gleam-lang/gleam
37.5
Weak · 27 September 2026
148.3k
lines of production code
Rust
primary language
4
measurements over time
What this system is
This system is the Gleam compiler and toolchain, a Rust-based implementation that compiles Gleam source code into Erlang and JavaScript targets. It provides a comprehensive CLI for managing project dependencies, generating builds, and publishing packages to the Hex repository, while also supporting a language server for IDE integration. The system includes a WebAssembly-compiled compiler for in-browser use and generates TypeScript declarations alongside JavaScript output.
How it got here
2016–2021 — Compiler core refactoring and multi-target support
34 changes.
This period focused on a comprehensive refactoring of the Gleam compiler's core, including a major AST restructuring, the introduction of a caching build system, and the migration to modern Rust practices. It established robust support for generating code to both Erlang and JavaScript targets, while simultaneously expanding test coverage through extensive snapshot testing and adding features like in-browser compilation via WebAssembly.
2022–2024 — JavaScript target and dependency management
50 changes.
This period focused on expanding the compiler to support JavaScript as a first-class target, including new project templates, FFI interoperability, and comprehensive test coverage for both Erlang and JavaScript backends. It also introduced a robust dependency management subsystem with manifest locking and modern Hex authentication, alongside significant improvements to documentation styling, offline search, and Windows support.
2025–2026 — Architecture refactoring and Hex integration
50 changes.
This period focused on restructuring the codebase by extracting the language server, formatter, and source span utilities into dedicated crates to improve modularity. Concurrently, significant work was done to integrate with the Hex package manager, including implementing a new client library, protobuf schemas, and semver parsing. The effort was heavily supported by extensive test coverage expansion and the addition of performance benchmarks for the lexer and list operations.
Features
Add Erlang Term Format (ETF) encoder
Introduces a new \erlang-term-format\ library that provides an encoder for the Erlang Term Format (ETF), allowing Gleam data structures to be serialized into the binary format used by Erlang/OTP. The implementation includes a \TermBuilder\ API for constructing ETF binaries, supporting encoding of atoms (including UTF-8), integers, floats, big integers, lists, tuples, and binaries. The encoder is designed to produce the most compact representation for each type and includes debug-only assertions to ensure lists are correctly closed.
erlang-term-format · high confidence
Added funding manifest URL
A new .well-known/funding-manifest-urls file has been added to the repository, pointing to https://gleam.run/funding.json. This allows external tools and platforms to discover the project's funding information via the standard well-known URI path.
.well-known · high confidence
Added lexer allocation and speed benchmarks
New benchmarking tools have been added to the compiler-benches directory to measure the performance and memory usage of the Gleam lexer. The \lexer\_speed.rs\ benchmark uses Criterion to measure the time required to tokenize source modules from the \gleam\_stdlib\, \emojindex\, and \squirrel\ packages, while \lexer\_alloc.rs\ uses dhat to report total allocations, bytes allocated, and peak memory usage for the same corpus. These benchmarks rely on a new \cases/corpus\ project structure containing the necessary dependencies and source files to provide a realistic workload for these measurements.
compiler-benches, compiler-benches/cases/corpus · high confidence
Added list benchmark entry point
A new benchmark file for list operations has been added to the project. The file serves as the main entry point for the benchmark suite, currently initialized to return Nil, and includes standard Apache-2.0 license and copyright headers.
benchmark/list · high confidence
Added nightly version suffix script
A new shell script, bin/add-nightly-suffix-to-versions.sh, has been added to support nightly builds. This script automatically appends a date-based nightly suffix (e.g., -nightly-20231027) to the version strings of all Rust crates in the workspace by modifying their Cargo.toml files.
bin · high confidence
Initial protobuf schema and Rust bindings for package, policy, and versioning data
This change introduces the core protocol buffer definitions and their generated Rust (prost) bindings for the Hex package manager's internal API. The new files define the data structures for package metadata, release details (including checksums, dependencies, and retirement status), security advisories, and repository policies (including visibility, restrictions, and allow/deny overrides). It also adds definitions for version lists, signed payloads, and name lookups, establishing the serialization format for these domain concepts.
hexpm/proto, hexpm/src/proto · high confidence
Introduce \`gleam add\` command for managing project dependencies
Users can now add dependencies to their project using the new \gleam add\ command. This command resolves the requested package versions, updates the \gleam.toml\ configuration with the new requirements (supporting both standard and dev dependencies), and writes the resolved versions to the manifest file, streamlining the process of incorporating external libraries into a Gleam project.
compiler-cli/src · high confidence
Introduce in-browser Gleam compiler via WebAssembly
The \compiler-wasm\ crate now provides a WebAssembly-compiled version of the Gleam compiler, enabling compilation directly in the browser. This release exposes a JavaScript API to manage a virtual file system (write modules, read source and compiled output), trigger package compilation for Erlang or JavaScript targets, and retrieve compiler warnings. It also includes a source formatting function and comprehensive test coverage for the new WASM integration.
compiler-wasm/src · high confidence
Introduce new Erlang code generation library
Added a new \erlang-generation\ library that provides the core infrastructure for generating Erlang code, including a builder trait for constructing Erlang Abstract Format structures, type definitions for module names and bit array segments, and utilities for documentation content.
erlang-generation · high confidence
Introduce new \`echo\` keyword and \`@\` attribute tokens
The parser now recognizes two new language constructs: the \echo\ keyword, which allows users to print values during development, and the \@\ symbol, which serves as the prefix for attributes (such as \@external\ or \@deprecated\). These changes expand the lexer and token definitions to support these new syntax elements, enabling the compiler to parse and handle these features in source code.
compiler-core/src/parse · high confidence
Introduce pretty-arena crate for allocation-aware pretty printing
The \pretty-arena\ crate has been extracted into its own separate library, providing a document-based pretty-printing implementation based on the 'Strictly Pretty' algorithm with extensions from Elixir's Inspect.Algebra. This new component utilizes \typed\_arena\ for memory allocation, allowing consumers to reuse memory pools across multiple formatting operations to reduce dynamic allocation overhead. It exposes a \Document\ API and associated macros (such as \docvec!\) for constructing formatted output trees, serving as the foundational formatting engine for other modules like JavaScript and TypeScript code generation.
pretty-arena · high confidence
Introduction of in-memory file system for testing and browser environments
The compiler now includes an in-memory file system implementation (InMemoryFileSystem) located in compiler-core/src/io/memory.rs. This component provides a shared, cloneable collection of pretend files that can replace the real file system, enabling usage in tests and browser-based environments where a native file system is unavailable. It supports absolute paths, ensures the root directory always exists, and implements core file system writer operations such as creating directories, copying files, and deleting directories, while explicitly marking directory copying as unimplemented.
compiler-core/src/io · high confidence
Multi-architecture Docker images with SBOM provenance
The container build process now produces multi-architecture images for Gleam, leveraging prebuilt binaries and base images for Elixir, Erlang, Node.js, and a scratch environment. Each image variant (latest, alpine, slim) is built for specific target architectures and includes a Software Bill of Materials (SBOM) in SPDX format, enabling users to verify build provenance and security compliance across different runtime environments.
containers · high confidence
New Hex package client library with OAuth and API key authentication
The \hexpm\ library has been introduced to handle communication with the Hex package manager. It supports both OAuth access tokens (with optional one-time passwords for write actions) and long-lived API keys for authentication. The library includes functionality for managing package owners, removing API keys, and handling version parsing compatible with Hex's requirements.
hexpm/src · high confidence
New documentation layout and JavaScript runtime templates
The documentation generator now uses a new \documentation\_layout.html\ template that supports dark/light theme switching, syntax highlighting theme toggling, and version selection. The \documentation\_module.html\ and \documentation\_page.html\ templates have been updated to render module types, values, and deprecation notices with improved styling. Additionally, new JavaScript runtime templates (\echo.mjs\, \prelude.mjs\, \prelude.d.mts\) have been added to handle \echo\ output formatting, bit array operations, and list handling in the JavaScript target, including support for printing NaN, Infinity, and circular references.
compiler-core/templates · high confidence
New licence-bundler tool generates dependency licence report
A new \licence-bundler\ program has been added to the project. This tool runs during the release process to generate a \gleam-licences.html\ file that details the licences of all code dependencies. It works by invoking \cargo tree\ to extract Rust dependency information (including SPDX licence identifiers) and reading local licence text files, then rendering this data into an HTML report that lists Rust packages with their versions and licences, alongside the full text of each active licence.
licence-bundler · high confidence
New project creation now supports JavaScript templates and configurable Git/GitHub initialization
The \gleam new\ command now offers a JavaScript target option via the \--template\ flag, allowing users to generate projects that compile to JavaScript instead of the default Erlang. Additionally, users can now control whether Git repositories and GitHub Actions workflows are created during project setup using the \--skip-git\ and \--skip-github\ flags, providing more flexibility for existing directories or alternative CI setups.
compiler-cli/src/new · high confidence
New test helper library for normalizing compiler output
Added a new \test-helpers-rs\ crate that provides utilities for Gleam compiler testing. It includes a \TestCompileOutput\ struct with an \as\_overview\_text\ method to format compilation results, stripping out volatile details like the compiler version string, JavaScript/TypeScript preambles, and binary content to ensure stable test snapshots. The library also offers a \to\_in\_memory\_filesystem\ function to load local files into an in-memory filesystem for testing and a \normalise\_diagnostic\ function to handle cross-platform differences in error message formatting, such as normalizing Windows-specific caret sequences in code snippets.
test-helpers-rs · high confidence
Removals
Removal of initial tokenizer implementation and application stub
The initial tokenizer implementation, including the source definition file (potion\_tokenizer.xrl) and the generated Erlang scanner module (potion\_tokenizer.erl), has been removed from the source tree. Additionally, the default OTP application stub (potion.app.src and potion.erl) has been deleted. This change removes the foundational lexical analysis components and the basic application structure that were previously present in the src directory.
src · high confidence
Architecture
Extracted source span and line number utilities into a dedicated crate
The \SrcSpan\ struct (representing byte ranges) and the \LineNumbers\ struct (handling conversions between byte offsets and LSP line/column positions, including UTF-8/UTF-16 mapping) have been moved from the main compiler into a new, standalone \src-span\ crate. This refactoring isolates the logic for tracking source locations and encoding conversions, making these utilities available as a reusable component for other parts of the toolchain or external integrations.
src-span · high confidence
Formatter extracted into its own crate
The code formatter has been moved from the core library into a dedicated \format\ crate. This refactoring isolates formatting logic, introducing new dependencies like \camino\ for path handling and \ecow\ for string management, while exposing a public \pretty\ function to handle source code formatting.
format/src · high confidence
Language server split into its own crate
The language server implementation has been extracted from the main compiler crate into a dedicated \language-server\ crate. This structural change separates the LSP protocol handling, code actions, completions, and file management from the core compiler logic, improving modularity and build isolation.
language-server/src · high confidence
Behavioural changes
Add PowerShell entrypoint and update Erlang compilation template
The Erlang shipment now includes a PowerShell entrypoint script (entrypoint.ps1) alongside the existing shell script, enabling Windows users to run and shell into Gleam projects. The compilation template (gleam@@compile.erl) has been updated to use the Elixir API for compiling Elixir modules and includes a compatibility fix for Erlang/OTP versions prior to 26 by conditionally using code:del\_paths or code:del\_path.
compiler-cli/templates · high confidence
Added SPDX license headers to test project source files
The test project source files in the \test-project-compiler\ suite (specifically \with\_dep\, \with\_dev\_dep\, and \support/package\_a\) now include SPDX license identifier comments (Apache-2.0) and copyright notices at the top of each file. This ensures that the generated application artifacts correctly reflect licensing information for compliance and distribution purposes.
_test-package-compiler/cases/erlang\_empty, test-package-compiler/cases/javascript\_empty, test-project-compiler/cases/with\_dep, test-project-compiler/cases/with\_dev\_dep, test-project-compiler/support/package\a · high confidence
Added contribution guide and updated build script for protobuf generation
A new CONTRIBUTING.md file has been added to the hexpm directory, providing instructions for developers on how to add new API functions by referencing existing Hex API implementations. Additionally, the build.rs script has been updated to comment out the automatic protobuf generation via prost\_build, requiring developers to manually copy generated proto files into the src directory instead.
hexpm · high confidence
Automated generation of test cases for the test-project-compiler
The test-project-compiler now uses a build script (build.rs) to automatically generate test code from the 'cases' and 'support' directories. This script scans these directories and creates corresponding test functions for 'Dev', 'Prod', and 'Lsp' modes, ensuring that new test cases are immediately included in the test suite without manual registration. Additionally, a .gitignore file has been added to exclude build artifacts and manifest files from version control.
test-project-compiler · high confidence
Compiler core refactoring and stability improvements
The compiler-core module has undergone extensive refactoring to improve stability, performance, and code quality. This includes migrating from \String\ to \EcoString\ and \SmolStr\ to reduce allocations, replacing \OnceCell\ with \OnceLock\ for better Clippy compliance, and updating to Rust 2021/2024 editions. Significant behavioral changes include stricter validation for module names, package publishing (e.g., rejecting non-hex dependencies, empty READMEs, and invalid versions), and improved error messages for common issues like unused imports, deprecated syntax, and pattern matching errors. The diff also shows enhancements to the type system and code generation, such as better handling of bit arrays, constants, and record updates, as well as fault-tolerant analysis for various language constructs.
compiler-core/src · high confidence
Compiler error when overwriting Erlang built-in modules
The package compiler now prevents projects from defining modules that clash with built-in Erlang modules (such as \code\). Previously, such definitions would silently overwrite the Erlang standard library, leading to cryptic runtime errors; the build tool now detects this conflict and fails the compilation to protect users from breaking their runtime environment. This change is validated by new test cases that verify both successful compilation for namespaced modules and the expected error for direct clashes.
_test-package-compiler/cases/not\_overwriting\_erlang\_module, test-package-compiler/cases/overwriting\_erlang\module · medium confidence
Duplicate module detection and app file generation in package compilation
The package compiler now enforces that modules must be unique, emitting a clear error if the same module name is defined multiple times within a single package or across different packages. Additionally, the compiler ensures that a .app file is generated when a package is compiled, containing the list of compiled modules.
_compiler-core/src/build/package\compiler · high confidence
Improved error messages for missing shell programs and dependency conflicts
The compiler now provides more helpful diagnostics when required shell programs (such as Bun, Deno, Elixir, Erlang, Git, Node.js, and Rebar3) are not found, including platform-specific installation instructions (e.g., Homebrew, apt) and documentation links. Additionally, new error messages guide users when adding dependencies that already exist in the wrong section of \gleam.toml\ (regular vs. dev dependencies), and clarify when output files already exist in the target directory.
compiler-core/src/error/snapshots · high confidence
Improved missing pattern reporting in exhaustiveness warnings
The compiler now provides clearer and more accurate messages when a case expression is not exhaustive. It prints the actual missing patterns using correct constructor names and labels, while hiding the internal structure of private types defined in other modules to prevent reliance on implementation details. Additionally, the ordering of these missing patterns has been improved for better readability.
compiler-core/src/exhaustiveness · high confidence
Improved type-checking diagnostics and const record update safety
The compiler now provides more precise error messages and stricter checks for const record updates, including warnings for redundant or fieldless updates and errors for type mismatches, unknown fields, and variant mismatches. Type inference for mutually recursive functions and anonymous functions in pipes has been refined to correctly report arity and type errors without halting analysis prematurely. Additionally, the type checker now prevents unsafe record updates on values that might be different variants of a union type, ensuring that variant inference does not escape clause scopes or cause false positives during unification.
compiler-core/src/type\/snapshots · high confidence_
JavaScript code generation rewritten with decision trees and TypeScript support
The JavaScript code generator has been completely rewritten to use decision trees for pattern matching, which optimizes the generated output by collapsing if-else chains and improving exhaustiveness checks. This change also introduces support for generating TypeScript declaration files (.d.mts) alongside JavaScript, allowing TypeScript consumers to get proper type information. The new implementation handles bit arrays, guards, and various edge cases more robustly, while also improving variable scoping and reducing code size through better block lifting and inlining strategies.
compiler-core/src/javascript · high confidence
New AST module for constants, typed/untyped expressions, and visitors
The compiler-core AST has been restructured with the introduction of dedicated modules for constants (\constant.rs\), typed expressions (\typed.rs\), untyped expressions (\untyped.rs\), and AST traversal (\visit.rs\). This change adds new AST node variants to support constant expressions (including records, record updates, and binary operators), enhances expression handling with explicit pipeline and block nodes, and provides a comprehensive visitor trait for walking the AST. These structural updates enable improved language server features (such as goto definition, hover, and code actions on constants and patterns) and more fault-tolerant analysis by allowing the compiler to continue processing even when type errors occur in constants.
compiler-core/src/ast · high confidence
New Erlang code generation infrastructure and echo implementation
The Erlang compiler backend has been refactored to use a new builder-based code generation system. This introduces a dedicated \echo\ function implementation for Erlang, replacing previous embedding methods, and adds a \PatternGenerator\ to handle complex pattern matching scenarios such as aliased string prefixes and bit array segments. The change also includes a comprehensive suite of snapshot tests to verify the correctness of the generated Erlang code across various language features.
compiler-core/src/erlang · high confidence
New build directory structure and caching system
The compiler's build process has been restructured to use a new directory layout and a robust caching system. The \ModuleLoader\ now determines whether to recompile a module by comparing source modification times and content hashes against cached metadata, allowing the compiler to skip unchanged modules and significantly speeding up rebuilds. A new \NativeFileCopier\ handles the copying of Erlang and Elixir source files, detecting duplicates and conflicts, while \ElixirLibraries\ automatically links Elixir core libraries into the build directory. The \PackageCompiler\ and \PackageLoader\ orchestrate this flow, ensuring that cached modules are correctly invalidated when their dependencies change or when modules are removed.
compiler-core/src/build · high confidence
New dependency management subsystem with manifest locking and resolution
The CLI now uses a new \DependencyManager\ in \compiler-cli/src/dependencies\ to handle dependency resolution, manifest locking, and updates. This introduces a manifest-based workflow where resolved versions are persisted to disk and reused unless requirements change, preventing unnecessary re-resolution. The system supports Hex, Git, and local path dependencies, including features like re-downloading Git packages when commits change, staging Git path dependencies via worktrees, and verifying Hex package checksums. It also provides user-facing commands to list dependencies in table or tree formats, check for outdated packages, and update specific packages with error handling for non-existent or already-present dependencies.
compiler-cli/src/dependencies · high confidence
New import analysis and name validation modules
The compiler now uses dedicated \imports.rs\ and \name.rs\ modules to handle import registration and name validation. The import logic has been refactored to provide more specific error messages, such as distinguishing between private types and unknown types, checking target support for imported values, and reporting entire imports as unused if all unqualified items are unused. Name validation is now enforced via regex patterns, ensuring correct casing for types (UpperCamelCase) versus values (snake\_case) and providing better error reporting for invalid names.
compiler-core/src/analyse · high confidence
New semver range lexer and parser implementation
The version module now includes a dedicated lexer and recursive-descent parser for semver ranges, replacing the previous implementation. This change introduces tokenization of version strings (supporting operators like \==\, \!=\, \\>\, \\<\, \\~\>\, and logical \and\/\or\) and parsing of version requirements, enabling more robust handling of version constraints in package dependencies.
hexpm/src/version · high confidence
New type-checking subsystem for constants and expressions
The compiler now uses a dedicated \ConstantTyper\ to type-check constant expressions (including record updates, lists, tuples, and bit arrays) and a new \Problems\ structure to collect errors and warnings. This refactors the type environment to track module imports, unqualified names, and variable usage more explicitly, while introducing stricter checks for JavaScript integer safety and floating-point values. The change also adds support for tracking feature usage (such as constant record updates) and improves fault tolerance during type inference.
compiler-core/src/type\ · high confidence_
Offline documentation search and syntax highlighting
The generated documentation now bundles the Highlight.js (v11.6.0) and Lunr.js (v2.3.9) libraries directly, removing the dependency on external CDNs to ensure offline availability and reliability. This update adds syntax highlighting support for JavaScript and TypeScript in addition to existing languages, and enhances the search interface with a keyboard shortcut (Cmd/Ctrl+K) to open the search modal.
compiler-core/templates/docs-js · high confidence
Redesigned documentation styling with local fonts and syntax highlighting themes
The generated documentation now uses a new visual style that includes the 'Karla' and 'Ubuntu Mono' web fonts (served locally as WOFF2 files) and updated CSS variables for colors and spacing. It also introduces Atom One Dark and Atom One Light syntax highlighting themes for code blocks, ensuring consistent formatting and improved readability across different code snippets.
compiler-core/templates/docs-css · high confidence
Rename \`peek\` to \`echo\`
The \peek\ keyword has been renamed to \echo\. This is a breaking syntax change where any existing use of \peek\ in source code must be updated to \echo\ to compile successfully.
(repo-wide) · high confidence
Support for Hex API keys and OAuth authentication
The Hex authentication mechanism has been updated to support modern API keys and OAuth flows, deprecating the legacy \HEXPM\_USER\ and \HEXPM\_PASS\ environment variables. Users can now authenticate using \HEXPM\_API\_KEY\ or \HEXPM\_READ\_API\_KEY\, or by completing an OAuth device authorization flow that stores encrypted refresh tokens locally. The system enforces a minimum length for the local encryption password and revokes old credentials when new ones are established.
compiler-cli/src/hex · high confidence
Updated \`gleam new\` project templates to use \`assert\` and explicit return types
The default project templates generated by \gleam new\ have been updated to reflect modern Gleam syntax. The main entry point now includes an explicit return type annotation (\-\> Nil\), and the generated test file uses the \assert\ keyword for assertions instead of the previous style. These changes apply to both the default and JavaScript target templates, ensuring new projects start with current best practices.
compiler-cli/src/new/snapshots · high confidence
Updated dependency version check output formatting
The CLI's dependency status reporting has been refined to provide clearer, more structured feedback when checking for updates. Users will now see a dedicated summary line indicating the total count of packages with newer versions available (e.g., "3 of 12 packages have newer versions available") alongside a formatted table listing the current and latest versions. Additionally, a specific message is now displayed when no major version updates are available, and the output for major version checks has been standardized to include a header and aligned columns for better readability.
compiler-cli/src/dependencies/snapshots · high confidence
Updated parser snapshot tests for new syntax and error handling
The parser test snapshots have been refreshed to reflect changes in parsing behavior and error messaging. Key updates include support for arithmetic operators in case guards, the ability to include messages in \assert\ statements (e.g., \assert False as "Uh oh"\), and stricter validation for constant list appends (rejecting spread syntax in constants). The snapshots also capture new error cases for invalid patterns, such as assigning to the left side of string concatenation patterns or using reserved keywords in tuple and bit array segments, as well as improved diagnostics for attributes without definitions and empty case guards.
compiler-core/src/parse/snapshots · high confidence
Windows binary statically links the Visual C++ runtime
The Gleam compiler binary now statically links the Visual C++ runtime (CRT) on Windows when built with the MSVC toolchain in release mode. This is achieved by adding a build script that invokes the \static\_vcruntime\ metabuild and configuring Cargo to pass the \-C target-feature=+crt-static\ flag for Windows MSVC targets, ensuring the resulting executable does not require the Visual C++ Redistributable to be installed on the user's system.
gleam-bin · high confidence
Fixes
Fix crash when linked OTP process exits with non-standard reason
The runtime now correctly handles linked processes that exit with reasons other than standard {Reason, StackTrace} tuples, such as {shutdown, binary()}, preventing a crash in the main template. This change ensures stability when interacting with Erlang processes that terminate with custom shutdown signals.
_test-output/cases/linked\_process\exit · high confidence
Test coverage
Added CI test for path dependencies; Added Deno runtime test project to verify location API integration; Added Erlang test project to validate compilation and dependency handling; Added FFI and language integration test fixtures; Added Gleam test cases for bitarray and tuple echo functionality; Added JavaScript prelude test suite; Added JavaScript target test project; Added SPDX license headers to test files; Added compile-package test fixture; Added echo\_singleton test case to verify FFI singleton behavior; Added echo\_with\_message test case; Added empty test fixture for OTP app override; Added integration test for Git dependencies; Added integration test for TypeScript declarations; Added integration tests for FFI support in subdirectories; Added integration tests for community packages; Added integration tests for the assert statement; Added language test suite infrastructure; Added list operation benchmarks; Added snapshot tests for compiler error diagnostics; Added snapshot tests for compiler output scenarios; Added snapshot tests for type-checking diagnostics; Added test case for NaN and infinity handling; Added test case for circular reference handling in FFI; Added test case for echo with non-record atom-tagged tuples; Added test case for import shadowing warning; Added test case for multi-file import cycles; Added test case for panic stack traces; Added test case for variable vs module name ambiguity; Added test cases for dev module handling; Added test cases for empty module warnings; Added test cases for error reporting in related and unrelated modules; Added test cases for importing and destructuring record constants; Added test cases for nested qualified constant imports; Added test cases for unknown module field errors; Added test coverage for default main publishing behavior; Added test files for the hello\_world module; Added test fixture for Erlang and Elixir interop on Windows; Added test fixture for compile-package command; Added test fixture for hex tarball export; Added test fixtures for Gleam command execution scenarios; Added test fixtures for module resolution in compile\_package1; Added test for Erlang shipment exclusion of dev dependencies; Added test for Erlang-only external dependencies; Added test for Int/String type unification error; Added test for JavaScript-only external function enforcement; Added test for multi-namespace project validation; Added test for rejecting package publication without a README; Added test for running dependency modules with broken root package; Added test infrastructure for compiler output snapshots; Added test project for unicode path handling; Added test suite for hello\_world module; Added test suite for path dependencies; Added test to prevent publishing projects with default README; Added tests for Erlang and Elixir interop in Erlang projects; Added tests for call graph dependency ordering; Added tests for escript, compile-package, and export commands; Added tests for file system operations; Added tests for git dependencies with path fields; Added tests for module interface serialization; Added tests for multi-namespace and empty README publish validation; Added tests for native file copying in subdirectories; Added tests for package loader behavior in dev and prod modes; Added tests for running modules; Added tests for symlink escape validation in publishing; Added tests for the package interface generation; Expanded Erlang code generation test coverage; Expanded formatter test coverage for Gleam syntax elements; Expanded language test coverage; Expanded package compiler test cases for Erlang and JavaScript targets; Expanded test coverage for language server features; Expanded type-checker test coverage for Gleam compiler; JavaScript backend test suite added; Language server test snapshots updated for code actions; Module loader cache validation tests; New test harness for package compiler integration tests; New test harness for validating \echo\ output across targets and runtimes; Removed lexer tokenization tests; Snapshot tests for JavaScript assert and assignment code generation; Snapshot tests for compiler configuration, dependency, and manifest validation; Test cases for imported external functions and record constructors; Test cases for opaque type accessor and destructure restrictions; Updated Erlang compiler test snapshots.
Dependencies
Initial dependency lock and workspace manifest setup
The project now includes a generated Cargo.lock file and a comprehensive set of Cargo.toml manifests defining the workspace structure. This establishes the dependency graph for the Gleam compiler toolchain, including the CLI, core compiler, language server, and various test and utility crates, ensuring reproducible builds across all components.
(dependencies) · high confidence
Housekeeping
Added SPDX license headers to test case files
Added SPDX license identifier comments (Apache-2.0) to the example Gleam source files used in the test-project-compiler cases for Erlang and JavaScript backends, including source maps and TypeScript declarations.
(repo-wide) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 31 → 37 (+6.5)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 33 → 40 (+6.5)
- Architecture 97 (new)
- Maturity 31 → 34 (+2.5)
- Readiness 27 → 69 (+42.5)
- Security 51 → 69 (+17.9)
- Accessibility 28 (new)
Resolved (54)
- (anonymous) (cognitive 19) (compiler-core/templates/docs-js/index.js)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- FileTooLong: javascript_prelude/main.mjs (test/javascript_prelude/main.mjs)
- High: security finding (details withheld)
- Hotspot: compiler-core/templates/docs-js/index.js (compiler-core/templates/docs-js/index.js)
- LLM evaluation failed
- Low IaC: DS-0026 (containers/elixir-alpine.dockerfile)
- Low IaC: DS-0026 (containers/elixir-slim.dockerfile)
- Low IaC: DS-0026 (containers/elixir.dockerfile)
- Low IaC: DS-0026 (containers/erlang-alpine.dockerfile)
- Low IaC: DS-0026 (containers/erlang-slim.dockerfile)
- Low IaC: DS-0026 (containers/erlang.dockerfile)
- Low IaC: DS-0026 (containers/node-alpine.dockerfile)
- Low IaC: DS-0026 (containers/node-slim.dockerfile)
- Low IaC: DS-0026 (containers/node.dockerfile)
- Low IaC: DS-0026 (containers/scratch.dockerfile)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- …and 34 more
New (700)
- (anonymous)::searchLoaded::update::addResult (cognitive 58) (compiler-core/templates/docs-js/index.js)
- (anonymous)::searchLoaded::update::addResult (cyclomatic 22) (compiler-core/templates/docs-js/index.js)
- Ambiguous naming: run.command and run.setup have identical signatures. It is unclear if 'setup' is a prelude to 'command', a different execution mode, or a redundant alias. Without distinct behavior implied by the name, this is confusing.
- BitArray.equals (cognitive 24) (compiler-core/templates/prelude.mjs)
- Boundary-crossing change coupling: ast_folder.rs ↔ lib.rs (compiler-core/src/ast_folder.rs)
- Boundary-crossing change coupling: call_graph.rs ↔ lib.rs (compiler-core/src/call_graph.rs)
- Boundary-crossing change coupling: compile_package.rs ↔ project_compiler.rs (compiler-cli/src/compile_package.rs)
- Boundary-crossing change coupling: pretty.rs ↔ lib.rs (compiler-core/src/type_/pretty.rs)
- Boundary-crossing change coupling: wasm_filesystem.rs ↔ files.rs (compiler-wasm/src/wasm_filesystem.rs)
- Branch::move_unconditional_patterns (cognitive 24) (compiler-core/src/exhaustiveness.rs)
- Branch::move_unconditional_patterns (cyclomatic 18) (compiler-core/src/exhaustiveness.rs)
- CI installs an unverified third-party binary (.github/workflows/ci.yaml)
- CallGraphBuilder::constant (cognitive 18) (compiler-core/src/call_graph.rs)
- CallGraphBuilder::constant (cyclomatic 17) (compiler-core/src/call_graph.rs)
- CallGraphBuilder::expression (cognitive 45) (compiler-core/src/call_graph.rs)
- CallGraphBuilder::expression (cyclomatic 35) (compiler-core/src/call_graph.rs)
- CasePrinter::switch (cognitive 28) (compiler-core/src/javascript/decision.rs)
- CasePrinter::switch (cyclomatic 19) (compiler-core/src/javascript/decision.rs)
- CaseToCompile::bit_array_to_tests (cognitive 17) (compiler-core/src/exhaustiveness.rs)
- Change coupling: ast_folder.rs ↔ expression.rs (compiler-core/src/ast_folder.rs)
- …and 680 more
Changes since last survey
- 300 commits — 251 feature/other, 49 fixes
By area
- compiler-core/src — 143 commits
- (root) — 48 commits
- compiler-cli/src — 25 commits
- language-server/src — 21 commits
- erlang-generation/src — 13 commits
- test-package-compiler/src — 11 commits
- hexpm/src — 5 commits
- test-commands/src — 5 commits
- test-commands/packages — 3 commits
- .github/pull_request_template.md — 2 commits
- compiler-core/Cargo.toml — 2 commits
- docs/v2.md — 2 commits
- test/compile_package1 — 2 commits
- test/language — 2 commits
- .github/actions — 1 commit
- .github/workflows — 1 commit
- changelog/v1.8.md — 1 commit
- compiler-benches/cases — 1 commit
- compiler-cli/templates — 1 commit
- compiler-core/templates — 1 commit
Notable commits
- fix: Add this fix to the changelog
- fix: Fix JavaScript name leak from a matching case
- fix: Fix LSP panic on client disconnect
- fix: Fix after rebase
- fix: Fix bit array name lost to a redundant test
- fix: Fix bit array slice binding in split branches
- fix: Fix cargo deny loading
- fix: Fix duplicate let from a guard in a matching case
- fix: Fix erlang badarg error when concat'ing a single string expr block
- fix: Fix hex-tarball export failing on Windows extended-length paths
- fix: Fix horrendous mistake
- fix: Fix invalid codegen for empty string match
- fix: Fix my parsing bug
- fix: Fix order-dependent optional dependency resolution
- fix: Fix string prefix fall-through in split branches
- fix: Fix string prefix name binding in split branches
- fix: Revert turn constants into module functions
- fix: fix bug that would result int runtime crush
- fix: fix compile-package command
- fix: fix compiler crash
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
gleam-lang/gleam was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 79c0cdd334365612e8712ab5a5c37cf4c461dd81 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-7c1cb6328e11.