Skip to content
CAI
Software that uses CAICheck a score

square/moshi

61.7

Adequate · 25 September 2026

13.5k

lines of production code

Kotlin

with Java

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Add recipe examples for custom adapters and data handling

Added a collection of example files in the \examples\ directory to demonstrate various Moshi usage patterns. These include custom adapters for types like \ByteString\ and \Card\, handling multiple JSON formats, unwrapping envelope objects, recovering from data mismatches, and serializing nulls for annotated types. The examples also cover custom field names, qualifiers, and date formatting.

examples · high confidence

Added support for Java 16+ records via RecordJsonAdapter

The Moshi library now includes a new \RecordJsonAdapter\ implementation located in the \java16\ source set, enabling serialization and deserialization of Java 16+ record classes. This adapter uses reflection to map record components to JSON properties, allowing users to serialize and deserialize Java records directly with Moshi.

moshi/src/main/java16 · high confidence

Initial project scaffolding and documentation

The repository was initialized with essential configuration and documentation files, including \.editorconfig\ for code formatting, \.gitattributes\ and \.gitignore\ for version control hygiene, and \releasing.md\ for release procedures. The \README.md\ was expanded to include comprehensive usage examples for Java and Kotlin, and the \gradlew\ wrapper scripts were added to support the build system.

(repo-wide) · high confidence

Behavioural changes

Add Moshi ProGuard/R8 rules for code generation and annotations

A new ProGuard configuration file (moshi.pro) is embedded in the Moshi library to preserve critical classes and members during minification. This ensures that methods annotated with @FromJson and @ToJson are retained, as are the fields and synthesized values() methods for annotated enums. It also preserves classes with Moshi annotations and specific internal utility methods, preventing R8/ProGuard from stripping necessary reflection or code-generation artifacts.

moshi/src/main/resources · medium confidence

Convert Moshi adapters to Kotlin

The \moshi-adapters\ module has been converted from Java to Kotlin. This includes the \Rfc3339DateJsonAdapter\, \EnumJsonAdapter\, \Iso8601Utils\, and \PolymorphicJsonAdapterFactory\. The \Rfc3339DateJsonAdapter\ was moved to the \com.squareup.moshi.adapters\ package to avoid Java Platform Module System conflicts, with the old location marked as deprecated. The \PolymorphicJsonAdapterFactory\ was also converted, ensuring consistent Kotlin implementation across the library's core adapters.

moshi-adapters/src/main · high confidence

Converted internal adapters to Kotlin

The internal \com.squareup.moshi.internal\ package has been converted from Java to Kotlin. This includes rewriting core adapter implementations such as \AdapterMethodsFactory\, \ArrayJsonAdapter\, \ClassFactory\, \ClassJsonAdapter\, \CollectionJsonAdapter\, \JsonScope\, \JsonValueSource\, \KotlinReflectTypes\, \LinkedHashTreeMap\, \MapJsonAdapter\, \NonNullJsonAdapter\, \NullSafeJsonAdapter\, \RecordJsonAdapter\, and \StandardJsonAdapters\ into Kotlin source files. This change modernizes the internal implementation while maintaining the same serialization and deserialization behavior for standard types, collections, maps, and custom adapters.

moshi/src/main/java/com/squareup/moshi/internal · high confidence

Migrate code generation API to Kotlin and restructure internal API

The internal code generation API in \moshi-kotlin-codegen\ has been migrated from Java to Kotlin, with all classes in the \com.squareup.moshi.kotlin.codegen.api\ package (including \AdapterGenerator\, \DelegateKey\, \ProguardRules\, and others) now written in Kotlin. This change introduces an \@InternalMoshiCodegenApi\ annotation to mark the internal API and updates the implementation of the code generator, which may affect how generated adapters are structured or how ProGuard rules are applied. The migration also includes updates to support Kotlin 2.3 compilation and handling of value classes.

moshi-kotlin-codegen/src/main/java/com/squareup/moshi/kotlin/codegen/api · high confidence

Migrated Kotlin reflection implementation to kotlin-metadata

The Kotlin reflection implementation has been refactored to use the kotlin-metadata library for parsing Kotlin metadata annotations. This change introduces new internal classes in the \com.squareup.moshi.kotlin.reflect\ package, including \KotlinJsonAdapterFactory\, \KtTypes\, \KmExecutable\, and \JvmDescriptors\, which handle the parsing of Kotlin-specific types, constructors, and properties. The old \KotlinJsonAdapterFactory\ in the \com.squareup.moshi\ package is now deprecated and redirects to the new location to avoid package name conflicts in the Java Platform Module System. Additionally, ProGuard/R8 rules have been updated to preserve the necessary metadata annotations and classes at runtime.

moshi-kotlin/src/main · high confidence

Moshi Kotlin codegen migrates to KSP2

The Moshi Kotlin codegen module has been migrated to use KSP2, the second generation of the Kotlin Symbol Processing API. This change replaces the previous KSP-based implementation with new files in the \moshi-kotlin-codegen/ksp\ directory (including \AppliedType\, \JsonClassSymbolProcessorProvider\, \KspUtil\, \MoshiApiUtil\, \TargetTypes\, and \shadedUtil\), enabling compatibility with newer Kotlin versions and improved symbol resolution.

moshi-kotlin-codegen/src/main/java/com/squareup/moshi/kotlin/codegen/ksp · high confidence

Moshi core library migrated to Kotlin

The Moshi core library has been migrated from Java to Kotlin. This includes the conversion of key components such as \JsonReader\, \JsonWriter\, \JsonAdapter\, and internal readers/writers (e.g., \-JsonUtf8Reader\, \-JsonValueWriter\) to Kotlin. Additionally, Kotlin-specific extension functions and type utilities (e.g., \MoshiKotlinExtensions\, \MoshiKotlinTypesExtensions\) have been added to the main package, providing idiomatic Kotlin support for type reflection and adapter creation.

moshi/src/main/java/com/squareup/moshi · high confidence

Test coverage

Added DualKotlinTest for Moshi Kotlin integration; Added Java test helper class for Moshi codegen tests; Added KSP2 integration tests for Moshi code generation; Added compile-only and runtime tests for codegen edge cases; Added comprehensive tests for Kotlin JSON adapter functionality; Added test coverage for Moshi adapters; Added test infrastructure for multi-module and reflective adapter scenarios; Added tests for Java Records support in Moshi; Expanded test coverage for Moshi JSON parsing and serialization.

Dependencies

Migrate build system to Gradle with Kotlin DSL

The project has been migrated from its previous build system to Gradle using Kotlin DSL (build.gradle.kts). This update introduces a modernized build configuration, including support for JDK 21, Kotlin 2.3.21, and KSP 2.3.9. The migration also includes updated plugins such as Spotless 8.7.0, Dokka 2.2.0, and Maven Publish 0.36.0, ensuring compatibility with the latest tooling and improved build performance.

(dependencies) · high confidence

Upgrade Gradle wrapper to version 9.5.1

The project's Gradle wrapper has been updated to version 9.5.1, ensuring that builds use this specific distribution. This change affects the build environment and may introduce behavioral changes or new features associated with Gradle 9.5.1.

gradle · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 39 → 62 (+23.1)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 93 → 88 (-5.7)
  • Architecture 94 → 96 (+2.3)
  • Maturity 50 → 55 (+5.1)
  • Readiness 26 → 58 (+32.7)
  • Security 30 → 65 (+34.9)

Resolved (16)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No artifact signing
  • No exposed public API
  • No tests found
  • Rotate the exposed credentials — git history can't be un-committed
  • Test reliability not included

New (71)

  • -JsonUtf8Reader.doPeek (cognitive 40) (moshi/src/main/java/com/squareup/moshi/-JsonUtf8Reader.kt)
  • -JsonUtf8Reader.doPeek (cyclomatic 40) (moshi/src/main/java/com/squareup/moshi/-JsonUtf8Reader.kt)
  • -JsonUtf8Reader.nextNonWhitespace (cognitive 18) (moshi/src/main/java/com/squareup/moshi/-JsonUtf8Reader.kt)
  • -JsonUtf8Reader.peekNumber (cognitive 44) (moshi/src/main/java/com/squareup/moshi/-JsonUtf8Reader.kt)
  • -JsonUtf8Reader.peekNumber (cyclomatic 33) (moshi/src/main/java/com/squareup/moshi/-JsonUtf8Reader.kt)
  • -JsonUtf8Reader.readEscapeCharacter (cyclomatic 19) (moshi/src/main/java/com/squareup/moshi/-JsonUtf8Reader.kt)
  • -JsonUtf8Reader.skipValue (cyclomatic 17) (moshi/src/main/java/com/squareup/moshi/-JsonUtf8Reader.kt)
  • AdapterGenerator.generateFromJsonRegular (cognitive 84) (moshi-kotlin-codegen/src/main/java/com/squareup/moshi/kotlin/codegen/api/AdapterGenerator.kt)
  • AdapterGenerator.generateFromJsonRegular (cyclomatic 50) (moshi-kotlin-codegen/src/main/java/com/squareup/moshi/kotlin/codegen/api/AdapterGenerator.kt)
  • AdapterMethodsFactory.create (cognitive 25) (moshi/src/main/java/com/squareup/moshi/internal/AdapterMethodsFactory.kt)
  • AdapterMethodsFactory.create (cyclomatic 17) (moshi/src/main/java/com/squareup/moshi/internal/AdapterMethodsFactory.kt)
  • ArrayJsonAdapter.toJson (cognitive 19) (moshi/src/main/java/com/squareup/moshi/internal/ArrayJsonAdapter.kt)
  • ArrayJsonAdapter.toJson (cyclomatic 19) (moshi/src/main/java/com/squareup/moshi/internal/ArrayJsonAdapter.kt)
  • Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
  • Documentation: no installation or build instructions (README.md)
  • FileTooLong: moshi/-JsonUtf8Reader.kt (moshi/src/main/java/com/squareup/moshi/-JsonUtf8Reader.kt)
  • Further orphaned files (smaller)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 51 more

Architecture

  • Containers 0 added · 0 removed · contexts 5 added · 0 removed · edges 2 added · 0 removed

Added bounded contexts (5)

  • examples
  • moshi
  • moshi-kotlin
  • moshi-kotlin-codegen
  • records-tests

Added dependency edges (2)

  • examples → moshi (coupling)
  • moshi-kotlin → moshi (coupling)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

square/moshi was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 889013ec2edb8d8034902662a1dc8c4f3b3f8111 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-dd72cc24c749.