Skip to content
CAI
Software that uses CAICheck a score

HigherOrderCO/Bend

48.6

Weak · 27 September 2026

18k

lines of production code

TypeScript

with C, JavaScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Bend is a programming language and runtime system that emphasizes formal verification, featuring a theorem prover and infrastructure for machine-checked proofs of program invariants. It provides a comprehensive standard library with support for file I/O, concurrency, and data structures, alongside a robust compiler and interpreter that enforce memory safety and termination. The system includes tooling for code formatting, automated testing gates, and performance benchmarking across multiple execution backends.

Features

Add a formatting-only Bend 2 language server

A new language server (bend2-fmt-lsp) has been added to provide automatic code formatting for Bend and Bend 2 source files. It integrates a custom formatter that handles indentation, spacing around operators, and preservation of comments and literals, and exposes this via the standard LSP document formatting capability so editors can format code on demand.

tools/bend-fmt-lsp · high confidence

Added ten new formal verification evals across five difficulty tiers

The evals directory now includes ten new proof-size evaluation files, with two added to each of the easy, firm, and hard tiers (cake, easy, firm, hard). These new tests cover diverse verification scenarios including memory allocation (arena carving), UI theme mirroring, queue prefix trimming, inventory tree pruning, streaming bytecode bijection, stack splitting and merging, timeline phase splicing, looper cue cancellation, pomodoro tallying, and tic-tac-toe undo/redo logic. Each file defines a specific property or law alongside a constructive solution, expanding the benchmark's coverage of formal reasoning capabilities.

evals · high confidence

New IO.args effect and expanded File operations

The effect kit in bend2/effs now includes IO.args, which exposes the program's command-line arguments (excluding runtime flags) to Bend programs. Additionally, the File effect has been expanded with new capabilities: File.read\_at allows reading bytes at a specific offset without changing the file position, File.size returns the file's size in bytes, and File.write\_bytes enables writing a list of raw bytes directly to a file.

bend2/effs · high confidence

New gate infrastructure for automated testing and verification

The repository introduces a new automated testing and verification system consisting of four distinct gates: \repo\ (structure and token limits), \test\ (functional correctness across C, JS, and interpreter lanes), \perf\ (performance benchmarks against hardware-specific pins), and \ping\ (installer, launcher, and hub integration). This system is orchestrated by \\_run.ts\, which executes the gates in parallel with a strict 30-second cap, and relies on \\_lib.ts\ for shared utilities including SSH-based cluster execution, job pooling across 48 mini-computers, and robust session management.

gates · high confidence

Removals

Removal of the legacy file loader module

The \src/loader/mod.rs\ module, which previously handled reading files and parsing them into a definition book using the \ariadne\ library for error reporting, has been removed from the codebase. This change eliminates the specific file-loading and error-display logic that was previously implemented in this location.

src/loader · high confidence

Removal of the legacy hvm-lang parser and lexer

The \src/parser\ directory, which previously contained the \lexer.rs\, \parser.rs\, and \mod.rs\ files for the hvm-lang language, has been completely removed. This deletes the custom implementation that used the \logos\ and \chumsky\ crates to tokenize and parse hvm-lang source code into an AST. Users relying on this specific parser module for hvm-lang syntax will no longer have access to it in this location, as the code has been stripped from the repository.

src/parser · high confidence

Removed legacy src/main.rs entry point

The original \src/main.rs\ file, which served as the initial CLI entry point for loading and printing AST books, has been deleted. This removal reflects the project's transition to a more comprehensive CLI structure (managed in other parts of the codebase) that supports multiple commands, modes, and configuration options, replacing the simple single-file argument parser with a more robust implementation.

src · high confidence

Removed stub hvm-core compilation function

The \src/to\_core/mod.rs\ file, which previously contained a stub \book\_to\_hvm\_core\ function, has been removed. This eliminates the placeholder implementation for converting the AST definition book to the hvm-core format, reflecting the ongoing reorganization and migration to the new hvm repository structure.

_src/to\core · high confidence

Behavioural changes

App demos gain formal verification with laws and proofs

The 2D and 3D application demos (Pong, Triangle, Ray Tracer, Slash Boss, and the 'Winning Is Impossible' game) now include formal verification artifacts. Each demo ships with a \LAWS.bend\ file defining behavioral invariants (such as escape-to-quit, key-press handling, and game-specific logic) and a \PROOF.bend\ file that provides machine-checked proofs for those laws, ensuring the core logic holds for all possible inputs.

demos · high confidence

Bend is now licensed under Apache 2.0

The repository now includes a LICENSE file adopting the Apache License, Version 2.0, replacing the previous licensing terms. This change clarifies the permissions, conditions, and limitations for using, modifying, and distributing the Bend language and its associated tools.

(repo-wide) · high confidence

Removal of legacy AST module definitions

The \src/ast/mod.rs\ file has been deleted, removing the previous definitions for the Abstract Syntax Tree, including \DefinitionBook\, \Definition\, \Rule\, \Pattern\, \Term\, \Name\, \Number\, and \NumOper\. This change indicates that the AST structure has been refactored or replaced by other modules (such as \hvmc::LBook\ or new type definitions in other files), meaning users relying on these specific types or the previous AST representation will need to adapt to the new structure.

src/ast · high confidence

Runtime benchmarks and performance pins updated for Apple M4 hardware

The \bench/runtime\ directory now contains a standardized structure with one subdirectory per benchmark (e.g., \bfs\, \editdist\, \gameoflife\), each including the source \main.bend\ file and its native twins in C, Lean, and TypeScript. New performance pin files (\apple\_m4.txt\ and \apple\_m4\_max.txt\) have been added to record baseline execution times and memory usage for sequential CPU, parallel CPU, and parallel GPU modes on Apple M4 hardware, providing a reference for future performance regression checks.

bench/runtime · high confidence

Updated checker benchmark pins for Apple M4 and M4 Max

New performance baseline files have been committed for the checker benchmarks on Apple M4 and M4 Max hardware. These pin files record execution times for five verification tools (Isabelle, Agda, Lean, Rocq, and Bend) across four test suites (defs\_12800, generics\_3200, proofs\_3200, and trees\_400), providing a reference for measuring regression or improvement in type-checking and proof-checking performance.

bench/checker · high confidence

Test coverage

Added base library tests for List, Map, Set, Array, String, and numeric types; Added compile tests for alias definitions, array operations, and erasure semantics; Added comprehensive test coverage for compile-time template features; Added proof tests for the theorem prover; Added regression tests for array memory safety and borrow inference; Added stuck-reduction tests for the interpreter; Added tests for IO argument parsing, array depth limits, and audio effect reachability; Added tests for array operations, concurrency, and language semantics; Added tests for error pages and error messages; Added tests for flatten module edge cases and error handling; Added tests for linear App state, scripted App.play, and consistent window-open failure handling; Added tests for the left-to-right structural descent law; Ported check tests from bend3 to Bend; Test coverage for import validation, naming, and unsafe law tracking; Tests for parse/parse location updates.

Housekeeping

Bend 2.0.31

This release updates the version number to 2.0.31. The commit log indicates this is a minor version bump that includes various internal refinements and fixes, such as ensuring the help text's backticks are properly escaped to prevent template literal errors in the CLI, and correcting the layout packer to assign field offsets only once. No new user-facing features or behavioral changes are introduced in this specific update.

bend2 · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 45 → 49 (+3.6)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 47 (-53.2)
  • Architecture 99 (new)
  • Maturity 61 → 59 (-1.7)
  • Readiness 25 → 35 (+10.0)
  • Security 55 → 87 (+31.8)

Resolved (19)

  • Dimension evaluation failed
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • LLM evaluation failed
  • No automated tests
  • No exposed public API
  • No tests found
  • Test reliability not included

New (135)

  • Change coupling: ping.ts ↔ repo.ts (gates/ping.ts)
  • FileTooLong: bend2/bend.ts (bend2/bend.ts)
  • FileTooLong: bend2/comp.ts (bend2/comp.ts)
  • FileTooLong: bend2/main.ts (bend2/main.ts)
  • FileTooLong: bend2/safe.ts (bend2/safe.ts)
  • FileTooLong: intro/render.js (bend2/docs/intro/render.js)
  • FunctionTooLong: gen_anim.game (bend2/docs/gen_anim.ts)
  • FunctionTooLong: gen_anim.parallel (bend2/docs/gen_anim.ts)
  • Hotspot: bend2/bend.ts (bend2/bend.ts)
  • Hotspot: bend2/comp.ts (bend2/comp.ts)
  • Hotspot: bend2/docs/gen_anim.ts (bend2/docs/gen_anim.ts)
  • Hotspot: bend2/docs/intro/render.js (bend2/docs/intro/render.js)
  • Hotspot: bend2/main.ts (bend2/main.ts)
  • Hotspot: gates/test.ts (gates/test.ts)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • …and 115 more

Changes since last survey

  • 300 commits — 294 feature/other, 6 fixes

By area

  • bend2/comp.ts — 65 commits
  • (root) — 64 commits
  • bend2/main.ts — 27 commits
  • bend2/bend.ts — 21 commits
  • bend2/effs — 17 commits
  • guide/GUIDE.md — 15 commits
  • tests/check — 15 commits
  • (repo) — 11 commits
  • tests/io — 8 commits
  • bend2/base.bend — 7 commits
  • bend2/docs — 7 commits
  • gates/repo.ts — 7 commits
  • gates/ping.ts — 5 commits
  • tests/comptime — 5 commits
  • tests/compile — 4 commits
  • bench/runtime — 3 commits
  • tests/import — 3 commits
  • tests/run — 3 commits
  • guide/EFFECTS.md — 2 commits
  • tests/parse — 2 commits

Notable commits

  • fix: A GPU span under the fixed region fails with its message, not a segfault
  • fix: Bend 2.0.23: Array.map walks the block, and five fixes from the issue scan
  • fix: Bend 2.0.8: one executable per platform, no self-update, a daily version check, +field patterns, the hub client fixed, WONTFIX's RUNTIME section
  • fix: Metal folds a constant U32 dividend within 128 of 2^32 through an f32, so U32 division and remainder now divide the halved dividend and fix the odd bit (#824)
  • fix: Revert "Prevent exponential memory usage for deeply nested product types in the C backend (#844)"
  • fix: WONTFIX.txt lists what Bend will not fix, and why
  • change: --check-only checks a file and its imports without running main or building it
  • change: A !-free program on macOS builds as plain C; it no longer takes the Objective-C lane
  • change: A + on a binder is a quantity mark, not a rebinding let
  • change: A - local is erased again: its name is dead and its value is checked dead
  • change: A Bend binary starts in 2 ms: the arena maps 8 GiB and doubles in place
  • change: A C table's F32 row is the constant's own bits
  • change: A GPU out-of-heap reports at once, not after seconds of aliased allocation
  • change: A List Cons spare survives val_box over a sum: Pair no longer steals it from Scalar (#987)
  • change: A Nat literal past 256n parses as U32.to_nat(n), up to the u32 bound
  • change: A Nix flake at the root installs the release archive for the host, written by the site's release.ts so the version and sums are never bumped by hand (#830)
  • change: A U32 table carries the default a bit pattern's variable is
  • change: A bang marks its caller forky, not its callee
  • change: A click that refocuses a Bend window is delivered
  • change: A constructor of any width builds on C: term_drop walks a node past 247 words as an array (#1068)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

HigherOrderCO/Bend was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit af569d4826913b2ce3557e9829ccad31fcf86f94 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-7c1cb6328e11.