GraphiteEditor/Graphite
42.6
Weak · 29 July 2026
153.7k
lines of production code
Rust
primary language
2
measurements over time
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 41 → 43 (+1.3)
- Rubric changed (rubric-2026.08.17 → rubric-2026.08.18) — scores are not directly comparable.
Lenses
- Code Health 47 → 47 (-0.0)
- Architecture 99 → 99 (+0.1)
- Maturity 52 → 59 (+7.3)
- Readiness 48 → 51 (+3.1)
- Security 45 → 47 (+2.0)
- Domain Modelling 88 → 88 (+0.0)
- Event-Driven 80 → 80 (+0.0)
- Event Sourcing 100 → 100 (+0.0)
- Accessibility 31 → 31 (+0.7)
Resolved (146)
- Boundary-crossing change coupling: document_node_definitions.rs ↔ context_modification.rs (editor/src/messages/portfolio/document/node_graph/document_node_definitions.rs)
- Boundary-crossing change coupling: document_node_derive.rs ↔ lib.rs (editor/src/messages/portfolio/document/node_graph/document_node_definitions/document_node_derive.rs)
- Change coupling: app.rs ↔ intercept_frontend_message.rs (desktop/src/app.rs)
- Change coupling: app.rs ↔ main.rs (desktop/src/app.rs)
- Change coupling: demo_artwork_dialog.rs ↔ images.ts (editor/src/messages/dialog/simple_dialogs/demo_artwork_dialog.rs)
- Change coupling: menu_bar_message_handler.rs ↔ portfolio_message_handler.rs (editor/src/messages/menu_bar/menu_bar_message_handler.rs)
- Dependency hygiene not measured — no supported dependency manifest was read
- FlowIter.next (cognitive 16) (editor/src/messages/portfolio/document/utility_types/network_interface.rs)
- GridSnapper.free_snap (cognitive 17) (editor/src/messages/tool/common_functionality/snapping/grid_snapper.rs)
- High CVE: [GHSA redacted] (Cargo.lock)
- High CVE: [GHSA redacted] (Cargo.lock)
- High CVE: [GHSA redacted] (Cargo.lock)
- High CVE: [GHSA redacted] (Cargo.lock)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (Cargo.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 126 more
New (159)
- Boundary-crossing change coupling: app_window_message_handler.rs ↔ editor_wrapper.rs (editor/src/messages/app_window/app_window_message_handler.rs)
- Boundary-crossing change coupling: document_node_definitions.rs ↔ node_registry.rs (editor/src/messages/portfolio/document/node_graph/document_node_definitions.rs)
- Boundary-crossing change coupling: macros.rs ↔ editor_wrapper.rs (editor/src/messages/input_mapper/utility_types/macros.rs)
- Build action pinned to a mutable branch
- Change coupling: app.rs ↔ native_handle.rs (desktop/src/app.rs)
- Change coupling: arw1.rs ↔ arw2.rs (libraries/rawkit/src/decoder/arw1.rs)
- Change coupling: main.rs ↔ browser_process_handler.rs (desktop/src/main.rs)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- FileTooLong: color/color_types.rs (node-graph/libraries/no-std-types/src/color/color_types.rs)
- FileTooLong: common_functionality/graph_modification_utils.rs (editor/src/messages/tool/common_functionality/graph_modification_utils.rs)
- FileTooLong: common_functionality/shape_editor.rs (editor/src/messages/tool/common_functionality/shape_editor.rs)
- FileTooLong: data_panel/data_panel_message_handler.rs (editor/src/messages/portfolio/document/data_panel/data_panel_message_handler.rs)
- FileTooLong: document/document_message_handler.rs (editor/src/messages/portfolio/document/document_message_handler.rs)
- FileTooLong: document/value.rs (node-graph/graph-craft/src/document/value.rs)
- FileTooLong: graph_operation/graph_operation_message_handler.rs (editor/src/messages/portfolio/document/graph_operation/graph_operation_message_handler.rs)
- FileTooLong: graph_operation/utility_types.rs (editor/src/messages/portfolio/document/graph_operation/utility_types.rs)
- FileTooLong: menu_bar/menu_bar_message_handler.rs (editor/src/messages/menu_bar/menu_bar_message_handler.rs)
- FileTooLong: network_interface/caches.rs (editor/src/messages/portfolio/document/utility_types/network_interface/caches.rs)
- FileTooLong: network_interface/layout.rs (editor/src/messages/portfolio/document/utility_types/network_interface/layout.rs)
- FileTooLong: network_interface/mutations.rs (editor/src/messages/portfolio/document/utility_types/network_interface/mutations.rs)
- …and 139 more
Changes since last survey
- 20 commits — 15 feature/other, 5 fixes
By area
- editor/src — 14 commits
- node-graph/nodes — 4 commits
- libraries/math-parser — 2 commits
Notable commits
- fix: Fix assorted node graph correctness bugs and replace network interface panics with logged errors (#4364)
- fix: Fix the 'Divide' node dividing partially-zero Vec2 denominators and the 'Logarithm' node misdetecting base e (#4359)
- fix: Fix the math parser's implicit multiplication precedence and other regressions from the rewrite (#4383)
- fix: Fix wrong-input disconnects, ghost wire caches, and partial import removal in the network interface (#4381)
- fix: Make the 'Angle Between' node report the signed angle and fix its zero-vector output (#4362)
- change: Add Vec2 support to the scalar math operator nodes (#4360)
- change: Add a Connect Cells option to the 'Grid' node (#4374)
- change: Add additional tests to the network interface (#4370)
- change: Box big enum variants to satisfy Clippy's lint warnings (#4292)
- change: Break apart the enormous network_interface.rs into submodules (#4371)
- change: Deduplicate the network interface query helpers and collapse TransientMetadata into TransientCache (#4382)
- change: Improve number fields/labels in the UI to filter out floating point noise and truncate at correct precision (#4363)
- change: Introduce the NetworkView read cursor with typed errors and convert the network queries onto it (#4376)
- change: Make double-clicking a text layer begin editing in shallow select mode, not just deep select mode (#4373)
- change: Make the network interface's queries take &self instead of &mut self (#4378)
- change: Move session state out of the network interface caches and replace the selection hijacks with explicit parameters (#4379)
- change: Move the math expression parser from Pest to Chumsky and add more features (#2685)
- change: New nodes: 'Sign', 'Distance', 'Cross Product', and 'Lerp' (#4361)
- change: Replace NodeTemplate's parallel node and metadata trees with a single flat recursive shape (#4377)
- change: Replace raw node input indices with compile-time parameter symbols (#4387)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
GraphiteEditor/Graphite was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 29 July 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 5927eff0597b0caea7a1d808c909920ff9f90f9d — the exact code this score is about.
- Scored under rubric-2026.08.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer latest.