Skip to content
CAI
Software that uses CAICheck a score

typicode/husky

43.1

Weak · 25 September 2026

205

lines of production code

TypeScript

with JavaScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Removals

Removed src/index.js utility module

The src/index.js file, which previously provided utility functions for managing Git hooks (including detection of Husky hooks, writing hook scripts, and removing them), has been deleted from the codebase.

src · high confidence

Behavioural changes

Added pre-commit hook script

A new pre-commit hook script has been added to the .husky directory, which will execute the test.sh script before each commit.

.husky · high confidence

Husky v10.0.0: Simplified API and modernized configuration

Husky has been refactored to a modern, simplified API. The legacy 'add', 'set', and 'uninstall' commands have been removed in favor of a single 'init' command that automatically configures Git hooks. The library now uses ES modules (import/export) instead of CommonJS, and the default hook directory has changed from '.husky' to a new structure managed by the 'init' script. The project has also migrated from Travis CI to GitHub Actions for testing, and the README now links to the official documentation site.

(repo-wide) · high confidence

Removed bin/install.js and bin/uninstall.js scripts

The Node.js scripts previously used to automatically install and uninstall Git hooks during package installation and removal have been removed. This means the automatic setup and cleanup of .git/hooks (specifically pre-commit and pre-push hooks) will no longer occur via these entry points.

bin · high confidence

Test coverage

Migrate end-to-end tests from Node.js to shell scripts

The test suite for Husky has been rewritten from JavaScript (test/index.js) to a series of shell scripts (test/\*.sh) that automate git and npm interactions. This change improves the reliability of the integration tests by simulating real user workflows—such as running \npx husky init\, verifying \core.hooksPath\ settings, and handling environment variables like \HUSKY=0\—across various scenarios including subdirectories, missing git directories, and deprecated code paths.

test · high confidence

Dependencies

Husky 9.1.7 release with modernized package configuration

The project has been updated to version 9.1.7, shifting the package to an ES module ("type": "module") and requiring Node.js 18 or later. The package.json has been streamlined by removing legacy scripts and repository metadata, while the docs subdirectory now includes a new package.json and package-lock.json for VitePress and Sponsorkit dependencies.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 43 → 43 (+0.3)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (+0.0)
  • Architecture 40 (new)
  • Maturity 41 → 41 (+0.0)
  • Readiness 28 → 33 (+4.7)
  • Security 63 → 87 (+24.1)

Resolved (16)

  • Dimension evaluation failed
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • LLM evaluation failed
  • No artifact signing
  • No build provenance
  • No exposed public API

New (19)

  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (the committed lockfile resolved no direct production dependency)
  • Documentation: no architecture or design documentation (docs/ru/index.md)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Job token omits the contents scope its checkout needs
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No ADRs found
  • No dependency advisory monitoring

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

typicode/husky was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 3f0023dc10d7003d70f2e31aa56300eab80e76d6 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-dd72cc24c749.