Skip to content
CAI
Software that uses CAICheck a score

dart-lang/pub

58.9

Weak · 19 September 2026

31.7k

lines of production code

Dart

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is the \pub\ package manager for the Dart ecosystem, responsible for resolving, downloading, and managing software dependencies. It provides a command-line interface and embeddable API for operations such as adding, upgrading, and removing packages from hosted registries, Git repositories, or local paths. The tool also handles global executable activation, package publishing with quality validation, and comprehensive cache management.

How it got here

2012–2015 — pub tool foundation and solver rewrite

28 changes.

This period established the core infrastructure for the pub package manager, featuring a complete rewrite of the dependency resolution engine to improve error reporting and support for complex constraints. It introduced essential command-line utilities such as version bumping, cache management, and global activation, alongside comprehensive validation checks for package publishing. The work was heavily supported by the creation of a robust test suite and project scaffolding to ensure reliability across hosted, Git, and path dependency sources.

2017–2020 — Embeddable pub API and test expansion

11 changes.

This period focused on establishing a stable public API for embedding the pub tool, enabling external programs to programmatically manage package resolution. Significant effort was also dedicated to expanding test coverage, particularly for the new \pub add\ command, SDK-vendored package support, and the embedding infrastructure itself.

2021–2026 — Authentication and test coverage expansion

5 changes.

This period focused on implementing third-party registry authentication via a new token configuration system and significantly expanding test coverage. Comprehensive tests were added for token management, dependency services, and command override logic to ensure robust handling of credentials and package resolution.

Features

Add ASCII tree rendering utility for file listings

A new \ascii\_tree.dart\ library has been added to \lib/src\ to render file hierarchies as text trees. It supports Unicode branch symbols with an ASCII fallback, and can optionally display file sizes by stat-ing each file. This utility is intended for use in command-line output to visualize directory structures.

lib/src · high confidence

Introduce standalone entry points for pub and dependency services

The repository now includes dedicated executable scripts in the bin directory: bin/pub.dart serves as the main entry point for the pub package manager, and bin/dependency\_services.dart provides a separate command-line interface for automated upgrade operations (listing, reporting, and applying dependency changes). This change establishes the concrete execution boundaries for these tools, allowing them to be invoked directly as standalone binaries rather than relying on internal library calls.

bin · high confidence

New \`dart pub bump\` command to update package versions

A new \bump\ subcommand has been added to \dart pub\, allowing users to increment the version number in their \pubspec.yaml\ file. It supports subcommands for \major\, \minor\, \patch\, and \breaking\ version increments, and includes a \--dry-run\ flag to preview changes without modifying the file.

lib/src/command · high confidence

New public API for embedding pub and resolving packages

The \lib/pub.dart\ file introduces a new public entrypoint for embedding the pub tool and programmatically managing package resolution. It exports the \pubCommand\ function, allowing embedders to integrate pub as a subcommand with customizable options like verbosity, file system, and HTTP client. It also provides \ensurePubspecResolved\, a function that ensures a project's dependencies are downloaded and up-to-date, throwing a \ResolutionFailedException\ if resolution fails. Additionally, \getPackageNameFromGitRepo\ is exposed to retrieve package names from Git repositories. This change establishes a stable interface for external tools to interact with pub's core functionality.

lib · high confidence

New repository tagging and extraction utilities added to the tool directory

The tool directory now includes three new Dart scripts: \create\_version\_tags\_from\_sdk.dart\ automates the creation and optional pushing of \SDK-\<version\>\ git tags by syncing with the Dart SDK repository's tags; \extract\_all\_pub\_dev.dart\ provides a resumable, parallelized utility to download and extract all version archives for every package on pub.dev, saving progress to a status file; and \test.dart\ serves as a test wrapper that precompiles the \pub\ executable into a snapshot to speed up integration tests before forwarding arguments to the test runner.

tool · high confidence

New validation checks for publishing packages

The \pub publish\ command now runs a comprehensive suite of validators to check package quality before upload. This includes verifying that \dart analyze\ passes on \lib/\, \bin/\, and specific build scripts; ensuring a \CHANGELOG.md\ exists and mentions the current version; confirming a \LICENSE\ file is present; and validating that the package name is a valid Dart identifier. It also checks for common pubspec issues like typos in keys, missing required fields (description, version), and invalid URLs for homepage or repository. Additional checks warn against using deprecated pubspec fields (like \transformers\ or \author\), detect potential secret leaks in source files, ensure no gitignored files are checked in, and validate Flutter plugin formats and SDK constraints.

lib/src/validator · high confidence

Project initialization and configuration scaffolding

The repository has been initialized with essential project configuration files, including a BSD-style LICENSE, a CONTRIBUTING guide requiring a Google CLA, and a README detailing how to run and test the pub tool. Development workflows are now supported by an analysis\_options.yaml file enforcing the dart\_flutter\_team\_lints package with strict language modes, a dart\_test.yaml for configuring test platforms and CI presets, and a .gitignore to exclude build artifacts and IDE settings.

(repo-wide) · high confidence

Support for SDK-vendored packages via sdk\_packages.yaml

The SDK detection logic in lib/src/sdk now supports resolving packages that are vendored directly within an SDK distribution. A new sdk\_package\_config.dart file introduces parsing for the sdk\_packages.yaml format, allowing the Dart SDK to read a configuration of bundled packages. The DartSdk class uses this to locate its own packages, while the FlutterSdk and FuchsiaSdk classes have been updated to respect this mechanism (with Flutter also maintaining backward compatibility with its legacy package locations). This enables tools like pub to correctly resolve dependencies for packages shipped inside the SDK itself.

lib/src/sdk · high confidence

Support for third-party hosted registry authentication

Users can now authenticate with third-party pub registries by storing credentials in a \pub-tokens.json\ configuration file. The system supports two credential types: direct bearer tokens and environment variable references, allowing flexible integration with external package sources while automatically removing invalid tokens upon 401/403 responses.

lib/src/authentication · high confidence

Behavioural changes

Refactored package source architecture with new base classes and dedicated source implementations

The package resolution system has been restructured to improve modularity and caching behavior. A new \CachedSource\ base class has been introduced to handle common logic for sources that install packages into the system cache, such as \GitSource\ and \HostedSource\, which now inherit from it. \GitSource\ has been updated to support Git LFS, relative paths within git repositories, and tag patterns. \HostedSource\ now normalizes URLs (redirecting \pub.dartlang.org\ to \pub.dev\) and validates hosted URLs more strictly. New dedicated sources have been added: \SdkSource\ for packages vendored in the Dart SDK, \RootSource\ to represent the root package of the dependency graph, and \UnknownSource\ to handle unrecognized dependency types gracefully. The \PathSource\ has been refined to better handle relative paths and resolve dependencies from within git contexts.

lib/src/source · high confidence

Rewritten version solver with improved error reporting and backtracking

The dependency resolution engine in \lib/src/solver\ has been completely rewritten to use a backtracking algorithm, replacing the previous approach. This change introduces new internal structures such as \Assignment\, \PartialSolution\, and \Incompatibility\ to track solver state and conflict causes. For users, this results in significantly more detailed and human-readable error messages when version solving fails, including specific hints for SDK mismatches and missing packages. The solver also now supports features like dependency overrides, workspace resolution, and better handling of retracted or discontinued packages, while providing more precise suggestions for resolving conflicts.

lib/src/solver · high confidence

Test coverage

Added comprehensive tests for pub global activate; Added embedding integration tests; Added golden test data for dependency\_services; Added golden tests for \pub outdated\ command; Added integration tests for \pub run\ behavior; Added test coverage for the \pub add\ command; Added tests for Git package upgrade behavior; Added tests for OAuth2 credential lifecycle and logout; Added tests for \pub add\ with path dependencies; Added tests for adding packages from Git repositories; Added tests for adding packages from non-default hosted servers; Added tests for dependency\_services commands; Added tests for global binstub behavior; Added tests for hosted package resolution and advisory handling; Added tests for hosted package resolution and error handling; Added tests for new and existing pub commands and behaviors; Added tests for new pub cache management commands; Added tests for path dependency resolution and symlink handling; Added tests for pub cache repair behavior; Added tests for pub command overrides and resolution logic; Added tests for pub get behavior and edge cases; Added tests for pub publish validators; Added tests for pub upgrade flags and behaviors; Added tests for pub upgrade reporting details; Added tests for the \pub cache add\ command; Added tests for the pub deps --executables command; Added tests for the pub global list command; Added tests for token management and authentication; Expanded test coverage for Git dependency resolution and caching; Expanded test coverage for package publishing and archiving; New test descriptors for Git, symlinks, package config, tar, and YAML; New test harness for embedding and testing pub commands.

Dependencies

Initial dependency lock and manifest setup

The project now includes a \pubspec.yaml\ and a generated \pubspec.lock\ file, establishing the dependency graph for the \pub\ tool. This sets the SDK constraint to \^3.7.0\ and pins direct dependencies such as \analyzer\ (10.2.0), \args\ (2.7.0), \http\ (1.6.0), and \test\ (1.31.0), ensuring reproducible builds for the package.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 59.

Lenses

  • Code Health 79
  • Architecture 90
  • Maturity 65
  • Readiness 43
  • Security 71
  • Domain Modelling 100

Changes since last survey

  • 300 commits — 265 feature/other, 35 fixes

By area

  • lib/src — 159 commits
  • (root) — 54 commits
  • .github/workflows — 23 commits
  • test/testdata — 10 commits
  • (repo) — 9 commits
  • test/global — 5 commits
  • test/get — 4 commits
  • test/lish — 4 commits
  • test/workspace_test.dart — 4 commits
  • lib/pub.dart — 3 commits
  • test/embedding — 3 commits
  • tool/create_version_tags_from_sdk.dart — 3 commits
  • .github/ISSUE_TEMPLATE — 2 commits
  • .github/dependabot.yml — 2 commits
  • doc/repository-spec-v2.md — 2 commits
  • test/add — 1 commit
  • test/cache — 1 commit
  • test/check_resolution_up_to_date_test.dart — 1 commit
  • test/descriptor — 1 commit
  • test/descriptor.dart — 1 commit

Notable commits

  • fix: Dependency services Fix applying when only a single pubspec has dependency (#4338)
  • fix: Fix Zizmor findings (#4900)
  • fix: Fix _refreshBinStubs (#4189)
  • fix: Fix pub deps behavior (#4397)
  • fix: Fix add package with offline flag (#4395)
  • fix: Fix bug in ensureUpToDate fast path, when following workspaceRef (#4276)
  • fix: Fix calculation of padding in windows binstubs (#4188)
  • fix: Fix compilation of global path activated packages (#4541)
  • fix: Fix dependency_overrides validator in workspaces (#4564)
  • fix: Fix deprecations (#4309)
  • fix: Fix detection of root packages in PackageGraph.transitiveDependencies (#4620)
  • fix: Fix fast path check of ensureUpToDate (#4271)
  • fix: Fix flutter version update on fast path (#4272)
  • fix: Fix handling of directories in archives (#4306)
  • fix: Fix handling of ignore patterns ending in * (#4552)
  • fix: Fix ordering of listed files in test. (#4321)
  • fix: Fix package name when refreshing binstubs (#4205)
  • fix: Fix package name when refreshing binstubs (#4205)
  • fix: Fix parsing of sdk constraints from lockfile (#4726)
  • fix: Fix path-activated packages not picking up source changes (#4748)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

dart-lang/pub was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit a9ed06f7fb180b39b950aec878d4aa0911b7675e — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.