doorgan/sourceror
69.4
Adequate · 23 September 2026
51k
lines of production code
Erlang
with Elixir
5
measurements over time
What this system is
Sourceror is an Elixir library for parsing, formatting, and programmatically manipulating Abstract Syntax Trees (ASTs). It provides robust tools for traversing and patching source code, including high-performance zippers and utilities for modifying function calls, modules, and data structures. The system supports backported Elixir syntax features and ensures accurate source mapping and comment preservation across various Elixir versions.
How it got here
2021 — v1.12.3 release and internal refactoring
8 changes.
This period focused on releasing version 1.12.3, which included a major internal refactoring of AST manipulation and source mapping with new modules like FastZipper and Patch. The work also established compatibility with Elixir 1.13+ and older versions, added comprehensive test coverage, and introduced documentation and examples for AST traversal and code patching.
2023–2026 — Elixir 1.12+ support and AST utilities
4 changes.
This period focused on backporting Elixir 1.12+ syntax support by vendoring the compiler's parser and formatter, enabling handling of newer language constructs. The work also involved porting code-manipulation utilities from the Igniter project to provide robust AST navigation and modification tools via the Zipper implementation.
Features
Add TypedStruct macro for defining structs with typespecs and defaults
A new \Sourceror.Utils.TypedStruct\ module has been added, providing a \typedstruct\ macro that simplifies the definition of Elixir structs. This macro allows developers to define struct fields with associated typespecs, default values, and enforcement rules in a single declaration, automatically generating the corresponding \@type\, \@enforce\_keys\, and \defstruct\ directives.
lib/sourceror/utils · high confidence
Add project description
The README.md file has been updated to replace the placeholder 'TODO: Add description' with comprehensive documentation. This includes installation instructions for version 1.11+, a note on compatibility with Elixir 1.10 and OTP 21, an explanation of how Sourceror stores comments in AST metadata, and examples for AST traversal and patching source code.
(repo-wide) · high confidence
Added Elixir example scripts for AST manipulation
New example scripts have been added to the \examples\ directory to demonstrate how to use Sourceror for parsing and transforming Elixir code. The \add\_dependency.exs\ script shows how to programmatically inject a dependency into a \mix.exs\ file by walking the AST, while \sort\_dependencies.exs\ demonstrates sorting existing dependencies alphabetically. These examples use \Mix.install\ to run as standalone scripts.
examples · high confidence
Added Livebook examples for AST manipulation and zippers
New Livebook notebooks have been added to the \notebooks\ directory to demonstrate advanced Sourceror capabilities. The \expand\_multi\_alias.livemd\ notebook provides a step-by-step guide on expanding multi-alias syntax (e.g., \alias Foo.{Bar, Baz}\) into individual alias calls while preserving comments and handling AST block unwrapping. The \zippers.livemd\ notebook introduces the \Sourceror.Zipper\ data structure, explaining how to traverse and modify the AST tree with localized operations like moving focus, inserting siblings, and navigating parent/child relationships.
notebooks · high confidence
Port Igniter.Code utilities to Sourceror
Added a suite of code-manipulation utilities in lib/sourceror/code (Common, Function, Keyword, List, Map, Module, String, Tuple) branched from the Igniter project. These modules provide functions for navigating and modifying Elixir ASTs using Sourceror's Zipper, enabling users to perform operations such as finding and updating function calls, managing keyword lists and maps, and manipulating module structures.
lib/sourceror/code · high confidence
Vendored Elixir 1.12+ parser and formatter for backported language features
The project now includes vendored copies of the Elixir compiler's tokenizer, parser, normalizer, and formatter (specifically \Sourceror.Code.Formatter\ and \Sourceror.Code.Normalizer\ in Elixir, and \sourceror\elixir\\*\ modules in Erlang). These components are integrated to backport Elixir 1.12+ syntax support, enabling the parsing and formatting of newer language constructs such as the range step operator (\..//\), the \+++\ and \---\ operators, and updated operator precedence rules that require parentheses for logical binary operands.
_lib\_vendored, src\vendored · high confidence
Behavioural changes
Compatibility layer for Elixir 1.13+ and column/indentation handling
The library now uses a conditional module alias to switch between the standard \Code\ module (for Elixir 1.13+) and a vendored \Sourceror.Code\ module (for older versions), ensuring compatibility with pre-1.13 Elixir releases. Additionally, \parse\_string\ and \parse\_string!\ now accept \:line\ and \:column\ options to control the starting position of the source code, and include internal logic to apply indentation fixes and handle column offsets specifically for Elixir versions prior to 1.19.
lib · high confidence
Major internal refactoring of AST manipulation and source mapping
This release introduces a high-performance \Sourceror.FastZipper\ as an alternative to the existing \Sourceror.Zipper\, alongside a new \Sourceror.Patch\ module for generating source patches (such as renaming calls or identifiers) and a dedicated \Sourceror.Range\ struct for precise start/end position tracking. The core parsing and formatting pipeline has been restructured with a new \Sourceror.Code\ module and a \Sourceror.LinesCorrector\ to improve line number accuracy and comment placement, while the \Sourceror.Comments\ module has been rewritten to use \Macro.traverse\ for more robust comment merging and extraction.
lib/sourceror · high confidence
Test coverage
Added benchmark comparing standard and record-based zipper traversal performance; Added comprehensive test suite for Sourceror code manipulation and parsing; Added tests for the code normalizer's AST formatting and quoting.
Dependencies
Initial dependency lock and project configuration for Sourceror v1.12.3
This change introduces the \mix.lock\ file, locking development dependencies such as Credo 1.7.15, Dialyxir 1.3.0, ExDoc 0.31.2, and Sobelow 0.11.1, and updates \mix.exs\ to set the project version to 1.12.3 with Elixir compatibility starting from 1.12. It also adds project metadata (description, licenses, links), configures documentation generation to include notebooks, and sets up Dialyzer and ExCoveralls for static analysis and test coverage.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 65 → 69 (+4.8)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 95 (-4.3)
- Architecture 100 → 90 (-10.3)
- Maturity 55 → 55 (-0.2)
- Readiness 62 → 73 (+10.8)
- Security 70 → 93 (+22.9)
Resolved (18)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — no supported dependency manifest was read
- High CVE: [GHSA redacted] (mix.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- No exposed public API
- Test reliability not included
- The README is clipped mid-sentence inside the 'Goals of the library' section: "Sourceror's take is to use the node metadata to store the comments." then it clips before the outline sections Comment for :a, Traversing the AST, Patching the source code, Background, Documentation, Examples, Contributing, Getting assistance, Copyright and License are named. (README.md)
- TooManyMethods: sourceror_elixir_tokenizer (src_vendored/sourceror_elixir_tokenizer.erl)
- complexity unreadable for .erl, .ex, .exs — churn × complexity hotspots could not be measured
New (57)
- Documentation: no usage examples (README.md)
- FileTooLong: code/common.ex (lib/sourceror/code/common.ex)
- FileTooLong: code/formatter.ex (lib_vendored/code/formatter.ex)
- FileTooLong: code/function.ex (lib/sourceror/code/function.ex)
- FileTooLong: lib/sourceror.ex (lib/sourceror.ex)
- FileTooLong: sourceror/fast_zipper.ex (lib/sourceror/fast_zipper.ex)
- FileTooLong: sourceror/zipper.ex (lib/sourceror/zipper.ex)
- FileTooLong: src_vendored/sourceror_elixir_parser.erl (src_vendored/sourceror_elixir_parser.erl)
- High CVE: [GHSA redacted] (mix.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 37 more
Changes since last survey
- 2 commits — 1 feature/other, 1 fixes
By area
- (root) — 1 commit
- test/code — 1 commit
Notable commits
- fix: fix: properly calculate ranges for special atoms and docs (#212)
- change: chore(main): release 1.12.3 (#213)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
doorgan/sourceror was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit b2ea9e947b433b7ffbf7d0d3af90553529c73f35 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.