sxyazi/yazi
40.8
Weak · 29 July 2026
59k
lines of production code
Rust
primary language
2
measurements over time
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 39 → 41 (+2.1)
- Rubric changed (rubric-2026.08.17 → rubric-2026.08.18) — scores are not directly comparable.
Lenses
- Code Health 86 → 86 (-0.1)
- Architecture 99 → 99 (-0.5)
- Maturity 50 → 58 (+8.5)
- Readiness 83 → 83 (+0.0)
- Security 59 → 59 (+0.0)
- Domain Modelling 100 → 100 (+0.0)
- Event-Driven 10 → 10 (+0.0)
Resolved (59)
- Boundary-crossing change coupling: relative.rs ↔ file.rs (yazi-fs/src/path/relative.rs)
- Boundary-crossing change coupling: task.rs ↔ progress.rs (yazi-actor/src/lives/task.rs)
- Boundary-crossing change coupling: task.rs ↔ progress.rs (yazi-actor/src/lives/task.rs)
- Change coupling: deploy.rs ↔ install.rs (yazi-cli/src/package/deploy.rs)
- Change coupling: in.rs ↔ out.rs (yazi-scheduler/src/in.rs)
- Change coupling: install.rs ↔ package.rs (yazi-cli/src/package/install.rs)
- Change coupling: mod.rs ↔ utils.rs (yazi-plugin/src/utils/mod.rs)
- Change coupling: out.rs ↔ progress.rs (yazi-scheduler/src/file/out.rs)
- Change coupling: progress.rs ↔ progress.rs (yazi-scheduler/src/file/progress.rs)
- Change coupling: progress.rs ↔ scheduler.rs (yazi-scheduler/src/file/progress.rs)
- Child.add_methods (cyclomatic 26) (yazi-binding/src/process/child.rs)
- Command.add_methods (cyclomatic 18) (yazi-binding/src/process/command.rs)
- Dependency hygiene not measured — no supported dependency manifest was read
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 39 more
New (57)
- Boundary-crossing change coupling: boot.rs ↔ xdg.rs (yazi-boot/src/boot.rs)
- Boundary-crossing change coupling: mux.rs ↔ term.rs (yazi-emulator/src/mux.rs)
- Boundary-crossing change coupling: term.rs ↔ tty.rs (yazi-term/src/term.rs)
- Build action pinned to a mutable branch
- Change coupling clique: task.rs, progress.rs, progress.rs, scheduler.rs (yazi-actor/src/lives/task.rs)
- Change coupling: border.rs ↔ list.rs (yazi-binding/src/elements/border.rs)
- Change coupling: dimension.rs ↔ emulator.rs (yazi-emulator/src/dimension.rs)
- Change coupling: iip.rs ↔ kgp.rs (yazi-adapter/src/drivers/iip.rs)
- Change coupling: kgp.rs ↔ kgp_old.rs (yazi-adapter/src/drivers/kgp.rs)
- Copy::act (cognitive 18) (yazi-actor/src/mgr/copy.rs)
- Copy::act (cyclomatic 17) (yazi-actor/src/mgr/copy.rs)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- FileTooLong: translit/table.rs (yazi-shared/src/translit/table.rs)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 37 more
Changes since last survey
- 13 commits — 7 feature/other, 6 fixes
By area
- yazi-fs/src — 4 commits
- yazi-actor/src — 2 commits
- yazi-config/src — 2 commits
- yazi-shared/src — 2 commits
- (root) — 1 commit
- .github/pull_request_template.md — 1 commit
- yazi-core/src — 1 commit
Notable commits
- fix: fix: copy path should always copy file paths (#4169)
- fix: fix: common opener matching misbehaves (#4172)
- fix: fix: privilege hovered file when splatting commands in the shell action (#4137)
- fix: fix: reconcile selected and yanked file states on a full list update (#4161)
- fix: fix: refresh file list after deleting a file from search view (#4174)
- fix: fix: refresh restored directories on Windows (#4168)
- change: docs: add a note about following the contribution guidelines in the PR template (#4140)
- change: feat: Unicode normalization for user regex patterns in find, filter, and search actions (#4177)
- change: feat: allow restoring trashed items recursively (#4159)
- change: feat: new --follow option for the link action (#4184)
- change: feat: show config path on parse error (#4150)
- change: feat: trash bin (#4144)
- change: perf: enable SSO (small string optimization) for custom schemes and custom styles (#4164)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
sxyazi/yazi was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 29 July 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 319f90e0eab185a231eef5562215ba322e320286 — the exact code this score is about.
- Scored under rubric-2026.08.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer latest.