You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A discussion dedicated to the JupyterLab module. Share your thoughts, questions, and feedback here.
Module Scorecard
Presentation & Onboarding
IDE Integration
Credential Hygiene
Restricted-Environment Readiness
Engineering Quality
Overall
11 / 17
16 / 25
20 / 20
7 / 20
10 / 10
70 / 100
Drilldown
Presentation & Onboarding — 11 / 17
Criterion
Max
Score
Notes
Configuration-mode examples
12
6
README documents default (loopback/subdomain), external host (host = "0.0.0.0"), and custom config JSON. However, the path mode (subdomain = false) is a major alternative access mode with no README example, and share options are undocumented. Two of three major modes shown.
Visual preview
5
5
README embeds ; image verified to exist at 428.3 KB.
Credential Hygiene — 20 / 20
Criterion
Max
Score
Notes
Secrets marked sensitive
16
16
No dedicated secret inputs exist (no token, password, api_key variables). The config variable is a general-purpose JSON blob, not an inherently sensitive input. No README example inlines a literal or placeholder secret.
Non-hardcoded auth path
4
4
README explicitly states JupyterLab binds to 127.0.0.1 so "unauthenticated traffic must pass through Coder's application proxy." The script sets --ServerApp.token='' and --ServerApp.password='', relying entirely on Coder's proxy for auth.
Restricted-Environment Readiness — 7 / 20
Criterion
Max
Score
Notes
Mirrorable artifact source
5
0
run.sh hardcodes pipx install jupyterlab and uv pip install -q jupyterlab. No module input variable overrides the package index or download URL. No pip_index_url, package_source, or equivalent variable exists.
Bring-your-own binary
10
5
run.sh checks command -v jupyter-lab and skips installation if already present ("🥳 jupyterlab is already installed"). Behavior is implemented but not documented in the README—no section tells users they can pre-bake jupyter-lab into their image.
Egress transparency
3
0
The "External network access" section addresses host binding, not egress. No dedicated section enumerates PyPI (pypi.org) or any other external endpoints contacted during install or runtime.
Runs without sudo
2
2
run.sh uses pipx/uv (user-space installs to $HOME) and the config script uses mkdir -p "$HOME/.jupyter". No sudo invocation anywhere in either script.
Engineering Quality — 10 / 10
Criterion
Max
Score
Notes
Input quality
6
6
All 9 variables have description fields. Sensible defaults (host="127.0.0.1", port=19999, share="owner", subdomain=true). Security-critical host has regex validation; share has enum validation.
Test coverage
4
4
main.tftest.hcl covers secure defaults, path mode, IPv6 loopback, and unsafe-host rejection at plan level. main.test.ts runs end-to-end container tests: installer detection, config file writing, CSP fallback, loopback binding, path-mode URL rendering, and 4 injection-attack host rejections. Two installer tests (uv, pipx) are TODO-commented due to timeout, but the core logic is well-covered.
IDE Integration — 16 / 25
Criterion
Max
Score
Notes
Dashboard entry point
7
7
coder_app resource with proper URL construction for both subdomain and path modes, healthcheck (/api endpoint, 5s interval, 6 threshold), share, order, group, and subdomain support.
Managed configuration
6
6
config variable (JSON string) documented in README with a full example showing ServerApp settings including tornado_settings and root_dir. Written to ~/.jupyter/jupyter_server_config.json via a dedicated coder_script.
Configurable folder or workdir
6
3
README's config example shows root_dir = "/workspace/notebooks", but it is one line within a general JSON example—not called out as a dedicated workdir feature or exposed as a first-class module variable.
Pre-installed extensions
6
0
No variable, script, or README section supports pre-installing JupyterLab extensions (e.g., jupyter labextension install). The config JSON could reference extension settings but no extension installation mechanism is documented.
Overall — 70 / 100
Raw 64 / 92 → round(64 / 92 × 100) = 70
Scored against SCORECARD.md on 2026-09-28 with solstice-1.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
A discussion dedicated to the JupyterLab module. Share your thoughts, questions, and feedback here.
Module Scorecard
Drilldown
Presentation & Onboarding — 11 / 17
host = "0.0.0.0"), and customconfigJSON. However, the path mode (subdomain = false) is a major alternative access mode with no README example, andshareoptions are undocumented. Two of three major modes shown.; image verified to exist at 428.3 KB.Credential Hygiene — 20 / 20
token,password,api_keyvariables). Theconfigvariable is a general-purpose JSON blob, not an inherently sensitive input. No README example inlines a literal or placeholder secret.127.0.0.1so "unauthenticated traffic must pass through Coder's application proxy." The script sets--ServerApp.token=''and--ServerApp.password='', relying entirely on Coder's proxy for auth.Restricted-Environment Readiness — 7 / 20
run.shhardcodespipx install jupyterlabanduv pip install -q jupyterlab. No module input variable overrides the package index or download URL. Nopip_index_url,package_source, or equivalent variable exists.run.shcheckscommand -v jupyter-laband skips installation if already present ("🥳 jupyterlab is already installed"). Behavior is implemented but not documented in the README—no section tells users they can pre-bake jupyter-lab into their image.run.shusespipx/uv(user-space installs to$HOME) and the config script usesmkdir -p "$HOME/.jupyter". Nosudoinvocation anywhere in either script.Engineering Quality — 10 / 10
descriptionfields. Sensible defaults (host="127.0.0.1",port=19999,share="owner",subdomain=true). Security-criticalhosthas regex validation;sharehas enum validation.main.tftest.hclcovers secure defaults, path mode, IPv6 loopback, and unsafe-host rejection at plan level.main.test.tsruns end-to-end container tests: installer detection, config file writing, CSP fallback, loopback binding, path-mode URL rendering, and 4 injection-attack host rejections. Two installer tests (uv, pipx) are TODO-commented due to timeout, but the core logic is well-covered.IDE Integration — 16 / 25
coder_appresource with proper URL construction for both subdomain and path modes, healthcheck (/apiendpoint, 5s interval, 6 threshold),share,order,group, andsubdomainsupport.configvariable (JSON string) documented in README with a full example showingServerAppsettings includingtornado_settingsandroot_dir. Written to~/.jupyter/jupyter_server_config.jsonvia a dedicatedcoder_script.root_dir = "/workspace/notebooks", but it is one line within a general JSON example—not called out as a dedicated workdir feature or exposed as a first-class module variable.jupyter labextension install). TheconfigJSON could reference extension settings but no extension installation mechanism is documented.Overall — 70 / 100
Raw 64 / 92 → round(64 / 92 × 100) = 70
Scored against SCORECARD.md on 2026-09-28 with
solstice-1.All reactions