alibaba/arthas
49.5
Weak · 22 September 2026
90.6k
lines of production code
Java
with TypeScript, JavaScript
7
measurements over time
What this system is
Arthas is a Java diagnostic tool that attaches to running JVM processes to provide real-time monitoring and troubleshooting capabilities. It exposes a rich set of commands for inspecting threads, memory, classloaders, and application logs, accessible via a terminal shell, HTTP API, or web console. The system also supports programmatic integration through Spring Boot starters and exposes diagnostic tools via the Model Context Protocol for AI agent interaction.
How it got here
2018 — Initial project scaffolding and core shell architecture
42 changes.
This period established the foundational structure of the Arthas Java diagnostic tool, introducing the initial repository scaffolding, build scripts, and Docker configurations. It focused on building the core shell infrastructure, including the agent attachment mechanism, session management, and a modular command execution engine with extensive diagnostic capabilities.
2019–2020 — remote tunneling and Spring Boot integration
34 changes.
This period focused on enabling remote agent management through the introduction of a Tunnel Server and Client, supporting WebSocket connectivity, HTTP proxying, and cluster deployment. It also established deep integration with the Spring Boot ecosystem via a new auto-configuration starter and expanded core capabilities with in-memory compilation, structured command result distribution, and unified terminal protocols.
2021–2026 — MCP integration and native agent expansion
23 changes.
This period focused on integrating the Model Context Protocol (MCP) to expose Arthas diagnostic tools to AI agents, alongside a major architectural shift toward native agent support. The work included rewriting the Web UI for modern deployment modes, adding deep heap analysis capabilities via native libraries, and establishing cluster management infrastructure for distributed agent operations.
Features
Add Debian package support for Arthas
Users can now install Arthas on Debian-based systems via a native .deb package. This change introduces the necessary packaging metadata, including the control file specifying dependencies on JDK 1.6+, telnet, curl, and unzip, along with the corresponding copyright and man page documentation to facilitate standard system integration.
packaging/src/deb · high confidence
Add logger command with support for Log4j2, Log4j, and Logback
The new \logger\ command allows users to inspect and update logging levels for applications using Log4j, Logback, or Log4j2. It detects the active logging framework via reflection and provides detailed information about loggers, including their levels, appenders, and configuration sources. The command supports filtering by logger name and classloader, and includes options to include loggers without appenders or specify a classloader by hash or class name. Helper classes for each logging framework are included to handle framework-specific interactions.
core/src/main/java/com/taobao/arthas/core/command/logger · high confidence
Added Maven Wrapper with version 3.9.9
The project now includes a Maven Wrapper (mvnw) to ensure consistent builds across environments. The configuration file sets the wrapper version to 3.3.2 and specifies that it should download and use Apache Maven 3.9.9.
.mvn · high confidence
Added RateCounter and SumRateCounter metrics utilities
New classes RateCounter and SumRateCounter have been added to the core metrics utility package. RateCounter calculates the average rate of recorded values over a fixed window, while SumRateCounter computes the average rate of change between cumulative totals. These components provide foundational tools for monitoring application performance metrics within the Arthas core.
core/src/main/java/com/taobao/arthas/core/util/metrics · high confidence
Added demo-external command example for loading external commands
A new demo module has been added to illustrate how to load external commands into Arthas. It includes a \demo-external\ command implementation and a \CommandResolver\ SPI registration, allowing users to place the resulting JAR in the \${arthas.home}/commands/\ directory to extend Arthas with custom commands.
arthas-demo-external-command · high confidence
Initial implementation of the Arthas Tunnel Server
This change introduces the core components of the Arthas Tunnel Server, enabling remote management of Arthas agents via WebSocket. The server now supports agent registration, client connection handling, and bidirectional traffic relaying between web console clients and agents. Key features include support for SSL/TLS encryption, HTTP proxying, and cluster deployment via a configurable cluster store (e.g., Redis). It also handles client IP detection via X-Forwarded-For headers, manages connection idle timeouts, and maintains agent state information.
tunnel-server/src/main/java/com/alibaba/arthas/tunnel/server · high confidence
Initial project scaffolding with documentation, build scripts, and Dockerfiles
This change introduces the foundational repository structure for the Arthas Java diagnostic tool. It adds core documentation files (README, CONTRIBUTING, AGENTS, USERS) and legal notices (LICENSE, NOTICE). It also includes build and deployment assets: the \as-package.sh\ script for local packaging with Maven parallel build support, the Apache Maven Wrapper (mvnw/mvnw.cmd) version 3.3.2, and Dockerfiles (including a no-JDK variant) configured to download and install Arthas version 4.3.5.
(repo-wide) · high confidence
Initial release of Arthas core resources and readline configuration
This change introduces the initial set of core resource files for the Arthas diagnostic tool. It adds a logo display file and a thanks file acknowledging contributors from the Greys Anatomy project. Most significantly, it establishes the readline inputrc configuration, which enables standard Emacs-style keyboard shortcuts (such as Ctrl+A/E for line navigation, Ctrl+F/B for word movement, and Ctrl+R for history search) and maps specific terminal key sequences (Home, End, Page Up/Down, Delete) to their corresponding readline commands, ensuring consistent command-line editing behavior across various terminal emulators like xterm, rxvt, and Linux consoles.
core/src/main/resources · high confidence
Initial release of Arthas core shell and hidden commands
This change introduces the initial version of the Arthas core shell infrastructure, including the asynchronous \Future\ utility, session and terminal server lifecycle handlers, and term input/output event handlers. It also adds two hidden CLI commands: \july\, which outputs a specific text string, and \thanks\, which displays product credits via the banner utility.
(repo-wide) · high confidence
Initial release of Arthas diagnostic scripts and Windows service support
This change introduces the core Arthas diagnostic tooling for the first time, adding the primary shell scripts (as.sh, install.sh, install-local.sh, jps.sh) and new Windows batch files (as.bat, as-service.bat). The as.sh and as.bat scripts provide the main entry point for attaching the Arthas agent to Java processes, supporting features like process selection, port configuration, and JDK version detection. The new as-service.bat enables running Arthas as a Windows service, while install.sh and install-local.sh facilitate downloading and setting up the Arthas libraries locally.
bin · high confidence
Introduce Arthas Spring Boot Starter for automatic agent integration
This change introduces the \arthas-spring-boot-starter\ module, which automatically configures and initializes the Arthas diagnostic agent within Spring Boot applications. It provides an \ArthasProperties\ configuration class to map \arthas.\*\ properties (such as \ip\, \telnetPort\, \httpPort\, \tunnelServer\, \agentId\, \appName\, \username\, \password\, \disabledCommands\, and \commandLocations\) to the agent's configuration. The starter includes an \ArthasConfiguration\ bean that handles agent initialization, including setting a default \appName\ from the Spring environment and managing default disabled commands. Additionally, it exposes an Actuator endpoint (\/actuator/arthas\) to read the current Arthas configuration and any initialization error messages.
arthas-spring-boot-starter/src/main/java · high confidence
Introduce ArthasAgent API for programmatic agent attachment
Added the arthas-agent-attach module, providing a new Java API (ArthasAgent) that allows applications to attach the Arthas diagnostic agent programmatically. This change enables users to initialize Arthas within their code, supporting configuration via a config map, specifying a custom arthasHome directory, and handling silent initialization to prevent crashes during startup.
arthas-agent-attach · high confidence
Introduce ArthasEnvironment for structured property resolution
Arthas now includes a dedicated \ArthasEnvironment\ component in the core module that manages configuration properties with a defined precedence order. This new environment abstraction aggregates system properties and environment variables into a unified property source hierarchy, allowing users to resolve configuration values (including placeholder substitution like \${key}\) through a consistent API. The change adds the underlying infrastructure for this behavior, including property resolvers, placeholder helpers, and type conversion services, enabling more robust and predictable configuration management within Arthas sessions.
core/src/main/java/com/taobao/arthas/core/env · high confidence
Introduce HTTP API for command execution and session management
Adds a new HTTP REST API handler that allows users to execute Arthas commands, manage sessions, and retrieve results via HTTP requests. The implementation includes request/response models (ApiRequest, ApiResponse), action enums (EXEC, ASYNC\_EXEC, PULL\_RESULTS, etc.), and an ObjectVOFilter to support plain text ObjectView output in API responses.
core/src/main/java/com/taobao/arthas/core/shell/term/impl/http/api · high confidence
Introduce JFR analysis backend and frontend
Added a new JFR (Java Flight Recorder) analysis capability, including a Spring Boot backend and a corresponding frontend. The backend exposes REST APIs for uploading, managing, and analyzing JFR files, generating flame graphs, and retrieving analysis metadata and supported dimensions. It includes file management services, configuration for Arthas storage paths, CORS settings, and a comprehensive set of extractors for processing JFR events such as CPU samples, memory allocations, and thread activity.
labs/arthas-jfr-backend, labs/arthas-jfr-frontend · high confidence
Introduce VmTool JMX API for JVM diagnostics
This change adds the \VmTool\ class and its \VmToolMXBean\ interface to the \arthas\ package, providing a JMX-accessible API for JVM diagnostics. Users can now register this MBean to perform operations such as forcing garbage collection, retrieving class instances with optional limits, calculating instance sizes, listing all loaded classes, trimming malloc memory, and performing heap or reference analysis. The implementation bridges Java methods to native JNI calls for these low-level JVM interactions.
arthas-vmtool/src/main/java · high confidence
Introduce arthas-boot bootstrap utility with enhanced process selection and download capabilities
The arthas-boot tool is introduced as the primary entry point for launching Arthas, replacing the previous as.sh script. This new Java-based bootstrap utility provides a more robust process selection mechanism, allowing users to target processes by name or JAR filename via the --select option, and automatically prefers jcmd over jps for listing Java processes. It also includes improved download logic with progress reporting, support for HTTP redirects, and configurable session timeouts, while maintaining backward compatibility with existing command-line options like --telnet-port and --http-port.
boot/src/main · high confidence
Introduce arthas-mcp-server module with Streamable HTTP MCP support
The new arthas-mcp-server module exposes Arthas diagnostic tools (such as dashboard, thread, and trace) via the Model Context Protocol (MCP). It defaults to the Streamable HTTP transport protocol, allowing AI clients to connect to port 8563 at the /mcp endpoint. The server supports authentication via Bearer tokens, manages Arthas command sessions, and includes built-in capabilities for long-running server tasks.
arthas-mcp-server · high confidence
Introduce command history management
Added a new history management system for the Arthas shell, including the HistoryManager interface and its implementation. This feature allows users to save, load, and manage command history, with a maximum limit of 500 items stored in memory. The implementation ensures thread-safe operations for adding, retrieving, and clearing history entries, enhancing the user experience by preserving command history across sessions.
core/src/main/java/com/taobao/arthas/core/shell/history · high confidence
Introduce common utility module for Arthas
A new \common\ module has been added to centralize shared utilities used across the Arthas codebase. This includes \AnsiLog\ for colored console output with configurable output streams, \OSUtils\ for platform and architecture detection (including support for LoongArch64 and musl libc), \PidUtils\ for retrieving the current process ID and main class name, \IOUtils\ and \FileUtils\ for file and stream operations, \SocketUtils\ for finding available TCP ports, and \ReflectUtils\ for advanced reflection capabilities. This change consolidates previously scattered utility code into a single location.
common/src/main/java/com/taobao/arthas/common · high confidence
Introduce core shell server and session implementation
This change adds the foundational shell server infrastructure for Arthas, including the \ShellServerImpl\ and \ShellImpl\ classes that manage terminal sessions, command resolution, and job control. It introduces a new handler framework (\Handler\, \BindHandler\, \NoOpHandler\) for processing asynchronous events and defines a \BuiltinCommandResolver\ to register internal commands like \exit\, \quit\, \jobs\, and \fg\. The implementation supports multiple connection types (Telnet, HTTP) with specific authentication handling for local connections and HTTP cookies, and enforces session timeouts with automatic eviction of inactive sessions.
core/src/main/java/com/taobao/arthas/core/shell/impl · high confidence
Introduce core shell system implementation classes for job and process management
Added new implementation classes in the core shell system package to handle command execution, job control, and process lifecycle. This includes GlobalJobControllerImpl for managing background jobs with configurable timeouts, InternalCommandManager for resolving and completing commands (including pipe support), and ProcessImpl for executing commands with support for foreground/background modes, interruption, and status tracking. These changes provide the underlying infrastructure for Arthas' interactive shell capabilities.
core/src/main/java/com/taobao/arthas/core/shell/system/impl · high confidence
Introduce core terminal and signal handling abstractions
Added new interfaces and abstract classes to the core shell term module to standardize terminal interactions. The new \Term\ interface defines methods for reading input, writing output, handling terminal resizing, and managing interrupt/suspend signals via the new \SignalHandler\ interface. \TermServer\ provides an abstract base for creating terminal servers (currently supporting Telnet), allowing the application to bind to ports and handle incoming client connections. \Tty\ exposes basic terminal properties like type, width, and height. These changes establish the foundational API for remote terminal access within Arthas.
core/src/main/java/com/taobao/arthas/core/shell/term · high confidence
Introduce internal shell command handlers for grep, tee, wc, and output redirection
Added a new set of internal handler classes in the command shell package to support piping and output processing. This includes GrepHandler for filtering text with regex, context lines, and count options; TeeHandler for duplicating output to a file; WordCountHandler for line counting; RedirectHandler for saving results to files; and supporting interfaces like CloseFunction and StatisticsFunction. These handlers are registered via StdoutHandler to enable command chaining and structured output management within the Arthas shell.
core/src/main/java/com/taobao/arthas/core/shell/command/internal · high confidence
Introduce memorycompiler module for in-memory Java compilation
The new \memorycompiler\ module provides a \DynamicCompiler\ that compiles Java source code in memory and returns the resulting class files or bytecode without writing to disk. It includes a \DynamicClassLoader\ to load the compiled classes and a \PackageInternalsFinder\ with a \JarFileIndex\ to efficiently locate classes within JARs, supporting file paths with whitespace and Unicode characters.
memorycompiler · high confidence
Introduce native-agent-proxy for cluster management
This change adds the \native-agent-proxy\ component, which acts as an intermediary for managing Arthas native agents in a cluster. The proxy supports registering itself and discovering agents via either Etcd or Zookeeper, using factory-based implementations for extensibility. It exposes an HTTP API at \/api/native-agent-proxy\ to list active agents and forward commands (such as \listProcess\ and \monitor\) to specific agent instances, while also handling WebSocket upgrades to proxy real-time sessions. The component includes bootstrap logic for startup configuration and utility classes for HTTP handling and welcome messages.
labs/cluster-management/native-agent, labs/cluster-management/native-agent-common, labs/cluster-management/native-agent-proxy · high confidence
Introduce new diagnostic commands and refactor core monitoring infrastructure
This release adds several new diagnostic capabilities to Arthas, including the \line\ command for watching local variables at specific source code lines, the \heapdump\ command for generating heap dumps, the \mbean\ command for inspecting JMX MBeans, and the \jvm\ command for displaying detailed JVM information (including file descriptors and deadlocked threads). The \dashboard\ command has been updated to display the current timestamp and now supports exiting via the 'Q' key. Under the hood, the core monitoring package (\monitor200\) has been refactored to use a new \AbstractTraceAdviceListener\ for better trace management, and the deprecated Groovy scripting support has been retained but marked for removal due to memory leak concerns.
core/src/main/java/com/taobao/arthas/core/command/monitor200 · high confidence
Introduce structured terminal view components for command output
The core view package now includes a set of UI components (TableView, TreeView, LadderView, KVView, ClassInfoView, MethodInfoView, ObjectView, and Ansi) that replace ad-hoc string formatting with structured, styled terminal output. Users will see richer, formatted displays for object introspection (including class metadata, method signatures, and field values), hierarchical tree structures, and key-value pairs, with support for ANSI colors and borders to improve readability in the CLI.
core/src/main/java/com/taobao/arthas/core/view · high confidence
Introduce tunnel client for remote agent connectivity
Adds a new tunnel client module that enables Arthas agents to connect to a remote tunnel server via WebSocket (WS/WSS). This client handles agent registration, supports HTTP proxying through the tunnel, and establishes local forwarding channels to relay traffic to the local Arthas server, including automatic reconnection logic and idle ping handling to maintain the connection.
tunnel-client · high confidence
Introduce tunnel-common module with HTTP proxy support and secure deserialization
The new tunnel-common module centralizes tunnel communication constants and introduces a SimpleHttpResponse class that enforces a deserialization whitelist to prevent unsafe object deserialization. This module also defines the URI parameters and method constants required for the tunnel client and server to support HTTP proxying, including the new 'httpProxy' method and associated target URL and request ID parameters.
tunnel-common · high confidence
Introduce web-based management server for native agents
A new standalone web server for managing native agents has been added to the labs directory. This server provides an HTTP API and a web UI for discovering native agent proxies via service registries (currently supporting Etcd and Zookeeper) and listing active agents. It includes a bootstrap entry point that accepts registration type and address arguments, an HTTP request handler routing API calls, and a resource handler serving the frontend assets (HTML, CSS, JS) for the management console.
labs/cluster-management/native-agent-management-web · high confidence
Introduces structured result distribution interfaces for command output
This change adds a new set of interfaces in the core distribution package to manage how command results are delivered to consumers. It defines \ResultDistributor\ as the base interface for appending and closing results, \ResultConsumer\ for receiving and polling result batches, and \SharingResultDistributor\ to manage multiple consumers within a single session. Additionally, \CompositeResultDistributor\ allows chaining multiple distributors, \PackingResultDistributor\ enables retrieving packed results, and \ResultConsumerHelper\ provides utilities for estimating result item counts to optimize data slicing. These changes establish the infrastructure for distributing command output to various clients (such as Telnet or HTTP APIs) by decoupling result generation from result consumption.
core/src/main/java/com/taobao/arthas/core/distribution · high confidence
Introduction of MathGame demo application
A new Java-based demo application named MathGame has been added to the math-game module. This application runs a continuous loop that generates random numbers, calculates their prime factors, and prints the results to the console, while tracking and reporting any illegal argument exceptions that occur during the process.
math-game · high confidence
Introduction of Session and SessionManager implementations
Added \SessionImpl\ and \SessionManagerImpl\ classes to handle session lifecycle, including creation, removal, and timeout-based eviction. The implementation manages foreground jobs, result distribution, and user ID tracking, ensuring that resources like result distributors are properly closed when sessions are removed or the system shuts down.
core/src/main/java/com/taobao/arthas/core/shell/session/impl · high confidence
Introduction of Session and SessionManager interfaces for shell session management
New interfaces \Session\ and \SessionManager\ have been added to the core shell package to manage agent sessions. The \Session\ interface defines the structure for session data, including identifiers, user tracking (\userId\), quiet mode support, and access time management, while \SessionManager\ provides the API for creating, retrieving, and removing these sessions. This establishes the foundational contract for session lifecycle and state handling within the Arthas shell.
core/src/main/java/com/taobao/arthas/core/shell/session · high confidence
Introduction of SpyAPI for instrumentation lifecycle management
A new SpyAPI class has been added to the spy module, providing a centralized interface for managing instrumentation events such as method entry, exit, exceptions, and line-level tracing. This API introduces an AbstractSpy base class with a NopSpy default implementation, allowing the system to switch between active and no-operation spying modes via setSpy and setNopSpy methods. This change establishes the foundational mechanism for the SpyAPI integration mentioned in the commit messages, enabling other components to bind to this interface for runtime code inspection.
spy · high confidence
Introduction of annotated command implementation and builder
The core shell command subsystem now includes \AnnotatedCommandImpl\ and \CommandBuilderImpl\. \AnnotatedCommandImpl\ allows commands to be defined via Java annotations, automatically configuring CLI options and invoking the command handler, while also capturing user ID for usage statistics reporting. \CommandBuilderImpl\ provides a fluent API to construct commands with custom process and completion handlers.
core/src/main/java/com/taobao/arthas/core/shell/command/impl · high confidence
Introduction of core shell server infrastructure with configurable session timeouts
This change introduces the foundational shell server components for Arthas, including the \Shell\, \ShellServer\, and \ShellServerOptions\ classes. These new files define the API for managing interactive sessions, registering command resolvers and terminal servers, and handling job execution. A key behavioral aspect is the configuration of session management, where the default session timeout is set to 3 hours (10,800,000 ms) and the session reaper interval is set to 60 seconds, allowing users to maintain long-lived connections without immediate expiration.
core/src/main/java/com/taobao/arthas/core/shell · high confidence
Introduction of core shell system interfaces for job and process management
This change introduces the foundational interfaces for the Arthas shell's execution model, specifically defining how jobs and processes are managed within a session. New types include ExecStatus to track execution states (READY, RUNNING, STOPPED, TERMINATED), Job and JobController to handle lifecycle operations like running, suspending, and terminating jobs, and Process to manage individual process execution, TTY attachment, and signal handling. Additionally, JobListener and ProcessAware interfaces are added to support event notification and process context awareness, enabling the shell to coordinate background/foreground execution and integrate with various transport layers like Telnet and HTTP.
core/src/main/java/com/taobao/arthas/core/shell/system · high confidence
Native Agent module and Vite-based build system added to Web UI
The Arthas Web UI now includes a new 'native-agent' module that allows users to list native agents, view Java process information, and attach to or monitor specific JVM processes via a dedicated interface. This feature is supported by a complete migration to a Vite build system, which replaces the previous setup with Vue 3, Tailwind CSS, and DaisyUI, and introduces environment-specific configurations (tunnel, ui, native-agent) to manage proxy targets and build outputs.
web-ui/arthasWebConsole · high confidence
Native heap analysis capabilities added to vmtool
The arthas-vmtool native library now includes a new heap analyzer implementation (heap\_analyzer.c/h) and updated JNI bindings (jni-library.cpp). This adds support for deep heap analysis features, including tracing object reference paths back to GC roots and identifying the largest objects by class, in addition to existing capabilities like force GC, instance counting, and size summation.
arthas-vmtool/src/main/native · high confidence
New Affect utility classes for tracking instrumentation impact
Added three new classes in the core utility package to track and report the impact of bytecode instrumentation: Affect (base class for timing), EnhancerAffect (tracks affected classes, methods, dump files, and errors with verbose support), and RowAffect (tracks row counts). These classes provide structured feedback on the scope and performance of enhancement operations.
core/src/main/java/com/taobao/arthas/core/util/affect · high confidence
New MCP diagnostic tools for JVM, options, and file operations
This change introduces a suite of new Model Context Protocol (MCP) tools in the core module, enabling AI agents to interact with Arthas diagnostics. The new tools include \options\ for managing global switches, \stop\ to terminate Arthas, \version\ to check the current version, and \upload\_file\ for securely uploading small artifacts (like .class or .java files) with SHA-256 verification. File inspection is handled by \viewfile\, which supports cursor-based pagination and configurable allowed directories. A comprehensive set of JVM diagnostic tools is also added: \dashboard\ and \mbean\ for real-time monitoring with configurable intervals and execution counts, \jvm\, \memory\, \perfcounter\, \sysenv\, and \sysprop\ for runtime information, \thread\ for thread analysis, \heapdump\ for memory dumps, \getstatic\ and \ognl\ for static field and expression evaluation, and \vmtool\ (referenced in commit messages) for class analysis. These tools are built on a new \AbstractArthasTool\ base class that handles authentication context extraction and supports both synchronous and streamable execution modes with configurable timeouts.
core/src/main/java/com/taobao/arthas/core/mcp/tool · high confidence
New annotation-driven configuration binding system
The core configuration module now supports automatic binding of properties to Java objects via the new @Config and @NestedConfig annotations. Users can define configuration classes with standard setters, and the new BinderUtils will automatically resolve and inject values from the environment (e.g., arthas.properties) based on the configured prefix, including support for nested configuration objects. This simplifies the management of complex configuration structures like those in the Configure class.
core/src/main/java/com/taobao/arthas/core/config · high confidence
New arthas-grpc-web-proxy demo application in labs
A new demo application has been added to the labs directory to demonstrate gRPC-Web proxying capabilities. This component includes a bootstrap entry point that starts a gRPC server, a gRPC-Web proxy, and a Netty-based HTTP server serving static web assets. It implements the necessary model classes (such as WatchRequestModel and EnhancerRequestModel) to translate gRPC-Web requests into Arthas commands, handles object serialization via a JavaObjectConverter, and manages the lifecycle of gRPC streams and job execution through a custom observer and process implementation.
labs/arthas-grpc-web-proxy, labs/arthas-grpc-web-proxy/ui · high confidence
New basic utility and security commands added to Arthas
This change introduces a suite of new commands to the core basic1000 package, expanding Arthas's diagnostic and operational capabilities. Users can now authenticate sessions via the new \auth\ command, which supports username/password login and status checking. Several standard Unix-like utilities are now available: \cat\ for displaying file contents, \base64\ for encoding/decoding files with size limits, \echo\ for printing arguments, \pwd\ for the working directory, \cls\ for clearing the screen, and \history\ for viewing or clearing command history. Additionally, \grep\ is added for filtering output in pipes, \help\ provides detailed command documentation, \keymap\ displays terminal key bindings, \options\ allows viewing and changing global settings (including OGNL strict mode), \reset\ reverts class enhancements, \session\ shows current connection and tunnel status, and \stop\ safely shuts down the Arthas server. These commands are implemented as new Java classes in the \basic1000\ package, integrating with the existing shell and session management infrastructure.
core/src/main/java/com/taobao/arthas/core/command/basic1000 · high confidence
New classloader-metaspace command and classloader command enhancements
Added the classloader-metaspace command to show ClassLoader metaspace statistics using JFR, and enhanced the classloader command with new options including --url-classes, --load, --classLoaderClass, and url statistics. Also added the dump command to dump class byte arrays from the JVM, and improved the jad command with --source-only and --lineNumber options.
core/src/main/java/com/taobao/arthas/core/command/klass100 · high confidence
New concurrent utility classes added
Added two new classes to the common concurrent package: ConcurrentWeakKeyHashMap, a thread-safe map implementation that allows keys to be garbage collected, and ReusableIterator, an interface extending Iterator with a rewind capability.
common/src/main/java/com/taobao/arthas/common/concurrent · high confidence
New experimental labs for JFR analysis and gRPC web proxy
The \labs\ directory now contains experimental projects, explicitly marked as not guaranteed for production use. This includes a new JFR (Java Flight Recorder) analysis feature with a Spring Boot 3.5.3 backend for parsing JFR files and generating flame graph data, and a React 18 frontend for visualizing these analyses. Additionally, a gRPC web proxy module has been added, utilizing Netty for forwarding gRPC-web requests.
labs · high confidence
New matcher utility classes for pattern matching
The core matcher utility package now includes several new classes to support different matching strategies: EqualsMatcher for exact string matches, RegexMatcher for regular expression matching with compiled pattern caching, WildcardMatcher for wildcard pattern matching, and GroupMatcher (with And/Or implementations) for combining multiple matchers. Additionally, TrueMatcher and FalseMatcher provide constant match results.
core/src/main/java/com/taobao/arthas/core/util/matcher · high confidence
New reflection utility classes for field access and class scanning
Added ArthasReflectUtils and FieldUtils to the core reflection package. ArthasReflectUtils provides functionality to scan packages for classes from both file systems and JAR archives, while FieldUtils offers safe methods to read and write object fields, including support for force-accessing non-public fields and handling static fields.
core/src/main/java/com/taobao/arthas/core/util/reflect · high confidence
New terminal rendering views for Arthas commands
Added dedicated ResultView implementations for multiple Arthas commands, including Base64, Cat, ClassLoader (with URL and metaspace statistics), Dashboard, DumpClass, Echo, Enhancer, GetStatic, Help, JFR, Jad, Jvm, Line, Logger, MBean, Memory, and MemoryCompiler. These views define how command results are formatted and displayed in the terminal, introducing structured table layouts for complex data like classloader hierarchies, memory usage, and JMX MBean metadata, while providing simple text output for commands like echo and base64.
core/src/main/java/com/taobao/arthas/core/command/view · high confidence
New tunnel server web API endpoints for agent management, HTTP proxying, and statistics
The tunnel server now exposes several new REST API endpoints to enhance agent visibility and connectivity. Users can now retrieve agent details and list agents by application via \/api/tunnelAgents\, \/api/tunnelApps\, and \/api/tunnelAgentInfo\, supporting better cluster management. An HTTP proxy endpoint at \/proxy/{agentId}/\\\ allows forwarding HTTP requests directly to specific Arthas agents, enabling remote interaction through the tunnel. Additionally, a \/api/stat\ endpoint is available for agents to report usage statistics, including optional agent identification. These changes are gated by the \enableDetailPages\ configuration property.
tunnel-server/src/main/java/com/alibaba/arthas/tunnel/server/app/web · high confidence
New utility classes for core operations
Added several new utility classes in the core package to support Arthas functionality: ArrayUtils for primitive array conversion, ArthasBanner for displaying startup information and checking for updates, ArthasCheckUtils for equality and containment checks, ClassLoaderUtils for classloader operations, ClassUtils for class information rendering, CommandUtils for command process handling, Constants for application constants, DateUtils for date formatting, Decompiler for class decompilation with line number mappings, FileUtils for file operations and command history management, HttpUtils for HTTP response handling, IOUtils for stream operations, IPUtils for IP address detection, InstrumentationUtils for class retransformation, and LogUtil for logging operations.
core/src/main/java/com/taobao/arthas/core/util · high confidence
Spring Boot auto-configuration metadata for Arthas starter
The arthas-spring-boot-starter module now includes the necessary Spring Boot metadata files to enable automatic configuration. Specifically, it registers \ArthasConfiguration\ and \ArthasEndPointAutoConfiguration\ via both the legacy \spring.factories\ file and the modern \AutoConfiguration.imports\ file, ensuring compatibility with different Spring Boot versions. Additionally, a \spring.provides\ file declares the module name for module-path support.
arthas-spring-boot-starter/src/main/resources · high confidence
Terminal shell implementation and HTTP session management
This change introduces the core implementation for Arthas's terminal shell, including the \TermImpl\ class that manages readline interactions, command history, and completion. It adds \CompletionAdaptor\ and \CompletionHandler\ to handle command-line completion logic, ensuring proper token processing. A key behavioral addition is the \FunctionInvocationHandler\, which wraps readline functions (specifically history search) to enforce authentication, preventing unauthenticated users from viewing command history. The update also implements \HttpTermServer\ and \TelnetTermServer\ to expose the terminal via HTTP (WebSocket) and Telnet, supported by a new \HttpSessionManager\ and \LRUCache\ to manage HTTP session state and cookies for the web-based terminal.
core/src/main/java/com/taobao/arthas/core/shell/term/impl · high confidence
Tunnel server exposes Spring Boot Actuator endpoint for runtime status
The tunnel server now registers a Spring Boot Actuator endpoint (id 'arthas') that exposes runtime information via the standard actuator interface. Users can query the current Arthas properties, the list of connected agents, and client connection details through this new endpoint, facilitating easier monitoring and integration with Spring Boot actuator-based tooling.
tunnel-server/src/main/java/com/alibaba/arthas/tunnel/server/endpoint · high confidence
Tunnel server now supports in-memory cluster storage
The tunnel server cluster module introduces a new InMemoryClusterStore implementation backed by Caffeine, allowing users to run the tunnel server in a single-node or non-distributed mode without requiring an external Redis instance. This is provided alongside the existing RedisTunnelClusterStore and the new TunnelClusterStore interface, giving users the flexibility to choose between in-memory and Redis-based agent state persistence depending on their deployment topology.
tunnel-server/src/main/java/com/alibaba/arthas/tunnel/server/cluster · high confidence
Unified HTTP and Telnet terminal server on a single port
The terminal server now supports both HTTP (WebSocket) and Telnet connections on the same port. A new \ProtocolDetectHandler\ inspects incoming traffic to distinguish between HTTP requests and Telnet streams, routing them to the appropriate Netty pipeline (WebSocket/HTTP handlers or Telnet channel handler). This allows users to connect to Arthas via either protocol without needing separate ports or configurations.
core/src/main/java/com/taobao/arthas/core/shell/term/impl/httptelnet · high confidence
Architecture
Extract command result models to separate arthas-model module
The command result data models (such as CommandRequestModel, EnhancerModel, SessionModel, and ResultModel) have been moved from the core command package into the new arthas-model module. This refactoring centralizes the data structures used for command execution results, improving modularity and separation of concerns within the Arthas codebase.
arthas-model · high confidence
Behavioural changes
Added internal type-conversion service for environment properties
The core module now includes a new \com.taobao.arthas.core.env.convert\ package that provides a \ConversionService\ implementation (\DefaultConversionService\) and a set of built-in converters. This enables Arthas to automatically convert string-based environment property values into specific Java types, including \Integer\, \Long\, \Boolean\, \InetAddress\, \Enum\, and arrays. This change supports the new \ArthasEnvironment\ feature by allowing configuration values to be parsed and typed correctly during bootstrapping.
core/src/main/java/com/taobao/arthas/core/env/convert · high confidence
Arthas MCP server defaults to STREAMABLE protocol and moves implementation to core module
The Arthas MCP server now defaults to the STREAMABLE protocol instead of the previous default, ensuring more efficient, stateful connections for clients. This change is part of moving the MCP server implementation into the core module, making it a first-class component of the Arthas runtime. The server now supports both STREAMABLE and STATELESS modes, with STREAMABLE being the default, and includes a 15-second keepalive mechanism to maintain connections. Additionally, the server now classifies tools based on their task support requirements (REQUIRED, OPTIONAL, FORBIDDEN), allowing for better handling of long-running tasks and improving overall stability and performance.
core/src/main/java/com/taobao/arthas/core/mcp · high confidence
Arthas Web UI rewritten in Vue 3 with XState and ECharts
The Arthas Web Console UI has been completely rewritten using Vue 3 (Composition API), replacing the previous implementation. This update introduces a new application shell (\App.vue\) with a responsive navigation header (\NavHeader.vue\) and integrated dialog components for errors, success messages, warnings, and user input. The interface now leverages XState for managing complex state transitions in console interactions and session handling, and utilizes ECharts for rendering dashboard visualizations. New input components provide auto-completion for classes and methods, while the overall layout and styling have been modernized.
web-ui/arthasWebConsole/all/ui/ui · high confidence
Arthas client now bundles Apache Commons Net to support pure Java telnet connections
The Arthas client has been refactored to include a bundled copy of the Apache Commons Net library (specifically classes like TelnetClient, SocketClient, and DatagramSocketClient). This change allows the client to operate as a pure Java telnet client without relying on external system-level telnet binaries or native dependencies, ensuring consistent behavior across different operating systems and environments.
client · high confidence
Arthas core command infrastructure restructured and expanded
The core command execution engine has been refactored to support a more modular and extensible architecture. A new BuiltinCommandPack centralizes the registration of built-in commands, explicitly adding support for System Environment (sysenv), VM Options (vmoption), and various classloader/memory diagnostics (classloader-metaspace, heapdump, memory, perfcounter), while also introducing new utility commands like base64, cat, echo, grep, history, mc, pwd, and tee. The command execution flow now includes dedicated session management and authentication handling, allowing for user ID tracking and secure command execution. Additionally, the core now supports the Model Context Protocol (MCP) for external tool integration and provides a standalone line command interface for programmatic access.
core/src/main/java/com/taobao/arthas/core/command · high confidence
ArthasBootstrap refactored to use ArthasEnvironment and new server architecture
The ArthasBootstrap class has been rewritten to initialize the ArthasEnvironment first, allowing configuration properties (such as output path and config location) to be resolved before initializing the logger and enhancing the ClassLoader. It now integrates a new MCP (Model Context Protocol) request handler and uses a dedicated TransformerManager for bytecode transformation, replacing previous inline instrumentation logic.
core/src/main/java/com/taobao/arthas/core/server · high confidence
Improved CLI token parsing for pipe characters
The command-line interface now correctly handles pipe characters ('\|') in user input. Previously, inputs like 'thread\| grep xxx' or 'thread \|grep xxx' were not parsed as distinct tokens. The new implementation splits these cases into separate tokens (e.g., 'thread', '\|', 'grep'), enabling proper execution of piped commands within the Arthas shell.
core/src/main/java/com/taobao/arthas/core/shell/cli/impl · high confidence
Improved SpyAPI class loading via extension classloader
The ClassLoader instrumentation now attempts to load classes prefixed with 'java.arthas.' using the extension classloader (the parent of the system classloader) before falling back to the default loading mechanism. This change addresses issues where the SpyAPI classes could not be loaded in certain environments, ensuring that Arthas' internal instrumentation classes are resolved correctly.
core/src/main/java/com/taobao/arthas/core/server/instrument · high confidence
Initial tunnel server configuration defaults
The tunnel server now ships with a default application.properties file that configures the server to bind to all network interfaces (0.0.0.0) on port 7777. It enables all management endpoints for web exposure, sets the default security username to 'arthas', and disables the tunnel detail pages by default to prevent unauthorized access. Additionally, it configures an in-memory Caffeine cache with a maximum size of 3000 entries and a 3600-second access expiration, while including commented-out settings for an optional embedded Redis instance.
tunnel-server/src/main/resources · high confidence
Introduce new command shell API and registry
The command execution layer has been refactored to use a new, extensible command shell API. This change introduces a \CommandRegistry\ for managing command discovery and registration, a \CommandBuilder\ for constructing commands programmatically, and an \AnnotatedCommand\ base class for defining commands via Java annotations. It also adds a \CommandProcess\ interface to handle command lifecycle events (such as stdin, interrupts, and backgrounding) and an \ExitStatus\ class to standardize command completion codes. These components replace the previous command handling mechanism, providing a more structured way to define, register, and execute shell commands.
core/src/main/java/com/taobao/arthas/core/shell/command · high confidence
Introduces dedicated Arthas classloader and binding thread for agent startup
The agent now uses a custom ArthasClassloader to isolate Arthas classes from the application's classpath, preventing conflicts with system classes (java.\, sun.\) and avoiding duplicate initializations. Additionally, the agent startup logic has been updated to run the server binding logic in a dedicated daemon thread named 'arthas-binding-thread', which helps prevent potential memory leaks and ensures the agent initializes cleanly without blocking the main JVM thread.
agent · high confidence
Introduces new Advice-based instrumentation architecture
The core instrumentation engine has been refactored to use a new listener-based model. This change introduces the Advice, AdviceListener, and AdviceListenerManager classes, which replace the previous mechanism for managing method interception. Users will benefit from more robust listener lifecycle management, including automatic cleanup of terminated processes, and support for finer-grained tracing via line numbers and invocation tracking through the new SpyAPI integration.
core/src/main/java/com/taobao/arthas/core/advisor · high confidence
MCP tool output now defaults to ObjectView format with safe serialization
The MCP module now uses the ObjectView format by default for tool outputs, replacing the previous JSON-format approach. This change includes a new McpObjectVOFilter that serializes ObjectVO instances using ObjectView's structure, ensuring consistent and readable output. Additionally, the filter prevents JSON-format output from invoking constructors during serialization, addressing a potential side-effect issue in object inspection.
core/src/main/java/com/taobao/arthas/core/mcp/util · high confidence
New CLI tokenization and completion infrastructure
The CLI shell layer now uses a new tokenization model (CliToken/CliTokens) and a dedicated completion interface (Completion) to handle command-line input. This introduces structured auto-completion for command options (via OptionCompleteHandler and CompletionUtils), file paths, and class names, replacing the previous ad-hoc parsing logic with a more robust, session-aware completion system.
core/src/main/java/com/taobao/arthas/core/shell/cli · high confidence
New Netty-based gRPC server implementation in labs/arthas-grpc-server
The gRPC server module has been rewritten to use Netty instead of the previous implementation, introducing a new bootstrap entry point (ArthasGrpcBootstrap) and a core server class (ArthasGrpcServer) that listens on port 9091. This change adds support for all four gRPC invocation types—unary, client streaming, server streaming, and bidirectional streaming—via a new handler pipeline (Http2Handler, GrpcDispatcher) and a pluggable executor factory (GrpcExecutorFactory with UnaryExecutor, ClientStreamExecutor, ServerStreamExecutor, and BiStreamExecutor). A sample service (ArthasSampleServiceImpl) and corresponding protobuf definitions (arthasGrpc.proto) are included to demonstrate these capabilities.
labs/arthas-grpc-server · high confidence
New authentication mechanisms and local connection bypass
The core security module now supports Bearer Token authentication for MCP requests, allowing clients to authenticate using a token instead of basic credentials. Additionally, a new configuration option \arthas.localConnectionNonAuth\ enables automatic authentication for local connections (127.0.0.1), simplifying setup for localhost usage. These changes are implemented via new \BearerPrincipal\, \LocalConnectionPrincipal\, and updated \SecurityAuthenticatorImpl\ logic.
core/src/main/java/com/taobao/arthas/core/security · high confidence
New default configuration and logging setup for Arthas core
This change introduces default configuration files for the Arthas core module. The new arthas.properties file sets default network ports (telnet 3658, HTTP 8563), configures a 3-hour session timeout, enables non-authenticated local connections by default, and sets the Model Context Protocol (MCP) to use the STREAMABLE protocol on the /mcp endpoint. Additionally, a new logback.xml file establishes a structured logging configuration that writes main logs to arthas.log and command results to result.log, with rolling policies to manage file sizes and history.
core/src/main/java · high confidence
New global options and cross-namespace attach support in Arthas core
The Arthas core module now includes a new \Arthas.java\ entry point that supports attaching to Java processes across different mount namespaces (useful for Kubernetes ephemeral debug containers) by exposing the attach socket via symlinks. Additionally, \GlobalOptions.java\ introduces several new global configuration switches: \object-size-limit\ to cap ObjectView output size, \strict\ mode to restrict OGNL property setting by default, \print-parent-fields\ to control inheritance field display, \support-default-method\ for interface method matching, and \verbose\ for detailed logging. The \Option.java\ annotation is also added to define these global settings.
core/src/main/java/com/taobao/arthas/core · high confidence
Refactored HTTP terminal server with dedicated authentication and local address support
The HTTP terminal implementation in the core shell has been restructured to improve security and connectivity. A new BasicHttpAuthenticatorHandler now explicitly manages HTTP Basic and Bearer token authentication, handling 401 responses and session state before requests reach the main handler. The server bootstrap now supports listening on a Netty LocalAddress for intra-VM communication, allowing tunnel clients to connect via local sockets. Additionally, the WebSocket handler now supports a 'quiet' mode via URL parameters to suppress output, and idle connections are maintained using WebSocket ping frames.
core/src/main/java/com/taobao/arthas/core/shell/term/impl/http · high confidence
Refactored OGNL expression engine with strict mode and thread-local safety
The expression evaluation subsystem in core/src/main/java/com/taobao/arthas/core/command/express has been restructured to improve stability and security. A new ArthasObjectPropertyAccessor enforces strict mode (via GlobalOptions.strict) by blocking property writes that would otherwise succeed, preventing unintended state mutations. Thread-local memory leaks are mitigated in ExpressFactory by storing Express instances in WeakReferences, ensuring the ArthasClassLoader can be garbage collected after detachment. Additionally, new resolvers (ClassLoaderClassResolver, CustomClassResolver) and a configurable DefaultMemberAccess class provide finer control over class loading and private/protected member access during expression evaluation.
core/src/main/java/com/taobao/arthas/core/command/express · high confidence
Refactored Web UI into Native Agent and Tunnel entry points
The web console UI has been restructured to support distinct deployment modes. A new 'native-agent' entry point provides standalone HTML pages and TypeScript entry points for direct local connections, while the 'tunnel' directory now contains dedicated HTML pages and Vue components (Agent.vue, Apps.vue) for managing remote agents via the tunnel server. The shared Console.vue component has been updated to accept isTunnel and isNativeAgent props to handle connection logic for both modes, and the previous generic 'ui' entry point has been replaced by these specific implementations.
web-ui/arthasWebConsole/all · high confidence
Refactored result distribution to support concurrent HTTP and Telnet consumers
The core result distribution mechanism has been restructured to allow command outputs to be delivered simultaneously to multiple clients, such as a terminal session and an HTTP API consumer. This is achieved by introducing a new \SharingResultDistributor\ that manages a pool of \ResultConsumer\ instances, ensuring that results are buffered and dispatched to all active listeners without blocking the executing command. The previous single-target distribution model is replaced by this multi-consumer architecture, which includes health checks to automatically interrupt commands if all consumers become unhealthy, thereby preventing resource leaks and output interleaving issues.
core/src/main/java/com/taobao/arthas/core/distribution/impl · high confidence
Structured result models for Arthas commands
The command model layer now uses dedicated, structured result classes (extending ResultModel) for commands such as classloader, dashboard, dump, getstatic, jad, jvm, logger, and others. This replaces ad-hoc or text-based output with typed data, enabling consistent serialization (including for HTTP APIs) and richer client-side rendering. The models also carry command metadata (options, arguments) and support features like classloader filtering by class name, URL statistics, and line-mapping for decompiled sources.
core/src/main/java/com/taobao/arthas/core/command/model · high confidence
Styled command help output with bold formatting
The command help display now uses a new \StyledUsageFormatter\ to render usage information with enhanced visual structure. Users will see help text organized into clearly defined sections (USAGE, SUMMARY, OPTIONS) where section headers and option names are rendered in bold green, improving readability compared to the previous plain-text format.
core/src/main/java/com/taobao/arthas/core/util/usage · high confidence
Support pressing Q to exit interactive commands
Users can now press the Q key to exit interactive commands such as dashboard, watch, monitor, tt, stack, and trace. This change introduces a new QExitHandler in the shell handler layer that detects the 'q' input and terminates the current command process, providing a quicker way to stop long-running diagnostic sessions without needing to wait for them to complete or using other exit methods.
core/src/main/java/com/taobao/arthas/core/shell/handlers/shell · high confidence
Tunnel server configuration and cluster store support
The tunnel server now supports configurable cluster storage backends, allowing it to use either an in-memory cache (Caffeine) or Redis for managing agent cluster information. This is enabled via new configuration properties under the 'arthas' prefix, including settings for embedded Redis (host, port, and settings) and server details (host, port, SSL, path). The server also exposes options to enable detail pages for apps/agents and controls iframe support via the 'enableIframeSupport' property, which defaults to true.
tunnel-server/src/main/java/com/alibaba/arthas/tunnel/server/app/configuration · high confidence
Tunnel server introduces Spring Boot application entry point and configurable iframe support
The tunnel server now includes a dedicated Spring Boot application class (ArthasTunnelApplication) that enables caching and scans both the app and endpoint packages. Additionally, a new web security configuration allows iframe embedding by default; this behavior is controlled by the enableIframeSupport property, which disables the X-Frame-Options header when enabled to permit iframing.
tunnel-server/src/main/java/com/alibaba/arthas/tunnel/server/app · high confidence
Test coverage
Added integration test for ArthasClassLoader leak detection; Added integration tests for Arthas MCP tools and task capabilities; Added integration tests for Spring Boot 3 support; Added integration tests for VmTool native methods; Added integration tests for external command loading; Added test case files for Arthas Pojo and Test scenarios; Added unit tests for Bootstrap CLI and DownloadUtils; Added unit tests for StringUtils key normalization; Added unit tests for core Arthas components; Added unit tests for tunnel server URI handling, application context, and HTTP utilities.
Dependencies
New Maven modules for agent attachment, Spring Boot integration, and Model Context Protocol
This change introduces several new Maven modules to the Arthas build. The \arthas-agent\ and \arthas-agent-attach\ modules provide the core Java agent and a library for attaching it to running JVMs using ByteBuddy. The \arthas-spring-boot-starter\ module adds Spring Boot 2 and 3 support, including integration tests for both versions. Additionally, the \arthas-mcp-server\ and \arthas-mcp-integration-test\ modules implement the Model Context Protocol (MCP) base protocol using Netty and Jackson, while \arthas-demo-external-command\ and \arthas-external-command-integration-test\ support loading external commands from startup JARs.
(dependencies) · high confidence
Updated Async Profiler Java API to version 4.4
The in-process profiling API in the \one.profiler\ package has been upgraded to Async Profiler version 4.4. This update refreshes the Java wrapper classes (including \AsyncProfiler\, \AsyncProfilerMXBean\, \Events\, and \Counter\) to align with the latest native library capabilities, ensuring compatibility with the newest profiling features and performance improvements provided by the underlying engine.
core/src/main/java/one · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 49 → 49 (+0.1)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 67 → 72 (+5.4)
- Architecture 93 → 79 (-13.8)
- Maturity 75 → 74 (-0.9)
- Readiness 52 → 50 (-2.1)
- Security 44 → 52 (+7.2)
- Accessibility 44 → 41 (-2.7)
Resolved (299)
- ArthasMcpJavaSdkIT.createArgumentsForTool (cognitive 24) (arthas-mcp-integration-test/src/test/java/com/taobao/arthas/mcp/it/ArthasMcpJavaSdkIT.java)
- ArthasMcpJavaSdkIT.createArgumentsForTool (cyclomatic 25) (arthas-mcp-integration-test/src/test/java/com/taobao/arthas/mcp/it/ArthasMcpJavaSdkIT.java)
- CPUTimeExtractor.buildThreadCPUTime (cognitive 29) (labs/arthas-jfr-backend/src/main/java/org/example/jfranalyzerbackend/extractor/CPUTimeExtractor.java)
- Change coupling: en.js ↔ zh.js (site/docs/.vuepress/configs/sidebar/en.js)
- Change coupling: zh.js ↔ zh.js (site/docs/.vuepress/configs/navbar/zh.js)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (labs/arthas-grpc-web-proxy/ui/package-lock.json)
- Critical CVE: [GHSA redacted] (labs/arthas-jfr-frontend/package-lock.json)
- Critical CVE: [GHSA redacted] (web-ui/arthasWebConsole/yarn.lock)
- Critical CVE: [GHSA redacted] (labs/arthas-grpc-web-proxy/ui/package-lock.json)
- Critical CVE: [GHSA redacted] (labs/arthas-grpc-web-proxy/ui/package-lock.json)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (arthas-mcp-server/src/main/java/com/taobao/arthas/mcp/server/protocol/server/handler/McpStreamableHttpRequestHandler.java)
- Duplicated block (10 lines × 2) (arthas-mcp-server/src/main/java/com/taobao/arthas/mcp/server/task/DefaultTaskManager.java)
- Duplicated block (10 lines × 2) (arthas-mcp-server/src/main/java/com/taobao/arthas/mcp/server/util/McpAuthExtractor.java)
- Duplicated block (10 lines × 2) (arthas-mcp-server/src/main/java/com/taobao/arthas/mcp/server/util/McpAuthExtractor.java)
- Duplicated block (10 lines × 2) (boot/src/main/java/com/taobao/arthas/boot/ProcessUtils.java)
- Duplicated block (10 lines × 2) (boot/src/main/java/com/taobao/arthas/boot/ProcessUtils.java)
- Duplicated block (10 lines × 2) (core/src/main/java/com/taobao/arthas/core/advisor/AdviceListenerManager.java)
- Duplicated block (10 lines × 2) (core/src/main/java/com/taobao/arthas/core/advisor/SpyImpl.java)
- …and 279 more
New (562)
- Analysis.Analysis (cognitive 239) (labs/arthas-jfr-frontend/src/pages/Analysis/Analysis.tsx)
- Analysis.Analysis (cyclomatic 180) (labs/arthas-jfr-frontend/src/pages/Analysis/Analysis.tsx)
- Arthas.attachAgent (cyclomatic 16) (core/src/main/java/com/taobao/arthas/core/Arthas.java)
- ClassTooLong: Analysis (labs/arthas-jfr-frontend/src/pages/Analysis/Analysis.tsx)
- ClassTooLong: Ansi (core/src/main/java/com/taobao/arthas/core/view/Ansi.java)
- ClassTooLong: ArthasBootstrap (core/src/main/java/com/taobao/arthas/core/server/ArthasBootstrap.java)
- ClassTooLong: Bootstrap (boot/src/main/java/com/taobao/arthas/boot/Bootstrap.java)
- ClassTooLong: ClassLoaderCommand (core/src/main/java/com/taobao/arthas/core/command/klass100/ClassLoaderCommand.java)
- ClassTooLong: ClassLoaderMetaspaceCommand (core/src/main/java/com/taobao/arthas/core/command/klass100/ClassLoaderMetaspaceCommand.java)
- ClassTooLong: DefaultTaskManager (arthas-mcp-server/src/main/java/com/taobao/arthas/mcp/server/task/DefaultTaskManager.java)
- ClassTooLong: FlameGraph (labs/arthas-jfr-frontend/public/flame-graph/flame-graph-class.js)
- ClassTooLong: FlameGraph (labs/arthas-jfr-frontend/src/components/FlameGraph/flame-graph-class.js)
- ClassTooLong: McpStreamableHttpRequestHandler (arthas-mcp-server/src/main/java/com/taobao/arthas/mcp/server/protocol/server/handler/McpStreamableHttpRequestHandler.java)
- ClassTooLong: ObjectUtils (core/src/main/java/com/taobao/arthas/core/util/ObjectUtils.java)
- ClassTooLong: ObjectView (core/src/main/java/com/taobao/arthas/core/view/ObjectView.java)
- ClassTooLong: ProcessImpl (core/src/main/java/com/taobao/arthas/core/shell/system/impl/ProcessImpl.java)
- ClassTooLong: StringUtils (core/src/main/java/com/taobao/arthas/core/util/StringUtils.java)
- ClassTooLong: Telnet (client/src/main/java/org/apache/commons/net/telnet/Telnet.java)
- CompletionUtils.completeMethodName (cognitive 24) (core/src/main/java/com/taobao/arthas/core/shell/cli/CompletionUtils.java)
- CompletionUtils.completeMethodName (cyclomatic 17) (core/src/main/java/com/taobao/arthas/core/shell/cli/CompletionUtils.java)
- …and 542 more
Changes since last survey
- 12 commits — 10 feature/other, 2 fixes
By area
- (root) — 4 commits
- core/src — 4 commits
- site/docs — 4 commits
Notable commits
- fix: fix(jfr): treat unitless time values as seconds (#3265)
- fix: fix: upgrade fastjson2 to 2.0.64 (#3261)
- change: Prettified Code!
- change: chore: remove unavailable online tutorial references (#3263)
- change: docs: add complex OGNL expression guide (#3262)
- change: docs: document Kubernetes cross-container attach
- change: feat(mcp): add upload_file tool (#3258)
- change: feat: log cross-namespace attach success (#3259)
- change: feat: support attach across mount namespace for k8s ephemeral debug container (#3247)
- change: release 4.3.3
- change: release 4.3.4
- change: release 4.3.5
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
alibaba/arthas was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 141a349a150b4ee0fed986672581e556b6e2b3ca — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.