Skip to content
CAI
Software that uses CAICheck a score

yargs/yargs

67.5

Adequate · 2 October 2026

5.9k

lines of production code

TypeScript

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Node.js command-line argument parsing library that has recently transitioned from a CommonJS to an ESM-first architecture. It provides core parsing utilities and platform-specific shims, with recent activity heavily focused on stabilizing the codebase, resolving security vulnerabilities, and maintaining extensive test coverage. The project is currently in a maintenance phase aimed at ensuring build reliability and compatibility across different Node.js versions.

How it got here

2020 — Expose helper utilities for legacy Node.js compatibility

1 change.

A new helpers module has been added to expose specific utility functions (applyExtends, hideBin, and Parser) that wrap internal implementation details. This change ensures these helpers are accessible for use in legacy versions of Node.js, addressing compatibility concerns by providing a stable interface for these underlying utilities.

April 2025 — Removal of CommonJS helpers module

1 change.

The \helpers/index.js\ file, which previously served as a CommonJS wrapper for yargs functionality (exporting \applyExtends\, \hideBin\, and \Parser\ via \require\), has been removed. This change aligns with the project's shift to an ESM-first architecture, eliminating the legacy CJS compatibility layer in this location.

June 2026 — 21 commits (12 fixes) fixing lib/platform-shims

1 change.

A fix in lib/platform-shims — 21 commits (12 fixs), 4 files.

July 2026 — dependency updates and test coverage

2 changes.

The period was dominated by extensive dependency maintenance, involving 531 commits across seven manifests to update and fix build requirements. Alongside this infrastructure work, significant effort was directed towards improving test coverage, with 25 commits focused on adding and updating tests within the test fixtures directory. The overall activity reflects a phase of stabilizing the build environment and enhancing the reliability of the test suite.

September 2026 — v18.2.0 stabilization and security fixes

4 changes.

The period was dominated by a massive repository-wide effort involving over a thousand commits, primarily focused on applying fixes and behavioral changes to stabilize the codebase. This work culminated in a version bump to 18.2.0, marking a significant release milestone. Additionally, eight security findings were resolved, although three regressions occurred without associated commits.

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 65 → 67 (+2.2)
  • Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 67 → 67 (+0.0)
  • Architecture 91 → 90 (-1.3)
  • Maturity 60 → 62 (+1.5)
  • Readiness 67 → 66 (-1.1)
  • Security 74 → 87 (+13.2)
  • Performance 100 (new)

Resolved (15)

  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High: security finding (details withheld)
  • Hotspot: lib/command.ts (lib/command.ts)
  • Hotspot: lib/usage.ts (lib/usage.ts)
  • Hotspot: lib/yargs-factory.ts (lib/yargs-factory.ts)
  • No artifact signing
  • No build provenance
  • Off-boarding risk: anonymized user #1
  • Release publish has no approval gate
  • Secret passed as a command-line argument

New (7)

  • Documentation: written for insiders (README.md)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • Low cohesion: YargsInstance (LCOM4 9) (lib/yargs-factory.ts)
  • Off-boarding risk: anonymized user #1
  • Outdated (npm): string-width

Changes since last survey

  • 4 commits — 4 feature/other, 0 fixes

By area

  • (root) — 2 commits
  • .github/workflows — 1 commit
  • docs/api.md — 1 commit

Notable commits

  • change: Set up staged trusted publishing, and remove stale deno workflow (#2591)
  • change: chore(main): release 18.2.0 (#2569)
  • change: docs: minor tidy. Remove stale references to Deno, Standard, and @next. (#2602)
  • change: docs: tidy intro to docs/api (#2604)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

yargs/yargs was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 10f1dda5991fba2cea6a4b4dc6bd90da6e5292b2 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.