jeremyjh/dialyxir
73.3
Strong · 23 September 2026
3.7k
lines of production code
Elixir
primary language
5
measurements over time
What this system is
This system is Dialyxir, an Elixir wrapper for the Dialyzer static analysis tool that integrates type checking into the Mix build process. It manages Persistent Lookup Tables (PLTs) for dependencies and provides a configurable mix task to run analysis with various output formats, including GitHub-compatible and ignore-file styles. The tool also includes a dedicated task to explain specific warning types and ensures robust handling of ignore rules and umbrella project structures.
How it got here
2013–2014 — Initial project scaffolding and dialyzer task introduction
5 changes.
The project was initialized with essential configuration, documentation, and environment pinning, establishing the foundational structure for the codebase. A new configurable dialyzer mix task was introduced to manage PLTs and static analysis, accompanied by dependency updates and test coverage for OTP 28 compatibility.
2016–2018 — warning filtering and test coverage expansion
7 changes.
This period focused on enhancing Dialyxir's usability by introducing structured warning filtering, multiple output formats, and a standalone explain task for detailed warning information. Significant effort was also dedicated to expanding test coverage for core components, including PLT handling, ignore file parsing, and umbrella project support, ensuring robust behavior across various configurations.
2019–2026 — Dialyzer test coverage expansion
5 changes.
This period focused on expanding the test suite for Dialyxir by adding comprehensive fixtures for various Dialyzer warning scenarios. The work included creating test cases for function applications, callback mismatches, opaque types, and guard failures, as well as verifying the handling of ignored warnings and custom ignore file formats. These additions ensured robust detection of warnings and prevented crashes in edge cases involving configuration precedence.
Features
Initial project scaffolding and configuration
The repository is initialized with essential configuration files: a \.formatter.exs\ to standardize code formatting, a \.dialyzer\_ignore.exs\ to suppress known false-positive warnings from Erlang internals (\:erl\_types\), a \.gitignore\ to exclude build artifacts and PLT files, and a \.tool-versions\ file pinning the development environment to Elixir 1.20.3 and Erlang 29.0.5. Documentation and licensing are established via \README.md\, \CHANGELOG.md\, \LICENSE\, and \NOTICE\.
(repo-wide) · high confidence
New dialyzer mix task with configurable PLT management and output formats
Introduces the \mix dialyzer\ task, which compiles the project, manages Persistent Lookup Tables (PLTs) for dependencies, and runs the Dialyzer static analysis tool. Users can now control PLT behavior via configuration options like \plt\_add\_apps\, \plt\_ignore\_apps\, and \plt\_core\_path\, and customize warning output using the \--format\ flag (supporting \dialyxir\, \github\, \raw\, and \ignore\_file\ formats). The task also supports \--quiet\ modes, \--force-check\ for local dependencies, and \--ignore-exit-status\ to prevent halting on warnings, providing a more flexible and configurable static analysis experience.
lib/mix/tasks · high confidence
Behavioural changes
Expanded Dialyzer warning coverage and improved message formatting
Dialyxir now supports a significantly broader set of Dialyzer warnings, including new handlers for OTP 28 features like \exact\_compare\, \opaque\_compare\, and \opaque\_union\, as well as previously missing checks such as \map\_update\, \contract\_range\, and \callback\_not\_exported\. The warning output has been refactored to provide clearer, more detailed explanations for users, with specific improvements to how function contracts, guards, and opaque types are displayed in both short and long formats.
lib/dialyxir/warnings · high confidence
Introduces structured warning filtering and multiple output formatters
Dialyxir now uses a new \FilterMap\ module to track and report unused warning filters, ensuring that ignore rules are actually applied. The tool supports multiple output formats via the \--format\ flag, including \dialyzer\, \dialyxir\, \github\, \ignore\_file\, \ignore\_file\_strict\, \raw\, and \short\, allowing users to choose the style that best fits their workflow or CI integration.
lib/dialyxir · high confidence
Standalone dialyzer.explain task for warning details
The \dialyzer.explain\ functionality has been moved from the main \dialyzer\ task into a standalone Mix task. Users can now run \mix dialyzer.explain\ without arguments to list all available warning atoms, or provide a specific warning name (e.g., \mix dialyzer.explain pattern\_match\) to display detailed information about that specific warning.
lib/mix/tasks/dialyzer · high confidence
Warning emitted when dialyxir application starts
The dialyxir application now emits a warning when its start function is called, indicating that the dependency was likely not configured with \runtime: false\. This change helps users avoid unnecessary application starts and increased build times by encouraging the recommended dependency configuration in \mix.exs\.
lib · high confidence
Test coverage
Added dialyzer ignore warning fixture; Added regression test fixture for plt\_add\_apps precedence; Added test examples for Dialyxir warning scenarios; Added test fixture for Elixir umbrella project structure; Added test fixture for custom empty ignore file handling; Added test fixture for strict ignore file format; Added test fixtures for ignore file parsing; Added tests for OTP 28 warning formatters; Added tests for dialyzer task behavior and flags; Added unit tests for Dialyxir core components.
Dependencies
Dialyxir 1.4.8 release with updated dependencies
This release updates the project to version 1.4.8 and bumps the \erlex\ dependency to version 0.2.8, along with updating \ex\_doc\ to 0.40.3. The release also includes test fixtures to validate configuration options such as \plt\_core\_path\, \plt\_ignore\_apps\, and \no\_umbrella\.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 70 → 73 (+3.5)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 98 → 98 (+0.4)
- Architecture 100 → 100 (+0.0)
- Maturity 56 → 56 (+0.0)
- Readiness 64 → 79 (+15.1)
- Security 100 → 96 (-4.0)
Resolved (5)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — no supported dependency manifest was read
- No exposed public API
- Off-boarding risk: anonymized user #1
- Test reliability not included
New (17)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (28 lines × 2) (lib/dialyxir/warnings/callback_argument_type_mismatch.ex)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- No dependency advisory monitoring
- Off-boarding risk: anonymized user #1
- Outdated: erlex
- Outdated: ex_doc
- TodoComment (lib/dialyxir/warnings/call_without_opaque.ex)
- TodoComment (lib/dialyxir/warnings/contract_subtype.ex)
- TodoComment (test/dialyxir/formatter_test.exs)
- Unbounded dependency requirement: erlex
- Workflow token permissions not restricted
Changes since last survey
- 7 commits — 4 feature/other, 3 fixes
By area
- (repo) — 4 commits
- (root) — 2 commits
- test/fixtures — 1 commit
Notable commits
- fix: Fix operator precedence for loading apps in plt_add_apps
- fix: Merge branch 'master' into fix/ignoring-by-line
- fix: Merge pull request #584 from lud-wj/fix/ignoring-by-line
- change: Merge pull request #601 from BobbieBarker/docs/exdoc-0.40
- change: Merge pull request #604 from jessestimpson/plt-add-apps-load-precedence
- change: Release 1.4.8
- change: Update ExDoc to 0.40.3
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
jeremyjh/dialyxir was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit f4fd5b7edcc4f00ab8393bed04fbb136188e503f — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.