lucasg/Dependencies
45.5
Weak · 22 September 2026
13.2k
lines of production code
C#
with C++
5
measurements over time
What this system is
This system is a Windows dependency analysis tool that parses PE files, resolves DLL dependencies, and demangles C++ symbols. It provides a managed .NET interface to native libraries for deep system interaction, including API set and side-by-side assembly resolution. The application features a WPF-based GUI for visualizing module, import, and export data, alongside a CLI for structured output.
How it got here
2017 — Managed interop layer and third-party updates
13 changes.
This period focused on establishing a managed .NET interop layer (ClrPhlib) to bridge native Windows APIs with the UI, alongside significant updates to third-party dependencies like Process Hacker and Dragablz. The work also introduced structured output capabilities for dependency analysis and modernized the build and CI configuration.
2018–2019 — GUI and library refactoring
11 changes.
This period focused on modernizing the application's architecture by introducing a dedicated library for binary caching and PE resolution, alongside a significant overhaul of the GUI layer. The team implemented new data models, UI controls, and demangling utilities to improve performance, cross-platform symbol handling, and user configuration management.
Features
About dialog gains an on-demand version check and clickable issue link
The About dialog has been converted to WPF, displaying the application version and a link to the GitHub issues page. It now includes a 'Check for updates' link that fetches the latest release version from GitHub and displays it, allowing users to easily verify if they are running the newest version.
DependenciesGui · high confidence
Add LLVM demangler for symbol unmangling
The third\_party/llvm-demangle directory now contains a standalone copy of the LLVM demangling library, including headers for Itanium and Microsoft C++ name mangling schemes, utility classes, and build configuration files. This provides the capability to demangle C++ and MSVC-style mangled symbols directly, without depending on the full LLVM codebase.
_third\party/llvm-demangle · high confidence
Add PE resource parsing and symbol provider loading for unmanaged components
The unmanaged library now includes new capabilities to parse PE file resources and load the dbghelp symbol provider. A new UnmanagedPE class provides explicit LoadPE/UnloadPE methods to map and unload PE images, and a GetPeManifest method to extract embedded manifest resources. Additionally, UnmanagedSymPrv implements logic to locate and load dbghelp.dll from the Windows Kits directory (or fallback to system32), and initializes the symbol provider with Microsoft's public symbol server. This enables the library to resolve and display unmanaged symbol names more accurately.
ClrPhlib/src/unmanaged · high confidence
Add explicit PE, NativeFile, and symbol provider APIs
Introduces new managed classes for direct native filesystem access (NativeFile), PE file parsing (PE, PeExport, PeImport), and symbol demangling (PhSymbolProvider). NativeFile provides methods to check file existence, copy files, and compute partial SHA-256 hashes while handling WOW64 filesystem redirection. The PE class exposes properties for image base, entry point, subsystem version, and exports/imports, alongside manifest extraction. PhSymbolProvider wraps the demangle library to support multiple demangling strategies (Ph, LLVM Itanium, LLVM Microsoft, and Demumble) and returns the specific demangler used.
ClrPhlib/src/managed · high confidence
Added FilterControl UI component and supporting helpers
Introduced a new FilterControl user control for the Dependencies GUI, featuring a text box for filtering, a clear button, and routed events for filter and direction changes. The control includes a generic XAML template defining the visual tree and styles, along with a custom DependencyProperty-based API for binding and configuration. Supporting this, a RelayCommand implementation of ICommand was added to the Helpers namespace, and a SettingBindingHandler class was introduced to bridge application settings with the UI's property change notifications.
DependenciesGui/FilterControl, DependenciesGui/Helpers · high confidence
Added demumble tool for demangling C++ symbols
The project now bundles the 'demumble' utility, which demangles C++ symbols from both GCC (using libcxxabi) and Visual Studio (using Wine's undname). This tool provides cross-platform support for converting mangled C++ names into human-readable forms, handling differences in underscore conventions between Linux and macOS, and offering smarter filtering of function symbols compared to standard tools like c++filt.
_third\party/demumble · high confidence
Adds user settings for GUI preferences and application metadata
The Dependencies GUI now persists user preferences and application metadata through new configuration files. Users can now customize options such as the font family (defaulting to Courier New), the path to the PE viewer tool (defaulting to peview.exe), tree build behavior, tree depth, and display options like the status bar and full paths. Additionally, the application's assembly metadata (title, description, version 1.11.1.0) and localized resource definitions have been added to support the GUI's user interface.
DependenciesGui/Properties · high confidence
Initial project structure and build configuration
The repository was initialized with the core project files, including the \Dependencies.sln\ solution file that defines the build targets (such as \DependenciesGui\, \ClrPhlib\, and third-party dependencies like \Dragablz\ and \demumble\). A \.gitignore\ file was added to exclude build artifacts, and a \Deploy-Dependencies.ps1\ script was introduced to handle the packaging of dependencies, system DLLs, and regression tests. Additionally, an \appveyor.yml\ configuration was added to automate the build and deployment process on the CI server, and a \nuget.config\ file was created to specify the NuGet package source.
(repo-wide) · high confidence
Introduce BinaryCache and PE resolution logic in DependenciesLib
The DependenciesLib project was created, introducing the BinaryCache singleton to cache PE files on disk, preventing file locks and improving performance. This includes new FindPeModule logic to resolve DLL search paths (SxS, ApiSet, system folders) and SxsManifest parsing for side-by-side assemblies. Users benefit from faster analysis and more accurate module resolution, particularly for ApiSet and SxS dependencies.
DependenciesLib · high confidence
Introduce ClrPhlib as the new .NET interop layer for Process Hacker
The ClrPhlib project has been added to the solution, providing a managed C++/CLI library that bridges the native Process Hacker library with the .NET environment. This new component exposes key functionalities such as PE file parsing, symbol provider capabilities, and native filesystem access to managed code. The library is configured to target .NET Framework 4.6.1 and includes a manifest to resolve Common Controls dependencies, ensuring stable loading of the UI components. This change establishes the foundation for the application's managed layer, allowing the UI and other .NET components to interact with the underlying native libraries.
ClrPhlib · high confidence
Introduce new data models for displaying module, import, and export information in the GUI
Added new model classes to the GUI layer to support the tree view and status bar features. ModuleInfo.cs introduces the ModuleInfo struct and specialized display classes (DisplayModuleInfo, NotFoundModuleInfo, ApiSetModuleInfo) to represent modules, including handling of API sets, missing modules, and delay-loaded states. PeExport.cs and PeImport.cs add corresponding DisplayPeExport and DisplayPeImport classes that wrap the core parsing results, exposing properties for ordinals, hints, demangled names, and icons. These models enable the UI to display import/export details, handle clipboard copying, and provide context-sensitive help links for each entry.
DependenciesGui/Models · high confidence
Introduce pretty-printing interface and JSON output for dependency analysis
The Dependencies CLI tool now supports structured output and improved formatting. A new IPrettyPrintable interface is implemented across various analysis classes (such as NtKnownDlls, NtApiSet, PEManifest, and PEImports) to enable consistent console formatting. Additionally, the tool now supports JSON output formatting for dependency data, allowing users to easily parse the results programmatically.
Dependencies · high confidence
New ClrPhLib API for PE, symbol, and ApiSet analysis
Added a new C++/CLI library (ClrPhLib) that exposes managed classes for parsing PE files (imports, exports, properties, manifests), resolving and demangling C/C++ symbols using multiple backends (demumble, LLVM, Microsoft), and querying Windows ApiSet schemas (v2, v4, v6). This provides a unified .NET-facing interface for low-level Windows binary analysis features.
ClrPhlib/include · high confidence
Behavioural changes
Initial versioning for DependenciesLib assembly metadata
The DependenciesLib assembly metadata has been initialized with version 1.10.0.0, establishing the baseline versioning for the library.
DependenciesLib/Properties · high confidence
Switched from MDI to Dragablz for tab and layout management
The application has replaced the previous MDI (Multiple Document Interface) implementation with the Dragablz library. This change introduces new components for managing tabbed interfaces and dockable layouts, including classes for handling inter-tab transfers, branch-based layouts, and various UI converters and helpers. Users will experience a different mechanism for dragging, dropping, and organizing windows and tabs within the application.
_third\party/Dragablz · high confidence
Updated Process Hacker Native API (phnt) headers
The Process Hacker third-party library (phnt) has been updated to a newer version. This brings updated definitions for Windows Native API headers, including debugging (ntdbg.h), execution (ntexapi.h), GDI (ntgdi.h), I/O (ntioapi.h), kernel (ntkeapi.h), loader (ntldr.h), LPC (ntlpcapi.h), memory (ntmmapi.h), and other subsystems. These headers provide the internal structures and function prototypes required for deep system interaction and debugging.
_third\party/phnt · medium confidence
Updated ProcessHacker sources with CLR compilation and bug fixes
The ProcessHacker third-party sources were updated to include a patch that fixes the \_\_acrt\_fp\_format bug and specifies CLR compilation for the C++/CLI DLL target. The update also modifies the phlib project's output and intermediate directories to use the solution directory structure and updates include paths to reference the third\_party/phnt directory, ensuring correct compilation and build artifact placement.
_third\party · medium confidence
Updated phlib headers with new API and utility definitions
The phlib headers in third\_party/phlib/include have been updated to include new function declarations and type definitions. This includes API import stubs for Windows system calls (such as NtQueryInformationEnlistment and SHCreateShellItem), app resolver interfaces for querying application IDs and shortcuts, and new utility headers for circular buffers, text table formatting, and fast locks. These changes expand the available library functions for system interaction and data management.
_third\party/phlib/include · high confidence
Updated phlib with new source files and fixes
The phlib library in third\_party has been updated with new source files including apiimport.c, appresolver.c, avltree.c, basesup.c, circbuf.c, colorbox.c, cpysave.c, data.c, dspick.c, emenu.c, error.c, and extlv.c. These additions provide core data structures (AVL tree, circular buffer, hashtable), utility functions (string manipulation, memory allocation, error handling), and UI components (color picker, extended list view). The update also includes fixes for PE exports parsing and mapped resources data parsing, addressing issues \#110 and related bugs.
_third\party/phlib · medium confidence
Test coverage
Added binary cache loading test executable; Added demangler test executable; Added manifest regression tests.
Dependencies
Updated Dependencies assembly version to 1.10
The version metadata for the Dependencies assembly has been updated to 1.10.0.0, reflecting the latest release numbering.
Dependencies/Properties · high confidence
Upgrade to .NET Framework 4.6.1 and update NuGet packages
The project files and package configurations have been updated to target .NET Framework 4.6.1. This change includes updating the NuGet package references for Mono.Cecil (version 0.11.4), NDesk.Options (version 0.2.1), and Newtonsoft.Json (version 13.0.1) to their latest stable releases, ensuring the application builds against the newer framework and uses the specified library versions.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 49 → 45 (-3.8)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 66 → 55 (-11.3)
- Architecture 97 → 97 (+0.1)
- Maturity 43 → 43 (-0.2)
- Readiness 35 → 35 (+0.0)
- Security 100 → 71 (-29.0)
Resolved (11)
- Bounded contexts not declared
- Duplicated block (23 lines × 3) (DependenciesGui/Models/ModuleInfo.cs)
- Inconsistent naming for dependency-related concepts: 'PeDependencyItem' vs 'PeDependencies'. One is singular, the other plural, suggesting the same or related concepts are named differently.
- Inconsistent naming for file path properties: some use 'Filepath' (camelCase) while others use 'ModuleFilePath' (PascalCase) or 'ModuleName' (different concept). Specifically, 'Filepath' vs 'ModuleFilePath' represents a naming inconsistency for the same or similar concept (file path).
- LLM evaluation failed
- Low cohesion: DependencyWindow (LCOM4 4) (DependenciesGui/DependencyWindow.xaml.cs)
- Low cohesion: DragablzItemsControl (LCOM4 5) (third_party/Dragablz/Dragablz/DragablzItemsControl.cs)
- No exposed public API
- Test reliability not measured — no test run produced results
- The phnt header collection README is a short 'This collection of Native API header files has been maintained since 2009...' entry with no usage example and only PHNT_VERSION defines; it does not explain how to use the headers or what symbols are exposed. (third_party/phnt/README.md)
- dormant codebase — no living knowledge left to concentrate
New (15)
- Documentation: no installation or build instructions (README.md)
- Duplicated block (11 lines × 2) (DependenciesGui/Models/PeExport.cs)
- Duplicated block (24 lines × 3) (DependenciesGui/Models/ModuleInfo.cs)
- Duplicated block (8 lines × 2) (DependenciesGui/DependencyWindow.xaml.cs)
- High: security finding (details withheld)
- Hotspot: DependenciesGui/DependencyWindow.xaml.cs (DependenciesGui/DependencyWindow.xaml.cs)
- Inconsistent naming for cache retrieval methods: 'LookupApiSetLibrary' vs 'GetBinary'. While the return types differ (Library vs Binary), the pattern 'Get' is used for 'GetBinary' in both cache implementations, whereas 'Lookup' is used for a specific library lookup. This is a minor style difference, but 'Get' is the dominant pattern for simple retrieval in the cache implementations.
- Inconsistent naming for file path parameters: 'FilePath', 'ModuleFilePath', 'PePath'. While 'ModuleFilePath' and 'PePath' are more specific, 'FilePath' is generic. In the context of the 'Dependencies' namespace, 'FilePath' is used in a parameter while 'Filepath' (lowercase p) is used in a property. This is a casing inconsistency between parameter and property naming conventions for the same concept.
- Inconsistent naming for file path properties: some use 'Filepath' (camelCase compound), others use 'FilePath' (PascalCase compound), and others use 'ModuleFilePath' or 'RecentFilesIndex'. Specifically, 'Filepath' vs 'FilePath' is a spelling inconsistency for the same concept.
- Medium: security finding (details withheld)
- No SBOM
- No build provenance
- No dependency advisory monitoring
- WriteOnlyPrivateField (Dependencies/Program.cs)
- redundant comment (DependenciesLib/SxsManifest.cs)
Architecture
- Unchanged — 1 containers · 0 contexts · 0 edges
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
lucasg/Dependencies was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 1997a40000b77bd3326cbc33672a7b9f78bb23f3 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-0849c4f988a8.