struppigel/PortEx
61.6
Adequate · 20 September 2026
26.6k
lines of production code
Scala
with Java
1
measurement over time
What this system is
This system is a Java and Scala library for parsing and analyzing Portable Executable (PE) files and .NET CLR metadata. It provides core capabilities for interpreting PE headers, extracting section data, and inspecting detailed metadata tables such as assemblies, security declarations, and imports. The tool also includes file-type signature databases to classify diverse formats and utilities for robustness testing and performance benchmarking.
Features
Expanded PE and .NET metadata parsing specifications
The data directory now includes comprehensive specification files for parsing PE headers (COFF, Optional, Data Directories, Debug, Relocations, DLL/Section Characteristics) and .NET CLR metadata tables (Assembly, AssemblyRef, ClassLayout, Constant, CustomAttribute, DeclSecurity, Event, Field, GenericParam, ManifestResource, MemberRef, and more). Additionally, new signature databases for file type detection (customsigs\_GCK.txt), Java wrapper executables (javawrapperdb), and Windows API import categorization (importcategories.txt) have been added to support enhanced file analysis and anomaly detection.
src/main/java/data · high confidence
Expanded PE and CLR metadata parsing with new file-type signatures
The analysis engine now supports parsing additional PE and .NET CLR metadata tables (including Assembly, AssemblyRef, ClassLayout, Constant, CustomAttribute, DeclSecurity, Event, EventMap, ExportedType, Field, FieldLayout, FieldMarshal, FieldRVA, File, GenericParam, GenericParamConstraint, ImplMap, InterfaceImpl, and MethodSpec) and their corresponding header specifications. This enables deeper inspection of .NET assembly references, metadata, and security declarations. Additionally, the tool has added a comprehensive set of file-type signatures (in \customsigs\_GCK.txt\) for identifying various formats such as JPEG2000, MPEG-4, Windows icons, TrueType fonts, and various archives, enhancing its ability to detect and classify diverse file types during scanning.
src/main/resources · high confidence
Initial release of PE file parsing library
The library now provides core capabilities for parsing Portable Executable (PE) files, including loading and interpreting headers (MS-DOS, COFF, Optional, Section Table, and Rich headers), mapping virtual to physical file addresses, and extracting data from various PE sections such as exports, imports, resources, and debug information. This initial release introduces the foundational parser classes and utilities required to analyze PE file structures.
repository, src/main/java/io · high confidence
Behavioural changes
License changed from BSD to Apache 2.0 and project documentation updated
The project license has been switched from the BSD-style license to the Apache License, Version 2.0, which changes the terms under which the software can be used, modified, and distributed. The README has been significantly expanded to include detailed feature lists, usage instructions for Maven and SBT, build requirements, and author contact information.
(repo-wide) · high confidence
Test coverage
Added comprehensive test suite and analysis utilities for PE parsing
Added a new set of test classes in src/test to verify the PE parser's robustness and specification compliance, including RobustnessTest for loading problematic files, SpecificationTest for header enum coherence, and unit tests for PEData, PELoader, PESignature, COFF headers, and utility classes. Also added test support utilities (TestreportsReader, TestData) and analysis scripts (PerformanceTester, PortexStats, WhiteNBlackListing, WikiExampleCodes) to support testing, performance benchmarking, and documentation examples.
src/test · high confidence
Dependencies
PortEx 5.0.7-SNAPSHOT dependency and build configuration update
The build configuration has been updated to Scala 2.12.20 and includes significant dependency upgrades, most notably to Guava 33.4.8-jre and Log4j API 2.25.0, alongside TestNG 6.14.3 for testing. The project is now configured to publish snapshots to Sonatype Central and utilizes GitHub Packages for releases, with local builds automatically bypassing GitHub credentials when no token is present.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 62.
Lenses
- Code Health 88
- Architecture 99
- Maturity 59
- Readiness 51
- Security 74
Changes since last survey
- 300 commits — 276 feature/other, 24 fixes
By area
- src/main — 146 commits
- progs/PortexAnalyzer.jar — 65 commits
- (root) — 59 commits
- (repo) — 15 commits
- src/test — 11 commits
- progs/readme.txt — 2 commits
- progs/maldet.jar — 1 commit
- project/build.properties — 1 commit
Notable commits
- fix: #6 export ordinal table with negative entry number fixed.
- fix: #6 version fix
- fix: ComplexReHintAnomaly scanning added. Fixed out of memory error from too many exports.
- fix: Description fixed
- fix: Fix for parsing non-existant ExportOrdinalTable like in Petna sample
- fix: Fixed a bug in Visualizer that caused a null pointer exception if image creation is done in specific order.
- fix: ImageBase anomaly fix Update of Wiki example codes
- fix: PortExAnalyzer quick fixes
- fix: PortexAnalyzer update for latest fix
- fix: Quick fixes
- fix: Resource name bug fixed
- fix: RichHeader fix of misaligned values
- fix: added more ReHint tests, fixed issues, applied filetype scanning to overlay
- fix: bug fix for ordinal table rva after eof
- fix: bugfix for #5, ordinal export table with invalid offset
- fix: bugfix parent directory for dump output
- fix: export bug fix
- fix: fixed RichHeader alignment bug
- fix: fixed crash from invalid codeview structure
- fix: fixed unknown subsystem error
- …and 280 more
Architecture
- 0 containers · 1 bounded contexts · 0 dependency edges (baseline)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
struppigel/PortEx was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit d38dbae65c35f5af8b4eda17efc0da96675b503b — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.