voidzero-dev/vite-plus
66.9
Adequate · 29 September 2026
119.9k
lines of production code
Rust
with TypeScript
2
measurements over time
What this system is
This system is a unified command-line interface and toolchain for the Vite+ ecosystem, designed to replace or augment standard JavaScript development tools. It provides capabilities for scaffolding new projects, migrating existing Vite or ESLint setups, and managing Node.js and package manager environments with strict security and integrity checks. The CLI integrates linting, formatting, and build orchestration into a single entry point, leveraging a Rust core for performance and native bindings for deep integration with the JavaScript runtime.
Features
Add Vite+ code generator starter template
A new starter template for creating Vite+ code generators has been added to the CLI. Users can now scaffold custom generators using \vp create\, which supports both interactive mode and non-interactive automation via command-line arguments. The template leverages the Bingo library for file generation and includes a pre-configured TypeScript setup with NodeNext module resolution, allowing developers to define custom options and file structures for their own generator projects.
packages/cli/templates/generator · high confidence
Add \`vp exec\` command for running local binaries
Users can now run commands from local \node\_modules/.bin\ directories using the new \vp exec\ CLI command. This feature supports filtering by workspace packages, executing in shell mode, running in parallel or reverse order, resuming from a specific package, and generating execution summaries. It mirrors the behavior of \pnpm exec\ by defaulting to the current working directory when no package filters are specified.
packages/cli/binding/src/exec · high confidence
Add built-in pre-commit hook via \`vp staged\`
The CLI now includes a new \vp staged\ command that runs linters on staged files using the lint-staged programmatic API. This command reads the \staged\ configuration from \vite.config.ts\ and passes it to lint-staged, allowing users to define pre-commit hooks directly in their Vite configuration. If no staged config is found, the command exits with a warning and provides an example configuration snippet.
packages/cli/src/staged · high confidence
Add native binding loader for Vite+ CLI
The \packages/cli/binding\ directory now includes the generated NAPI-RS binding files (\index.cjs\, \index.d.ts\, etc.) and build configuration. This adds a native binding loader that automatically detects the platform and architecture (including Android, Windows, and Linux with musl/glibc support) to load the correct prebuilt native addon, ensuring the CLI can execute its Rust-based core functionality across supported environments.
packages/cli/binding · high confidence
Added benchmark infrastructure for large-scale monorepo testing
A new benchmark suite has been introduced to the project, featuring a TypeScript generator script that creates a synthetic monorepo containing 1,000 packages with complex dependency graphs and transitive script relationships. This tool allows for performance testing of build and resolution logic against large-scale workspaces, supported by a dedicated TypeScript configuration and a .gitignore rule to exclude the generated fixtures.
bench · high confidence
Forked @clack/prompts with custom renderers and PTY snapshot testing
The \packages/prompts/src\ directory now contains a forked implementation of \@clack/prompts\ featuring custom prompt renderers (for select, multiselect, autocomplete, confirm, and group multiselect) that support pointer markers, checkboxes, and aligned multiline labels. This change introduces a new milestone system for PTY-based interactive CLI snapshot testing, emitting invisible window-title markers when the \VP\_EMIT\_MILESTONES\ environment variable is set, and adds comprehensive Vitest snapshot tests to verify the visual output of these prompt components.
packages/prompts/src · high confidence
Initial monorepo template with Vite+ configuration and tooling
The monorepo starter template now includes a \vite.config.ts\ that enables task caching by default, a \tsconfig.json\ configured for Node.js Next module resolution, and a \README.md\ documenting standard development commands (ready, test, build, dev). It also provides updated configuration files: \\_yarnrc.yml\ sets the node linker to node-modules and defines a catalog for TypeScript and Node types, \pnpm-workspace.yaml\ establishes workspace packages and a catalog mode, and \\_gitignore\ excludes environment files, editor settings, and AI agent worktrees.
packages/cli/templates/monorepo · high confidence
Introduce Vite+ Global CLI with interactive command picker and environment management
The \vp\_global\_cli\ crate now provides the main \vp\ command-line interface, featuring an interactive top-level command picker for selecting actions like \create\, \dev\, \build\, and \test\. It includes a comprehensive \vp env\ command suite for managing Node.js and package manager versions, supporting configuration of default versions, shim modes (managed vs. system-first), and environment diagnostics via \vp env doctor\. The CLI also introduces \vp hooks\ for Git hook management, \vp toolchain\ for viewing tool versions, and \vp config\ for in-repo configuration. Bash completion scripts are provided to enable tab-completion for \vp\ and \vpr\ commands.
_crates/vp\_global\cli · high confidence
Introduce \`vp create\` CLI for scaffolding new projects
The \vp create\ command is now available to scaffold new Vite+ applications, libraries, and monorepos, as well as to integrate with popular frameworks like Next.js, Nuxt, Svelte, and Vue. It supports local templates defined in \create.templates\, org-scoped templates via \@scope\ manifests, and remote GitHub repositories. The command handles interactive prompts for package names, target directories, and editor configurations, and automatically initializes Git repositories with an initial commit.
packages/cli/src/create · high confidence
Introduce \`vp migrate\` command for upgrading existing projects
The CLI now includes a \vp migrate\ command that detects and upgrades existing Vite, Vitest, ESLint, Prettier, and tsup projects to the Vite+ ecosystem. The migration handles toolchain transitions such as ESLint to Oxlint, Prettier to Oxfmt, and tsup to tsdown, while also managing configuration merging, dependency resolution, and editor setup.
packages/cli/src/migration · high confidence
Introduce \`vp toolchain\` command and toolchain manifest schema
A new \vp toolchain\ CLI command is added, backed by the \crates/vp\_toolchain\ library which defines the data structures and validation logic for the toolchain manifest. Users can now interact with a manifest format that describes project nodes (packages, tools, engines) and their relationships (dependencies, bundles, uses, compiles), with the library handling manifest loading, schema version validation, and integrity checks for node identifiers and metadata.
_crates/vp\toolchain · high confidence
Introduce \`vp\_pm\_cli\` crate for unified package-manager command handling
The new \vp\_pm\_cli\ crate centralizes the package-manager lifecycle for Vite+, providing a shared Clap command surface that detects the project's package manager (pnpm, npm, Yarn, or Bun) and resolves typed arguments for commands like install, add, update, and audit. It manages downloading and caching of package-manager binaries, verifies integrity hashes (including modern Yarn Berry CLI binary hashes), and dispatches resolved commands with pre-run actions. This crate exposes the CLI interface used by both the global and local CLIs, while managed Node.js runtimes and global package stores remain in the global CLI.
_crates/vp\_pm\cli · high confidence
Introduce standalone Windows installer with DLL security and legacy support
The \vp\_installer\ crate now provides a standalone Windows executable (\vp-setup.exe\) that mirrors the existing PowerShell installer's functionality. This new installer enforces Windows security by restricting DLL searches to system32 to prevent DLL hijacking when run from folders like Downloads. It supports both modern binaries (via a self-setup protocol) and legacy binaries (via a fallback \legacy\ module) that lack first-start self-setup. The installer features an interactive menu for configuration, respects the \NO\_COLOR\ environment variable to suppress ANSI escape codes in output, and handles Node.js and package-manager environment setup preferences.
_crates/vp\installer · high confidence
Introduce unified \`vp\` CLI entry point and configuration system
The CLI now uses a single \bin.ts\ entry point that delegates global commands (create, migrate, config, hooks, staged, version) to local JavaScript modules while routing all other commands (dev, build, test, lint, fmt, pack, doc) to the Rust core via NAPI bindings. This change introduces a centralized configuration system in \define-config.ts\ that extends Vite's \UserConfig\ with Vite+ specific options including \lint\, \fmt\, \check\, \pack\, \defaultPackage\, \run\, \staged\, \create\, and \test\. The CLI now supports a \-C\ flag for working directory switching, handles \vpr\ as a shorthand for \vp run\, and transforms \vp help \[command\]\ syntax. Tool resolvers for lint, fmt, doc, pack, test, and vite are now explicitly defined in separate modules, and the system automatically initializes tool configurations in \vite.config.ts\ when running \vp lint --init\ or \vp fmt --init\. The \pack\ command now uses tsdown with support for the \--exe\ flag and DTS bundling with external type handling for postcss, vitest, and vite-plus packages.
packages/cli/src · high confidence
Introduce vpt test utility binary for snapshot testing
The \vpt\ test utility binary is added to support snapshot testing, providing a suite of subcommands that mirror standard shell utilities (such as \cp\, \rm\, \chmod\, \grep-file\, \json-edit\, and \list-dir\) alongside specialized tools for controlling process execution and environment (like \backpressure-run\, \barrier\, \exit-on-ctrlc\, and \probe\). This tool allows tests to assert on file system states, manipulate JSON fixtures, and verify terminal behavior without relying on external system commands.
_crates/vp\_cli\snapshots/src · high confidence
Introduces a bundled core package combining Vite, Rolldown, and Tsdown
The \packages/core\ directory now contains the build infrastructure and documentation for a new unified \@voidzero-dev/vite-plus-core\ package. This package bundles Vite (v8 beta), Rolldown, and Tsdown into a single distribution, handling module specifier rewrites and native binding resolution so users can access these tools through one package. The build process (defined in \build.ts\) merges these upstream projects, rewrites imports to point to the core package, and manages CommonJS dependencies for Tsdown, while \BUNDLING.md\ documents this multi-project bundling strategy.
packages/core · high confidence
New CLI utility modules for agent, editor, and package management
The CLI now includes a suite of new utility modules in \packages/cli/src/utils\ to support project scaffolding and configuration. \agent.ts\ introduces a multi-agent selection system, allowing users to configure instruction files for tools like Claude, Gemini, Copilot, and Cursor during project creation. \editor.ts\ adds support for generating configuration files for VS Code, Zed, and JetBrains editors, including language-specific formatter overrides. \approve-builds.ts\ handles package-manager-specific build script approvals for pnpm, Bun, npm, and Yarn, ensuring smooth dependency installation. Additional utilities include \npm-config.ts\ for resolving npm registries and authentication, \legacy-vitest-alias.ts\ to detect and recover from stale Vitest aliases, and \package-overrides.ts\ for parsing package-manager override selectors.
packages/cli/src/utils · high confidence
New JavaScript runtime management library
The \vp\_js\_runtime\ crate introduces a new library for managing JavaScript runtimes (currently Node.js). It handles downloading, caching, and installing runtimes based on project requirements (\.node-version\, \.nvmrc\, or \package.json\ engines). Key features include automatic platform detection, integrity verification via SHASUMS256.txt with PGP signature validation against vendored release keys, and support for resuming interrupted downloads with configurable timeouts.
_crates/vp\_js\runtime/src · high confidence
New automated migration tooling for Vite to Vite-Plus
The \vp\_migration\ crate introduces a suite of automated migration capabilities to help users transition from Vite to Vite-Plus. It now rewrites JavaScript/TypeScript imports from \vite\ to \vite-plus\ (including subpaths, dynamic imports, and CommonJS requires) and updates shell scripts in \package.json\ by replacing \eslint\ with \vp lint\ and \prettier\ with \vp fmt\, while stripping tool-specific flags. Additionally, it upgrades \tsdown\ pack configurations for compatibility with version 0.23 and provides source analysis using Oxc to resolve symbol bindings and comments for complex migration scenarios.
_crates/vp\migration · high confidence
New command execution library with Windows PowerShell shim support
The \vp\_command\ crate introduces a new library for executing external commands, featuring robust handling of Windows \.cmd\ shims by transparently rewriting them to use PowerShell to prevent terminal state corruption on Ctrl+C. It includes utilities for resolving binary paths via \PATH\, synchronizing the child process's \PWD\ environment variable with its working directory, and guarding terminal state during execution on Unix systems.
_crates/vp\command · high confidence
New ecosystem CI infrastructure for validating Vite+ migrations
The ecosystem CI now includes a dedicated tooling suite to automatically clone, patch, and verify a curated set of real-world projects (defined in \repo.json\) against local Vite+ builds. This infrastructure handles cloning repositories to specific commits, serving local Vite+ packages via a temporary npm registry, and applying project-specific patches to resolve compatibility issues with Vitest 5, Oxlint, and other dependencies. It also includes verification steps to ensure that migrations correctly pin the local Vite+ version and that specific ecosystem fixtures (like Video.js or Nuxt) behave as expected after migration.
ecosystem-ci · high confidence
New error handling crate for package manager and integrity checks
The \crates/vp\_error\ crate introduces a comprehensive error type for the CLI, specifically supporting package manager validation and artifact integrity verification. It defines variants for unsupported or unrecognized package managers, invalid version formats, and network issues, while also providing specific error types for hash mismatches during integrity checks of package manager binaries. A helper method \is\_integrity\_failure\ allows callers to distinguish critical integrity failures from other errors, ensuring that unverified artifacts halt execution rather than being silently ignored.
_crates/vp\error · high confidence
New internal tooling for Vite+ branding, dependency synchronization, and local registry management
The \packages/tools/src\ directory now contains the core implementation for the Vite+ toolchain, introducing several new capabilities. The \brand-vite\ script applies Vite+ branding patches to the upstream Vite source code, modifying CLI names, banners, and log prefixes while ensuring idempotency and preserving unrelated local changes. The \sync-remote-deps\ tool synchronizes dependencies from upstream repositories (like Vite and Rolldown) into the workspace, handling catalog merging, Vitest version alignment, and workspace YAML updates while preserving comments. A \local-npm-registry\ utility allows developers and tests to serve locally packed Vite+ packages via a standard npm registry interface, facilitating offline development and snapshot testing without publishing. Additionally, \install-global-cli\ manages the installation of the \vp\ CLI binary, handling platform-specific shims, local development versions, and CI legacy paths, while \build-trampoline\ provides a wrapper for building the Rust trampoline binary with configurable target directories.
packages/tools/src · high confidence
New native CLI binding layer for JavaScript integration
The CLI now exposes a Rust-based NAPI binding layer that bridges JavaScript tool resolvers with the core logic. This enables JavaScript functions to invoke native commands (lint, fmt, vite, test, pack, doc) via thread-safe callbacks, while also providing utilities for migrating project configurations (such as ESLint to vp lint, Prettier to vp fmt, and JSON config merging into vite.config.ts), detecting workspace roots and package managers (including Bun support), and executing commands with file-system access tracking via fspy.
packages/cli/binding/src · high confidence
New shared help rendering library for CLI tools
Added a new \vp\_cli\_help\ crate that provides shared help document generation and rendering for Vite+ command-line interfaces. This library parses \clap\ command metadata to build structured help documents and renders them with support for terminal styling, respecting the \NO\_COLOR\ environment variable to disable ANSI escape codes when appropriate. It handles formatting of arguments, options, and subcommands, including proper indentation, wrapping based on terminal width, and accenting of specific text elements.
_crates/vp\_cli\help · high confidence
New skill to verify interactive CLI prompts and detect spinner bugs
Added a new verification skill for the \vp\ interactive CLI that uses a tmux-based driver script to capture and analyze prompt behavior. This tool allows users to manually verify interactive flows (such as \vp migrate\) by auto-accepting defaults or stopping at specific prompts to check for UX bugs, specifically detecting cases where progress spinners animate underneath static prompt text.
.claude/skills/verify-interactive-cli · high confidence
Static extraction of Vite configuration files
The \vp\_static\config\ crate now parses \vite.config.\\ files without executing JavaScript, using \oxc\_parser\ to extract top-level fields that are pure JSON literals. This allows the system to read configuration (such as the \run\ section) without requiring a Node.js runtime, falling back to runtime evaluation only when the config contains dynamic expressions or cannot be statically analyzed.
_crates/vp\_static\config · high confidence
Unified 'vp check' command with configurable lint, format, and type-check phases
The CLI now exposes a single \vp check\ command that orchestrates formatting, linting, and optional TypeScript type-checking in one pass. Users can control which phases run via CLI flags (\--no-fmt\, \--no-lint\) or by setting \check.fmt\ and \check.lint\ in \vite.config.ts\. The command respects \--quiet\ for concise output, supports \--fix\ for auto-fixing lint issues, and handles type-checking by leveraging oxlint's type-aware analysis when enabled in the config. It also introduces \--no-error-on-unmatched-pattern\ to suppress errors when no files match the provided paths, and ensures stable output parsing in CI environments by forcing the default reporter.
packages/cli/binding/src/check · high confidence
Vite+ CLI package structure and build process documented
The \packages/cli\ directory now includes comprehensive documentation and configuration files that define the Vite+ CLI package. The \AGENTS.md\ file provides a user guide for the unified toolchain, explaining built-in commands versus scripts, tool version management via \vp toolchain\, and a review checklist for development workflows. The \BUNDLING.md\ file details the four-step build process (tsdown bundling, NAPI binding compilation, core package export syncing, and test package export syncing) that enables the CLI to serve as a drop-in replacement for Vite. The \README.md\ outlines the complete CLI workflow including environment management, dependency installation, development, testing, building, and packaging. Additionally, \.gitignore\ has been added to exclude build artifacts, and \build.ts\ contains the build script implementation that orchestrates these steps.
packages/cli · high confidence
Removals
Removal of vite\_task crate
The \vite\_task\ crate has been removed from the codebase, eliminating the module that previously handled task execution and caching logic for Vite-related operations.
_crates/vite\task · high confidence
Architecture
Migration logic reorganized into category-specific modules
The monolithic migration implementation has been split into distinct modules (e.g., \catalog.ts\, \eslint.ts\, \git-hooks.ts\, \orchestrators.ts\) to improve maintainability. A central barrel file (\migrator.ts\) re-exports these modules, ensuring that external code continues to import from the same path without modification. This structural change preserves all existing migration behaviors while organizing the code by responsibility.
packages/cli/src/migration/migrator · high confidence
Behavioural changes
Adopts vp git hooks for pre-commit validation
The project has replaced the previous pre-commit hook implementation with a new script located at .vite-hooks/pre-commit. This script invokes the 'vp' command to stage changes, indicating a shift to the 'vp' tooling for managing pre-commit workflows.
.vite-hooks · medium confidence
Automated Git hook installation and management via \`vp config\`
The CLI now automatically installs and manages Git hooks (such as pre-commit) during the \vp config\ run or lifecycle scripts like \prepare\ and \postinstall\. This replaces manual setup by auto-configuring \core.hooksPath\ and installing a dispatcher script in \.vite-hooks\. Users can opt out via the \VP\_GIT\_HOOKS\ environment variable or the new \vp hooks\ command (enable/disable/status), and the system preserves existing project-owned hooks while suppressing prompts in non-interactive contexts.
packages/cli/src/config · high confidence
Automated aggregation of bundled dependency licenses
The build process now automatically generates a merged LICENSE file that includes the core project license alongside the licenses and text of all bundled dependencies. This script scans the package dependencies, extracts their license information, and aggregates it into a single output file, ensuring that all third-party license terms are included in the final release artifact without manual intervention.
scripts · high confidence
CLI argument parsing now uses Clap for structured validation
The CLI binding for commands like \vp config\, \vp create\, \vp hooks\, \vp migrate\, and \vp staged\ now uses the Clap library to parse command-line arguments. This change introduces structured validation for options such as \--hooks\, \--agent\, \--editor\, and \--concurrent\, ensuring that invalid arguments are rejected with specific error types (e.g., 'unknown-argument', 'invalid-value') and that help text is generated automatically. Users benefit from more consistent and robust command-line interfaces with clearer error messages and standardized help output.
_packages/cli/binding/src/js\_command\args · high confidence
Enable Node.js compile cache for CLI execution
The CLI entry points (vp and vpr) now enable Node.js compile cache before importing the main CLI bundle. This optimization is applied to both the vp and vpr scripts to improve startup performance by caching compiled modules.
packages/cli/bin · high confidence
Enforce Rust coding standards and performance via .clippy.toml
The repository now enforces a stricter Rust coding standard through a new \.clippy.toml\ configuration. This change disallows standard library methods that cause memory allocations (such as \str::to\_lowercase\ and \std::format\), requiring the use of zero-allocation alternatives like \cow\_utils\ and \vt\_str\. It also mandates faster hash maps (\rustc\_hash::FxHashMap\), specific path types (\vt\_path\), and structured output functions (\vp\_shared::output\) instead of direct \println!\ or \eprintln!\ macros. Additionally, it prevents potential deadlocks by disallowing the holding of \dashmap\ references across \await\ points.
(repo-wide) · high confidence
Fork of @clack/prompts with updated build configuration
The prompts package has been forked from the external @clack/prompts library (originally from bombshell-dev/clack) and now includes its own MIT license file. Additionally, the build process has been updated to use a new tsdown configuration file that explicitly sets the dependency bundling behavior to not bundle dependencies.
packages/prompts · high confidence
Introduce XDG-compliant directory layout and centralized environment configuration
The \vp\_shared\ crate now manages the application's on-disk structure through a new \VpDirs\ system that supports both a legacy single-root layout and a modern split layout adhering to XDG Base Directory specifications. This change introduces a robust resolution chain that prioritizes explicit environment overrides (\VP\_HOME\, \VP\_BIN\_DIR\, \VP\_DATA\_DIR\, \VP\_CACHE\_DIR\) before falling back to platform-specific defaults (such as \XDG\_DATA\_HOME\ on Unix or known folders on Windows). Alongside this structural shift, the crate centralizes all Vite+ environment variable definitions in \env\_vars.rs\ and provides a process-wide \EnvConfig\ singleton to manage settings like Node.js mirrors, package manager versions, and HTTP client trust stores, ensuring consistent path resolution and configuration access across the CLI.
_crates/vp\shared · high confidence
Local CLI now elicits workspace targets and synthesizes built-in commands in scripts
The local \vp\ CLI now intelligently resolves which workspace package to run when \dev\, \build\, \preview\, or \pack\ are invoked at a workspace root. It uses the \defaultPackage\ config, root intent signals (like \index.html\ or \vite.config.ts\ fields), or an interactive fuzzy picker to select the target, preventing commands from silently running against the root. Additionally, when \vp\ commands are used inside task scripts (e.g., \vp build\ in a \vite.config.ts\ script), they are now synthesized in-session rather than spawning a new process, improving performance and caching. The CLI also provides helpful notes when a built-in command name conflicts with a \package.json\ script, guiding users to use \vpr\ for scripts.
packages/cli/binding/src/cli · high confidence
New raw Win32 trampoline with versioned shim pointer validation
The \vp\_trampoline\ crate now includes a new, minimal Windows binary that replaces previous wrapper approaches. Built with raw Win32 calls and a recompiled standard library for size, this trampoline shrinks the executable to approximately 14 KB. It validates shim pointers by requiring a specific versioned header (\vite-plus-shim-v1\), rejecting unversioned or malformed sidecar files to ensure correct directory layout resolution. The trampoline reads tool-specific configuration from adjacent \.shim\ files to locate the active \vp.exe\ and sets the appropriate environment variables (\VP\_HOME\ or split \VP\_DATA\_DIR\/\VP\_BIN\_DIR\/\VP\_CACHE\_DIR\) before launching the child process.
_crates/vp\trampoline · high confidence
New vp\_setup library enforces npm provenance and integrity checks
The new \vp\_setup\ library introduces stricter security and reliability measures for the \vp upgrade\ and \vp-setup.exe\ workflows. It now requires platform packages to include valid npm provenance metadata (SLSA v0.2 or v1); releases without this provenance will be rejected, except for commit-preview builds. Additionally, all downloaded tarballs are verified against SHA-512 integrity hashes provided by the npm registry. The library also isolates pnpm installations from parent workspaces using \--ignore-workspace\ and pins pnpm to version 10.33.0 to ensure consistent dependency resolution.
_crates/vp\setup · high confidence
Refactor project scaffolding into a modular template execution system
The CLI's project creation logic has been restructured into a modular template execution system located in \packages/cli/src/create/templates\. This change introduces distinct handlers for different template sources: \builtin.ts\ manages internal templates (like \vite:monorepo\ and \vite:library\) and now provides helpful error messages for unknown \vite:\ templates; \bundled.ts\ handles pre-extracted local templates; \generator.ts\ scaffolds generator projects with support for inlining dependencies when catalog support is unavailable; \remote.ts\ executes external commands (via \npx\/\pnpm dlx\/\degit\) and includes troubleshooting tips for common failures; and \monorepo.ts\ orchestrates the creation of monorepo structures, including automatic generation of default apps and libraries, and ensures nested library configs are cleaned up. This refactoring improves error handling, supports silent mode better, and separates concerns for different template types.
packages/cli/src/create/templates · high confidence
Support for bundling CommonJS dependencies and resolving native bindings
The build system now includes new support scripts in packages/core/build-support to handle CommonJS (CJS) dependencies and native module resolution. The build-cjs-deps.ts script bundles CJS dependencies into CJS format, while find-create-require.ts analyzes source code to replace third-party CJS requires with local entry files. Additionally, rewrite-rolldown-binding.ts rewrites Rolldown native binding requires to use Vite+ platform packages, ensuring proper resolution of native addons across different platforms. These changes improve the bundling process for projects using CJS dependencies and native modules.
packages/core/build-support · high confidence
Updated Node.js release keys and shasums for v16, v18, v20, and v22
The runtime now includes refreshed PGP public keys and updated SHA-256 checksum files for Node.js versions 16.20.0, 18.14.0, 20.18.0, and 22.13.1. This ensures that the integrity of Node.js binaries can be verified against the latest official release signatures, maintaining security and reliability for the JavaScript execution environment.
_crates/vp\_js\runtime/src/assets · high confidence
Test coverage
Add CLI snapshot test suite and benchmark fixtures; Add PTY-backed CLI snapshot test suite for interactive flows; Added benchmark for workspace task graph loading; Added snapshot fixtures for CLI snapshot tests; Added snapshot fixtures for tsup-based monorepo migration tests; Added test coverage for CLI configuration and plugin injection logic; Added test coverage for CLI utility modules; Added test coverage for the \vp create\ command logic; Added test fixture for npm provenance validation; Added test fixtures for workspace lint and format config discovery; Added tests for CLI git hooks configuration and installation logic; Added tests for Vitest v5 workspace API identity and snapshot verification; Added tests for native binding resolution and build artifacts; Added tests for the Vite+ migration tooling; Added type tests for StagedConfig.
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 68 → 67 (-0.8)
- Rubric changed (rubric-2026.09.10 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 64 → 61 (-3.2)
- Architecture 85 → 87 (+2.7)
- Maturity 90 → 83 (-6.7)
- Readiness 78 → 75 (-3.3)
- Security 60 → 69 (+8.9)
- Performance 71 (new)
Resolved (146)
- Critical CVE: [CVE redacted] (pnpm-lock.yaml)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Documentation: written for insiders (docs/team.md)
- Duplicated block (10 lines × 2) (crates/vp_global_cli/src/commands/env/off.rs)
- Duplicated block (10 lines × 2) (packages/cli/binding/src/cli/resolver.rs)
- Duplicated block (12 lines × 2) (crates/vp_pm_cli/src/package_manager.rs)
- Duplicated block (13 lines × 2) (crates/vp_global_cli/src/main.rs)
- Duplicated block (20 lines × 2) (crates/vp_js_runtime/src/download.rs)
- Duplicated block (5 lines × 2) (crates/vp_global_cli/src/commands/env/current.rs)
- Duplicated block (5 lines × 2) (packages/cli/binding/src/js_command_args/commands/create.rs)
- Duplicated block (6 lines × 2) (packages/cli/binding/src/cli/resolver.rs)
- Duplicated block (8 lines × 2) (crates/vp_pm_cli/src/resolution/commands/add.rs)
- FixmeComment (crates/vp_pm_cli/src/package_manager.rs)
- FunctionTooLong: vp_js_runtime::download::download_file (crates/vp_js_runtime/src/download.rs)
- High CVE: [CVE redacted] (pnpm-lock.yaml)
- High CVE: [CVE redacted] (pnpm-lock.yaml)
- High CVE: [CVE redacted] (pnpm-lock.yaml)
- High CVE: [CVE redacted] (pnpm-lock.yaml)
- High CVE: [CVE redacted] (pnpm-lock.yaml)
- …and 126 more
New (127)
- Coverage not measured — JavaScript/TypeScript suite
- Documentation: no architecture or design documentation (docs/config/create.md)
- Duplicated block (10 lines × 2) (crates/vp_pm_cli/src/resolution/commands/add.rs)
- Duplicated block (10–14 lines × 2) (crates/vp_migration/src/vite_config.rs)
- Duplicated block (11 lines × 2) (crates/vp_global_cli/src/commands/env/off.rs)
- Duplicated block (13 lines × 2) (crates/vp_global_cli/src/main.rs)
- Duplicated block (5 lines × 2) (crates/vp_shared/src/output.rs)
- Duplicated block (6 lines × 2) (crates/vp_global_cli/src/commands/env/doctor.rs)
- Duplicated block (8 lines × 2) (crates/vp_shared/src/output.rs)
- Duplicated block (8 lines × 2) (packages/cli/binding/src/js_command_args/commands/create.rs)
- FileTooLong: migrator/eslint.ts (packages/cli/src/migration/migrator/eslint.ts)
- FileTooLong: migrator/vitest-v5.ts (packages/cli/src/migration/migrator/vitest-v5.ts)
- FileTooLong: vitest-v5/scopes.ts (packages/cli/src/migration/vitest-v5/scopes.ts)
- FileTooLong: vitest-v5/source.ts (packages/cli/src/migration/vitest-v5/source.ts)
- FunctionTooLong: benchmarks.migrateBenchmarks (packages/cli/src/migration/vitest-v5/benchmarks.ts)
- FunctionTooLong: config.migrateConfig (packages/cli/src/migration/vitest-v5/config.ts)
- FunctionTooLong: orchestrators.rewriteMonorepo (packages/cli/src/migration/migrator/orchestrators.ts)
- FunctionTooLong: scopes.resolveVitestV5TestModes (packages/cli/src/migration/vitest-v5/scopes.ts)
- FunctionTooLong: source.rewriteSource (packages/cli/src/migration/vitest-v5/source.ts)
- FunctionTooLong: sync-remote-deps.syncRemote (packages/tools/src/sync-remote-deps.ts)
- …and 107 more
Changes since last survey
- 96 commits — 56 feature/other, 40 fixes
By area
- crates/vp_cli_snapshots — 44 commits
- packages/cli — 12 commits
- .github/workflows — 11 commits
- (root) — 8 commits
- .claude/skills — 5 commits
- .github/scripts — 4 commits
- docs/.vitepress — 4 commits
- crates/vp_pm_cli — 2 commits
- docs/guide — 2 commits
- crates/vp_error — 1 commit
- crates/vp_global_cli — 1 commit
- crates/vp_js_runtime — 1 commit
- crates/vp_migration — 1 commit
Notable commits
- fix: fix(cli): handle broken pipes in command output (#2785)
- fix: fix(ci): exclude Void packages from release age checks (#2737)
- fix: fix(ci): install committed dependencies before preview migrations (#2822)
- fix: fix(ci): reuse native preview installations (#2693)
- fix: fix(ci): update npmx.dev ecosystem fixture (#2756)
- fix: fix(cli): default unpinned npm to Node's bundled version (#2742)
- fix: fix(cli): expose Vitest 5 options in test help (#2809)
- fix: fix(cli): handle Homebrew installs during first-run setup (#2729)
- fix: fix(cli): honor --ignore-scripts for install and add (#2682)
- fix: fix(cli): honor NO_COLOR in Rust output (#2716)
- fix: fix(cli): import local versions module via file URL (#2749)
- fix: fix(cli): prevent download progress from overwriting terminal output (#2741)
- fix: fix(cli): remove oxlint and oxfmt bin wrappers (#2672)
- fix: fix(cli): resolve lowercase Windows shims in case-sensitive directories (#2727)
- fix: fix(cli): resolve package manager defaults centrally (#2748)
- fix: fix(cli): use native config discovery for lint and fmt (#2807)
- fix: fix(config): type async tool options contextually (#2803)
- fix: fix(create): honor non-interactive mode in scaffolded generators (#2677)
- fix: fix(create): inline generator dependencies without catalog support (#2720)
- fix: fix(create): remove nested monorepo lint config (#2667)
- …and 76 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
voidzero-dev/vite-plus was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 29 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit db29f8bf97339bd2ab849f4a507c41e3af6caedf — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-5ff527f25b99.