vercel/ncc
46.5
Weak · 2 October 2026
1.4k
lines of production code
JavaScript
primary language
2
measurements over time
What this system is
This system is a Node.js compiler and bundler that packages projects into single-file distributions. It leverages Webpack to handle TypeScript compilation, asset management, and source map generation while supporting both CommonJS and ES module outputs. The tool provides a CLI and programmatic API for building, running, and caching bundles, with extensive support for native addons, external modules, and various package resolution strategies.
How it got here
2018 — Webpack migration and v0.2.0 release
13 changes.
The project underwent a major architectural shift by migrating its bundler from Rollup to Webpack, enabling TypeScript support, asset handling, and watch mode. This period saw the release of v0.2.0, which included a restructured CLI, a switch to pnpm for dependency management, and the initial implementation of the ncc tool with comprehensive loader infrastructure. Extensive test suites were added to verify compatibility with third-party libraries, native addons, and TypeScript features.
2019–2020 — test coverage expansion
9 changes.
This period focused on expanding test coverage for the bundler's core functionality, including module interop, TypeScript resolution, and external dependencies. New unit tests were added to validate error handling, minification with source maps, and complex bundling scenarios involving subassets and worker bridges.
2021–2022 — test coverage expansion
9 changes.
This period focused on expanding unit test coverage for the bundler's core functionality. New test suites were added to verify correct behavior for custom emit, TypeScript declaration directories, package exports resolution, and ES module import handling. Additional tests ensured proper handling of minification with coverage instrumentation, nested builds, source maps, V8 caching, browser module resolution, and import.meta.url preservation.
2023–2026 — test coverage and dependency patching
4 changes.
This period focused on expanding unit test coverage for TypeScript configuration handling, module resolution priorities, and CommonJS build transformations. Additionally, a patch was applied to the unfetch package to ensure it correctly references compiled distribution files rather than source code.
Features
Added new usage examples for ncc
The examples directory now includes four new demonstrations: a basic 'Hello World' script, a TypeScript project with a tsconfig, a guide on building multiple bundles (such as a library and a CLI) from a single source, and a programmatic build script that uses ncc to bundle multiple route files into a serverless-ready structure.
examples · high confidence
Initial release of ncc bundler
Introduces the ncc tool, a Node.js compiler/bundler that packages projects into a single file. The diff establishes the core CLI interface (src/cli.js), the programmatic API (src/index.js) using Webpack, and support for TypeScript resolution (src/typescript.js). It adds features such as source map generation, minification, asset handling, and ESM/CJS output modes.
src · high confidence
New build script for bundling ncc components
A new build script (scripts/build.js) has been added to automate the bundling of the ncc CLI, core library, and various internal loaders (relocate, shebang, TypeScript, stringify) using the ncc tool itself. The script configures minification and V8 caching for these builds, handles asset management including license files and cache artifacts, and outputs the final bundled files to the dist/ncc directory, ensuring that TypeScript types are also copied over for loader usage.
scripts · high confidence
New loader infrastructure for TypeScript, shebangs, and asset handling
The build system now includes a dedicated set of loaders in src/loaders to handle specific bundling scenarios. TypeScript compilation is managed via a custom ts-loader wrapper that suppresses compatibility warnings and ensures the bundled TypeScript version is used. Shebang scripts are supported through a shebang-loader, and asset relocation is delegated to the @vercel/webpack-asset-relocator-loader. Additionally, new loaders handle edge cases: empty-loader ignores non-analyzable packages like uglify-js, stringify-loader converts source to JSON strings, notfound-loader handles missing modules gracefully, and uncacheable-loader disables caching for specific inputs.
src/loaders · high confidence
Behavioural changes
Major release: v0.1.4 to v0.2.0 with Webpack migration and new CLI commands
This release upgrades the underlying bundler from Rollup to Webpack, enabling new capabilities such as TypeScript support, asset building, and watch mode. The CLI interface has been restructured with new commands (\build\, \run\, \cache\, \help\, \version\) and options (e.g., \--asset-builds\, \--source-map\, \--target\). The package scope has changed from \@zeit/ncc\ to \@vercel/ncc\, and the programmatic API now returns \code\, \map\, and \assets\. Documentation has been updated to reflect these changes, including a new \package-support.md\ for specific package configurations.
(repo-wide) · high confidence
New utility modules for package resolution, ESM detection, secure caching, and shebang handling
The src/utils directory now includes four new helper modules: get-package-base.js identifies the base package folder by parsing node\_modules boundaries; has-type-module.js checks for ESM configuration by reading package.json files up the directory tree; ncc-cache-dir.js generates a secure, non-predictable cache directory using the user's XDG\_CACHE\_HOME or \~/.cache and a hash of the current working directory to mitigate symlink risks; and shebang.js provides a regex to detect Node shebang scripts. These utilities support improved performance, ESM compatibility, and security in build and execution contexts.
src/utils · high confidence
Patch applied to unfetch package exports
A patch has been added for the unfetch package (version 5.0.0) to modify its module exports. Specifically, the entry points for the main module have been updated to reference the built distribution files (dist/unfetch.mjs and dist/unfetch.js) instead of the source files (index.mjs and index.js). This ensures that the library uses its compiled output rather than raw source code when imported.
patches · high confidence
Test coverage
Add Jest-based test suite for CLI, unit, integration, and watcher functionality; Added minification unit tests with coverage validation; Added test coverage for TypeScript declaration directory output; Added test coverage for TypeScript paths with allowJs; Added test coverage for import.meta.url handling; Added test coverage for sub-asset bundling with Piscina worker bridge; Added test fixtures for TypeScript error handling; Added test fixtures for module interop and error handling; Added test for Node.js native addon compilation; Added test for browser module resolution via mainFields; Added test for minification with coverage instrumentation; Added tests for runtime module-not-found handling; Added tests for tsconfig array extends support; Added unit test for TypeScript declaration emission; Added unit tests for Node shebang script support; Added unit tests for TypeScript module resolution and compilation targets; Added unit tests for TypeScript over JSON extension resolution; Added unit tests for bundle subasset handling; Added unit tests for custom emit functionality; Added unit tests for external module handling; Added unit tests for import handling; Added unit tests for import.meta evaluation in CJS builds; Added unit tests for minified source map register and V8 cache scenarios; Added unit tests for nested and double-nested builds; Added unit tests for package exports resolution; Added unit tests for tsconfig paths resolution and external module conflicts; Expanded integration test coverage for third-party libraries.
Dependencies
Migrate package management from Yarn to pnpm
The project has switched its dependency management tool from Yarn to pnpm. This change is evidenced by the deletion of the \yarn.lock\ file and the addition of a \pnpm-lock.yaml\ file, along with the introduction of a \packageManager\ field in \package.json\ specifying pnpm. The \package.json\ itself has been significantly updated to reflect the new dependency structure, including a rename from \@zeit/ncc\ to \@vercel/ncc\, updated build scripts, and a comprehensive list of devDependencies required for the new build and test infrastructure.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 50 → 47 (-3.7)
- Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 54 → 54 (+0.3)
- Architecture 69 → 69 (+0.0)
- Maturity 62 → 62 (+0.0)
- Readiness 55 → 41 (-13.7)
- Security 43 → 43 (+0.0)
- Performance 60 (new)
Resolved (13)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- Medium CVE: [GHSA redacted] (pnpm-lock.yaml)
- Medium CVE: [GHSA redacted] (pnpm-lock.yaml)
- Medium CVE: [GHSA redacted] (pnpm-lock.yaml)
New (14)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- Medium CVE: [GHSA redacted] (pnpm-lock.yaml)
- Medium CVE: [GHSA redacted] (pnpm-lock.yaml)
- Medium CVE: [GHSA redacted] (pnpm-lock.yaml)
- Medium vulnerability: [GHSA redacted] (pnpm-lock.yaml)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
vercel/ncc was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit cb1f1f058bfa7de4cb63f2411e14a724e714e260 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.