square/moshi
61.7
Adequate · 25 September 2026
13.5k
lines of production code
Kotlin
with Java
4
measurements over time
What this system is
Features
Add recipe examples for custom adapters and data handling
Added a collection of example files in the \examples\ directory to demonstrate various Moshi usage patterns. These include custom adapters for types like \ByteString\ and \Card\, handling multiple JSON formats, unwrapping envelope objects, recovering from data mismatches, and serializing nulls for annotated types. The examples also cover custom field names, qualifiers, and date formatting.
examples · high confidence
Added support for Java 16+ records via RecordJsonAdapter
The Moshi library now includes a new \RecordJsonAdapter\ implementation located in the \java16\ source set, enabling serialization and deserialization of Java 16+ record classes. This adapter uses reflection to map record components to JSON properties, allowing users to serialize and deserialize Java records directly with Moshi.
moshi/src/main/java16 · high confidence
Initial project scaffolding and documentation
The repository was initialized with essential configuration and documentation files, including \.editorconfig\ for code formatting, \.gitattributes\ and \.gitignore\ for version control hygiene, and \releasing.md\ for release procedures. The \README.md\ was expanded to include comprehensive usage examples for Java and Kotlin, and the \gradlew\ wrapper scripts were added to support the build system.
(repo-wide) · high confidence
Behavioural changes
Add Moshi ProGuard/R8 rules for code generation and annotations
A new ProGuard configuration file (moshi.pro) is embedded in the Moshi library to preserve critical classes and members during minification. This ensures that methods annotated with @FromJson and @ToJson are retained, as are the fields and synthesized values() methods for annotated enums. It also preserves classes with Moshi annotations and specific internal utility methods, preventing R8/ProGuard from stripping necessary reflection or code-generation artifacts.
moshi/src/main/resources · medium confidence
Convert Moshi adapters to Kotlin
The \moshi-adapters\ module has been converted from Java to Kotlin. This includes the \Rfc3339DateJsonAdapter\, \EnumJsonAdapter\, \Iso8601Utils\, and \PolymorphicJsonAdapterFactory\. The \Rfc3339DateJsonAdapter\ was moved to the \com.squareup.moshi.adapters\ package to avoid Java Platform Module System conflicts, with the old location marked as deprecated. The \PolymorphicJsonAdapterFactory\ was also converted, ensuring consistent Kotlin implementation across the library's core adapters.
moshi-adapters/src/main · high confidence
Converted internal adapters to Kotlin
The internal \com.squareup.moshi.internal\ package has been converted from Java to Kotlin. This includes rewriting core adapter implementations such as \AdapterMethodsFactory\, \ArrayJsonAdapter\, \ClassFactory\, \ClassJsonAdapter\, \CollectionJsonAdapter\, \JsonScope\, \JsonValueSource\, \KotlinReflectTypes\, \LinkedHashTreeMap\, \MapJsonAdapter\, \NonNullJsonAdapter\, \NullSafeJsonAdapter\, \RecordJsonAdapter\, and \StandardJsonAdapters\ into Kotlin source files. This change modernizes the internal implementation while maintaining the same serialization and deserialization behavior for standard types, collections, maps, and custom adapters.
moshi/src/main/java/com/squareup/moshi/internal · high confidence
Migrate code generation API to Kotlin and restructure internal API
The internal code generation API in \moshi-kotlin-codegen\ has been migrated from Java to Kotlin, with all classes in the \com.squareup.moshi.kotlin.codegen.api\ package (including \AdapterGenerator\, \DelegateKey\, \ProguardRules\, and others) now written in Kotlin. This change introduces an \@InternalMoshiCodegenApi\ annotation to mark the internal API and updates the implementation of the code generator, which may affect how generated adapters are structured or how ProGuard rules are applied. The migration also includes updates to support Kotlin 2.3 compilation and handling of value classes.
moshi-kotlin-codegen/src/main/java/com/squareup/moshi/kotlin/codegen/api · high confidence
Migrated Kotlin reflection implementation to kotlin-metadata
The Kotlin reflection implementation has been refactored to use the kotlin-metadata library for parsing Kotlin metadata annotations. This change introduces new internal classes in the \com.squareup.moshi.kotlin.reflect\ package, including \KotlinJsonAdapterFactory\, \KtTypes\, \KmExecutable\, and \JvmDescriptors\, which handle the parsing of Kotlin-specific types, constructors, and properties. The old \KotlinJsonAdapterFactory\ in the \com.squareup.moshi\ package is now deprecated and redirects to the new location to avoid package name conflicts in the Java Platform Module System. Additionally, ProGuard/R8 rules have been updated to preserve the necessary metadata annotations and classes at runtime.
moshi-kotlin/src/main · high confidence
Moshi Kotlin codegen migrates to KSP2
The Moshi Kotlin codegen module has been migrated to use KSP2, the second generation of the Kotlin Symbol Processing API. This change replaces the previous KSP-based implementation with new files in the \moshi-kotlin-codegen/ksp\ directory (including \AppliedType\, \JsonClassSymbolProcessorProvider\, \KspUtil\, \MoshiApiUtil\, \TargetTypes\, and \shadedUtil\), enabling compatibility with newer Kotlin versions and improved symbol resolution.
moshi-kotlin-codegen/src/main/java/com/squareup/moshi/kotlin/codegen/ksp · high confidence
Moshi core library migrated to Kotlin
The Moshi core library has been migrated from Java to Kotlin. This includes the conversion of key components such as \JsonReader\, \JsonWriter\, \JsonAdapter\, and internal readers/writers (e.g., \-JsonUtf8Reader\, \-JsonValueWriter\) to Kotlin. Additionally, Kotlin-specific extension functions and type utilities (e.g., \MoshiKotlinExtensions\, \MoshiKotlinTypesExtensions\) have been added to the main package, providing idiomatic Kotlin support for type reflection and adapter creation.
moshi/src/main/java/com/squareup/moshi · high confidence
Test coverage
Added DualKotlinTest for Moshi Kotlin integration; Added Java test helper class for Moshi codegen tests; Added KSP2 integration tests for Moshi code generation; Added compile-only and runtime tests for codegen edge cases; Added comprehensive tests for Kotlin JSON adapter functionality; Added test coverage for Moshi adapters; Added test infrastructure for multi-module and reflective adapter scenarios; Added tests for Java Records support in Moshi; Expanded test coverage for Moshi JSON parsing and serialization.
Dependencies
Migrate build system to Gradle with Kotlin DSL
The project has been migrated from its previous build system to Gradle using Kotlin DSL (build.gradle.kts). This update introduces a modernized build configuration, including support for JDK 21, Kotlin 2.3.21, and KSP 2.3.9. The migration also includes updated plugins such as Spotless 8.7.0, Dokka 2.2.0, and Maven Publish 0.36.0, ensuring compatibility with the latest tooling and improved build performance.
(dependencies) · high confidence
Upgrade Gradle wrapper to version 9.5.1
The project's Gradle wrapper has been updated to version 9.5.1, ensuring that builds use this specific distribution. This change affects the build environment and may introduce behavioral changes or new features associated with Gradle 9.5.1.
gradle · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 39 → 62 (+23.1)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 93 → 88 (-5.7)
- Architecture 94 → 96 (+2.3)
- Maturity 50 → 55 (+5.1)
- Readiness 26 → 58 (+32.7)
- Security 30 → 65 (+34.9)
Resolved (16)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- No artifact signing
- No exposed public API
- No tests found
- Rotate the exposed credentials — git history can't be un-committed
- Test reliability not included
New (71)
- -JsonUtf8Reader.doPeek (cognitive 40) (moshi/src/main/java/com/squareup/moshi/-JsonUtf8Reader.kt)
- -JsonUtf8Reader.doPeek (cyclomatic 40) (moshi/src/main/java/com/squareup/moshi/-JsonUtf8Reader.kt)
- -JsonUtf8Reader.nextNonWhitespace (cognitive 18) (moshi/src/main/java/com/squareup/moshi/-JsonUtf8Reader.kt)
- -JsonUtf8Reader.peekNumber (cognitive 44) (moshi/src/main/java/com/squareup/moshi/-JsonUtf8Reader.kt)
- -JsonUtf8Reader.peekNumber (cyclomatic 33) (moshi/src/main/java/com/squareup/moshi/-JsonUtf8Reader.kt)
- -JsonUtf8Reader.readEscapeCharacter (cyclomatic 19) (moshi/src/main/java/com/squareup/moshi/-JsonUtf8Reader.kt)
- -JsonUtf8Reader.skipValue (cyclomatic 17) (moshi/src/main/java/com/squareup/moshi/-JsonUtf8Reader.kt)
- AdapterGenerator.generateFromJsonRegular (cognitive 84) (moshi-kotlin-codegen/src/main/java/com/squareup/moshi/kotlin/codegen/api/AdapterGenerator.kt)
- AdapterGenerator.generateFromJsonRegular (cyclomatic 50) (moshi-kotlin-codegen/src/main/java/com/squareup/moshi/kotlin/codegen/api/AdapterGenerator.kt)
- AdapterMethodsFactory.create (cognitive 25) (moshi/src/main/java/com/squareup/moshi/internal/AdapterMethodsFactory.kt)
- AdapterMethodsFactory.create (cyclomatic 17) (moshi/src/main/java/com/squareup/moshi/internal/AdapterMethodsFactory.kt)
- ArrayJsonAdapter.toJson (cognitive 19) (moshi/src/main/java/com/squareup/moshi/internal/ArrayJsonAdapter.kt)
- ArrayJsonAdapter.toJson (cyclomatic 19) (moshi/src/main/java/com/squareup/moshi/internal/ArrayJsonAdapter.kt)
- Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
- Documentation: no installation or build instructions (README.md)
- FileTooLong: moshi/-JsonUtf8Reader.kt (moshi/src/main/java/com/squareup/moshi/-JsonUtf8Reader.kt)
- Further orphaned files (smaller)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 51 more
Architecture
- Containers 0 added · 0 removed · contexts 5 added · 0 removed · edges 2 added · 0 removed
Added bounded contexts (5)
- examples
- moshi
- moshi-kotlin
- moshi-kotlin-codegen
- records-tests
Added dependency edges (2)
- examples → moshi (coupling)
- moshi-kotlin → moshi (coupling)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
square/moshi was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 889013ec2edb8d8034902662a1dc8c4f3b3f8111 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-dd72cc24c749.