talentdeficit/jsx
57.9
Adequate · 23 September 2026
4.5k
lines of production code
Erlang
primary language
5
measurements over time
What this system is
This system is a JSON processing library that provides encoding and decoding capabilities for converting between JSON and Erlang terms. It supports streaming and incremental parsing through incomplete result tuples and offers a structured configuration system to manage parser behavior. The library also includes utilities for reading multiple JSON terms from files and maintains standard project documentation and dependency management.
Features
Initial release of jsx v3.0.0
This commit introduces the initial state of the jsx library at version 3.0.0, establishing the project's build and documentation infrastructure. It adds the \.gitignore\ file to exclude build artifacts and dependencies, a \rebar.config\ to configure Erlang compilation with debug info and Dialyzer warnings, and a \rebar.lock\ for dependency management. Additionally, it includes the \README.md\ with usage examples and API documentation, the \CHANGES.md\ file detailing version history, and the \LICENSE\ file containing the MIT license text.
(repo-wide) · high confidence
Behavioural changes
Major API overhaul with new modules and configuration system
The library introduces a completely new API surface, replacing the previous \json\_to\_term\/\term\_to\_json\ functions with \decode\ and \encode\ in the main \jsx\ module. This change is supported by new modules \jsx\_config\ and \jsx\_config.hrl\ which manage a structured configuration record, replacing the previous proplist-based options. The decoder and encoder now return \{incomplete, Fun}\ tuples to support streaming and incremental parsing, and the \jsx\_parser\ module provides a token-based interface for custom tokenizers. Additionally, a \consult\ function is added to read multiple JSON terms from a file.
src · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 48 → 58 (+9.8)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 92 → 92 (-0.5)
- Architecture 100 → 100 (+0.0)
- Maturity 33 → 32 (-0.7)
- Readiness 33 → 67 (+33.8)
- Security 85 → 97 (+12.1)
Resolved (10)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High: security finding (details withheld)
- High: security finding (details withheld)
- No automated tests
- No exposed public API
- No tests found
- Test reliability not included
- TooManyMethods: jsx_decoder (src/jsx_decoder.erl)
- complexity unreadable for .erl, .hrl — churn × complexity hotspots could not be measured
- dormant codebase — no living knowledge left to concentrate
New (21)
- Coverage not measured — no coverage collector is wired up
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (12 lines × 3) (src/jsx_to_json.erl)
- Duplicated block (5 lines × 7) (src/jsx_decoder.erl)
- Duplicated block (7 lines × 2) (src/jsx_decoder.erl)
- Duplicated block (7 lines × 2) (src/jsx_decoder.erl)
- Duplicated block (7 lines × 2) (src/jsx_decoder.erl)
- Duplicated block (7 lines × 2) (src/jsx_to_json.erl)
- Duplicated block (8–9 lines × 2) (src/jsx_decoder.erl)
- Duplicated block (8–9 lines × 3) (src/jsx_parser.erl)
- Edited copy of a member (13 corresponding lines) (src/jsx_to_json.erl)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium: security finding (details withheld)
- TodoComment (src/jsx_decoder.erl)
- Workflow token permissions not restricted
- jsx_decoder.is_partial_escape (cognitive 26) (src/jsx_decoder.erl)
- jsx_decoder.is_partial_escape (cyclomatic 32) (src/jsx_decoder.erl)
- jsx_decoder.unescape (cognitive 38) (src/jsx_decoder.erl)
- …and 1 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
talentdeficit/jsx was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 1d3407aa9752430ec0a06111ac1b046ffafdca22 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.