Skip to content
CAI
Software that uses CAICheck a score

joernio/joern

65.7

Adequate · 27 September 2026

111.6k

lines of production code

Scala

primary language

3

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a static analysis platform that converts source code and binaries from numerous languages into a unified Code Property Graph (CPG). It provides a suite of language-specific frontends for parsing, alongside core modules for data flow analysis, security scanning, and interactive console-based querying. The tool supports both open-source and commercial analysis pipelines, enabling developers to trace code execution, detect vulnerabilities, and visualize program structure.

How it got here

2019–2021 — Frontend expansion and console refactoring

55 changes.

This period focused on significantly expanding language support by introducing new CPG frontends for C/C++, Ghidra binary analysis, and Jimple bytecode, alongside consolidating the build infrastructure. The console architecture was refactored into modular components to improve workspace management and query execution, while the introduction of a central query database and macro infrastructure standardized security analysis workflows.

2022 — New language frontend development

59 changes.

This period focused on the introduction and stabilization of multiple new language frontends, including Kotlin, PHP, JavaScript/TypeScript, and Python. Significant work involved implementing core parsing, AST creation, and type resolution for these languages, alongside extensive test coverage to ensure correctness. The release also included architectural improvements to the CLI, such as a new console interface and advanced analysis commands for code slicing and flow tracing.

2023 — multi-language frontend expansion

57 changes.

This period focused on the initial release and development of new source-to-CPG frontends for Ruby, Go, Rust, C\#, and Swift, significantly broadening the project's language support. Concurrently, existing frontends like Java, Kotlin, and Jimple underwent major architectural refactoring to modularize AST creation and improve scope management. The work was complemented by extensive test coverage additions and CI infrastructure updates to support the growing ecosystem.

2024–2026 — New frontend development and language support

35 changes.

This period focused on introducing initial support for new programming languages, specifically Rust and ABAP, while significantly enhancing type resolution and scope handling in existing C\#, Ruby, and Java frontends. The work also included standardizing launcher scripts across tools and expanding test coverage for HTTP server modes and modern C++ features to ensure stability and correctness.

Features

Add ARM function parsing pass for Ghidra frontend

The Ghidra frontend now includes a dedicated ArmFunctionPass to handle ARM architecture binaries. This new pass extends the base FunctionPass and utilizes the ArmProcessor to parse functions, creating the corresponding method, block, and return nodes in the Code Property Graph (CPG). It also handles function parameters and local variables, ensuring that ARM-specific code is correctly decompiled and represented in the analysis graph.

joern-cli/frontends/ghidra2cpg/src/main/scala/io/joern/ghidra2cpg/passes/arm · high confidence

Add CFR-based decompilation and recursive JAR unpacking support

The jimple2cpg frontend now supports decompiling Java class files using CFR when Jimple source is unavailable, and handles nested archives (JARs inside JARs) with configurable recursion depth. This allows the tool to process more complex inputs by extracting and analyzing classes from deeply nested archives, while also emitting configuration files found during unpacking.

joern-cli/frontends/jimple2cpg/src/main/scala/io/joern/jimple2cpg/util · high confidence

Add EJS template preprocessing support

The JavaScript source-to-CPG frontend now supports preprocessing EJS template files. A new EjsPreprocessor class handles EJS-specific syntax by stripping script tags, ignoring comments and includes, and transforming output tags (like \<%= and \<%-) into fake function calls to ensure they are correctly detected as sinks in the control flow graph.

joern-cli/frontends/jssrc2cpg/src/main/scala/io/joern/jssrc2cpg/preprocessing · high confidence

Add Kotlin frontend (kotlin2cpg) with Bazel build support

Introduces the kotlin2cpg frontend, enabling users to analyze Kotlin source code. This change adds the Bazel build configuration (BUILD file) for compiling the frontend and its tests, along with shell scripts (kotlin2cpg.sh) and a launcher script (jar\_from\_aar.sh) to facilitate running the tool and handling Android Archive dependencies.

joern-cli/frontends/kotlin2cpg · high confidence

Add general-purpose utility scripts for code analysis

New scripts have been added to the general category to assist with code analysis workflows. The \list-funcs.sc\ script allows users to retrieve a list of all method names from the currently loaded Code Property Graph (CPG). Additionally, \help.sc\ and \run.sc\ provide validation checks to ensure help text is available and that the base layer has been correctly applied, respectively. A \scripts.json\ manifest has also been introduced to register these scripts within the CLI's general script collection.

joern-cli/src/main/resources/scripts/general · high confidence

Add php2cpg frontend for PHP to CPG conversion

Users can now convert PHP source code into Code Property Graphs (CPG) using the new php2cpg frontend. This tool relies on the php-parse library to generate JSON ASTs from PHP files (requiring PHP \>=7.0), which are then converted into CPGs. The change introduces the build configuration (BUILD), entry-point scripts (php2cpg.sh, php2cpg.bat), and documentation (README.md) necessary to build and run this specific frontend.

joern-cli/frontends/php2cpg · high confidence

Added MSVC support and improved system header auto-discovery in C2C

The C2C frontend now supports automatic discovery of system include paths for MSVC projects on Windows, in addition to the existing GCC support. This change introduces a new \GccSpecificExternalCommand\ utility to handle external command execution and updates \IncludeAutoDiscovery\ to detect MSVC installations via \vswhere.exe\ and \vcvars64.bat\, ensuring that C and C++ headers are correctly resolved for Visual Studio projects. It also includes a workaround for a Windows-specific issue where GCC header discovery commands return an unexpected exit code.

joern-cli/frontends/c2cpg/src/main/scala/io/joern/c2cpg/utils · high confidence

Added script runner documentation and test utilities

The scripts directory now includes a README explaining how to use the \runScript\ method to execute scripts within a Joern session, along with utility scripts for testing: \assertions.sc\ provides an \assertContains\ helper for validating script outputs, and \trigger-error.sc\ is a simple script designed to throw an exception for testing error handling.

joern-cli/src/main/resources/scripts · high confidence

C\# frontend AST creation implementation

The C\# source-to-CPG frontend now includes the core AST creation logic in the \astcreation\ package. This implementation handles the translation of C\# source code into the Code Property Graph, covering top-level statements, class and record declarations, method signatures, and control flow structures like loops and switch statements. It also supports expression handling, including member access, property setters, and type resolution, enabling the frontend to parse and analyze C\# codebases.

joern-cli/frontends/csharpsrc2cpg/src/main/scala/io/joern/csharpsrc2cpg/astcreation · high confidence

C\# frontend adds dependency downloading, implicit usings support, and AST generation utilities

The C\# frontend now automatically downloads and summarizes NuGet dependencies to improve symbol resolution, supports implicit global usings defined in .csproj files (including Include/Remove directives), and introduces a dedicated runner for the dotnetastgen tool to handle native binary execution and output parsing. These changes are implemented in new utility classes (DependencyDownloader, ImplicitUsingsCollector, DotNetAstGenRunner, ProgramSummaryCreator) alongside helper functions for method signature composition and top-level statement handling.

joern-cli/frontends/csharpsrc2cpg/src/main/scala/io/joern/csharpsrc2cpg/utils · high confidence

C\# frontend introduces AST and dependency parsing passes

The C\# frontend now includes dedicated passes for generating the Control Flow Graph (AST) and extracting project dependencies. The new AstCreationPass processes source files in parallel to build the AST, while the DependencyPass parses C\# project files (XML) to extract package references and versions, registering them as dependency nodes in the code property graph.

joern-cli/frontends/csharpsrc2cpg/src/main/scala/io/joern/csharpsrc2cpg/passes · high confidence

Distribution includes launcher scripts for new language frontends and CLI tools

The joern-cli distribution now ships with executable wrapper scripts for a broad set of language frontends (abap2cpg, c2cpg, csharpsrc2cpg, ghidra2cpg, gosrc2cpg, javasrc2cpg, jimple2cpg, jssrc2cpg, kotlin2cpg, php2cpg, pysrc2cpg, rubysrc2cpg, rust2cpg, swiftsrc2cpg) and core CLI commands (joern, joern-cpg2scpg, joern-export, joern-flow, joern-parse, joern-scan, joern-slice, joern-vectors). These scripts ensure the frontends and tools are launched with consistent JVM options (G1GC, 128m compressed class space, log4j2 config) and handle platform-specific path resolution, making these capabilities immediately available in the installed distribution.

joern-cli/src/universal · high confidence

Experimental Bazel build system support

Joern now includes an experimental Bazel build system, allowing developers to build and test the project using Bazel alongside the existing SBT setup. This change introduces Bazel configuration files (MODULE.bazel, BUILD, .bazelrc) and documentation (bazel.md), enabling builds for a subset of frontends (e.g., javasrc2cpg, jssrc2cpg, kotlin2cpg, pysrc2cpg, rubysrc2cpg, rust2cpg, swiftsrc2cpg) and supporting features like multi-platform builds for AST generators. The Bazel build is currently experimental, not used in CI or for releases, and requires Bazelisk and specific IntelliJ plugins.

(repo-wide) · high confidence

Ghidra2cpg frontend integration and startup script

The ghidra2cpg frontend is now integrated as a single project within the build, accompanied by a new README detailing setup requirements (OpenJDK 11, sbt) and known issues, along with a shell script (ghidra2cpg.sh) that serves as the entry point to execute the staged binary.

joern-cli/frontends/ghidra2cpg · high confidence

Go frontend introduces initial AST creation and dependency processing passes

The Go source-to-CPG frontend now includes a set of new processing passes to handle the initial stages of code analysis. This adds \AstCreationPass\ for generating the main Abstract Syntax Tree from Go source files, \InitialMainSrcPass\ and \DependencySrcProcessorPass\ for building pre-processing caches from main and dependency sources respectively, and \PackageCtorCreationPass\ to handle package-level constructors. Additionally, \DownloadDependenciesPass\ is introduced to automatically fetch and process Go module dependencies, enabling the frontend to analyze code that relies on external packages.

joern-cli/frontends/gosrc2cpg/src/main/scala/io/joern/gosrc2cpg/passes · high confidence

Go source-to-CPG frontend adds AST generation runner and utility constants

The Go frontend now includes a dedicated AST generation runner (GoAstGenRunner) that executes the external goastgen binary, handles platform-specific binaries (Windows, Linux, macOS on x86/ARM), filters input files, and segregates parsed results by Go module structure. Additionally, a new Constants file provides utility patterns for file separators and operator identifiers, supporting the underlying AST generation and parsing logic.

joern-cli/frontends/gosrc2cpg/src/main/scala/io/joern/gosrc2cpg/utils · high confidence

Improved MIPS data-flow tracking for Lo/Hi registers and return values

The ghidra2cpg MIPS frontend now adds explicit data-flow edges for architecture-specific behaviors. A new LoHiPass creates REACHING\_DEF edges linking instructions that write to the MIPS Lo/Hi registers (e.g., div, mul) to those that read from them (e.g., mflo, mfhi), enabling better tracking of intermediate calculation results. Additionally, a new MipsReturnEdgesPass connects call sites to their return values by linking calls to the specific v0/v1 register arguments, improving the accuracy of return value analysis in the generated code property graph.

joern-cli/frontends/ghidra2cpg/src/main/scala/io/joern/ghidra2cpg/passes/mips · high confidence

Improved type resolution for Java modules and JAR archives

The Java source-to-CPG frontend now includes a new \JarTypeSolver\ that enhances type resolution by properly handling JAR and JMOD archives, as well as the Java runtime image (\lib/modules\). This change ensures that type information is correctly extracted from module exports and bytecode, reducing unresolved symbol errors when analyzing code that depends on external libraries or JDK internals.

joern-cli/frontends/javasrc2cpg/src/main/scala/io/joern/javasrc2cpg/typesolvers/noncaching · high confidence

Initial AST creation and type handling passes for Rust frontend

The Rust frontend now includes core processing passes to handle source code analysis. AstCreationPass enables parallel processing of Rust files by reading JSON AST output and building the Code Property Graph, while RustTypeNodePass manages type name resolution using full-to-short name mapping. Additionally, RustConfigFileCreationPass automatically detects and processes Rust project configuration files including Cargo.toml, Cargo.lock, and rust-toolchain.toml.

joern-cli/frontends/rust2cpg/src/main/scala/io/joern/rust2cpg/passes · high confidence

Initial AST creation support for Rust source code

The rust2cpg frontend now includes the core AST creation logic for converting Rust source files into the Code Property Graph. This change introduces the AstCreator, ContextStack, and RustVisitor components, which handle the traversal of Rust syntax trees and the generation of CPG nodes for items such as functions, structs, enums, and modules. It also implements the RustFullNames trait to compute qualified names for types and methods, and defines specific operators for Rust-specific expressions like tuple literals, array repeats, await, and try-unwrap.

joern-cli/frontends/rust2cpg/src/main/scala/io/joern/rust2cpg/astcreation · high confidence

Initial Bazel build support for pysrc2cpg frontend

The pysrc2cpg frontend now includes a Bazel build configuration (BUILD file) that defines the Scala library, Java CC parser generation, test targets, and distribution packaging. This change introduces experimental Bazel build system support, allowing the frontend to be built and tested using Bazel alongside existing build methods.

joern-cli/frontends/pysrc2cpg · high confidence

Initial Bazel build support for x2cpg

The x2cpg module now includes a Bazel BUILD file and associated Java source files to enable building with the Bazel build system. This introduces a dedicated java\_library target for Java sources required by annotation processors, a scala\_library target for the main Scala code, and a scala\_test target for tests. It also adds a resource file containing PHP known function signatures and test code fixtures (C source files and symlinks) to support the build and test environments.

joern-cli/frontends/x2cpg · high confidence

Initial C\# JSON AST parser infrastructure

The C\# frontend now includes a new JSON-based AST parser layer. This introduces a comprehensive type hierarchy in \DotNetJsonAst\ covering C\# language constructs such as statements, expressions, types, and literals, alongside a \DotNetJsonParser\ to read and structure the JSON input. This provides the foundational data structures required for subsequent AST-to-CPG translation.

joern-cli/frontends/csharpsrc2cpg/src/main/scala/io/joern/csharpsrc2cpg/parser · high confidence

Initial C\# source-to-CPG frontend release

Introduces the C\# frontend (csharpsrc2cpg) for converting C\# source code into the Code Property Graph. The tool parses C\# projects by leveraging the DotNetAstGen tool to generate ASTs, then processes them to create nodes for metadata, types, methods, and dependencies. It supports optional downloading of external dependencies to resolve symbols and provides command-line options to disable built-in type summaries or specify paths to external summary files.

joern-cli/frontends/csharpsrc2cpg/src/main/scala/io/joern/csharpsrc2cpg · high confidence

Initial C2C parser implementation with JSON compilation database support

The C2C parser module is introduced, providing the core infrastructure for parsing C and C++ source files into the Code Property Graph. This includes the main CdtParser class which leverages the Eclipse CDT library, along with supporting components for file discovery (HeaderFileFinder), configuration management (ParserConfig, FileDefaults), and logging of parse problems and preprocessor statements. A key addition is the JSONCompilationDatabaseParser, which allows the parser to ingest compilation commands from a compile\_commands.json file to automatically resolve include paths and macro definitions, improving parsing accuracy for complex projects.

joern-cli/frontends/c2cpg/src/main/scala/io/joern/c2cpg/parser · high confidence

Initial Go source-to-CPG frontend AST creation logic

The \gosrc2cpg\ frontend now includes the core AST creation implementation in the \astcreation\ package. This adds the \AstCreator\ class and supporting traits (such as \AstForExpressionCreator\, \AstForFunctionsCreator\, and \AstForStatementsCreator\) that parse Go source JSON and generate Code Property Graph nodes for expressions, functions, statements, and type declarations. This change enables the tool to construct the initial structural representation of Go code for analysis.

joern-cli/frontends/gosrc2cpg/src/main/scala/io/joern/gosrc2cpg/astcreation · high confidence

Initial PHP frontend AST creation implementation

The PHP frontend (php2cpg) now includes the core AST creation logic, enabling the conversion of PHP source code into the Code Property Graph. This implementation covers the parsing and graph generation for a wide range of PHP language constructs, including control structures (if, while, for, foreach, switch, try-catch), expressions (binary/unary operators, casts, ternary, match, yield), declarations (classes, methods, closures, namespaces, traits, enums), and statements (echo, unset, global, use). It also handles specific PHP features such as static method resolution, closure variable capture, and array unpacking, while managing file content encoding and scope resolution to ensure accurate dataflow and call graph analysis.

joern-cli/frontends/php2cpg/src/main/scala/io/joern/php2cpg/astcreation · high confidence

Initial configuration and logging setup for rust2cpg

The rust2cpg frontend now includes its own application configuration and logging setup. An application.conf file defines the rust\_ast\_gen\_version as 0.25.1, specifying the version of the AST generator used for parsing. Additionally, a log4j2.xml file configures console logging with a highlighted pattern, defaulting to the 'info' level unless overridden by the SL\_LOGGING\_LEVEL environment variable.

joern-cli/frontends/gosrc2cpg/src/main/resources, joern-cli/frontends/rust2cpg/src/main/resources · high confidence

Initial configuration for ABAP frontend

The ABAP frontend now includes its default configuration files. The application configuration sets the ABAP AST generator version to 0.5.1, and logging is configured to output to the console with a color-coded pattern, defaulting to the INFO level unless overridden by the SL\_LOGGING\_LEVEL environment variable.

joern-cli/frontends/abap2cpg/src/main/resources · high confidence

Initial implementation of the JavaScript/TypeScript source frontend AST creation

The \jssrc2cpg\ frontend now includes the core AST creation logic in the \astcreation\ package, introducing \AstCreator\ and its supporting traits (\AstForDeclarationsCreator\, \AstForExpressionsCreator\, \AstForFunctionsCreator\, \AstForPrimitivesCreator\, \AstForStatementsCreator\, and \AstCreatorHelper\). This implementation enables the conversion of JavaScript and TypeScript source code (parsed via Babel) into the Code Property Graph, covering support for declarations (classes, interfaces, exports, imports), expressions (calls, member access, assignments), functions (including decorators and rest parameters), primitives (literals, identifiers), and statements (control flow, try-catch, loops).

joern-cli/frontends/jssrc2cpg/src/main/scala/io/joern/jssrc2cpg/astcreation · high confidence

Initial implementation of the JavaScript/TypeScript source-to-CPG parser

The JavaScript/TypeScript frontend (jssrc2cpg) has been initialized with core parsing infrastructure. This change introduces the Babel AST node definitions (BabelAst.scala) to map Babel's JSON output to internal representations, a JSON parser (BabelJsonParser.scala) to load and process AST files along with optional type maps, and node metadata structures (BabelNodeInfo.scala). This provides the foundational capability to ingest JavaScript and TypeScript source code into the Code Property Graph.

joern-cli/frontends/jssrc2cpg/src/main/scala/io/joern/jssrc2cpg/parser · high confidence

Initial implementation of the jssrc2cpg frontend passes

This change introduces the core processing pipeline for the new JavaScript/TypeScript frontend (jssrc2cpg) within the Joern CLI. It adds a suite of passes that handle the end-to-end creation of the Code Property Graph (CPG) for JavaScript projects: AstCreationPass manages the parallel parsing of source files using astgen and Babel; ConfigPass identifies and ingests configuration files (including .pug, .vue, and .html); DependenciesPass extracts dependency metadata from package.json files; ImportsPass resolves CommonJS require statements; and JavaScriptMetaDataPass records project metadata. Additionally, it includes specialized passes for handling private key files securely, managing type node naming conventions, and defining EcmaScript built-ins.

joern-cli/frontends/jssrc2cpg/src/main/scala/io/joern/jssrc2cpg/passes · high confidence

Initial instruction mapping support for ARM, MIPS, X86, and PCode in ghidra2cpg

The ghidra2cpg frontend now includes processor-specific instruction mappers for ARM, MIPS, X86, and Ghidra's PCode intermediate representation. These new files define how specific assembly instructions and PCode operations are translated into Code Property Graph (CPG) operators (such as assignments, calls, and control flow), enabling the tool to analyze binaries for these architectures.

joern-cli/frontends/ghidra2cpg/src/main/scala/io/joern/ghidra2cpg/processors · high confidence

Initial parser infrastructure for Go source-to-CPG conversion

The Go source frontend now includes a new parser layer that reads Go AST JSON output and maps it to internal node types. This adds GoAstJsonParser to deserialize AST JSON and go.mod files, ParserAst to define the set of supported Go AST node types (expressions, statements, primitives, declarations), and ParserNodeInfo to carry node metadata such as source location and code snippets.

joern-cli/frontends/gosrc2cpg/src/main/scala/io/joern/gosrc2cpg/parser · high confidence

Initial release of Joern Query Database with Android security scanners

The querydb module is introduced as the central query database for Joern, providing a standalone library of security and metrics queries that can be used with or without the full Joern installation. This release includes a new Android query bundle containing scanners for critical vulnerabilities such as arbitrary file writes, external storage code execution, intent-based command injection, insecure JavaScript interfaces, and misconfigurations like tap-jacking and backup exposure. It also adds a \dumpq\ utility to export the query database to JSON and establishes the foundational structure for query bundles, tags, and author metadata.

querydb · high confidence

Initial release of jssrc2cpg JavaScript/TypeScript frontend

Adds the jssrc2cpg frontend, a Babel-based parser that generates Code Property Graphs for JavaScript and TypeScript source code. The change introduces the build configuration (BUILD), a launcher script (jssrc2cpg.sh), and documentation (README.md) for the tool, which relies on native astgen binaries to parse source files.

joern-cli/frontends/jssrc2cpg · high confidence

Initial release of the Go source-to-CPG frontend

Adds the \gosrc2cpg\ tool, enabling users to convert Go source code into the Code Property Graph (CPG). The frontend parses Go modules, optionally fetches direct or indirect dependencies for enhanced type information, and generates AST nodes for constructs such as for-loops, package-level variables, and type declarations.

joern-cli/frontends/gosrc2cpg/src/main/scala/io/joern/gosrc2cpg · high confidence

Initial release of the JavaScript/TypeScript source-to-CPG frontend

Introduces the \jssrc2cpg\ frontend, enabling users to convert JavaScript and TypeScript source code into the Code Property Graph (CPG). The tool leverages an AST generation runner to parse source files and applies a series of passes—including AST creation, type recovery, import resolution, and dependency analysis—to build the graph. Users can invoke the tool via the command line, with support for disabling TypeScript type generation through the \--no-tsTypes\ flag.

joern-cli/frontends/jssrc2cpg/src/main/scala/io/joern/jssrc2cpg · high confidence

Initial release of the PHP frontend (php2cpg)

This change introduces the php2cpg frontend, enabling the conversion of PHP source code into the Code Property Graph (CPG). The new tool parses PHP files using php-parser, supports PHP versions 7.1.0 and above, and includes a dependency pass that processes composer.json files to resolve symbols. It also offers command-line options to specify custom php.ini paths and php-parser binaries, and can optionally download and parse external dependencies.

joern-cli/frontends/php2cpg/src/main/scala/io/joern/php2cpg · high confidence

Initial release of the Rust2CPG frontend

This change introduces the Rust2CPG tool, enabling users to convert Rust source code into a Code Property Graph (CPG) for analysis. The frontend parses Rust files using an external AST generator and constructs the CPG through a series of passes, including AST creation, type node generation, and configuration file handling. Users can control the conversion process via command-line options to skip sysroot loading or bypass the resolution of \#\[cfg(...)\] attributes, providing flexibility for faster processing or specific configuration needs.

joern-cli/frontends/gosrc2cpg, joern-cli/frontends/rust2cpg/src/main/scala/io/joern/rust2cpg · high confidence

Initial release of the Swift source-to-CPG frontend

This change introduces the \swiftsrc2cpg\ frontend, a new tool that parses Swift source code and generates Code Property Graphs (CPG). It relies on the \SwiftAstGen\ binary (bundled at version 0.4.4) to extract the AST, which is then processed by a suite of Scala passes to create nodes for declarations, expressions, statements, and types. The frontend supports command-line options for defining macros, enabling early schema validation, and optionally using the Swift compiler (\--swift-build\) to retrieve full type information. It also includes build configuration for Bazel and standard logging setup.

joern-cli/frontends/swiftsrc2cpg · high confidence

Initial scaffolding for the Ruby source-to-CPG frontend

The \joern-cli/frontends/rubysrc2cpg\ directory is introduced with the foundational build and configuration files for the new Ruby frontend. This includes a Bazel \BUILD\ file defining the Scala library, test suite, and binary distribution, alongside a \.gitignore\ to manage generated artifacts like type stubs and the embedded \ruby\_ast\_gen\ binary. A shell script (\rubysrc2cpg.sh\) is added to launch the application with the correct logging configuration, and a \README\ documents the dependency on the \parser\ Gem and the embedded AST generator.

joern-cli/frontends/rubysrc2cpg · high confidence

Initial support for Rust code analysis via rust2cpg

This change introduces the initial build infrastructure and entry point for the rust2cpg frontend, enabling users to analyze Rust source code. It adds a Bazel BUILD file that defines the Scala library, tests, and binary distribution for the tool, along with a shell script wrapper to launch the executable with the correct logging configuration.

joern-cli/frontends/rust2cpg · high confidence

Introduce ABAP Code Property Graph frontend

Adds a new frontend that converts ABAP source files into a Code Property Graph (CPG) for analysis with Joern. The implementation includes a shell wrapper (abap2cpg.sh) to invoke the converter, which relies on external abapgen binaries to parse ABAP into JSON and then transforms that into CPG nodes via Scala passes. Documentation (README.md, architecture.md) is provided to guide users through building the frontend, generating the CPG, and running queries such as finding authorization checks or potential command injection vulnerabilities.

joern-cli/frontends/abap2cpg, joern-cli/frontends/abap2cpg/src/main/scala · high confidence

Introduce C2CPG AST creation implementation

The C2CPG frontend now includes its own AST creation logic, implemented in the \AstCreator\ class and a set of focused traits (\AstForExpressionsCreator\, \AstForFunctionsCreator\, \AstForInitializersCreator\, \AstForPrimitivesCreator\, \AstForStatementsCreator\, and \AstForTypesCreator\). This new implementation translates the Eclipse CDT AST into the Code Property Graph, handling C and C++ constructs such as binary and unary expressions, function declarations and definitions, initializers, identifiers, control flow statements, and type declarations. It also introduces scope-local unique naming for anonymous entities, safe handling of CDT resolution errors (including \StackOverflowError\), and support for C++17/20 features like structured bindings, lambdas, and fold expressions.

joern-cli/frontends/c2cpg/src/main/scala/io/joern/c2cpg/astcreation · high confidence

Introduce C2Cpg frontend for C/C++ code property graph generation

The C2Cpg frontend is now available in the joern-cli to parse C and C++ source code into a Code Property Graph (CPG). This new component supports standard source files, preprocessed files (.i), and JSON Compilation Database inputs (compile\_commands.json). It allows users to configure header include paths, enable auto-discovery of system headers, skip function bodies, and log preprocessor statements or parsing problems. The frontend handles AST creation for both source and header files, manages type declarations, and ensures unique full names for methods and types within the generated graph.

joern-cli/frontends/c2cpg/src/main/scala/io/joern/c2cpg · high confidence

Introduce Kotlin CPG type system and call classification

The kotlin2cpg frontend now includes a dedicated types package that establishes the foundational type handling for the Code Property Graph. This adds a \CallKind\ enumeration to distinguish between static, dynamic, extension, and unknown calls, and introduces a \TypeInfoProvider\ that leverages the Kotlin compiler's binding context to accurately classify these call types and resolve property descriptors. A \NameRenderer\ is added to translate Kotlin type descriptors into Java-compatible full names, including mapping Kotlin primitives to their Java equivalents and handling nested class naming conventions. Additionally, a \ContentSourcesPicker\ is provided to intelligently identify source directories by analyzing the project structure for \.kts\ files, and \TypeConstants\ define standard type identifiers used throughout the analysis.

joern-cli/frontends/kotlin2cpg/src/main/scala/io/joern/kotlin2cpg/types · high confidence

Introduce PHP frontend parser infrastructure and domain models

Adds the core parsing components for the new PHP frontend, including the \PhpParser\ class which orchestrates the external PHP-Parser tool and processes its JSON output, the \Domain\ object defining the internal AST node structures (such as classes, methods, and operators) and modifier handling, and the \ClassParser\ for extracting high-level symbol information. This change establishes the foundational data structures and parsing logic required to convert PHP source code into the Code Property Graph.

joern-cli/frontends/php2cpg/src/main/scala/io/joern/php2cpg/parser · high confidence

Introduce c2cpg frontend for C/C++ code analysis

Adds the c2cpg frontend, a new tool that parses C and C++ source code into Code Property Graphs using the Eclipse CDT parser. This release includes support for various C++17 and C++20 language features (such as folding expressions, inline variables, and constexpr if), provides a self-published version of the cdt-core dependency for easier integration, and supplies build scripts (Bazel and sbt) along with a CLI entry point for generating CPGs from C/C++ projects.

joern-cli/frontends/c2cpg · high confidence

Introduce ghidra2cpg frontend for binary analysis

Adds a new \ghidra2cpg\ frontend that converts binary executables into the Code Property Graph (CPG) using the Ghidra reverse-engineering framework. The implementation includes a main entry point (\Main.scala\) and the core frontend logic (\Ghidra2Cpg.scala\), which initializes a headless Ghidra environment, loads the input binary, and runs architecture-specific passes for MIPS, ARM, and x86 to extract functions, control flow, and types. It also integrates standard passes for metadata, namespaces, jumps, and literals, while silencing Ghidra's verbose console output to reduce noise.

joern-cli/frontends/ghidra2cpg/src/main/scala/io/joern/ghidra2cpg · high confidence

Introduce jimple2cpg frontend for Java CPG generation

Adds the jimple2cpg frontend, enabling users to generate Code Property Graphs (CPG) from Java class files, JARs, and Android APK/DEX files. The tool leverages the Soot framework to parse bytecode and construct the AST, supporting recursive JAR unpacking with configurable depth, optional decompilation of class files to Java source, and specific handling for Android applications (including dynamic package/directory marking). It also generates metadata, type nodes, declaration reference edges, and config files as part of the standard x2cpg pipeline.

joern-cli/frontends/jimple2cpg/src/main/scala/io/joern/jimple2cpg · high confidence

Introduce jimple2cpg frontend for Soot's Jimple IR

Adds the jimple2cpg frontend, formerly known as Plume, which converts Soot's Jimple IR into a Code Property Graph (CPG). This change introduces the necessary build artifacts, shell scripts (jimple2cpg.sh), and documentation (README.md) to allow users to generate CPGs from Jimple-based Java code and import them into Joern.

joern-cli/frontends/jimple2cpg · high confidence

Introduce query database and macro infrastructure for Joern

The macros module now provides the core infrastructure for defining, discovering, and executing code queries. It introduces a \QueryDatabase\ that automatically scans classpaths for query bundles (classes implementing \QueryBundle\) and instantiates queries using reflection, supporting default argument injection for parameters. A new Scala 3 macro, \withStrRep\, allows query authors to capture the source code of traversal lambdas as string representations, which are stored alongside the executable traversal logic in the \Query\ case class. This enables the console to display the original query code alongside its results.

macros · high confidence

Introduce scan pass and finding output utilities

Adds a new ScanPass component in the console module that executes security queries against the Code Property Graph (CPG) and collects findings. To prevent undefined behavior caused by nested parallelism with the data-flow engine, the pass runs sequentially using CpgPass rather than a parallel variant. The change also includes helper utilities to format and print human-readable scan results to standard output, including sorting by score and displaying evidence locations.

console/src/main/scala/io/joern/console/scan · high confidence

Introduce structured workspace and project management components

The console now uses new \Project\, \Workspace\, \WorkspaceLoader\, and \WorkspaceManager\ classes to manage code analysis projects. \Project\ tracks the state of individual codebases (including loaded CPGs and applied overlays), while \Workspace\ provides a unified view of all projects and renders them in a formatted table. \WorkspaceManager\ handles the lifecycle of these projects, including creating directories, persisting metadata in \project.json\, and managing the underlying file system structure for CPG storage and overlays.

console/src/main/scala/io/joern/console/workspacehandling · high confidence

Introduces Kotlin compiler environment builder with assertion-error resilience

Adds a new \CompilerAPI\ component in the Kotlin frontend that constructs the \KotlinCoreEnvironment\ for analysis. This implementation configures content roots, Java source roots, and JDK home, while specifically handling resource-based dependencies by copying them to temporary files to satisfy JVM classpath requirements. It also integrates a custom logger factory that suppresses \AssertionError\ exceptions from the underlying Kotlin compiler's default logger, allowing the analysis to continue on a best-effort basis rather than failing on internal compiler errors.

joern-cli/frontends/kotlin2cpg/src/main/scala/io/joern/kotlin2cpg/compiler · high confidence

Introduction of OSS Data Flow Engine with Data Dependence Graph Visualization

The dataflowengineoss module now provides a complete, standalone data flow analysis engine. It introduces a new ANTLR grammar for defining flow semantics and a DefaultSemantics object that configures taint tracking for common C and Java operators and library functions. The engine computes reaching definitions to build a Data Dependence Graph (DDG), which is now visualizable via new layer creators that dump DDG, Program Dependence Graph (PDG), and full CPG dot files. Additionally, the language API is extended with implicit conversions for traversing data flows (ddgIn, reachableBy) and rendering path results in tables.

dataflowengineoss/src/main · high confidence

Introduction of the semanticcpg module with access path analysis and graph visualization

This change introduces the \semanticcpg\ module, establishing a new location for core semantic analysis capabilities. It adds a comprehensive access path algebra system (\AccessPath\, \AccessElement\, \TrackedBase\) to model and track memory references, including support for pointer shifts, indirection, and address-of operations. Additionally, it provides a suite of DOT graph generators (\AstGenerator\, \CallGraphGenerator\, \CfgGenerator\, \TypeHierarchyGenerator\) for visualizing code structure, control flow, and type hierarchies, alongside a \CodeDumper\ for source code extraction and highlighting.

semanticcpg · high confidence

JavaScript/TypeScript frontend introduces AST generation runner and package dependency parser

The jssrc2cpg frontend now includes a dedicated AstGenRunner utility to manage the external astgen binary, handling environment variable configuration (ASTGEN\_BIN), file filtering (excluding minified, transpiled, test, and config files), and graceful error handling during parsing. Additionally, a new PackageJsonParser utility has been added to extract project dependencies from package.json and package-lock.json files, supporting caching for performance. These changes enhance the robustness and configurability of the JavaScript/TypeScript source-to-CPG conversion process.

joern-cli/frontends/jssrc2cpg/src/main/scala/io/joern/jssrc2cpg/utils · high confidence

JavaSrc2cpg frontend now supports Bazel builds

The JavaSrc2cpg frontend now includes a Bazel build configuration (BUILD file), allowing users to build and test the component using Bazel in addition to the existing sbt workflow. This change introduces Bazel rules for the main library, tests, and binary distribution, integrating the frontend into the project's Bazel workspace.

joern-cli/frontends/javasrc2cpg · high confidence

New C code analysis scripts for memory safety and const correctness

Added a new set of built-in analysis scripts for C code in the Joern CLI, including detection of malloc memory leaks, potential integer overflows in malloc size arguments, assignments of pointer arithmetic results to integers, and accesses to userspace memory addresses. The release also introduces scripts to identify functions that may be marked as const and to detect assignments to const parameters or struct members, alongside a comprehensive list of Linux syscalls. These scripts are registered in the new scripts.json manifest for easy discovery.

joern-cli/src/main/resources/scripts/c · high confidence

New CLI commands for code slicing, flow analysis, and vector embeddings

The \joern-cli\ module now includes dedicated commands for advanced code analysis: \joern-slice\ extracts data-flow or usage slices from a CPG with configurable filters (e.g., method names, annotations, operator exclusion) and parallelism; \joern-flow\ traces data flows between source and sink parameters with configurable depth and verbose output; and \joern-vectors\ generates vector embeddings of code nodes and methods using feature hashing, with an option to map dimensions back to features. These commands rely on the new \CpgBasedTool\ and \DefaultOverlays\ utilities to automatically apply default and data-flow overlays when missing, ensuring consistent analysis across all new tools.

joern-cli/src/main/scala/io/joern/joerncli · high confidence

New GoMod model for dependency tracking and namespace resolution

The gosrc2cpg frontend now includes a dedicated GoMod model (GoMod.scala) to parse go.mod files and track dependency usage. This enables the frontend to resolve correct namespaces for code units by combining the module path with file paths, and to identify which external dependencies are actually used by the codebase. The model supports serialization of module metadata and dependency details, including indirect status and specific packages imported, facilitating more accurate code property graph generation for Go projects.

joern-cli/frontends/gosrc2cpg/src/main/scala/io/joern/gosrc2cpg/model · high confidence

New Java source frontend now reads type signatures from JAR files

The Java source frontend (javasrc2cpg) now includes a new \JarTypeReader\ component that parses Java class files directly from JAR archives to extract detailed type information. This change introduces a new internal type model and a combinator-based descriptor parser to resolve class signatures, method signatures, and field types, enabling the frontend to capture generic type arguments and complex type structures that were previously unavailable when only source code was analyzed.

joern-cli/frontends/javasrc2cpg/src/main/scala/io/joern/javasrc2cpg/jartypereader · high confidence

New Rust JSON parser and AST node syntax extensions

The rust2cpg frontend now includes a new RustJsonParser that reads AST data from JSON files, exposing metadata like crate name and module path, and provides an isMacroExpanded helper to distinguish macro-expanded nodes. Additionally, RustNodeSyntaxExtensions adds convenience accessors for range expressions, literals, name references, binary and prefix operators, if-else branches, and index expressions to compensate for missing codegen in the underlying rust\_ast\_gen library.

joern-cli/frontends/rust2cpg/src/main/scala/io/joern/rust2cpg/parser · high confidence

New gadget analysis script for binary analysis

A new script named gadgets.sc has been added to the binary analysis resources. This script allows users to identify potential return-oriented programming (ROP) gadgets by extracting the five instructions preceding each return node in the control flow graph and saving the results to /tmp/gadgets.txt.

joern-cli/src/main/resources/scripts/binary · high confidence

New linter rules for code style and iteration safety

The linter-rules module now includes three new scalafix rules: UnorderedIteration flags order-sensitive operations (such as foreach, map, or toList) on non-deterministic collections like HashMap or HashSet to prevent inconsistent analysis results; RestrictedImports warns against using BetterFiles and scala.sys.process in favor of internal utilities; and SingleLetterIdentifiers flags variable and parameter names that are too short to improve readability.

linter-rules · high confidence

New utility functions for Kotlin PSI object and destructuring handling

The Kotlin frontend now includes a new \PsiUtils\ object that provides helper methods for working with Kotlin PSI elements. Specifically, it adds \nonUnderscoreDestructuringEntries\ to filter out underscore placeholders from destructuring declarations, and \objectIdxMaybe\ to calculate the index of an object declaration within its containing scope by traversing the tree. These utilities support more accurate parsing and indexing of Kotlin object expressions and destructuring patterns.

joern-cli/frontends/kotlin2cpg/src/main/scala/io/joern/kotlin2cpg/psi · high confidence

PHP frontend introduces dedicated scope management and dependency downloading utilities

The PHP frontend now includes new utility classes to improve code analysis accuracy and project setup. A new \Scope\ and \ScopeElement\ implementation provides robust handling of namespaces, types, and methods, ensuring unique naming for anonymous classes, temporary variables, and closures to prevent duplicates. Additionally, a \DependencyDownloader\ utility automatically fetches and extracts PHP dependencies from Packagist, placing them in a temporary directory for parsing, while an \ArrayIndexTracker\ supports precise tracking of array access patterns.

joern-cli/frontends/php2cpg/src/main/scala/io/joern/php2cpg/utils · high confidence

Python parser now supports pattern matching syntax

The Python parser in the pysrc2cpg frontend has been updated to recognize and parse Python 3.10+ pattern matching constructs (the \match\/\case\ statement). This change introduces new AST nodes for match statements, match cases, and various match guards (such as \MatchValue\, \MatchSingleton\, \MatchSequence\, \MatchMapping\, \MatchClass\, \MatchStar\, \MatchAs\, and \MatchOr\), allowing static analysis tools to correctly model code using structural pattern matching.

joern-cli/frontends/pysrc2cpg/src/main/scala/io/joern/pythonparser · high confidence

Ruby frontend adds configuration file parsing and dependency resolution passes

The Ruby source-to-CPG frontend now includes dedicated passes to parse configuration files and resolve project dependencies. The new ConfigFileCreationPass identifies and processes Gemfiles, Gemfile.lock, YAML, XML, and ERB files to populate the configuration layer. Additionally, the DependencyPass parses Gemfile and Gemfile.lock contents to extract gem names, versions, and source URLs, creating corresponding dependency nodes in the graph. These changes enable better tracking of project structure and external library usage within the analyzed Ruby codebase.

joern-cli/frontends/rubysrc2cpg/src/main/scala/io/joern/rubysrc2cpg/passes · high confidence

Ruby frontend introduces program summary and typed scope data structures

The Ruby source-to-CPG frontend now includes core data structures to support type recovery and import resolution. A new \RubyProgramSummary\ class manages namespace-to-type mappings and loads built-in type stubs from bundled ZIP files, enabling the frontend to resolve types for standard library classes. Additionally, \RubyScope\ and \ScopeElement\ provide a typed scope mechanism that tracks variables, fields, and types across different scope levels (program, module, type, method, and block), allowing for more accurate static analysis of Ruby code.

joern-cli/frontends/rubysrc2cpg/src/main/scala/io/joern/rubysrc2cpg/datastructures · high confidence

kotlin2cpg: introduce jar4import service for dependency resolution

The \kotlin2cpg\ frontend now supports fetching dependency JARs via an external \jar4import\ service. Users can provide the service URL using the new \--jar4import-url\ CLI flag. When this service is configured, the frontend queries it for dependency coordinates based on import names found in the source files and downloads the required JARs, enabling more accurate type resolution for external dependencies without relying solely on local Gradle/Maven resolution.

joern-cli/frontends/kotlin2cpg/src/main/scala/io/joern/kotlin2cpg · high confidence

Architecture

Kotlin frontend AST creation logic is refactored into modular traits

The Kotlin frontend's AST generation code has been restructured from a single monolithic class into a set of focused traits (AstForDeclarationsCreator, AstForExpressionsCreator, AstForFunctionsCreator, AstForPrimitivesCreator, and AstForStatementsCreator) mixed into the main AstCreator. This change improves code organization and maintainability by separating concerns for different Kotlin language constructs, without altering the resulting Code Property Graph output.

joern-cli/frontends/kotlin2cpg/src/main/scala/io/joern/kotlin2cpg/ast · high confidence

Refactor Java source AST creation into modular declaration handlers

The Java source frontend (javasrc2cpg) has restructured its AST creation logic by extracting method, lambda, and type declaration handling into dedicated, separate traits (AstForMethodsCreator, AstForTypeDeclsCreator, and AstForDeclarationsCreator). This modularization improves code organization and maintainability for the internal AST generation process, while preserving existing functionality for method, constructor, and type resolution.

joern-cli/frontends/javasrc2cpg/src/main/scala/io/joern/javasrc2cpg/astcreation/declarations · high confidence

Refactor Java source AST creation into modular expression handlers

The \javasrc2cpg\ frontend has restructured its AST generation logic by extracting expression handling from the monolithic \AstCreator\ into a set of specialized, composable traits located in the \expressions\ package. This change introduces dedicated creators for call expressions (\AstForCallExpressionsCreator\), lambdas (\AstForLambdasCreator\), name expressions (\AstForNameExpressionsCreator\), pattern expressions (\AstForPatternExpressionsCreator\), simple expressions (\AstForSimpleExpressionsCreator\), and variable declarations/assignments (\AstForVarDeclAndAssignsCreator\). These traits are unified in \AstForExpressionsCreator\, which now serves as the central dispatcher for all Java expression types. This modularization improves code maintainability and isolates specific parsing concerns, such as lambda capture binding and pattern matching initialization, into their own implementation units.

joern-cli/frontends/javasrc2cpg/src/main/scala/io/joern/javasrc2cpg/astcreation/expressions · high confidence

Refactored Java statement AST creation into modular components

The Java source-to-CPG frontend has reorganized its AST generation logic for statements into dedicated, modular traits: \AstForForLoopsCreator\ handles \for\ and \foreach\ loops, while \AstForSimpleStatementsCreator\ manages control structures like \if\, \while\, \do-while\, \switch\, \try-catch\, and other simple statements. This refactoring, located in the \astcreation/statements\ package, improves code maintainability and isolation without changing the external behavior of the generated code property graph.

joern-cli/frontends/javasrc2cpg/src/main/scala/io/joern/javasrc2cpg/astcreation/statements · high confidence

Ruby AST creation refactored into focused internal traits

The \AstCreator\ class in the Ruby source-to-CPG frontend has been decomposed from a single monolithic implementation into a set of focused internal traits (\AstCreatorHelper\, \AstForStatementsCreator\, \AstForExpressionsCreator\, \AstForControlStructuresCreator\, \AstForFunctionsCreator\, and \AstForTypesCreator\). This structural change organizes the AST generation logic by Ruby language construct (e.g., separating control structures, expressions, functions, and types), improving code maintainability and separation of concerns within the \rubysrc2cpg\ module.

joern-cli/frontends/rubysrc2cpg/src/main/scala/io/joern/rubysrc2cpg/astcreation · high confidence

Behavioural changes

Added x86-specific control flow and return edge passes

The ghidra2cpg frontend now includes two new passes for x86 binaries: ReturnEdgesPass and X86FunctionPass. ReturnEdgesPass identifies return values by detecting calls where the RAX/EAX register is used as an argument, creating REACHING\_DEF edges to model data flow. X86FunctionPass handles the structural decomposition of x86 functions, explicitly managing control flow graph (CFG) edges while skipping connections after unconditional jumps (JMP) to preserve correct execution paths. These changes improve the accuracy of the control flow and data flow graphs generated for x86 architectures.

joern-cli/frontends/ghidra2cpg/src/main/scala/io/joern/ghidra2cpg/passes/x86 · high confidence

Build infrastructure consolidated and upgraded to sbt 1.12.5

The project's build system has been restructured into a single consolidated \project\ directory, replacing the previous multi-module meta-build setup. This change upgrades the build tool to sbt 1.12.5 and updates sbt-native-packager to 1.11.1. A new \Versions.scala\ file centralizes dependency management, and helper utilities like \DownloadHelper\ and \UrlRetry\ have been introduced to improve download reliability with retry logic. The build now explicitly requires JDK 13+ and defines a comprehensive list of subprojects, including frontends like \javasrc2cpg\, \ghidra2cpg\, and \x2cpg\.

project · high confidence

C\# frontend adds configuration and colorful logging

The C\# source-to-CPG frontend now includes an application configuration file that sets the dotnetastgen tool version to 0.43.0, alongside a new log4j2 configuration that enables colored console output for improved readability.

joern-cli/frontends/csharpsrc2cpg/src/main/resources · high confidence

C\# frontend introduces program summaries and enhanced scope resolution

The C\# frontend now supports program summaries, allowing it to load and merge type stubs from external JSON files and built-in type bundles to improve type resolution. This change introduces a new scope mechanism that handles global imports, resolves fully-qualified names without explicit imports, and supports extension method matching, resulting in more accurate code property graph generation for C\# projects.

joern-cli/frontends/csharpsrc2cpg/src/main/scala/io/joern/csharpsrc2cpg/datastructures · high confidence

C2CPG: Ensures unique fullNames for methods, type declarations, and namespace blocks

The C2CPG frontend now guarantees that method, type declaration, and namespace block fullNames are unique across the entire Code Property Graph. Previously, duplicate fullNames could occur when the same symbol appeared in multiple translation units (e.g., static functions in different files or classes split across headers and implementations), which violated CPG specification requirements for linking and querying. A new \FullNameUniquenessPass\ runs after AST creation to detect these duplicates and appends stable, location-based suffixes to resolve conflicts. Additionally, calls and bindings referencing the affected methods are updated to reflect the new unique fullNames, ensuring that downstream analysis tools can correctly resolve and link code elements without ambiguity.

joern-cli/frontends/c2cpg/src/main/scala/io/joern/c2cpg/passes · high confidence

Console architecture refactored into modular components with server-mode output capture

The console module has been restructured into a set of focused components: BridgeBase now handles CLI argument parsing and configuration, Console manages the interactive workspace and project lifecycle, and PluginManager handles plugin installation and removal. A new Commit component allows users to apply pending graph changes, while Run dynamically generates analyzer commands based on available LayerCreators. Additionally, server-mode users will now see captured output from the REPL session, as GlobalReporting now aggregates reported strings for retrieval outside the REPL context.

console/src/main/scala/io/joern/console · high confidence

Eclipse CDT core integration now uses a custom, OSGI-free logging plugin

The C2CPG frontend now bundles a stripped-down version of the Eclipse CDT core library (version 9.2.100) to run without the full Eclipse OSGI runtime. A new \CCorePlugin.java\ replaces the original Eclipse class to provide a simplified logging mechanism backed by SLF4J, preventing initialization exceptions in parser components that rely on this plugin. The release process has been updated to download the official CDT JAR, exclude its original signature and plugin class, inject the custom implementation, and publish the resulting artifact to Sonatype Central for use by Joern.

joern-cli/frontends/c2cpg/eclipse-cdt · high confidence

Ghidra2cpg migration to ForkJoinParallelCpgPass

The Ghidra frontend's analysis passes (FunctionPass, JumpPass, LiteralPass, MetaDataPass, NamespacePass, and PCodePass) have been refactored to extend ForkJoinParallelCpgPass instead of the previous SimpleCpgPass base class. This change updates the internal execution model to use parallel processing for analyzing functions and other code elements, which should improve performance and scalability when decompiling binaries into the Code Property Graph.

joern-cli/frontends/ghidra2cpg/src/main/scala/io/joern/ghidra2cpg/passes · high confidence

Improved type resolution for modular JDKs and non-standard archives

The Java source frontend now resolves types more reliably in complex environments. It introduces \BytecodeIndexedClassPath\ to handle fat JARs, repackaged JARs, and JMODs by reading the actual package declaration from bytecode rather than relying on file paths. It also adds \JrtRuntimeImageClassPath\ to support JDK modular runtime images (JEP 220), ensuring type information is available even when only a minimal \jlink\ image is present. Additionally, an \EagerSourceTypeSolver\ preloads type information from source files to speed up resolution, while \TypeSizeReducer\ removes method bodies from parsed types to reduce memory usage.

joern-cli/frontends/javasrc2cpg/src/main/scala/io/joern/javasrc2cpg/typesolvers · high confidence

Introduce configurable astgen version and colored logging for jssrc2cpg

The jssrc2cpg frontend now uses astgen version 3.50.1, as defined in the new application.conf configuration file, and provides colored console logging via a new log4j2.xml configuration that highlights log levels.

joern-cli/frontends/jssrc2cpg/src/main/resources · high confidence

Kotlin2CPG frontend introduces parallel AST creation and dedicated type recovery passes

The Kotlin frontend now uses \ForkJoinParallelCpgPassWithAccumulator\ for AST creation to improve performance and deduplicate types and SAM implementations across files. It adds a new \KotlinTypeRecoveryPassGenerator\ to handle type inference for Kotlin-specific constructs like \this\/\super\ confusion and import aliases. Additionally, it introduces \SamTypeDeclPass\ to explicitly model Single Abstract Method types, \DependenciesFromMavenCoordinatesPass\ to parse Maven coordinates into dependency nodes, and \KotlinTypeHintCallLinker\ to refine call resolution by excluding specific operators and unresolved namespaces.

joern-cli/frontends/kotlin2cpg/src/main/scala/io/joern/kotlin2cpg/passes · high confidence

New AST and declaration reference passes for Jimple2CPG

The jimple2cpg frontend now includes three new processing passes: AstCreationPass, SootAstCreationPass, and DeclarationRefPass. AstCreationPass and SootAstCreationPass handle the creation of the Abstract Syntax Tree (AST) layer from class files and Soot classes respectively, utilizing the ForkJoinParallelCpgPassWithAccumulator pattern for parallel processing and accumulating used types. DeclarationRefPass establishes declaration reference edges by linking method identifiers to their corresponding declaration nodes, addressing the flat AST structure of bytecode.

joern-cli/frontends/jimple2cpg/src/main/scala/io/joern/jimple2cpg/passes · high confidence

New AST creation architecture for Jimple2CPG

The Jimple2CPG frontend now uses a new AstCreator pattern that splits AST generation into dedicated traits for declarations, expressions, and statements. This refactoring improves how the tool translates Jimple bytecode into the Code Property Graph, specifically enhancing control-flow handling and error resilience during decompilation. Users benefit from more accurate AST nodes for binary/unary expressions, method invocations, and object allocations, with better support for try-catch blocks and unhandled Soot types.

joern-cli/frontends/jimple2cpg/src/main/scala/io/joern/jimple2cpg/astcreation · high confidence

New AlmaLinux-based Docker images for Joern

The CI pipeline now provides new container images based on AlmaLinux 9 and 8, replacing previous base images. These include standard images (Dockerfile.alma, Dockerfile.alma8) and a new slim variant (Dockerfile.slim) that reduces OS packages and excludes plugins to minimize size. The images use Java 17, set JOERN\_HOME to /opt/joern/joern-cli, and default to running the joern command via CMD.

ci · high confidence

New CPG generator architecture and expanded language support

The console now uses a new \CpgGenerator\ interface and factory to manage language frontends, replacing the previous implementation. This change introduces dedicated generator classes for ABAP, C/C++, C\# (both commercial and OSS), Go, Java (commercial and OSS), JavaScript, Kotlin, LLVM, PHP, Python, Ruby, Rust, and Swift. The \ImportCode\ API has been updated to expose these as \importCode.\<language\>\ methods (e.g., \importCode.abap\, \importCode.csharpsrc\), and the system now automatically detects the language based on file extensions or directory contents. Several frontends (Java, C\#, Go) now support both commercial and open-source variants, falling back to the OSS version if the commercial one is unavailable. Post-processing passes for type recovery are now automatically applied for source-based frontends like Java, JavaScript, Python, PHP, Ruby, and Swift.

console/src/main/scala/io/joern/console/cpgcreation · high confidence

New source file filtering logic for Kotlin CPG generation

The Kotlin frontend now uses a dedicated \SourceFilesPicker\ component to determine which files are included in the Code Property Graph. This logic explicitly filters out test directories (such as \src/test\, \androidTest\, \jvmTest\), build artifacts (\target\, \build\), and Android layout XMLs, while ensuring that configuration files like \build.gradle\, \build.gradle.kts\, and \.kts\ scripts are preserved and processed.

joern-cli/frontends/kotlin2cpg/src/main/scala/io/joern/kotlin2cpg/files · high confidence

PHP frontend adds internal parser, builtin function list, and configuration resources

The PHP frontend now ships with a bundled ClassParser.php script to parse PHP symbol information, a comprehensive builtin\_functions.txt list for recognizing PHP built-in functions, a php.ini configuration to set memory\_limit to -1 (preventing out-of-memory errors on large files), and a log4j2.xml configuration for colored console logging. These resources support the frontend's static analysis capabilities by providing local parsing logic, function metadata, and stable runtime behavior.

joern-cli/frontends/php2cpg/src/main/resources · high confidence

PHP frontend refactored into parallel CPG passes with dependency and uniqueness handling

The PHP frontend's code analysis pipeline has been restructured into a series of distinct, parallel processing passes. The new \AstCreationPass\ and \AstParsingPass\ handle source file discovery and AST generation using \ForkJoinParallelCpgPass\ for improved performance, while \DependencyPass\ now explicitly parses \composer.json\ to model project dependencies and autoload configurations in the CPG. To resolve naming collisions common in PHP (where the same class name may exist in multiple files), \FullNameUniquenessPass\ ensures all method, type, and namespace full names are unique across the entire graph. Additionally, \SymbolSummaryPass\ gathers importable symbols to support scope resolution, and \DependencySymbolsPass\ creates stub nodes for external dependency classes.

joern-cli/frontends/php2cpg/src/main/scala/io/joern/php2cpg/passes · high confidence

Python parser AST model and location tracking introduced

The Python source-to-CPG frontend now includes a new AST definition layer in the \pythonparser.ast\ package. This introduces a Scala-based model mirroring the CPython AST structure, featuring traits and case classes for statements (e.g., \FunctionDef\, \ClassDef\, \Return\) and expressions. A key addition is the \AttributeProvider\ trait and its implementations (\TokenAttributeProvider\, \NodeAttributeProvider\), which enable precise source location tracking (line numbers, column offsets, and input offsets) for AST nodes. This change establishes the foundational data structures required for the parser to map Python source code elements to the CPG, supporting features like end-line tracking and consistent namespace handling.

joern-cli/frontends/pysrc2cpg/src/main/scala/io/joern/pythonparser/ast · high confidence

Python source-to-CPG frontend rewritten with new architecture and dependency tracking

The \pysrc2cpg\ frontend has been completely rewritten to use the \X2CpgFrontend\ and \X2CpgConfig\ abstractions, introducing a parallel processing pipeline via \ForkJoinParallelCpgPass\ for improved performance. This update adds automatic dependency extraction from \requirements.txt\ files by creating \DEPENDENCY\ nodes in the graph, and expands configuration file support to include \.toml\, \.ini\, \.yaml\, \.jinja2\, \.html\, \.htm\, \Pipfile\, and \Pipfile.lock\. The frontend now supports command-line options to ignore specific paths and directory names, and includes logic to handle Python class and function redefinitions by mangling full names to ensure unique identifiers in the CPG.

joern-cli/frontends/pysrc2cpg/src/main/scala/io/joern/pysrc2cpg · high confidence

Refactor Jimple2CPG declaration handling into dedicated traits

The Jimple-to-CPG frontend now organizes AST creation for declarations into three new, focused traits: \AstForDeclarationsCreator\, \AstForMethodsCreator\, and \AstForTypeDeclsCreator\. This refactoring consolidates the logic for generating AST nodes for classes, methods, and fields, ensuring that modifiers, annotations, and inheritance information are correctly attached to the corresponding nodes in the Code Property Graph.

joern-cli/frontends/jimple2cpg/src/main/scala/io/joern/jimple2cpg/astcreation/declarations · high confidence

Refactor ghidra2cpg utils and silence Ghidra decompiler noise

The ghidra2cpg utility layer has been restructured into dedicated modules: CommandLineConfig provides static CLI arguments, Decompiler wraps the Ghidra DecompInterface with caching, PCodeMapper handles P-code to CPG node translation, Utils contains helper methods for creating CPG nodes, and WarnAndUpErrorLogger suppresses verbose Ghidra progress messages by demoting info and decompiler warnings to debug level, resulting in cleaner console output.

joern-cli/frontends/ghidra2cpg/src/main/scala/io/joern/ghidra2cpg/utils · high confidence

Refactored Java source AST creation into modular traits

The Java source frontend's AST creation logic has been restructured to improve maintainability and separation of concerns. The monolithic \AstCreator\ class now delegates specific responsibilities to focused internal traits: \AstForDeclarationsCreator\ handles method, lambda, and type declarations; \AstForExpressionsCreator\ manages expression parsing; and \AstForStatementsCreator\ processes statements. This decomposition allows for more granular updates and testing of individual AST generation components without affecting the entire creation pipeline.

joern-cli/frontends/javasrc2cpg/src/main/scala/io/joern/javasrc2cpg/astcreation · high confidence

Refactored Java source frontend passes and added AST printing utility

The Java source frontend's processing pipeline has been restructured into dedicated passes: AstCreationPass now handles file parsing and AST generation using a combined type solver (JDK JARs, inference jars, and source), TypeInferencePass resolves unresolved call signatures by matching argument types and method names with a caching mechanism, and OuterClassRefPass explicitly links outer class identifiers to constructor parameters. Additionally, a new JavaParserAstPrinter utility has been added to allow users to output the raw JavaParser YAML representation of source files for debugging or inspection purposes.

joern-cli/frontends/javasrc2cpg/src/main/scala/io/joern/javasrc2cpg/passes · high confidence

Refactored Java source frontend utility layer with new binding and capture logic

The \javasrc2cpg\ utility package has been restructured to improve how the frontend handles method bindings, variable captures, and Lombok processing. A new \BindingTable\ and \BindingTableAdapter\ system now manages method binding resolution, correctly handling generic type parameter overrides and inner class captures. Variable capture detection is now performed by a dedicated \CaptureUseFinder\ that accurately tracks undeclared variables across complex scopes like lambdas, switch expressions, and try-with-resources. Additionally, the \Delombok\ utility has been enhanced to automatically detect Lombok usage by scanning source code, run delombok in parallel, and filter stderr output to prevent silent errors, while \PackageRootFinder\ and \SourceParser\ now provide more robust handling of package structures and Java 25 language level support.

joern-cli/frontends/javasrc2cpg/src/main/scala/io/joern/javasrc2cpg/util · high confidence

Refactored Jimple statement AST creation into a dedicated trait

The logic for converting Jimple statements into Abstract Syntax Tree (AST) nodes has been extracted from the main AstCreator into a new \AstForStatementsCreator\ trait. This change centralizes the handling of specific statement types—including assignments, returns, switches, throws, and monitors—within the \jimple2cpg\ frontend, improving code organization and separation of concerns without altering the resulting code property graph output.

joern-cli/frontends/jimple2cpg/src/main/scala/io/joern/jimple2cpg/astcreation/statements · high confidence

Refactored scope management for precise variable capturing and pattern matching

The \javasrc2cpg\ frontend now uses a new, decomposed scope architecture (\JavaScopeElement\, \Scope\) to improve the accuracy of variable resolution. This change introduces specific scope types (Namespace, Block, Method, Field, TypeDecl) and tracks captured variables, enabling correct handling of lambda captures, inner classes, and Java pattern matching variables. It also adds support for name mangling of local variables to resolve shadowing conflicts and allows users to disable type fallbacks for wildcard imports via a new configuration option.

joern-cli/frontends/javasrc2cpg/src/main/scala/io/joern/javasrc2cpg/scope · high confidence

Replaced legacy REPL with new JoernConsole and ReplBridge

The Joern CLI console has been refactored to use a new \JoernConsole\ implementation and \ReplBridge\ entry point, replacing the previous REPL infrastructure. This change introduces a structured \JoernProject\ model for workspace handling, integrates the OssDataFlow layer by default via \applyDefaultOverlays\, and configures the interactive shell with specific pre-execution imports and commands (such as \ossDataFlowOptions\) defined in \RunBeforeCode\. Users will now interact with a console that explicitly manages data flow semantics and provides a standardized banner and prompt, while the underlying architecture for script execution and shell initialization has been reorganized into these new components.

joern-cli/src/main/scala/io/joern/joerncli/console · high confidence

Ruby frontend configuration and logging setup

The Ruby source-to-CPG frontend now includes explicit configuration for the \ruby\_ast\_gen\ version (0.59.7) and Joern type stubs version (0.6.0) via \application.conf\. Additionally, a \log4j2.xml\ file is introduced to provide colored console logging, enhancing visibility into the parsing process for users.

joern-cli/frontends/rubysrc2cpg/src/main/resources · high confidence

Ruby frontend parser refactored to use a new JRuby-based AST generation runner

The Ruby source-to-code-property-graph frontend now uses a new \RubyAstGenRunner\ that executes the \ruby\_ast\_gen\ tool via a persistent JRuby \ScriptingContainer\. This change introduces a reusable execution environment (with optional sharing across tests) and replaces previous process-spawning mechanisms, improving stability and performance. The parser layer has been restructured to include dedicated classes for handling the JSON AST output (\RubyJsonAst\, \RubyJsonHelpers\, \RubyJsonParser\, \RubyJsonToNodeCreator\), enabling more robust parsing of Ruby syntax elements like aliases, access modifiers, and pattern matching.

joern-cli/frontends/rubysrc2cpg/src/main/scala/io/joern/rubysrc2cpg/parser · high confidence

Ruby source-to-CPG frontend introduces parallel AST generation and type recovery

The \rubysrc2cpg\ frontend now processes Ruby source files using a parallelized architecture: it delegates AST generation to a shared JRuby environment via \RubyAstGenRunner\, then concurrently constructs AST creators and computes program summaries before applying the main \AstCreationPass\. This change also enables built-in type recovery and type stubs by default, adds support for ERB files, and configures default file exclusions for common directories like \spec\, \tests\, \vendor\, and \db\.

joern-cli/frontends/rubysrc2cpg/src/main/scala/io/joern/rubysrc2cpg · high confidence

Rust AST generation now logs stderr and reports skipped files

The Rust frontend's AST generation process now provides better visibility into its execution. When running the underlying rust\_ast\_gen tool, any messages written to standard error are now logged to the application logs. Additionally, the runner parses the tool's output to identify and collect files that were skipped during processing (indicated by 'Skipped:' lines), making it easier to track which source files were not included in the code property graph.

joern-cli/frontends/rust2cpg/src/main/scala/io/joern/rust2cpg/astgen · high confidence

Schema extender project reimplementation and build configuration

The schema extender project has been reimplemented using a new Scala-based DSL, introducing a new FileUtils helper object for recursive file operations and updating the build configuration to use sbt version 1.10.0.

joern-cli/src/universal/schema-extender/project · high confidence

Schema extender rewritten with Scala DSL and FlatGraph

The schema extender tool has been reimplemented using a new Scala-based DSL and the FlatGraph code generation library. This change replaces the previous implementation, allowing users to extend the CPG schema by defining new node types and properties directly in Scala code, which is then processed by the FlatGraph DomainClassesGenerator to produce the updated schema artifacts.

joern-cli/src/universal/schema-extender/schema · high confidence

Shell wrappers added for c2cpg and jssrc2cpg binaries

Shell scripts (c2cpg.sh and jssrc2cpg.sh) have been added to the universal distribution directories for the C and JavaScript/TypeScript frontends. These wrappers resolve the script's absolute path to locate the corresponding binary and configuration files, ensuring the JVM runs with G1GC and a 128m compressed class space, and passes through any additional arguments provided by the user.

joern-cli/frontends/c2cpg/src/universal, joern-cli/frontends/jssrc2cpg/src/universal · high confidence

Simplified C\# frontend startup script with explicit logging configuration

The csharpsrc2cpg frontend now uses a simplified shell wrapper script that explicitly resolves the script's absolute directory to locate the log4j2 configuration file (log4j2.xml) and passes it to the underlying Java process. This ensures consistent logging behavior by directly specifying the configuration file path and disabling log4j lookup patterns for security, rather than relying on default classpath resolution.

joern-cli/frontends/csharpsrc2cpg · high confidence

Standardized launcher scripts for frontend tools

The shell launcher scripts for the C\#, Ghidra, Java, Jimple, and PHP frontends have been replaced with a unified template. These scripts now automatically resolve their absolute paths to locate the main executable and the log4j2 configuration file, ensuring consistent behavior across different operating systems (including macOS and Linux). Additionally, the launchers now explicitly configure the JVM to use the G1 garbage collector and set the compressed class space size to 128 MB, standardizing the runtime environment for these analysis tools.

(repo-wide) · high confidence

javasrc2cpg frontend restructured with new CLI options and environment variables

The javasrc2cpg frontend has been refactored to use the X2CpgMain base class, introducing several new command-line flags and environment variables for users. Users can now control dependency fetching via --fetch-dependencies, configure Delombok behavior with --delombok-java-home and --delombok-mode (including a 'types-only' mode), and enable generic type recovery with --enable-type-recovery. Additional options allow caching the JDK type solver (--cache-jdk-type-solver), preserving type arguments (--keep-type-arguments), disabling type fallbacks (--disable-type-fallback), and enabling verbose type logging for debugging (--enable-verbose-type-logging). Environment variables JAVASRC\_JDK\_PATH, JAVASRC\_FETCH\_DEPENDENCIES, and JAVASRC\_ENABLE\_VERBOSE\_TYPE\_LOGGING provide equivalent configuration. The frontend also supports dumping JavaParser ASTs for debugging via --dump-javaparser-asts and displaying environment variable status via --show-env.

joern-cli/frontends/javasrc2cpg/src/main/scala/io/joern/javasrc2cpg · high confidence

Test coverage

Add PHP test fixture for CPG generation and validation; Added AST test coverage for Rust2Cpg; Added C\# test fixtures for code-to-CPG conversion and data-flow analysis; Added C++ test code for const-correctness scenarios; Added C2Cpg test fixtures and suites; Added Go code-to-CPG test fixtures; Added HTTP server integration tests for pysrc2cpg; Added MIPS-specific test coverage for call arguments and data flow; Added SlimAndroid test fixture for minimal Android app analysis; Added comprehensive parser tests for Python statements; Added comprehensive test coverage for C2Cpg AST creation; Added config tests for multiple frontends; Added dataflow and reaching-definition tests for C code analysis; Added dataflow test suite for Kotlin2CPG; Added dataflow test suite for Python source-to-CPG conversion; Added dataflow tests for Go source-to-CPG conversion; Added dataflow tests for Jimple2CPG querying; Added dataflow tests for Ruby source frontend; Added query tests for Ruby frontend parsing and AST modeling; Added test binaries and coverage script for Ghidra frontend; Added test case for detecting unfreed malloc calls; Added test code for free() usage in linked list; Added test code for malloc overflow detection; Added test code for syscalls and user-space memory access; Added test code for unsafe pointer subtraction scenarios; Added test configuration files for jimple2cpg; Added test coverage for C2C++ type system passes; Added test coverage for C2CPG parsing and metadata passes; Added test coverage for Joern CLI scripting, parsing, and export features; Added test coverage for Kotlin CPG querying capabilities; Added test coverage for console configuration, language detection, and workspace management; Added test coverage for javasrc2cpg querying capabilities; Added test coverage for jssrc2cpg frontend; Added test fixtures and scripts for multiple frontends and features; Added test fixtures for Android app and Kotlin compiler plugins; Added test fixtures for Ghidra binary-to-CPG conversion; Added test fixtures for Java type reader scenarios; Added test fixtures for Jimple data flow analysis; Added test fixtures for the Rust2CPG frontend; Added test resources for JavaSrc2CPG config file detection; Added tests for ARM binary CPG querying; Added tests for C macro expansion and handling; Added tests for C\# AST node creation; Added tests for C\# dependency resolution and metadata generation; Added tests for C\# frontend IO capabilities; Added tests for C++17 language features; Added tests for C++20 feature parsing support; Added tests for C2C PG DOT graph generators; Added tests for C2C control-flow graph creation; Added tests for C2Cpg IO capabilities; Added tests for FullNameSemanticsParser; Added tests for Go module namespace resolution; Added tests for HeaderFileFinder resolution logic; Added tests for JarTypeReader type signature parsing; Added tests for Java source config file discovery and content population; Added tests for Java source-to-CPG type resolution; Added tests for Jimple2CPG jar unpacking behavior; Added tests for Kotlin compiler API and Java interoperability; Added tests for Kotlin2CPG HTTP server mode and source file filtering; Added tests for Kotlin2Cpg dependency resolver V2; Added tests for PHP control flow, dependency resolution, and type recovery passes; Added tests for PHP dataflow analysis capabilities; Added tests for PHP scope resolution and import handling; Added tests for Python CPG generation passes; Added tests for Ruby config file inclusion and type recovery; Added tests for Ruby source-to-CPG HTTP server mode; Added tests for Rust AST generation runner; Added tests for Rust config file inclusion and type node pass; Added tests for TypeRecoveryPass; Added tests for access path handling in the query engine; Added tests for gosrc2cpg HTTP server mode; Added tests for javasrc2cpg utility components; Added tests for kotlin2cpg command-line argument parsing; Added tests for pysrc2cpg configuration and virtual environment exclusion; Added tests for rubysrc2cpg CLI argument parsing and default ignore regex; Added tests for the ABAP code property graph frontend; Added tests for the Rust JSON parser; Added unit tests for Go AST creation passes; Added validation tests for Kotlin CPG generation; C\# frontend test coverage for AST querying; Expanded dataflow test coverage for Java source analysis; Expanded test coverage for Python source-to-CPG conversion; Initial data-flow tests for C\# frontend; New Kotlin test fixture with V3 validation and OSS dataflow support; New Ruby test fixtures with shared JRuby environment and validation; New test fixture for Python frontend validation and data flow testing; New test fixtures for Java source-to-CPG conversion and dataflow analysis; New test fixtures for data-flow analysis configuration; PHP2CPG querying test coverage expanded.

Dependencies

Upgrade to CodePropertyGraph 1.7.77 and Scala 3.8.3

The Joern build system has been updated to use CodePropertyGraph version 1.7.77 and Scala 3.8.3. This upgrade is accompanied by a requirement for JDK 13 or higher for the build process and the addition of a dependency override for Guava 33.5.0-jre to resolve a known bug in the Heros library.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 66.

Lenses

  • Code Health 83
  • Architecture 98
  • Maturity 66
  • Readiness 71
  • Security 56
  • Domain Modelling 100

Changes since last survey

  • 300 commits — 236 feature/other, 64 fixes

By area

  • joern-cli/frontends — 230 commits
  • (root) — 36 commits
  • .github/workflows — 17 commits
  • semanticcpg/src — 6 commits
  • console/src — 2 commits
  • joern-cli/src — 2 commits
  • linter-rules/src — 2 commits
  • bazel/tooling — 1 commit
  • ci/Dockerfile.alma — 1 commit
  • dataflowengineoss/src — 1 commit
  • project/UrlRetry.scala — 1 commit
  • querydb/src — 1 commit

Notable commits

  • fix: Fixed scaladoc warnings (#6077)
  • fix: Revert optional parameter index intergration PR (#6011)
  • fix: [CI] Fix release workflow (#6144)
  • fix: [CI] Fix release-github workflow (#6143)
  • fix: [CI] fix Dockerfile.slim (from platform releases) (#6169)
  • fix: [CI] fix dockerfiles (from platform releases) (#6168)
  • fix: [CI] workaround for scalafix bug (#6247)
  • fix: [c2cpg] Fix missing dataflow through double pointers and address-of operators (#5580) (#6298)
  • fix: [c2cpg] JVM/Scala performance & memory fixes (#6112)
  • fix: [c2cpg] Revert change at MacroHandler.argumentTrees (#6116)
  • fix: [c2cpg][jssrc2cpg][swiftsrc2cpg] More validation fixes (#6085)
  • fix: [console] fix importCode.rust.fromString, add additional fromStringWithExtraDeps (#6054)
  • fix: [docs] Fix Docker image tags in README (#6195)
  • fix: [javasrc2cpg] Fix logic to determine if lib/modules must be used (#6201)
  • fix: [javasrc2cpg] Fix lombok detection (#6074)
  • fix: [javasrc2cpg] fix >>/>>> mixup. (#6231)
  • fix: [jimple2cpg] fix compile failure by scoping guava override to ThisBuild (#6199)
  • fix: [joern-cli] Fix NPE in joern-parse --overlaysonly (#6284)
  • fix: [joern-console] Fix NPE in importCode caused by REPL classloader (#6157)
  • fix: [jssrc2cpg] Fixed dangling locals from class/enum member initializations (#6062)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

joernio/joern was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit a88074bf983250ebe98b68c5b3e54c32c8032b58 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d00c643c3f66.