Skip to content
CAI
Software that uses CAICheck a score

lucasg/Dependencies

45.5

Weak · 22 September 2026

13.2k

lines of production code

C#

with C++

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Windows dependency analysis tool that parses PE files, resolves DLL dependencies, and demangles C++ symbols. It provides a managed .NET interface to native libraries for deep system interaction, including API set and side-by-side assembly resolution. The application features a WPF-based GUI for visualizing module, import, and export data, alongside a CLI for structured output.

How it got here

2017 — Managed interop layer and third-party updates

13 changes.

This period focused on establishing a managed .NET interop layer (ClrPhlib) to bridge native Windows APIs with the UI, alongside significant updates to third-party dependencies like Process Hacker and Dragablz. The work also introduced structured output capabilities for dependency analysis and modernized the build and CI configuration.

2018–2019 — GUI and library refactoring

11 changes.

This period focused on modernizing the application's architecture by introducing a dedicated library for binary caching and PE resolution, alongside a significant overhaul of the GUI layer. The team implemented new data models, UI controls, and demangling utilities to improve performance, cross-platform symbol handling, and user configuration management.

Features

The About dialog has been converted to WPF, displaying the application version and a link to the GitHub issues page. It now includes a 'Check for updates' link that fetches the latest release version from GitHub and displays it, allowing users to easily verify if they are running the newest version.

DependenciesGui · high confidence

Add LLVM demangler for symbol unmangling

The third\_party/llvm-demangle directory now contains a standalone copy of the LLVM demangling library, including headers for Itanium and Microsoft C++ name mangling schemes, utility classes, and build configuration files. This provides the capability to demangle C++ and MSVC-style mangled symbols directly, without depending on the full LLVM codebase.

_third\party/llvm-demangle · high confidence

Add PE resource parsing and symbol provider loading for unmanaged components

The unmanaged library now includes new capabilities to parse PE file resources and load the dbghelp symbol provider. A new UnmanagedPE class provides explicit LoadPE/UnloadPE methods to map and unload PE images, and a GetPeManifest method to extract embedded manifest resources. Additionally, UnmanagedSymPrv implements logic to locate and load dbghelp.dll from the Windows Kits directory (or fallback to system32), and initializes the symbol provider with Microsoft's public symbol server. This enables the library to resolve and display unmanaged symbol names more accurately.

ClrPhlib/src/unmanaged · high confidence

Add explicit PE, NativeFile, and symbol provider APIs

Introduces new managed classes for direct native filesystem access (NativeFile), PE file parsing (PE, PeExport, PeImport), and symbol demangling (PhSymbolProvider). NativeFile provides methods to check file existence, copy files, and compute partial SHA-256 hashes while handling WOW64 filesystem redirection. The PE class exposes properties for image base, entry point, subsystem version, and exports/imports, alongside manifest extraction. PhSymbolProvider wraps the demangle library to support multiple demangling strategies (Ph, LLVM Itanium, LLVM Microsoft, and Demumble) and returns the specific demangler used.

ClrPhlib/src/managed · high confidence

Added FilterControl UI component and supporting helpers

Introduced a new FilterControl user control for the Dependencies GUI, featuring a text box for filtering, a clear button, and routed events for filter and direction changes. The control includes a generic XAML template defining the visual tree and styles, along with a custom DependencyProperty-based API for binding and configuration. Supporting this, a RelayCommand implementation of ICommand was added to the Helpers namespace, and a SettingBindingHandler class was introduced to bridge application settings with the UI's property change notifications.

DependenciesGui/FilterControl, DependenciesGui/Helpers · high confidence

Added demumble tool for demangling C++ symbols

The project now bundles the 'demumble' utility, which demangles C++ symbols from both GCC (using libcxxabi) and Visual Studio (using Wine's undname). This tool provides cross-platform support for converting mangled C++ names into human-readable forms, handling differences in underscore conventions between Linux and macOS, and offering smarter filtering of function symbols compared to standard tools like c++filt.

_third\party/demumble · high confidence

Adds user settings for GUI preferences and application metadata

The Dependencies GUI now persists user preferences and application metadata through new configuration files. Users can now customize options such as the font family (defaulting to Courier New), the path to the PE viewer tool (defaulting to peview.exe), tree build behavior, tree depth, and display options like the status bar and full paths. Additionally, the application's assembly metadata (title, description, version 1.11.1.0) and localized resource definitions have been added to support the GUI's user interface.

DependenciesGui/Properties · high confidence

Initial project structure and build configuration

The repository was initialized with the core project files, including the \Dependencies.sln\ solution file that defines the build targets (such as \DependenciesGui\, \ClrPhlib\, and third-party dependencies like \Dragablz\ and \demumble\). A \.gitignore\ file was added to exclude build artifacts, and a \Deploy-Dependencies.ps1\ script was introduced to handle the packaging of dependencies, system DLLs, and regression tests. Additionally, an \appveyor.yml\ configuration was added to automate the build and deployment process on the CI server, and a \nuget.config\ file was created to specify the NuGet package source.

(repo-wide) · high confidence

Introduce BinaryCache and PE resolution logic in DependenciesLib

The DependenciesLib project was created, introducing the BinaryCache singleton to cache PE files on disk, preventing file locks and improving performance. This includes new FindPeModule logic to resolve DLL search paths (SxS, ApiSet, system folders) and SxsManifest parsing for side-by-side assemblies. Users benefit from faster analysis and more accurate module resolution, particularly for ApiSet and SxS dependencies.

DependenciesLib · high confidence

Introduce ClrPhlib as the new .NET interop layer for Process Hacker

The ClrPhlib project has been added to the solution, providing a managed C++/CLI library that bridges the native Process Hacker library with the .NET environment. This new component exposes key functionalities such as PE file parsing, symbol provider capabilities, and native filesystem access to managed code. The library is configured to target .NET Framework 4.6.1 and includes a manifest to resolve Common Controls dependencies, ensuring stable loading of the UI components. This change establishes the foundation for the application's managed layer, allowing the UI and other .NET components to interact with the underlying native libraries.

ClrPhlib · high confidence

Introduce new data models for displaying module, import, and export information in the GUI

Added new model classes to the GUI layer to support the tree view and status bar features. ModuleInfo.cs introduces the ModuleInfo struct and specialized display classes (DisplayModuleInfo, NotFoundModuleInfo, ApiSetModuleInfo) to represent modules, including handling of API sets, missing modules, and delay-loaded states. PeExport.cs and PeImport.cs add corresponding DisplayPeExport and DisplayPeImport classes that wrap the core parsing results, exposing properties for ordinals, hints, demangled names, and icons. These models enable the UI to display import/export details, handle clipboard copying, and provide context-sensitive help links for each entry.

DependenciesGui/Models · high confidence

Introduce pretty-printing interface and JSON output for dependency analysis

The Dependencies CLI tool now supports structured output and improved formatting. A new IPrettyPrintable interface is implemented across various analysis classes (such as NtKnownDlls, NtApiSet, PEManifest, and PEImports) to enable consistent console formatting. Additionally, the tool now supports JSON output formatting for dependency data, allowing users to easily parse the results programmatically.

Dependencies · high confidence

New ClrPhLib API for PE, symbol, and ApiSet analysis

Added a new C++/CLI library (ClrPhLib) that exposes managed classes for parsing PE files (imports, exports, properties, manifests), resolving and demangling C/C++ symbols using multiple backends (demumble, LLVM, Microsoft), and querying Windows ApiSet schemas (v2, v4, v6). This provides a unified .NET-facing interface for low-level Windows binary analysis features.

ClrPhlib/include · high confidence

Behavioural changes

Initial versioning for DependenciesLib assembly metadata

The DependenciesLib assembly metadata has been initialized with version 1.10.0.0, establishing the baseline versioning for the library.

DependenciesLib/Properties · high confidence

Switched from MDI to Dragablz for tab and layout management

The application has replaced the previous MDI (Multiple Document Interface) implementation with the Dragablz library. This change introduces new components for managing tabbed interfaces and dockable layouts, including classes for handling inter-tab transfers, branch-based layouts, and various UI converters and helpers. Users will experience a different mechanism for dragging, dropping, and organizing windows and tabs within the application.

_third\party/Dragablz · high confidence

Updated Process Hacker Native API (phnt) headers

The Process Hacker third-party library (phnt) has been updated to a newer version. This brings updated definitions for Windows Native API headers, including debugging (ntdbg.h), execution (ntexapi.h), GDI (ntgdi.h), I/O (ntioapi.h), kernel (ntkeapi.h), loader (ntldr.h), LPC (ntlpcapi.h), memory (ntmmapi.h), and other subsystems. These headers provide the internal structures and function prototypes required for deep system interaction and debugging.

_third\party/phnt · medium confidence

Updated ProcessHacker sources with CLR compilation and bug fixes

The ProcessHacker third-party sources were updated to include a patch that fixes the \_\_acrt\_fp\_format bug and specifies CLR compilation for the C++/CLI DLL target. The update also modifies the phlib project's output and intermediate directories to use the solution directory structure and updates include paths to reference the third\_party/phnt directory, ensuring correct compilation and build artifact placement.

_third\party · medium confidence

Updated phlib headers with new API and utility definitions

The phlib headers in third\_party/phlib/include have been updated to include new function declarations and type definitions. This includes API import stubs for Windows system calls (such as NtQueryInformationEnlistment and SHCreateShellItem), app resolver interfaces for querying application IDs and shortcuts, and new utility headers for circular buffers, text table formatting, and fast locks. These changes expand the available library functions for system interaction and data management.

_third\party/phlib/include · high confidence

Updated phlib with new source files and fixes

The phlib library in third\_party has been updated with new source files including apiimport.c, appresolver.c, avltree.c, basesup.c, circbuf.c, colorbox.c, cpysave.c, data.c, dspick.c, emenu.c, error.c, and extlv.c. These additions provide core data structures (AVL tree, circular buffer, hashtable), utility functions (string manipulation, memory allocation, error handling), and UI components (color picker, extended list view). The update also includes fixes for PE exports parsing and mapped resources data parsing, addressing issues \#110 and related bugs.

_third\party/phlib · medium confidence

Test coverage

Added binary cache loading test executable; Added demangler test executable; Added manifest regression tests.

Dependencies

Updated Dependencies assembly version to 1.10

The version metadata for the Dependencies assembly has been updated to 1.10.0.0, reflecting the latest release numbering.

Dependencies/Properties · high confidence

Upgrade to .NET Framework 4.6.1 and update NuGet packages

The project files and package configurations have been updated to target .NET Framework 4.6.1. This change includes updating the NuGet package references for Mono.Cecil (version 0.11.4), NDesk.Options (version 0.2.1), and Newtonsoft.Json (version 13.0.1) to their latest stable releases, ensuring the application builds against the newer framework and uses the specified library versions.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 49 → 45 (-3.8)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 66 → 55 (-11.3)
  • Architecture 97 → 97 (+0.1)
  • Maturity 43 → 43 (-0.2)
  • Readiness 35 → 35 (+0.0)
  • Security 100 → 71 (-29.0)

Resolved (11)

  • Bounded contexts not declared
  • Duplicated block (23 lines × 3) (DependenciesGui/Models/ModuleInfo.cs)
  • Inconsistent naming for dependency-related concepts: 'PeDependencyItem' vs 'PeDependencies'. One is singular, the other plural, suggesting the same or related concepts are named differently.
  • Inconsistent naming for file path properties: some use 'Filepath' (camelCase) while others use 'ModuleFilePath' (PascalCase) or 'ModuleName' (different concept). Specifically, 'Filepath' vs 'ModuleFilePath' represents a naming inconsistency for the same or similar concept (file path).
  • LLM evaluation failed
  • Low cohesion: DependencyWindow (LCOM4 4) (DependenciesGui/DependencyWindow.xaml.cs)
  • Low cohesion: DragablzItemsControl (LCOM4 5) (third_party/Dragablz/Dragablz/DragablzItemsControl.cs)
  • No exposed public API
  • Test reliability not measured — no test run produced results
  • The phnt header collection README is a short 'This collection of Native API header files has been maintained since 2009...' entry with no usage example and only PHNT_VERSION defines; it does not explain how to use the headers or what symbols are exposed. (third_party/phnt/README.md)
  • dormant codebase — no living knowledge left to concentrate

New (15)

  • Documentation: no installation or build instructions (README.md)
  • Duplicated block (11 lines × 2) (DependenciesGui/Models/PeExport.cs)
  • Duplicated block (24 lines × 3) (DependenciesGui/Models/ModuleInfo.cs)
  • Duplicated block (8 lines × 2) (DependenciesGui/DependencyWindow.xaml.cs)
  • High: security finding (details withheld)
  • Hotspot: DependenciesGui/DependencyWindow.xaml.cs (DependenciesGui/DependencyWindow.xaml.cs)
  • Inconsistent naming for cache retrieval methods: 'LookupApiSetLibrary' vs 'GetBinary'. While the return types differ (Library vs Binary), the pattern 'Get' is used for 'GetBinary' in both cache implementations, whereas 'Lookup' is used for a specific library lookup. This is a minor style difference, but 'Get' is the dominant pattern for simple retrieval in the cache implementations.
  • Inconsistent naming for file path parameters: 'FilePath', 'ModuleFilePath', 'PePath'. While 'ModuleFilePath' and 'PePath' are more specific, 'FilePath' is generic. In the context of the 'Dependencies' namespace, 'FilePath' is used in a parameter while 'Filepath' (lowercase p) is used in a property. This is a casing inconsistency between parameter and property naming conventions for the same concept.
  • Inconsistent naming for file path properties: some use 'Filepath' (camelCase compound), others use 'FilePath' (PascalCase compound), and others use 'ModuleFilePath' or 'RecentFilesIndex'. Specifically, 'Filepath' vs 'FilePath' is a spelling inconsistency for the same concept.
  • Medium: security finding (details withheld)
  • No SBOM
  • No build provenance
  • No dependency advisory monitoring
  • WriteOnlyPrivateField (Dependencies/Program.cs)
  • redundant comment (DependenciesLib/SxsManifest.cs)

Architecture

  • Unchanged — 1 containers · 0 contexts · 0 edges

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

lucasg/Dependencies was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 1997a40000b77bd3326cbc33672a7b9f78bb23f3 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-0849c4f988a8.