DioxusLabs/blitz
74.0
Strong · 30 September 2026
50.9k
lines of production code
Rust
primary language
2
measurements over time
What this system is
Blitz is a Rust-based web rendering engine that parses HTML and CSS to construct a DOM, compute layout, and paint visual content. It provides a modular architecture with separate crates for networking, accessibility, and JavaScript execution, while offering a Dioxus integration layer for building native applications. The system supports multiple platforms including Android, desktop, and WebAssembly, and includes a headless test harness for validating layout and accessibility compliance.
How it got here
2023–2024 — Blitz rebrand and architectural overhaul
19 changes.
The project was rebranded to Blitz and underwent a significant architectural restructuring, replacing the initial rendering engine with a modular system built on Dioxus 0.7 and the Stylo CSS engine. This period focused on establishing a robust, multi-crate foundation with dedicated modules for layout, networking, and shell integration, while removing legacy code to support a cleaner, more maintainable codebase.
2025 — Browser UI and rendering infrastructure
15 changes.
This period focused on building the Blitz browser application with a complete tabbed UI, history persistence, and initial Android support. Concurrently, the underlying rendering engine was significantly expanded through the new blitz-paint crate, which introduced robust CSS layout, border, and background rendering capabilities. The work also included architectural improvements to the DOM structure and the introduction of a WPT test runner to validate compliance.
2026 — Cross-platform expansion and testing infrastructure
6 changes.
This period focused on extending the engine's reach by introducing a cross-platform AccessKit adapter and adding WebAssembly support to example applications. Significant effort was also directed toward robustness, with the creation of a headless test harness, a comprehensive integration test suite, and initial JavaScript engine integration for document execution.
Features
Add Pulldown-Cmark Markdown Backend
The readme application now includes a new rendering backend using the \pulldown\_cmark\ library, alongside the existing \comrak\ implementation. This addition allows the system to process Markdown content (including strikethrough, tables, task lists, footnotes, and GFM features) via an alternative parser, providing flexibility in how readme content is converted to HTML.
apps/readme/src/markdown · high confidence
Add Seven GUIs benchmark example with WASM support
The \examples/seven\_guis\ directory now provides a complete implementation of the Seven GUIs benchmark suite, featuring seven distinct tasks: Counter, Temperature Converter, Flight Booker, Timer, CRUD, Circle Drawer, and Cells. The example includes a unified navigation shell and is configured to run on WebAssembly via \dioxus\_native::launch\_cfg\, including a custom font context for proper text rendering in the browser.
_examples/seven\guis · high confidence
Add WGPU texture rendering example with custom widget integration
The \examples/wgpu\_texture\ directory now contains a complete demo that renders a WGPU-based spinning cube using a custom widget. The example supports two rendering backends: a Dioxus Native implementation (\dioxus\_native.rs\) and a Blitz HTML implementation (\html.rs\), selectable via the \--html\ command-line flag. It demonstrates integrating raw WGPU shaders (\shader.wgsl\) into the UI layer, allowing the custom GPU content to be composited beneath and blended with standard HTML/Dioxus UI elements.
_examples/wgpu\texture · high confidence
Add default user-agent stylesheet for HTML elements
Introduces a comprehensive default CSS stylesheet (default.css) for the Blitz DOM engine, providing standard browser-like styling for form controls (inputs, buttons, checkboxes, radio buttons, file inputs), links, popovers, and bidirectional text attributes. This ensures that HTML elements render with expected visual defaults such as borders, padding, fonts, and layout behaviors without requiring custom stylesheets.
packages/blitz-dom/assets · high confidence
Browser UI assets and on-disk history persistence
This change introduces the static assets and persistence layer for the browser application. It adds the HTML and CSS files that define the visual structure and styling for the new tab page, history view, error pages, and the main browser frame (including tabs and URL bar). It also includes the SVG icons and logo assets used in the interface. Additionally, it implements the \HistoryStore\ in Rust, which provides on-disk persistence for browsing history using SQLite, allowing users to view and clear their history with associated favicons.
apps/browser/assets · high confidence
Counter example now supports Android and desktop platforms
The counter example has been updated to run on Android in addition to desktop environments. The application logic remains the same, but the entry points have been split: \main.rs\ now launches the app on desktop (with a Windows subsystem tweak to hide the console), while \lib.rs\ provides the \android\_main\ entry point for Android builds. This allows users to run the example via \cargo run\ on desktop or \cargo apk run\ on Android.
examples/counter · high confidence
HTTP caching and cookie support for Blitz networking
The blitz-net package now implements the NetProvider trait with support for HTTP caching and cookies. When the 'cache' feature is enabled, it uses a private cache mode to avoid rate-limiting issues on CDNs serving images with Set-Cookie headers, and stores cache data in a platform-appropriate directory (handling iOS sandboxing constraints). The 'cookies' feature enables cookie storage in the underlying HTTP client. It also sets a specific Firefox User-Agent string and enforces a per-host concurrency limit of 6 requests to mimic browser behavior.
packages/blitz-net · high confidence
Initial Android support for the Blitz browser app
The Blitz browser application now supports Android devices. This change introduces the necessary Android-specific configuration in Dioxus.toml, including the app identifier and icon assets, and adds a MainActivity.kt file to handle the native activity lifecycle and surface view initialization required for rendering on Android.
apps/browser · high confidence
Initial JavaScript engine integration for document execution and DOM scripting
This change introduces the \blitz-vibey-script\ crate, enabling JavaScript execution within Blitz documents. It provides a \ScriptDocument\ that parses and runs \\<script\>\ tags (including ES modules), exposes a full JavaScript DOM API (Document, Element, Node, Event prototypes) backed by the internal DOM, and implements a virtual clock to drive timers and \Date\ consistently with test runners. The entry point wires up the JS runtime, event dispatching, and DOM bindings so that scripts can interact with the page structure and events.
packages/blitz-vibey-script · high confidence
Initial release of the Dioxus Native DOM renderer
This change introduces the \dioxus-native-dom\ crate, providing a headless native renderer that bridges Dioxus's Virtual DOM with the Blitz DOM engine. It establishes the core integration layer by defining \DioxusDocument\ for managing the document lifecycle and \MutationWriter\ for translating Dioxus mutations into Blitz DOM operations. The implementation includes a \NativeConverter\ to map Blitz UI events (such as keyboard, pointer, scroll, and touch events) into Dioxus-compatible data structures, and adds support for custom widgets and sub-documents via new attribute types.
packages/dioxus-native-dom · high confidence
Initial split of the blitz-paint rendering crate
The \blitz-paint\ crate is introduced as a standalone module responsible for painting a \blitz\_dom::BaseDocument\ into an \anyrender::PaintScene\. This new location provides the core rendering infrastructure, including color conversion utilities, CSS filter and gradient support, layer management, and specialized modules for text, borders, backgrounds, and form controls. It also adds a debug overlay for visualizing layout boxes and supports custom widget rendering, effectively separating the painting logic from the rest of the Blitz engine.
packages/blitz-paint/src · high confidence
Introduce Blitz Browser UI with tabbed browsing, history, and mobile support
The browser application now features a complete user interface built on Dioxus Native, supporting multiple tabs, a URL bar with DuckDuckGo search fallback, and a history page. Users can navigate back and forward, view browsing history with relative timestamps, and use hardware back buttons on Android. The UI includes mobile-specific styling and safe-area padding, an FPS overlay for performance monitoring, and screenshot capture capabilities. Favicon loading is optimized with caching and background probing to avoid blocking page loads.
apps/browser/src · high confidence
Introduce BlitzShell as a dedicated windowing and event-loop layer
The \blitz-shell\ package has been split out from \dioxus-native\ to provide a standalone, platform-agnostic shell for managing windows, the event loop, and system integration. This change introduces a new \BlitzApplication\ that implements \winit::ApplicationHandler\ to coordinate window lifecycle events (creation, suspension, resumption, and closure) and routes internal \BlitzShellEvent\ messages (such as redraw requests and accessibility updates) through a \BlitzShellProxy\. It adds a \BlitzShellProvider\ that implements the \ShellProvider\ trait, exposing concrete capabilities for cursor management, IME handling, window decoration, and clipboard access (behind feature flags). The module also includes comprehensive event conversion logic to map \winit\ inputs into \blitz-traits\ events and handles platform-specific details like WASM resize debouncing and iOS redraw timing.
packages/blitz-shell · high confidence
Introduce the Readme application for viewing local and remote Markdown files
A new standalone application has been added to render README files from local paths or URLs. It supports both local file system access and network fetching (with automatic HTTPS fallback for bare hostnames), and automatically detects Markdown files to convert them into HTML using either the Comrak or Pulldown-cmark backend. The app features a configurable window renderer (supporting Skia, Vello GPU, Vello CPU, and Vello Hybrid backends via feature flags), applies GitHub-compatible and custom Blitz Markdown CSS styles, and includes a file watcher for hot-reloading local changes. Users can navigate links, toggle between light and dark themes, and use keyboard shortcuts (Ctrl/Cmd+R to reload, Ctrl/Cmd+T to toggle theme, Ctrl/Cmd+B to go back) to interact with the content.
apps/readme/src · high confidence
Introduce unified \`blitz\` crate with re-exports and launch helpers
The new \packages/blitz/src/lib.rs\ file establishes a central entry point that re-exports the core sub-crates (\blitz-dom\, \blitz-html\, \blitz-shell\, \blitz-paint\, \blitz-traits\, and \blitz-net\ when the \net\ feature is enabled) as modules. It provides high-level convenience functions \launch\_url\ and \launch\_static\_html\ to bootstrap a web engine instance, handling runtime setup, event loops, and document creation internally. This simplifies initial integration by allowing users to launch HTML content via a single crate without manually wiring together the underlying components.
packages/blitz · high confidence
New 'bump' utility for coordinated version updates
A new CLI tool located at apps/bump has been added to streamline version management for the project's monorepo. Users can now run this utility to simultaneously update the versions of specific package groups—either 'anyrender' (including anyrender\_vello, anyrender\_vello\_cpu, and anyrender\_svg) or 'blitz' (including blitz, blitz-dom, blitz-html, blitz-net, blitz-paint, blitz-shell, blitz-traits, and stylo\_taffy)—along with their corresponding workspace dependencies, ensuring consistent versioning across related components.
apps/bump · high confidence
New HTML examples for BBC News, animations, and layout demos
Added several new static HTML assets to the examples directory to demonstrate rendering capabilities. These include a BBC News homepage snapshot (bbc.html) for testing complex layouts and fonts, an animated layout demo (animated\_layout.html) showcasing CSS keyframe animations and gradients, a general animation example (animation.html) with transforms and transitions, and a specific test case for pseudo-element rendering (after\_bug.html).
examples · high confidence
New WASM hello-world example demonstrating browser-based rendering
A new \examples/wasm\_hello\ example has been added, providing a minimal proof-of-concept that runs \BlitzApplication\ in the browser via \wasm32\. This example demonstrates how to drive the Vello hybrid renderer on a canvas, handle font registration with bundled assets (since browsers do not expose system fonts to WASM), and manage the async renderer resume lifecycle using \wgpu\ and \winit\'s web platform support.
_examples/wasm\hello · high confidence
New abstraction layer for embedders to handle navigation, networking, and shell interactions
The \blitz-traits\ crate now exposes core abstractions that allow embedders to customize how the browser handles navigation, network requests, and operating system features. Users can implement \NavigationProvider\ to intercept link clicks and form submissions, \NetProvider\ to supply custom networking logic (including support for aborting requests and form data), and \ShellProvider\ to manage clipboard access, file dialogs, IME input, and window chrome controls. Additionally, the crate defines the \DevtoolSettings\ struct for configuring debug overlays and element pickers, and introduces a versioned \NodeId\ to safely identify DOM nodes across reuse.
packages/blitz-traits · high confidence
New cross-platform AccessKit adapter for Android, iOS, and desktop
The \accesskit\_xplat\ package introduces a new cross-platform adapter that provides accessibility support on Android, iOS, macOS, Windows, and Unix-like systems without depending on the Winit library. This allows applications to integrate AccessKit with any version of Winit (including beta or git versions) and other windowing frameworks. The package includes platform-specific implementations for Android (using \accesskit\_android\), macOS (using \accesskit\_macos\), Windows (using \accesskit\_windows\), and Unix (using \accesskit\_unix\), along with a null implementation for unsupported platforms. It also supports async runtimes like Tokio on Linux/Unix via feature flags.
_packages/accesskit\xplat · high confidence
New debug\_timer crate for conditional performance timing
A new \debug\_timer\ crate has been introduced, providing a \DebugTimer\ struct and associated macros (\debug\_timer!\, \debug\_timer\_type\) to record and print execution times. When the \enable\ feature is active, the timer uses \Instant\ to track durations with precision scaling (nanoseconds, microseconds, milliseconds, or seconds) and prints a summary including the start time and subsequent checkpoints; otherwise, it compiles to a no-op dummy implementation. This allows developers to instrument code paths with conditional performance logging that can be toggled at compile time.
_packages/debug\timer · high confidence
New headless test harness for Blitz documents
A new \blitz-test-harness\ crate has been added to provide a headless environment for testing Blitz documents without requiring a window, GPU, or compositor. The \Harness\ struct wraps underlying document types (such as \HtmlDocument\ or \DioxusDocument\) and exposes programmatic APIs for constructing documents from HTML or components, driving an animation clock via \pump\ and \tick\, and synthesizing user input events like clicks, taps, drags, and keyboard strokes. It also includes inspection utilities for querying the DOM by selector, retrieving layout rectangles, performing hit-tests, and dumping the DOM tree for snapshot assertions.
packages/blitz-test-harness · high confidence
New stylo\_taffy crate for Stylo-to-Taffy style conversion
The \packages/stylo\_taffy\ location now contains a dedicated crate that replaces the previous \stylo\_to\_taffy\ module. It provides the \TaffyStyloStyle\ wrapper and conversion logic (\convert.rs\) that maps Stylo computed styles (including direction, sizing, margins, padding, borders, and grid/float features) into Taffy layout styles, enabling the layout engine to process Stylo-generated CSS values.
_packages/stylo\taffy · high confidence
Project rebrand to Blitz and addition of developer tooling
The project has been renamed from 'stylo-dioxus' to 'Blitz' and is now dual-licensed under Apache 2.0 and MIT. To support development, a \justfile\ has been added to standardize build, lint, and run commands (e.g., \just browser\, \just wpt\), and a Nix flake (\flake.nix\) has been introduced to provide a reproducible development environment. The repository structure has also been updated with a new \CONTRIBUTING.MD\ guide and a \HOWTO\_WASM.md\ file to assist with building and running WASM examples.
(repo-wide) · high confidence
WPT runner adds support for attr, crashtest, and fuzzy reftest types
The WPT runner now executes three additional test categories: attribute layout tests (attr\_test) which validate CSS layout properties like width, padding, and margins against expected values; crashtests (crash\_test) that verify the engine can parse, script, and render documents without panicking; and fuzzy reftests (ref\_test) that parse \\<meta name=fuzzy\>\ tags to allow pixel-difference tolerances during image comparison. The runner also synthesizes HTML wrappers for \.any.js\ and \.window.js\ files to run them in a window context and implements a custom testharness report mechanism to capture testharness.js results without a live server.
_wpt/runner/src/test\runners · high confidence
Removals
Removal of initial rendering and layout subsystems
The initial implementation of the rendering and layout engine has been removed from the source code. This includes the deletion of \src/layout.rs\ (Taffy-based layout), \src/render.rs\ (Vello-based rendering logic), \src/style.rs\ (style resolution), \src/text.rs\ (text context and font handling), \src/node.rs\ (node references), and the main \src/lib.rs\ entry point that orchestrated the event loop and DOM mutations. These files contained the foundational code for layout calculation, text rendering, and scene building, which are no longer present in this location.
src · high confidence
Architecture
New modular layout system with dedicated table, inline, and paint-tree modules
The layout engine has been restructured into distinct modules (\construct\, \inline\, \list\, \table\, \replaced\, \paint\_tree\, \damage\) to improve organization and maintainability. This change introduces a new \construct.rs\ module for building layout children and handling anonymous blocks, an \inline.rs\ module for computing inline layout with support for sizing keywords and scroll containers, a \table.rs\ module for handling table-specific layout logic including column sizing and border collapse, a \replaced.rs\ module for managing replaced elements like images and videos, a \paint\_tree.rs\ module for constructing the paint tree and handling stacking contexts, and a \damage.rs\ module for tracking layout damage. The \mod.rs\ file now serves as the central coordinator, importing and exposing these new modules while maintaining the core layout computation logic.
packages/blitz-dom/src/layout · high confidence
Refactor DOM node data into specialized modules
The internal structure of \blitz-dom\ nodes has been reorganized to improve modularity and performance. Element-specific state (such as attributes, styles, layout data, and custom widget data) has been moved from the generic \Node\ struct into dedicated \ElementData\ and \DocumentData\ structs, allowing the \Node\ struct to focus purely on tree structure. This change introduces new modules for handling attributes (\attributes.rs\), custom widgets (\custom\_widget.rs\), and serialization (\serialize.rs\), and refactors the node tree to use \SlotMap\ for better memory efficiency. Users benefit from a more robust and maintainable DOM implementation, though this is primarily an internal architectural change.
packages/blitz-dom/src/node · high confidence
Behavioural changes
Expanded CSS rendering support for backgrounds, masks, borders, and form controls
The rendering engine now supports several new CSS properties and improves existing ones. Backgrounds and masks share a unified layering system, enabling \background-attachment: fixed\, \mask-\*\ properties (position, size, repeat, clip, origin), and proper SVG background scaling. Border rendering has been refactored to support \border-style\ (including inset/outset beveling and dashed patterns) and \border-collapse\ for tables. Box shadows are now drawn with correct inset behavior and shape preservation. Additionally, \clip-path\ (basic shapes) and the CSS 2 \clip\ property for absolutely positioned elements are implemented, and form controls (checkboxes/radios) are rendered with accent colors.
packages/blitz-paint/src/render · high confidence
Introduce CSS-compliant box model and border rendering logic
The \kurbo\_css\ module now provides a dedicated implementation for CSS box model calculations and border geometry, replacing previous dependencies on stylo and taffy. This change introduces the \CssBox\ struct to manage nested layout boxes (content, padding, border, outline) and handles non-uniform border radii, including automatic scaling to prevent intersection. It also implements precise border edge path generation (\border\_edge\_shape\) and slicing logic to support complex border styles like \double\, ensuring correct rendering of rounded corners and edge segments in the Vello backend.
_packages/blitz-paint/src/kurbo\css · high confidence
Introduce DocumentConfig and StyleThreading for document construction
The \BaseDocument\ constructor now accepts a \DocumentConfig\ struct instead of individual parameters, centralizing document setup options such as viewport, base URL, providers, and media type. A new \StyleThreading\ enum allows users to choose between parallel (defaulting to sequential for safety) and parallel style traversal, preventing panics when multiple documents resolve concurrently. Additionally, a \debug\_log\_node\ method has been added to \BaseDocument\ to print detailed layout, style, and tree information for debugging.
packages/blitz-dom/src · high confidence
Introduce HtmlDocument and HTML/XHTML parsing implementation
The \blitz-html\ crate now provides the \HtmlDocument\ type and the \DocumentHtmlParser\ sink, which implement the \Document\ trait to parse HTML and XHTML content into the \blitz-dom\ structure. This change adds explicit entry points for parsing (\from\_html\ and \from\_xml\), improves XHTML detection by sniffing for the XHTML namespace on the root element, and configures the underlying \html5ever\ parser with \scripting\_enabled: false\ to correctly handle \\<noscript\>\ tags.
packages/blitz-html · high confidence
Introduce WPT test runner with crash handling and report generation
The WPT test runner has been moved to wpt/runner/src and now includes robust error handling to prevent crashes when encountering missing or unresolvable reference files, as well as 'no matching nodes' errors in attribute tests. It also introduces a quiet output mode (enabled by default) and generates WPT-compatible reports that exclude non-test files like visual, manual, and support resources, ensuring cleaner test results.
wpt/runner/src · high confidence
Native application launch and configuration overhaul
The \dioxus-native\ crate now provides a new \Config\ struct for launch-time settings, allowing users to specify window attributes, custom font contexts, alpha compositing modes (for transparent windows), and base background colors. The application entry point has been refactored to support these configurations via \launch\_cfg\ and \launch\_cfg\_with\_props\, which accept typed configuration objects (such as \Config\ or \WindowAttributes\) instead of raw context vectors. Additionally, the crate introduces \use\_window\_event\ and \use\_back\_button\ hooks for handling native window events and Android back-button presses, and implements a \DioxusNativeNetProvider\ to handle network requests and asset fetching via the underlying \blitz\_shell\ proxy.
packages/dioxus-native · high confidence
Readme styling now supports system dark mode and GitHub image themes
The readme view now adapts to the user's system color scheme preference. When the system is in dark mode, the background switches to a dark theme and images or links marked with the GitHub-specific suffixes '\#gh-light-mode-only' are hidden. Conversely, in light mode, the background is white and images marked '\#gh-dark-mode-only' are hidden. This is achieved by introducing a new \blitz-markdown-overrides.css\ file that handles these visibility rules and padding, alongside an updated \github-markdown.css\ that defines the corresponding CSS variables for both light and dark themes.
apps/readme/assets · high confidence
Refactored event handling into a modular system with improved focus and input support
The event handling logic in \packages/blitz-dom/src/events\ has been reorganized into distinct modules (\driver\, \focus\, \ime\, \keyboard\, \pointer\) to improve maintainability and correctness. This change introduces a dedicated \EventDriver\ for managing event queues and pointer interactions, including precise handling of pointer enter/leave events and touch-action-based panning constraints. It also adds robust support for focus management, automatically dispatching \focus\, \blur\, \focusin\, and \focusout\ events when focus changes via keyboard navigation (Tab/Shift+Tab) or programmatic means. Additionally, the update enhances text input handling by properly processing IME (Input Method Editor) events and implementing Apple standard keybindings, ensuring more accurate text entry and selection behavior across platforms.
packages/blitz-dom/src/events · high confidence
TodoMVC example restructured for multi-platform support
The TodoMVC example has been reorganized into its own dedicated crate to support Windows, Android, and WebAssembly targets. This change introduces platform-specific entry points: a Windows build that hides the console window, an Android entry point using \dioxus\_native::launch\, and a WebAssembly configuration that initializes a custom font context. The application logic now uses \ondoubleclick\ to trigger todo editing and includes a \tracing\ feature for debugging, while the UI styling has been updated to disable transitions and use a pointer cursor for the delete button.
examples/todomvc · high confidence
Test coverage
Added integration test suite for Blitz layout and accessibility; Added test file for Stylo usage integration.
Dependencies
Upgrade to Dioxus 0.7 and Rust Edition 2024
The project has upgraded its core UI framework from Dioxus 0.6 to version 0.7.0, including the \dioxus-native\ renderer and \dioxus-native-dom\ packages. To support this upgrade and modernize the codebase, all workspace crates and examples have been migrated to Rust Edition 2024. This change also updates the Minimum Supported Rust Version (MSRV) to 1.86.0 and introduces new feature flags for capabilities such as hot-reloading, system font emboldening, and frame-time logging.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 70 → 74 (+4.4)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 81 → 81 (-0.5)
- Architecture 98 → 96 (-2.4)
- Maturity 75 → 75 (-0.3)
- Readiness 68 → 68 (+0.4)
- Security 62 → 74 (+12.4)
- Event Sourcing 100 → 100 (+0.0)
- Performance 100 (new)
Resolved (44)
- BaseDocument::compute_child_layout_internal (cognitive 46) (packages/blitz-dom/src/layout/mod.rs)
- BaseDocument::compute_child_layout_internal (cyclomatic 30) (packages/blitz-dom/src/layout/mod.rs)
- BaseDocument::flush_styles_to_layout_impl (cognitive 29) (packages/blitz-dom/src/layout/damage.rs)
- BaseDocument::flush_styles_to_layout_impl (cyclomatic 16) (packages/blitz-dom/src/layout/damage.rs)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (11 lines × 2) (packages/blitz-dom/src/node/node.rs)
- Duplicated block (12 lines × 2) (packages/blitz-paint/src/render.rs)
- Duplicated block (5 lines × 3) (packages/blitz-dom/src/font_metrics.rs)
- Duplicated block (8 lines × 2) (packages/blitz-dom/src/font_metrics.rs)
- FunctionTooLong: blitz_dom::layout::inline::layout_abspos_child (packages/blitz-dom/src/layout/inline.rs)
- HackComment (packages/blitz-dom/src/layout/construct.rs)
- HackComment (packages/blitz-dom/src/layout/inline.rs)
- High: security finding (details withheld)
- Hotspot: apps/browser/src/toolbar.rs (apps/browser/src/toolbar.rs)
- Hotspot: packages/blitz-dom/src/accessibility.rs (packages/blitz-dom/src/accessibility.rs)
- Hotspot: packages/blitz-dom/src/cssom.rs (packages/blitz-dom/src/cssom.rs)
- Hotspot: packages/blitz-dom/src/events/mod.rs (packages/blitz-dom/src/events/mod.rs)
- Hotspot: packages/blitz-dom/src/layout/list.rs (packages/blitz-dom/src/layout/list.rs)
- Hotspot: packages/blitz-dom/src/node/text.rs (packages/blitz-dom/src/node/text.rs)
- …and 24 more
New (43)
- Ambiguous return type for mutator methods. get_node_mut returns Node (likely a value or wrapper) rather than a mutable reference &mut Node or a guard type, making it unclear if the mutation is immediate or deferred. This contrasts with Document.inner_mut() which returns a DocGuardMut.
- BaseDocument::build_paint_tree_impl (cognitive 30) (packages/blitz-dom/src/layout/paint_tree.rs)
- BaseDocument::build_paint_tree_impl (cyclomatic 16) (packages/blitz-dom/src/layout/paint_tree.rs)
- BaseDocument::dispatch_child_layout (cognitive 53) (packages/blitz-dom/src/layout/mod.rs)
- BaseDocument::dispatch_child_layout (cyclomatic 32) (packages/blitz-dom/src/layout/mod.rs)
- BaseDocument::propagate_damage_flags (cyclomatic 16) (packages/blitz-dom/src/layout/damage.rs)
- BaseDocument::resolve_transforms (cognitive 20) (packages/blitz-dom/src/resolve.rs)
- Confusing naming and return types for root access. root_node and root_element likely refer to the same underlying node (the <html> or document root), but one is 'try' (implying it might fail) and the other doesn't. Furthermore, root_node_mut returns Node instead of a mutable guard/reference, inconsistent with the inner_mut pattern.
- Duplicate functionality across types. BaseDocument and DocumentMutator both expose set_style_property and remove_style_property. Since DocumentMutator is obtained via BaseDocument.mutate(), it is unclear if calling these on BaseDocument directly is valid or if it bypasses the mutation tracking system.
- Duplicated block (10–11 lines × 2) (packages/blitz-dom/src/node/element.rs)
- Duplicated block (12 lines × 2) (packages/blitz-dom/src/node/node.rs)
- Duplicated block (13 lines × 2) (packages/blitz-paint/src/render.rs)
- Duplicated block (14–15 lines × 2) (packages/blitz-dom/src/layout/construct.rs)
- Duplicated block (8 lines × 2) (packages/blitz-dom/src/font_metrics.rs)
- FunctionTooLong: blitz_paint::text::flush_line_decorations (packages/blitz-paint/src/text.rs)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Inconsistent scroll API design. scroll_to and scroll_by take a NodeId and ScrollBehavior, while scroll_node_by takes a callback dispatch_event and no behavior enum. scroll_viewport_by lacks behavior. The presence of _has_changed variants suggests a need for atomic check-and-set operations that are not consistently applied to all scroll methods.
- Inverted test pyramid
- Low cohesion: BlitzShellProvider (LCOM4 4) (packages/blitz-shell/src/lib.rs)
- …and 23 more
Changes since last survey
- 55 commits — 52 feature/other, 3 fixes
By area
- packages/blitz-dom — 37 commits
- (root) — 8 commits
- .github/workflows — 5 commits
- packages/stylo_taffy — 3 commits
- apps/readme — 1 commit
- wpt/runner — 1 commit
Notable commits
- fix: Fix hit-testing of hoisted children under a scrolled stacking-context root; move viewport_scroll into NodeTree (#944)
- fix: Fix unused NodeFlags import warning in release builds
- fix: Implement out-of-flow hoisting (position:absolute and position:fixed) (#922)
- change: Add UA rule mapping td/th nowrap attribute to white-space: nowrap (#931)
- change: Apply translate/rotate/scale in the correct order (T·R·S) (#934)
- change: Build the paint tree in a single damage-gated post-layout pass (#921)
- change: Bump Taffy: don't stretch absolutely positioned replaced elements between insets (#972)
- change: Bump Taffy: only resolve abspos auto margins when both insets are set (#971)
- change: Bump Taffy: respect the root element's position and insets (#976)
- change: Bump Taffy: viewport-sized initial containing block (#973)
- change: Bump pinned WPT revision to 375cf2548 (2026-09-28) (#970)
- change: Bump pinned WPT revision to d552535bc (2026-09-17) (#907)
- change: Bump taffy to main (out-of-flow refactor) (#912)
- change: CI: Add weekly job that bumps the pinned WPT revision (#908)
- change: Clamp an inline box's height to a finite value (#941)
- change: Clear stale stacking_context when a node stops being a stacking context root (#913)
- change: Compute ch/ic advances with the same scaling as Parley's glyph advances (#927)
- change: Don't clamp replaced elements' max size to the available space (#937)
- change: Don't count the empty line Parley adds after a final forced line break in inline height (#939)
- change: Don't drop whitespace-only text nodes whose whitespace is preserved (#930)
- …and 35 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
DioxusLabs/blitz was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 18f007ee4bae490b787f45a97fe898dc2e73f1bb — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-cb25ca4feafa.