Skip to content
CAI
Software that uses CAICheck a score

doorgan/sourceror

69.4

Adequate · 23 September 2026

51k

lines of production code

Erlang

with Elixir

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Sourceror is an Elixir library for parsing, formatting, and programmatically manipulating Abstract Syntax Trees (ASTs). It provides robust tools for traversing and patching source code, including high-performance zippers and utilities for modifying function calls, modules, and data structures. The system supports backported Elixir syntax features and ensures accurate source mapping and comment preservation across various Elixir versions.

How it got here

2021 — v1.12.3 release and internal refactoring

8 changes.

This period focused on releasing version 1.12.3, which included a major internal refactoring of AST manipulation and source mapping with new modules like FastZipper and Patch. The work also established compatibility with Elixir 1.13+ and older versions, added comprehensive test coverage, and introduced documentation and examples for AST traversal and code patching.

2023–2026 — Elixir 1.12+ support and AST utilities

4 changes.

This period focused on backporting Elixir 1.12+ syntax support by vendoring the compiler's parser and formatter, enabling handling of newer language constructs. The work also involved porting code-manipulation utilities from the Igniter project to provide robust AST navigation and modification tools via the Zipper implementation.

Features

Add TypedStruct macro for defining structs with typespecs and defaults

A new \Sourceror.Utils.TypedStruct\ module has been added, providing a \typedstruct\ macro that simplifies the definition of Elixir structs. This macro allows developers to define struct fields with associated typespecs, default values, and enforcement rules in a single declaration, automatically generating the corresponding \@type\, \@enforce\_keys\, and \defstruct\ directives.

lib/sourceror/utils · high confidence

Add project description

The README.md file has been updated to replace the placeholder 'TODO: Add description' with comprehensive documentation. This includes installation instructions for version 1.11+, a note on compatibility with Elixir 1.10 and OTP 21, an explanation of how Sourceror stores comments in AST metadata, and examples for AST traversal and patching source code.

(repo-wide) · high confidence

Added Elixir example scripts for AST manipulation

New example scripts have been added to the \examples\ directory to demonstrate how to use Sourceror for parsing and transforming Elixir code. The \add\_dependency.exs\ script shows how to programmatically inject a dependency into a \mix.exs\ file by walking the AST, while \sort\_dependencies.exs\ demonstrates sorting existing dependencies alphabetically. These examples use \Mix.install\ to run as standalone scripts.

examples · high confidence

Added Livebook examples for AST manipulation and zippers

New Livebook notebooks have been added to the \notebooks\ directory to demonstrate advanced Sourceror capabilities. The \expand\_multi\_alias.livemd\ notebook provides a step-by-step guide on expanding multi-alias syntax (e.g., \alias Foo.{Bar, Baz}\) into individual alias calls while preserving comments and handling AST block unwrapping. The \zippers.livemd\ notebook introduces the \Sourceror.Zipper\ data structure, explaining how to traverse and modify the AST tree with localized operations like moving focus, inserting siblings, and navigating parent/child relationships.

notebooks · high confidence

Port Igniter.Code utilities to Sourceror

Added a suite of code-manipulation utilities in lib/sourceror/code (Common, Function, Keyword, List, Map, Module, String, Tuple) branched from the Igniter project. These modules provide functions for navigating and modifying Elixir ASTs using Sourceror's Zipper, enabling users to perform operations such as finding and updating function calls, managing keyword lists and maps, and manipulating module structures.

lib/sourceror/code · high confidence

Vendored Elixir 1.12+ parser and formatter for backported language features

The project now includes vendored copies of the Elixir compiler's tokenizer, parser, normalizer, and formatter (specifically \Sourceror.Code.Formatter\ and \Sourceror.Code.Normalizer\ in Elixir, and \sourceror\elixir\\*\ modules in Erlang). These components are integrated to backport Elixir 1.12+ syntax support, enabling the parsing and formatting of newer language constructs such as the range step operator (\..//\), the \+++\ and \---\ operators, and updated operator precedence rules that require parentheses for logical binary operands.

_lib\_vendored, src\vendored · high confidence

Behavioural changes

Compatibility layer for Elixir 1.13+ and column/indentation handling

The library now uses a conditional module alias to switch between the standard \Code\ module (for Elixir 1.13+) and a vendored \Sourceror.Code\ module (for older versions), ensuring compatibility with pre-1.13 Elixir releases. Additionally, \parse\_string\ and \parse\_string!\ now accept \:line\ and \:column\ options to control the starting position of the source code, and include internal logic to apply indentation fixes and handle column offsets specifically for Elixir versions prior to 1.19.

lib · high confidence

Major internal refactoring of AST manipulation and source mapping

This release introduces a high-performance \Sourceror.FastZipper\ as an alternative to the existing \Sourceror.Zipper\, alongside a new \Sourceror.Patch\ module for generating source patches (such as renaming calls or identifiers) and a dedicated \Sourceror.Range\ struct for precise start/end position tracking. The core parsing and formatting pipeline has been restructured with a new \Sourceror.Code\ module and a \Sourceror.LinesCorrector\ to improve line number accuracy and comment placement, while the \Sourceror.Comments\ module has been rewritten to use \Macro.traverse\ for more robust comment merging and extraction.

lib/sourceror · high confidence

Test coverage

Added benchmark comparing standard and record-based zipper traversal performance; Added comprehensive test suite for Sourceror code manipulation and parsing; Added tests for the code normalizer's AST formatting and quoting.

Dependencies

Initial dependency lock and project configuration for Sourceror v1.12.3

This change introduces the \mix.lock\ file, locking development dependencies such as Credo 1.7.15, Dialyxir 1.3.0, ExDoc 0.31.2, and Sobelow 0.11.1, and updates \mix.exs\ to set the project version to 1.12.3 with Elixir compatibility starting from 1.12. It also adds project metadata (description, licenses, links), configures documentation generation to include notebooks, and sets up Dialyzer and ExCoveralls for static analysis and test coverage.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 65 → 69 (+4.8)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 95 (-4.3)
  • Architecture 100 → 90 (-10.3)
  • Maturity 55 → 55 (-0.2)
  • Readiness 62 → 73 (+10.8)
  • Security 70 → 93 (+22.9)

Resolved (18)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • High CVE: [GHSA redacted] (mix.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • Test reliability not included
  • The README is clipped mid-sentence inside the 'Goals of the library' section: "Sourceror's take is to use the node metadata to store the comments." then it clips before the outline sections Comment for :a, Traversing the AST, Patching the source code, Background, Documentation, Examples, Contributing, Getting assistance, Copyright and License are named. (README.md)
  • TooManyMethods: sourceror_elixir_tokenizer (src_vendored/sourceror_elixir_tokenizer.erl)
  • complexity unreadable for .erl, .ex, .exs — churn × complexity hotspots could not be measured

New (57)

  • Documentation: no usage examples (README.md)
  • FileTooLong: code/common.ex (lib/sourceror/code/common.ex)
  • FileTooLong: code/formatter.ex (lib_vendored/code/formatter.ex)
  • FileTooLong: code/function.ex (lib/sourceror/code/function.ex)
  • FileTooLong: lib/sourceror.ex (lib/sourceror.ex)
  • FileTooLong: sourceror/fast_zipper.ex (lib/sourceror/fast_zipper.ex)
  • FileTooLong: sourceror/zipper.ex (lib/sourceror/zipper.ex)
  • FileTooLong: src_vendored/sourceror_elixir_parser.erl (src_vendored/sourceror_elixir_parser.erl)
  • High CVE: [GHSA redacted] (mix.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 37 more

Changes since last survey

  • 2 commits — 1 feature/other, 1 fixes

By area

  • (root) — 1 commit
  • test/code — 1 commit

Notable commits

  • fix: fix: properly calculate ranges for special atoms and docs (#212)
  • change: chore(main): release 1.12.3 (#213)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

doorgan/sourceror was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit b2ea9e947b433b7ffbf7d0d3af90553529c73f35 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.