Skip to content
CAI
Software that uses CAICheck a score

ShiftLeftSecurity/codepropertygraph

58.8

Adequate · 28 September 2026

118k

lines of production code

Scala

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the Code Property Graph (CPG) library, which provides a structured graph representation of source code for static analysis. It manages the definition, generation, and traversal of graph schemas covering AST, control flow, and call graphs, while supporting multiple programming languages. The system handles the loading, conversion, and persistence of graph data using the FlatGraph storage backend, and offers a framework for executing single-threaded or parallel analysis passes.

How it got here

2018 — Build system and language migration

7 changes.

The project underwent a significant infrastructure overhaul, migrating its build system from SBT to Bazel and upgrading the programming language from Scala 2 to Scala 3. This period also involved replacing legacy TinkerPop-based graph components with FlatGraph and consolidating code generation tools from Python to Scala.

2019 — FlatGraph migration and pass framework

8 changes.

The codebase underwent a significant architectural shift by migrating the CPG loader to use FlatGraph as the primary storage backend, replacing legacy serialization mechanisms. This period also introduced a simplified, parallel execution framework for CPG passes and added utility classes to support robust file I/O and multi-threaded logging. Documentation was expanded with sample projects demonstrating custom schema extensions and external pass implementation.

2020–2026 — CPG schema migration to FlatGraph

10 changes.

The project migrated the Code Property Graph schema from a JSON-based approach to the FlatGraph DSL, resulting in a comprehensive reorganization of node types, edges, and layer definitions. This structural overhaul was accompanied by the regeneration of domain classes and traversal APIs to enforce data integrity and support new language features like C\# and Rust. Concurrently, test coverage was expanded to validate the new schema logic, pass lifecycle behaviors, and utility functions.

Features

Add sample code for an external CPG pass

A new sample file, SamplePass.scala, has been added to the samples/pass directory. It demonstrates how to implement a SimpleCpgPass that adds a NewFile node to the Code Property Graph and includes a main entry point to load a CPG from an overflow database, execute the pass, and serialize the result.

samples/pass · high confidence

Added sample code for custom CPG schema extensions and external passes

New sample projects have been added to demonstrate how to extend the Code Property Graph (CPG) with custom node and edge types and how to implement external CPG passes. The \samples/customcpg\ directory includes a sample schema definition (\myschema.json\) for adding custom node types, along with a script (\local-m2-publish.sh\) to build and publish a customized CPG version locally. The \samples/pass\ directory provides a template for creating an external pass compatible with Ocular/Joern, including necessary build configuration.

samples · high confidence

New schema2json tool generates comprehensive schema documentation

A new Scala application (Schema2Json) has been added to dump the Code Property Graph schema into a JSON file (/tmp/schema.json). The output includes schema summaries, node types (with base types, properties, cardinalities, inherited properties, and contained nodes), edge types, and property definitions, excluding hidden elements. The tool uses the flatgraph library for schema introspection and ujson for JSON serialization.

schema2json/src · high confidence

New utility classes for execution context, file I/O, and project root detection

Added several new utility classes to the \io.shiftleft.utils\ package to support core analysis operations. ExecutionContextProvider enables proper MDC (Message Diagnostic Context) propagation for logging in multi-threaded environments by providing a custom ExecutionContext. IOUtils introduces robust file reading capabilities, including \readLinesInFile\ and \readEntireFile\, with specific handling for UTF-8 BOMs and malformed characters. ProjectRoot provides a configurable mechanism to locate the project root directory by searching for a marker file (defaulting to \.git\), aiding test execution across different IDEs. Additionally, StringInterner offers a way to deduplicate strings to manage memory usage during loading, and TempFileCopy simplifies the creation and cleanup of temporary file copies.

codepropertygraph/src/main/scala/io/shiftleft/utils · high confidence

Architecture

Migrate build system from SBT to Bazel

The project has switched its build infrastructure from SBT to Bazel. This change introduces Bazel configuration files (\.bazelrc\, \.bazelversion\, \MODULE.bazel\, \BUILD\) and lockfiles (\MODULE.bazel.lock\, \maven\_install.json\), configuring the build to use Bazel 9.1.0, Java 21, and Scala 3.8.3. It also adds a \format\ alias for code formatting and updates the dependency management to use \rules\_jvm\_external\ for resolving Maven artifacts like \flatgraph\ and \protobuf\.

(repo-wide) · high confidence

Behavioural changes

1 commit (0 fixes) modifying img

A change to existing behaviour in img — 1 commit, 6 files.

img · medium confidence · unverified

CPG loader now converts legacy formats to FlatGraph storage

The CPG loader has been rewritten to support FlatGraph as the primary storage backend. When loading legacy Proto or OverflowDB files, the loader now automatically converts them into the new FlatGraph format and persists the result, ensuring consistent storage handling. This change introduces a two-pass loading mechanism for Proto files to handle node and edge mapping correctly within the FlatGraph architecture and includes utilities for detecting file formats via magic bytes.

codepropertygraph/src/main/scala/io/shiftleft/codepropertygraph/cpgloading · high confidence

CPG schema refactored to use FlatGraph DSL and reorganized layer definitions

The schema definition in \schema/src\ has been rewritten to use the FlatGraph schema DSL instead of the previous JSON-based approach, resulting in a complete reorganization of the code property graph structure. This change introduces new modular schema files (such as \Annotation.scala\, \Binding.scala\, and \CpgSchema.scala\) that explicitly define node types, edges, and properties for layers including AST, Control Flow, Call Graph, and Bindings. Key structural updates include the addition of \ANNOTATION\ and \BINDING\ node types, the redefinition of \AST\_NODE\ with explicit \ORDER\ and \CODE\ properties, and the establishment of a centralized \CpgSchema\ builder that wires these layers together, fundamentally changing how the graph schema is generated and consumed.

schema/src · high confidence

Code generation scripts migrated from Python to Scala

The Python-based code generation tools (\generateJava.py\, \generateProtobuf.py\, and \mergeSchemas.py\) have been removed from the codebase. This change reflects the migration of the code generation logic to Scala, as indicated by the deletion of these Python scripts which previously handled schema merging and the generation of Java and Protobuf sources from JSON schema definitions.

codepropertygraph/codegen/src/main/python · high confidence

Cpg class and loading logic moved to codepropertygraph project

The Cpg class and associated loading classes have been moved to the codepropertygraph project. This change introduces a new Cpg.scala file that forwards calls to the generated Cpg class, and a package.scala file that defines the Cpg type alias. This refactoring simplifies the codebase by centralizing the Cpg class and loading logic in a single location.

codepropertygraph/src/main/scala/io/shiftleft/codepropertygraph · high confidence

Deprecation of SerializedCpg and introduction of legacy Iterable extension

The \SerializedCpg\ class is now deprecated, signaling that new API functions no longer rely on this legacy serialization mechanism. Additionally, the \onlyChecked\ extension method for \IterableOnce\ has been deprecated in favor of the \loneElement\ method provided by flatgraph, which offers stricter validation by throwing an exception if more than one element is present.

codepropertygraph/src/main/scala/io/shiftleft · high confidence

Generated neighbor accessors now enforce mandatory graph edges with explicit validation

The generated neighbor accessor classes in \domainClasses/src/main/generated/io/shiftleft/codepropertygraph/generated/neighboraccessors\ have been updated to enforce mandatory graph edges. For nodes where an edge is required by the schema (such as \Binding\ linking to \Method\ or \Block\ linking to its parent \Block\), the generated code now throws a \flatgraph.SchemaViolationException\ if the mandatory edge is missing, rather than returning an empty iterator or failing silently. This change improves data integrity by ensuring that traversal operations on mandatory relationships fail fast with clear error messages when the graph structure is invalid.

domainClasses/src/main/generated/io/shiftleft/codepropertygraph/generated/neighboraccessors · high confidence

New simplified CpgPass and parallel execution framework

The \passes\ package now provides a simplified \CpgPass\ class for single-threaded graph modifications and a \ForkJoinParallelCpgPass\ framework for parallel execution using a fork/join model. This replaces older pass interfaces, offering a cleaner API where users override \run\ or \runOnPart\ to add changes via a \DiffGraphBuilder\. A new \Converters.java\ utility is also added to assist with Scala-Java collection interoperability.

codepropertygraph/src/main/scala/io/shiftleft/passes · high confidence

Regenerated traversal API for the code property graph

The generated traversal classes in the \domainClasses\ module have been regenerated to align with an updated \flatgraph\ library. This update refreshes the fluent query API for graph nodes, providing new or modified traversal methods for properties such as \fullName\, \name\, \code\, \columnNumber\, \lineNumber\, \methodFullName\, \signature\, \typeFullName\, \dispatchType\, and \staticReceiver\. Users querying the code property graph will interact with these updated traversal methods, which now leverage the underlying \flatgraph\ accessors and inverse indices for filtering and navigation.

domainClasses/src/main/generated/io/shiftleft/codepropertygraph/generated/traversals · high confidence

Removal of legacy Proto and Java code generation templates

The code generation resources for the Code Property Graph have been updated by removing the \cpg.proto.tpl\ and \javaTemplate.java\ templates. This deletion eliminates the legacy mechanism that generated Protocol Buffers definitions and corresponding Java classes from these resource files, indicating a shift in how the graph schema and language bindings are produced or managed within the project.

codepropertygraph/codegen/src/main/resources · high confidence

Removal of legacy TinkerPop predicate utilities

The \Text\ predicate class, which provided helper methods for constructing TinkerPop \P\ predicates for regex matching, has been removed from the codebase. This change eliminates the dependency on the TinkerPop Gremlin API for text-based graph traversals, aligning with the migration to the ODB traversal mechanism.

codepropertygraph/src/main/java · high confidence

Updated CPG schema with new control structure types, language support, and graph edges

The generated domain classes for the Code Property Graph have been updated to reflect schema changes. Control structures now explicitly support CATCH and FINALLY clauses, and new modifier types for MODULE and LAMBDA are available. The graph schema includes new edges such as JUMP\_ARGUMENT, IS\_CALL\_FOR\_IMPORT, and CATCH\_BODY/FINALLY\_BODY to better model control flow and imports. Additionally, new language frontends for CSHARPSRC and RUST are registered, and new properties like ARGUMENT\_LABEL and EVIDENCE\_DESCRIPTION have been added to support more detailed code and finding analysis.

domainClasses/src/main/generated/io/shiftleft/codepropertygraph/generated · high confidence

Updated generated domain classes with new node types and properties

The generated node classes in the domain model have been regenerated to include new node types such as Annotation, AnnotationLiteral, AnnotationParameter, and AnnotationParameterAssign, alongside existing nodes like Block and Call. These nodes now support additional properties including OFFSET and OFFSET\_END for precise source location tracking, ARGUMENT\_INDEX, ARGUMENT\_LABEL, and ARGUMENT\_NAME for better argument mapping, and POSSIBLE\_TYPES for approximate type recovery. The BaseTypes file also reflects these structural changes, ensuring type safety through erased marker traits for the new and updated properties.

domainClasses/src/main/generated/io/shiftleft/codepropertygraph/generated/nodes · high confidence

Test coverage

2 commits adding/updating tests in codepropertygraph/src/test/resources; Added tests for CPG loader and help steps; Added tests for CpgPass lifecycle and accumulator behavior; Added tests for IOUtils file reading utilities; Removed Text predicate test suite.

Dependencies

Build infrastructure modernized with sbt 1.12.5 and flatgraph codegen

The build system has been upgraded to sbt 1.12.5, replacing older plugins like sbt-coursier, sbt-release, and sbt-findbugs with sbt-ci-release-early, sbt-dynver, and sbt-native-packager. The project now uses the sbt-flatgraph plugin for domain class generation, removing the legacy DomainClassCreator and its dependencies (better-files, play-json). New utility objects (FileUtils, Projects, Utils, Versions) centralize file operations, project definitions, and version management.

project · high confidence

Migrate to FlatGraph and upgrade to Scala 3.8.3

The build system has been refactored to replace the previous TinkerGraph-based domain classes with FlatGraph, introducing new subprojects for schema generation and domain classes that depend on the \io.joern:flatgraph-core\ and \io.joern:flatgraph-help\ libraries. The project has also been upgraded from Scala 2.12 to Scala 3.8.3, targeting JDK 17, and updated to use Protobuf 3.20.1 with an automated local installation step for the \protoc\ binary. Additionally, the main \codepropertygraph\ module now depends on FlatGraph format and ODB conversion libraries, and publishing has been migrated to Sonatype Central.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 59 → 59 (+0.0)
  • Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.

Lenses

  • Code Health 98 → 98 (-0.0)
  • Architecture 100 → 93 (-6.8)
  • Maturity 56 → 56 (+0.5)
  • Readiness 46 → 47 (+0.8)
  • Security 73 → 73 (+0.0)

Resolved (10)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Members sharing a duplicated core (32 members, 50+ identical tokens) (domainClasses/src/main/generated/io/shiftleft/codepropertygraph/generated/nodes/Annotation.scala)
  • Members sharing a duplicated core (4 members, 50+ identical tokens) (domainClasses/src/main/generated/io/shiftleft/codepropertygraph/generated/nodes/AnnotationLiteral.scala)
  • Members sharing a duplicated core (4 members, 50+ identical tokens) (domainClasses/src/main/generated/io/shiftleft/codepropertygraph/generated/nodes/ArrayInitializer.scala)
  • Members sharing a duplicated core (4 members, 50+ identical tokens) (domainClasses/src/main/generated/io/shiftleft/codepropertygraph/generated/nodes/JumpLabel.scala)
  • Members sharing a duplicated core (4 members, 50+ identical tokens) (domainClasses/src/main/generated/io/shiftleft/codepropertygraph/generated/nodes/Local.scala)
  • Members sharing a duplicated core (4 members, 50+ identical tokens) (domainClasses/src/main/generated/io/shiftleft/codepropertygraph/generated/nodes/MethodParameterIn.scala)
  • Members sharing a duplicated core (6 members, 50+ identical tokens) (domainClasses/src/main/generated/io/shiftleft/codepropertygraph/generated/nodes/Block.scala)
  • Off-boarding risk: anonymized user #1

New (20)

  • Duplicated block (11 lines × 2) (domainClasses/src/main/generated/io/shiftleft/codepropertygraph/generated/nodes/ArrayInitializer.scala)
  • Duplicated block (12 lines × 2) (domainClasses/src/main/generated/io/shiftleft/codepropertygraph/generated/nodes/AnnotationLiteral.scala)
  • Duplicated block (12 lines × 2) (domainClasses/src/main/generated/io/shiftleft/codepropertygraph/generated/nodes/Local.scala)
  • Duplicated block (14 lines × 3) (domainClasses/src/main/generated/io/shiftleft/codepropertygraph/generated/nodes/Block.scala)
  • Duplicated block (8 lines × 3) (domainClasses/src/main/generated/io/shiftleft/codepropertygraph/generated/nodes/AnnotationParameter.scala)
  • Duplicated block (9 lines × 2) (domainClasses/src/main/generated/io/shiftleft/codepropertygraph/generated/nodes/Namespace.scala)
  • Members sharing a duplicated core (32 members, 50+ identical tokens) (domainClasses/src/main/generated/io/shiftleft/codepropertygraph/generated/nodes/Annotation.scala)
  • Members sharing a duplicated core (4 members, 50+ identical tokens) (domainClasses/src/main/generated/io/shiftleft/codepropertygraph/generated/nodes/AnnotationLiteral.scala)
  • Members sharing a duplicated core (4 members, 50+ identical tokens) (domainClasses/src/main/generated/io/shiftleft/codepropertygraph/generated/nodes/ArrayInitializer.scala)
  • Members sharing a duplicated core (4 members, 50+ identical tokens) (domainClasses/src/main/generated/io/shiftleft/codepropertygraph/generated/nodes/JumpLabel.scala)
  • Members sharing a duplicated core (4 members, 50+ identical tokens) (domainClasses/src/main/generated/io/shiftleft/codepropertygraph/generated/nodes/Local.scala)
  • Members sharing a duplicated core (4 members, 50+ identical tokens) (domainClasses/src/main/generated/io/shiftleft/codepropertygraph/generated/nodes/MethodParameterIn.scala)
  • Members sharing a duplicated core (6 members, 50+ identical tokens) (domainClasses/src/main/generated/io/shiftleft/codepropertygraph/generated/nodes/Block.scala)
  • No ADRs found
  • Off-boarding risk: anonymized user #1
  • Outdated: com.github.scopt:scopt_3
  • Outdated: org.apache.logging.log4j:log4j-core
  • Outdated: org.apache.logging.log4j:log4j-slf4j2-impl
  • Outdated: org.slf4j:slf4j-api
  • Projects may be oversized for their cohesion

Changes since last survey

  • 4 commits — 4 feature/other, 0 fixes

By area

  • (root) — 2 commits
  • codepropertygraph/src — 1 commit
  • domainClasses/src — 1 commit

Notable commits

  • change: Add common_javacopts to make_scala_rules call site (#1867)
  • change: IOUtils rework (#1865)
  • change: Replace json4s with com.lihaoyi.upickle (#1868)
  • change: update to latest flatgraph (#1866)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

ShiftLeftSecurity/codepropertygraph was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 1735c289d7258d4ef02f6c39ce635581cca4f330 — the exact code this score is about.
  • Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d46da229e3fd.