Skip to content
CAI
Software that uses CAICheck a score

vuejs/vue

54.7

Adequate · 22 September 2026

23.4k

lines of production code

TypeScript

with JavaScript

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a comprehensive framework for building user interfaces, specifically focusing on Vue.js's core rendering, reactivity, and compilation capabilities. It provides a modular architecture for server-side rendering, Single-File Component (SFC) compilation, and virtual DOM patching, all implemented in TypeScript. The codebase supports both the traditional Options API and the modern Composition API, enabling developers to manage state, handle DOM updates, and optimize performance through benchmarking tools.

How it got here

2016 — Monorepo migration and TypeScript adoption

18 changes.

The project underwent a major architectural shift to a TypeScript-based monorepo structure, replacing legacy build systems and modularizing the codebase. This period focused on modernizing the development environment, introducing comprehensive TypeScript type definitions, and establishing a modular package structure using pnpm workspaces.

2017–2021 — Vue 3 TypeScript migration and VDOM refactoring

20 changes.

This period focused on the comprehensive migration of the Vue 3 codebase to TypeScript, covering core modules, the virtual DOM, and web platform implementations. The work also involved significant architectural refactoring of the virtual DOM and reactivity systems to improve type safety, maintainability, and developer experience.

2022 — Vue 3 Composition API and SFC compiler rewrite

32 changes.

This period focused on introducing the Vue 3 Composition API and a new reactivity system, alongside a complete rewrite of the Single-File Component (SFC) compiler. The work was heavily supported by extensive test coverage for the new APIs, the server-side rendering package, and the updated compiler infrastructure.

Features

Add TypeScript type definitions for Vue internals

The \src/types\ directory now contains a comprehensive set of TypeScript definitions for Vue's internal structures, including \Component\, \ComponentOptions\, \VNode\, \GlobalAPI\, and compiler-related types. These types provide static typing for internal APIs and data structures, improving type safety and developer experience for contributors and tooling.

src/types · high confidence

Add TypeScript type definitions for server-renderer

The \packages/server-renderer/types\ directory now contains the TypeScript declaration files (\index.d.ts\, \plugin.d.ts\) and a \test.ts\ file that exercises the type definitions. This provides static typing for the server-renderer API, including the \createRenderer\ and \createBundleRenderer\ functions, their respective options interfaces, and the webpack plugin types.

packages/server-renderer/types · high confidence

Add Vue.js uptime benchmark

A new benchmark for measuring Vue.js performance has been added to the benchmarks/uptime directory. The implementation uses functional components for the uptime-day component to improve efficiency, and includes a pause/play toggle for the benchmark execution.

benchmarks/uptime · high confidence

Add big-table benchmark demo

A new benchmark demo for rendering large tables has been added to the benchmarks/big-table directory. The demo includes an HTML file that sets up a 1000x10 grid of data, allowing users to toggle between optimized (Object.freeze) and base rendering modes, perform text-based filtering, and measure render/unmount performance. The addition is accompanied by specific CSS rules in demo.css to style the filtered table states and a general style.css for layout and typography.

benchmarks/big-table · high confidence

Add reorder-list benchmark for performance testing

A new benchmark page has been added at benchmarks/reorder-list/index.html to measure the performance of reordering a list of 1000 items. The page renders a table of components using the :key attribute for list iteration and includes buttons to shuffle, add, select, and remove items, with timing measurements logged to the console.

benchmarks/reorder-list · high confidence

Add server-side rendering benchmark for performance comparison

A new server-side rendering (SSR) benchmark has been added to the \benchmarks/ssr\ directory. This test renders a large table structure (10,000 components, \~30,000 elements) to stress-test the framework. It specifically compares the performance of \renderToString\ versus \renderToStream\, allowing users to observe the performance benefits of streaming rendering (faster time-to-first-byte and non-event-loop-blocking) as reported in the benchmark output.

benchmarks/ssr · high confidence

Added CommonJS and ES module entry points for Vue runtime and core APIs

The dist directory now includes new entry points to support different module systems. A CommonJS wrapper (vue.common.js) has been added to conditionally load development or production builds based on the environment. Additionally, an ES module entry point (vue.runtime.mjs) has been introduced, which re-exports the Vue runtime and exposes a comprehensive set of reactivity, lifecycle, and utility functions (such as ref, reactive, watch, and various hooks) directly from the CommonJS build, making these APIs available to modern bundlers and tree-shaking.

dist · high confidence

Added SVG dot animation benchmark

A new benchmark page for animating 1000 SVG dots has been added at benchmarks/svg/index.html. The page renders a grid of animated circles using Vue.js, allowing users to toggle an optimization mode that freezes the model data to reduce reactivity overhead. This provides a way to measure rendering performance for SVG-based animations.

benchmarks/svg · high confidence

Added Transition and TransitionGroup components for DOM transitions

Introduced the \<transition\> and \<transition-group\> components, enabling declarative CSS/JS transition effects for single elements and lists respectively. The \<transition\> component supports enter, leave, and appear animations with configurable classes and modes, while \<transition-group\> provides move animations for list items using the FLIP technique, ensuring smooth reordering of elements during updates.

src/platforms/web/runtime/components · high confidence

Added TypeScript definitions for the template-compiler package

The template-compiler package now includes TypeScript type definitions (index.d.ts) and a test file (test.ts) to provide static typing for the compiler's API, including compile, compileToFunctions, ssrCompile, parseComponent, and generateCodeFrame. This enables better developer experience and type safety for users of the template-compiler package.

packages/template-compiler · high confidence

Added Vue.js-based dbmon benchmark

A new dbmon benchmark has been added to the benchmarks suite, implementing the 'dbmon' workload using Vue.js. The entry point is index.html, which loads ENV.js (data generation and simulation logic), app.js (Vue application logic), and supporting libraries (memory-stats.js, monitor.js, styles.css). This provides a reference implementation for measuring rendering performance with Vue.

benchmarks/dbmon · high confidence

Added classic and composition API examples

The examples directory now includes classic API implementations for commits, elastic header, Firebase, grid, markdown, modal, move animations, select2, SVG, TodoMVC, and tree views, alongside new composition API equivalents for commits, grid, markdown, SVG, TodoMVC, and tree views, providing users with modern and traditional coding patterns.

examples · high confidence

Added web-specific utility modules for attributes, classes, elements, and styles

New TypeScript files have been added to src/platforms/web/util, introducing web-specific utilities for handling HTML attributes (attrs.ts), CSS class merging (class.ts), element namespace and tag detection (element.ts), style normalization and inheritance (style.ts), and DOM querying (index.ts). These modules provide the platform-specific logic required for rendering and updating web elements, such as managing boolean attributes, resolving class strings from virtual nodes, and handling browser-specific quirks like newline encoding.

src/platforms/web/util · high confidence

Comprehensive TypeScript type definitions for Vue 2 and Vue 3 APIs

The project now includes a complete set of TypeScript declaration files (\.d.ts\) for the \types/\ directory, providing full type support for Vue 2 and Vue 3 APIs. This includes definitions for component options, props, setup context, directives, and built-in components like \Transition\ and \KeepAlive\. The \index.d.ts\ file exports all public types, enabling better IDE autocomplete and type checking for Vue applications.

types · high confidence

Core configuration and global API initialization

The core module now includes a new \config.ts\ file that defines the \Config\ interface and default settings for the framework, including options for error handling, silent mode, and lifecycle hooks. Additionally, \src/core/index.ts\ initializes the global API, sets up server-side rendering context properties, and exposes the \FunctionalRenderContext\ and \version\ on the main Vue object.

src/core · medium confidence

Implement VDOM modules for template refs and directives in TypeScript

The virtual DOM now includes dedicated modules for handling template refs and directives, both rewritten in TypeScript. The template ref module manages the creation, update, and removal of refs, including support for ref in for-loops and setup state binding. The directives module handles the lifecycle of directives (bind, update, unbind) and resolves directive definitions from the component's setup state or options. These changes provide a more robust and type-safe foundation for template ref and directive functionality.

src/core/vdom/modules · high confidence

Added a new \src/v3\ directory implementing the Vue 3 Composition API, including reactivity primitives (\ref\, \reactive\, \computed\), lifecycle hooks (\onMounted\, \onUnmounted\, etc.), dependency injection (\provide\, \inject\), and the \setup\ context (\useSlots\, \useAttrs\, \useListeners\). The diff also introduces \defineAsyncComponent\, \defineComponent\, and SFC helpers (\useCssModule\, \useCssVars\), while exporting \set\ and \del\ from the reactivity system.

src/v3 · high confidence

Introduce new reactivity API for Vue 3

Added the core reactivity primitives for Vue 3, including \ref\, \shallowRef\, \computed\, \reactive\, \readonly\, and \effectScope\. This new API provides a more flexible and powerful way to manage state and side effects compared to the previous system.

src/v3/reactivity · high confidence

New compiler-sfc implementation for Vue 3 SFC compilation

The \packages/compiler-sfc/src\ directory now contains a complete, new implementation of the Single-File Component (SFC) compiler, replacing the previous version. This includes new files for parsing (\parse.ts\, \parseComponent.ts\), compiling scripts (\compileScript.ts\), templates (\compileTemplate.ts\), and styles (\compileStyle.ts\), along with utilities for CSS variables, identifier prefixing, and AST walking. This change introduces support for \\<script setup\>\ syntax, \defineProps\/\defineEmits\ macros, and CSS variable injection, while maintaining backward compatibility by exporting \parseComponent\ for tools like \fork-ts-checker-webpack-plugin\.

packages/compiler-sfc/src · high confidence

New shared utility and constant definitions for Vue 3 lifecycle hooks

The shared module now includes a new \constants.ts\ file that defines the full set of Vue 3 lifecycle hooks (including \renderTracked\ and \renderTriggered\) and asset types, alongside a new \util.ts\ file providing type-checking helpers (e.g., \isRef\, \isPlainObject\), string conversion utilities, and array/object manipulation functions. This introduces new public API surface for lifecycle tracking and utility functions used across the framework.

src/shared · high confidence

Web platform entry points and runtime-compiler integration

The web platform module now exposes explicit entry points for the compiler, runtime, and runtime-with-compiler builds. The runtime-with-compiler build integrates the Vue 3 Composition API (vca) into the Vue instance and exposes Vue.effect. The runtime-with-compiler build also adds template compilation at mount time, supporting template strings, DOM elements, and outer HTML fallbacks, with dev-only warnings for mounting to \<html\>/\<body\> and invalid template options.

src/platforms/web · medium confidence

Removals

Removal of Component class from src/instance

The Component class, previously defined in src/instance/index.js, has been removed. This class previously handled component initialization, data observation, watcher management, and virtual DOM patching. Its removal indicates a refactoring where component logic has been moved or restructured, likely into the vdom implementation as suggested by the commit messages.

src/instance · medium confidence

Removal of legacy observer implementation

The legacy observer system has been removed from the codebase. This includes the deletion of \src/observer/array.js\, \src/observer/batcher.js\, \src/observer/dep.js\, \src/observer/index.js\, and \src/observer/watcher.js\. These files previously handled reactivity, dependency tracking, and watcher batching, indicating a significant architectural shift in how the application manages state changes and updates.

src/observer · high confidence

Architecture

Refactor VDOM helper functions into dedicated TypeScript modules

The VDOM helper utilities have been reorganized into separate TypeScript files within the \src/core/vdom/helpers\ directory. This includes extracting \extractPropsFromVNodeData\, \getFirstComponentChild\, \isAsyncPlaceholder\, \mergeVNodeHook\, \normalizeChildren\, \normalizeScopedSlots\, \resolveAsyncComponent\, and \updateListeners\ into their own modules, with a central \index.ts\ re-exporting them. This change improves code organization and type safety for internal VDOM rendering logic.

src/core/vdom/helpers · high confidence

Refactor core instance initialization and lifecycle management

The core instance initialization logic has been refactored into separate modules (init, state, events, lifecycle, render, inject, proxy) to improve code organization and maintainability. The \initMixin\ function now explicitly calls \initEvents\, \initRender\, and \initLifecycle\ in a specific order, ensuring that the component's internal state, event system, and lifecycle hooks are set up correctly. Additionally, the \lifecycle\ module now manages the \activeInstance\ and handles component mounting, updating, and destruction, including proper cleanup of effect scopes and watchers.

src/core/instance · high confidence

Repository migration to a TypeScript-based monorepo with updated tooling

The project has been refactored into a TypeScript-based monorepo structure, introducing a new build and test configuration. This includes the addition of a \tsconfig.json\ for TypeScript compilation, a \vitest.config.ts\ for the Vitest test runner, and an \api-extractor.json\ for API extraction. The repository now uses pnpm workspaces to manage multiple packages. As part of this migration, legacy configuration files such as \.babelrc\ and \webpack.config.js\ have been removed, and the \.gitignore\ has been updated to exclude new build artifacts and directories.

(repo-wide) · high confidence

Restructure server-side rendering into a dedicated package

The server-side rendering implementation has been reorganized into a new \packages/server-renderer\ package. This change moves the core rendering logic, including the bundle renderer, compiler, and template rendering, into this new location. As a result, the server-renderer is now a distinct, self-contained module within the monorepo, separating the SSR implementation from the main Vue core and web platform packages.

packages/server-renderer/src · high confidence

Virtual DOM implementation refactored into dedicated modules

The core virtual DOM logic has been reorganized into separate, dedicated files: create-component.ts, create-element.ts, create-functional-component.ts, patch.ts, and vnode.ts. This structural change separates concerns for component creation, element creation, functional components, and patching, while the VNode class and its cloning logic are now in their own module. This improves code maintainability and clarity for the virtual DOM system.

src/core/vdom · high confidence

Behavioural changes

Add ESM and CommonJS entry points for @vue/compiler-sfc

The compiler-sfc package now exposes explicit entry points for both ES modules (index.mjs) and CommonJS (index.js), alongside TypeScript declarations (index.d.ts). This change enables consumers to import from '@vue/compiler-sfc' using standard ES module syntax or CommonJS require(), improving compatibility with modern build tools and bundlers that prefer native ESM support.

compiler-sfc · medium confidence

Build system refactored into the scripts/ directory

The build configuration and scripts have been reorganized into the new scripts/ directory. This includes a new alias mapping for internal modules, a Rollup-based build script that generates CommonJS, ES modules, and browser UMD bundles, and a feature-flags configuration that introduces NEW\_SLOT\_SYNTAX and VBIND\_PROP\_SHORTHAND toggles. Additionally, the release workflow has been updated to use the v2-latest tag for publishing packages.

scripts · high confidence

Compiler refactored into modular TypeScript modules with enhanced error detection

The compiler implementation has been restructured from a monolithic JavaScript structure into a modular, TypeScript-based architecture. The template parsing, optimization, and code generation logic are now separated into distinct modules (e.g., \create-compiler.ts\, \optimizer.ts\, \to-function.ts\). This refactoring introduces a new \error-detector.ts\ that provides detailed, range-specific error and warning messages for invalid expressions, keywords, and syntax. Additionally, the \createCompilerCreator\ now supports custom modules and directives, and the compiler exposes a \compileToFunctions\ API that caches compiled templates and handles CSP restrictions.

src/compiler · high confidence

Global API initialization refactored into TypeScript modules

The initialization of Vue's global API (including use, mixin, extend, and asset registers) has been restructured into separate TypeScript modules within the core/global-api directory. This change introduces explicit type definitions for the GlobalAPI interface and leverages TypeScript for better type safety and code organization, while maintaining the same functional behavior for plugin installation, component extension, and asset registration.

src/core/global-api · high confidence

Implement scoped style processing and CSS trimming for SFCs

The Vue Single-File Component compiler now includes dedicated PostCSS plugins for handling scoped styles and formatting. The new \scoped.ts\ plugin processes CSS selectors to inject unique attributes for scoping, while also handling deep selectors (\:deep\, \::v-deep\) and global selectors (\:global\, \::v-global\). The \trim.ts\ plugin normalizes whitespace in the generated CSS. This change replaces the previous \@vue/component-compiler-utils\ implementation with a native, internal solution for style processing.

packages/compiler-sfc/src/stylePlugins · high confidence

Improved asset URL transformation in SFC templates

The SFC compiler now supports transforming asset URLs in templates with greater flexibility. Users can configure a \base\ option to rewrite relative asset URLs into absolute URLs, and an \includeAbsolute\ option to process absolute URLs as well. The compiler also correctly handles external URLs, data URLs, and URI fragments, ensuring that non-relative paths are transformed appropriately when a base is provided.

packages/compiler-sfc/src/templateCompilerModules · high confidence

KeepAlive component migrated to TypeScript

The KeepAlive component has been converted from JavaScript to TypeScript, introducing strict type definitions for internal caches, component instances, and pattern matching logic. This change improves type safety and developer experience when working with the component's caching and pruning mechanisms.

src/core/components · medium confidence

Migrate render helpers to TypeScript

The render helpers in src/core/instance/render-helpers have been converted from JavaScript to TypeScript. This includes new type definitions for VNode data and scoped slots, and the addition of type annotations across all helper functions (bind-dynamic-keys, bind-object-listeners, bind-object-props, check-keycodes, render-list, render-slot, render-static, resolve-filter, resolve-scoped-slots, and resolve-slots). The index.ts file now exports installRenderHelpers with proper typing, ensuring type safety for runtime rendering utilities.

src/core/instance/render-helpers · high confidence

Migrated web runtime modules to TypeScript

The web runtime implementation, including the patching logic, node operations, and built-in directives (v-model, v-show), has been converted from JavaScript to TypeScript. This change introduces static type checking for the browser-specific runtime code, improving type safety and developer experience for the platform-specific modules.

src/platforms/web/runtime · high confidence

Migrated web runtime modules to TypeScript

The web runtime modules (attrs, class, dom-props, events, style, transition) have been converted from JavaScript to TypeScript. This adds static type checking to the DOM manipulation and event handling logic, improving code reliability and developer experience.

src/platforms/web/runtime/modules · high confidence

Parser modules converted to TypeScript

The parser components in src/compiler/parser (entity-decoder, filter-parser, html-parser, index, and text-parser) have been converted from JavaScript to TypeScript (.ts). This change introduces static type definitions for the compiler's parsing logic, which improves code safety and developer experience when working with the template and text parsing modules.

src/compiler/parser · high confidence

Refactor core utilities to TypeScript and restructure module exports

The core utility modules (debug, env, error, lang, next-tick, options, perf, props) have been converted from JavaScript to TypeScript (.ts) and reorganized under src/core/util. The main index file now explicitly re-exports from these new TypeScript modules, while removing exports for dom and component utilities which have been moved elsewhere. This change improves type safety and code organization for the core utility layer.

src/core/util · high confidence

Refactor reactivity system with new observer and scheduler architecture

The internal reactivity system has been restructured to improve performance and debugging capabilities. The observer logic, dependency tracking, and scheduler have been rewritten to support more efficient dependency collection and update scheduling. Additionally, developer tools now receive detailed tracking and triggering events, enabling better debugging of reactive state changes.

src/core/observer · high confidence

Removal of legacy build script

The legacy build script (build/build.js) has been removed. This script previously handled the compilation of Vue.js into CommonJS, UMD, and minified distributions using Rollup and Uglify. Its removal indicates a shift in the build process, likely to a more modern or modular build configuration.

build · high confidence

Removed VDOM modules for attributes, classes, events, props, and styles

The VDOM modules responsible for handling attributes, classes, events, props, and styles have been removed from the virtual DOM rendering pipeline. This eliminates the separate update logic for these DOM properties, likely consolidating or replacing this functionality elsewhere in the framework.

src/vdom/modules · high confidence

Removed deprecated utility modules from src/util

The utility modules \component.js\, \debug.js\, \dom.js\, \env.js\, \lang.js\, and \options.js\ have been removed from the codebase. This eliminates the associated helper functions and logic, such as DOM manipulation, environment sniffing, and option merging strategies, which are no longer used or have been replaced by newer implementations.

src/util · high confidence

Removed legacy entry points and configuration

The library's main entry points (src/index.js, src/index.umd.js) and the central configuration object (src/config.js) have been removed. A new global type definition (src/global.d.ts) has been added to declare environment variables (\_\DEV\\, \\TEST\\, \\GLOBAL\\_) and the Vue DevTools hook interface, indicating a shift in how the library exposes its API and handles environment-specific behavior.

src · medium confidence

Support component resolution from \<script setup\> bindings

The codegen logic in src/compiler/codegen now checks component bindings to resolve components defined in \<script setup\> blocks. This allows templates to correctly identify and render components declared via script setup, ensuring that such components are treated as components rather than native HTML elements.

src/compiler/codegen · high confidence

Web compiler refactored to TypeScript with new module and directive structures

The web compiler has been refactored into TypeScript, introducing new module and directive structures. This includes new files for HTML, text, and model directives, as well as modules for class, style, and model processing. The compiler now uses a \baseOptions\ configuration that integrates these modules and directives, and includes utility functions for handling HTML tags. This change improves type safety and maintainability of the compiler.

src/platforms/web/compiler · medium confidence

Test coverage

Added comprehensive TypeScript tests for Vue 3 features and type definitions; Added comprehensive test coverage for the Vue SFC compiler; Added end-to-end tests for Vue examples and edge cases; Added server-side rendering tests for Vue.js; Added test environment configuration for Vitest; Added test helper utilities for assertions and async flows; Added transition test suite; Added type tests for Vue 3 APIs; Added unit tests for SSR compiler options; Added unit tests for VDOM module handlers; Added unit tests for VDOM patching; Added unit tests for Vue 3 Composition API features; Added unit tests for Vue 3 reactivity system; Added unit tests for Vue component features; Added unit tests for Vue component options; Added unit tests for Vue instance methods and properties; Added unit tests for Vue's observer and vdom modules; Added unit tests for Vue.js global API; Added unit tests for template refs, filters, error handling, and debug utilities; Added unit tests for the compiler modules; Added unit tests for utility modules; Updated SFC compiler-sfc test snapshots.

Dependencies

Restructure Vue 2.7.16 into a monorepo with separate packages

The project has been restructured into a monorepo, splitting the codebase into distinct packages: \@vue/compiler-sfc\, \vue-server-renderer\, and \vue-template-compiler\, each with their own \package.json\ and dependencies. The root \package.json\ now defines the main \vue\ package and manages the workspace, while a new \pnpm-lock.yaml\ file enforces consistent dependency versions across all packages. This change improves modularity and allows each component to be versioned and maintained independently.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 44 → 55 (+10.6)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 85 → 74 (-11.3)
  • Architecture 51 → 61 (+9.7)
  • Maturity 56 → 56 (+0.0)
  • Readiness 38 → 57 (+19.0)
  • Security 37 → 51 (+13.6)

Resolved (69)

  • Change coupling: attrs.ts ↔ class.ts (packages/server-renderer/src/modules/attrs.ts)
  • Change coupling: class.ts ↔ style.ts (packages/server-renderer/src/modules/class.ts)
  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Critical vulnerability: [GHSA redacted] (pnpm-lock.yaml)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • …and 49 more

New (262)

  • Coverage not measured — JavaScript/TypeScript suite
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Critical vulnerability: [GHSA redacted] (pnpm-lock.yaml)
  • EffectScope.stop (cognitive 17) (src/v3/reactivity/effectScope.ts)
  • FileTooLong: parser/index.ts (src/compiler/parser/index.ts)
  • FileTooLong: src/compileScript.ts (packages/compiler-sfc/src/compileScript.ts)
  • FileTooLong: vdom/patch.ts (src/core/vdom/patch.ts)
  • FunctionTooLong: html-parser.parseHTML (src/compiler/parser/html-parser.ts)
  • FunctionTooLong: index.parse (src/compiler/parser/index.ts)
  • FunctionTooLong: index.processAttrs (src/compiler/parser/index.ts)
  • FunctionTooLong: patch.createPatchFunction (src/core/vdom/patch.ts)
  • HackComment (src/core/vdom/patch.ts)
  • High CVE: [CVE redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • …and 242 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

vuejs/vue was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 9e88707940088cb1f4cd7dd210c9168a50dc347c — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-be726e82e277.