repository. This update likely includes styling adjustments and bug fixes contributed by the theme maintainers, ensuring the site's appearance and behavior reflect the most recent version of the Juice theme.

site/themes · medium confidence

Version enforcement and conditional update checks

The version module now enforces that the running trunk version matches the project's required version specification, failing with a clear error if there is a mismatch. Additionally, update check functionality is now conditional: it is active when the 'update\_check' feature is enabled and disabled (becoming a no-op) when the feature is off, allowing users to opt out of version checks.

src/version · high confidence

Fixes

Added failing Rust example to test error detection

A new example project located at examples/failing-rust has been added to demonstrate and verify that the tool correctly identifies and reports errors in Rust/Cargo configurations rather than silently falling back to a 'not found' state. This includes a Trunk configuration, an HTML entry point, and a source file to facilitate this test case.

examples/failing-rust · high confidence

Dependencies

Update example dependencies to latest versions

The Cargo lockfiles for the project's example applications (including cargo-manifest, cdylib, hooks, initializer, leptos, node-module, proxy, seed, target-path, vanilla, and wasm\_threads) have been updated to resolve dependencies to their latest compatible versions. This ensures the examples build against current releases of core libraries such as wasm-bindgen, web-sys, and js-sys, keeping the demonstration code aligned with the latest WebAssembly ecosystem standards.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 63 → 61 (-2.0)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 94 → 94 (+0.0)
  • Architecture 100 → 83 (-17.3)
  • Maturity 62 → 62 (+0.0)
  • Readiness 52 → 48 (-3.9)
  • Security 67 → 74 (+7.0)
  • Performance 100 (new)

Resolved (5)

  • Documentation: no installation or build instructions (README.md)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Hotspot: src/serve/mod.rs (src/serve/mod.rs)
  • Off-boarding risk: anonymized user #1

New (4)

  • Documentation: no contributor guidance (README.md)
  • Documentation: no usage examples (README.md)
  • Off-boarding risk: anonymized user #1
  • Projects may be oversized for their cohesion

Changes since last survey

  • 5 commits — 4 feature/other, 1 fixes

By area

  • (root) — 4 commits
  • examples/wasm_threads — 1 commit

Notable commits

  • fix: fix: select rustls crypto provider explicitly
  • change: chore: prepare release 0.22.0-rc.1
  • change: chore: refresh dependencies
  • change: chore: update bundled tool versions
  • change: update rustflags in config.toml to the flags suggested in wasm_thread

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

trunk-rs/trunk was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 6d62b6f8e16d4c3c3c62360d1bb0025f4aa7bbb3 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-cb25ca4feafa.