Vashkatsi/deply
58.4
Adequate · 22 September 2026
5.5k
lines of production code
Python
primary language
7
measurements over time
What this system is
Deply is a Python-based static analysis tool designed to validate project architecture against configurable layer definitions and structural rules. It enables teams to enforce constraints on dependencies, naming conventions, and imports by modeling code elements and tracking their relationships through an extensible collector system. The tool supports parallel processing, inline violation suppression, and exports results in multiple formats including SARIF and Mermaid diagrams for integration into CI/CD pipelines.
Features
Deply 1.1.2: New architecture analysis tool with configurable layers, validation, and multi-format reporting
Deply version 1.1.2 introduces a new Python architecture analysis tool that validates project structure against configurable layer definitions and rules. Users can define layers using various collectors (file regex, class inheritance, decorators, etc.) and enforce rules such as disallowing layer dependencies or enforcing naming conventions. The tool validates configuration files before analysis, supports parallel processing for performance, and allows suppressing violations via inline comments. Analysis results can be exported in text, JSON, GitHub Actions, or SARIF formats, and a Mermaid diagram can be generated to visualize layer dependencies and violations.
deply · high confidence
Initial release of static analysis utility modules
This change introduces the core utility components for the deply static analysis engine. It adds AST parsing helpers in \ast\_utils.py\ to handle Python source code, including support for various source encodings and Python 3.8+ type annotation syntax. The \dependency\_visitor.py\ module provides an AST visitor that tracks code dependencies such as function calls, imports, class inheritance, and decorators. Additionally, \ignore\_parser.py\ implements logic to parse \\# deply:ignore\ comments for suppressing specific analysis rules at the file or line level.
deply/utils · high confidence
Introduce core data models for code analysis and rule violations
This change introduces the foundational data structures for the deply analysis engine, defining how code elements, dependencies, and architectural violations are represented. Users can now expect the system to model code elements (classes, functions, variables) with detailed metadata such as decorators, inheritance, and type annotations. It also defines a Dependency model to track relationships between code elements and a Layer model to group them. Crucially, it establishes a structured Violation model and a ViolationType enum, enabling the system to report specific rule breaches like disallowed dependencies, external imports, decorator usage, naming conventions, and inheritance issues with standardized codes and display names.
deply/models · high confidence
Introduce extensible custom collector system for code analysis
The \deply/collectors\ module now provides a structured, extensible system for collecting code elements. It introduces a \BaseCollector\ abstract class and a \CollectorFactory\ that instantiates specific collectors based on configuration, including built-in types like \file\_regex\, \class\_inherits\, \class\_name\_regex\, \function\_name\_regex\, \directory\, \decorator\_usage\, and a \bool\ collector for logical composition (must/any\_of/must\_not). Additionally, a \custom\ collector type allows users to plug in external classes that inherit from \BaseCollector\, enabling tailored analysis logic without modifying the core library.
deply/collectors · high confidence
Introduce structured layer-based dependency and code-style rules
The \deply/rules\ module now provides a comprehensive rule engine for enforcing architectural and stylistic constraints. Users can define layer-specific policies via configuration, including disallowing dependencies between layers (\DependencyRule\), blocking external imports (\ExternalImportRule\), enforcing naming patterns for classes and functions, requiring specific decorators, mandating inheritance from base classes, and composing complex logic with boolean rules (\BoolRule\). These rules are instantiated through a \RuleFactory\ and report violations with detailed context, enabling automated quality gates for code structure and external dependencies.
deply/rules · high confidence
Behavioural changes
Deply v1.1.2 release with Python 3.14 support and CI hardening
This release updates the package version to 1.1.2 and adds explicit support for Python 3.14 in the setup classifiers. The CI release flow has been hardened, and the project now includes a Makefile with targets for linting, typing, security checks, and mutation testing, alongside a pre-commit configuration integrating Ruff, MyPy, and pip-audit.
(repo-wide) · high confidence
Test coverage
Initial test suite for the deply architecture analysis tool
Added a comprehensive set of unit tests for the deply code analysis engine, covering the core AST utility functions (import aliases, decorator names, annotations), the collector factory (including custom collector instantiation and error handling), and specific collectors such as FileRegex, ClassInherits, Directory, and DecoratorUsage. The suite also validates the configuration validator's ability to reject invalid paths and unknown fields, tests the dependency visitor's tracking of imports, function calls, and inheritance, and verifies the DeplyRunner's parallel execution worker count logic.
tests · high confidence
Dependencies
Initial project dependency and configuration setup
Established the project's build and development environment by adding pyproject.toml, requirements.txt, and requirements-dev.txt. The runtime dependency PyYAML (\>=5.1) is defined, while development tools including ruff, mypy, pip-audit, pre-commit, types-PyYAML, mutmut, and pytest are specified for code quality, security auditing, and mutation testing workflows.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 49 → 58 (+9.8)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 79 → 83 (+3.3)
- Architecture 100 → 100 (+0.0)
- Maturity 72 → 73 (+1.4)
- Readiness 46 → 50 (+3.9)
- Security 33 → 52 (+18.5)
Resolved (57)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (11 lines × 2) (deply/rules/class_decorator_rule.py)
- Duplicated block (11 lines × 2) (deply/utils/dependency_visitor.py)
- Duplicated block (11 lines × 2) (deply/utils/dependency_visitor.py)
- Duplicated block (12 lines × 2) (deply/collectors/class_inherits_collector.py)
- Duplicated block (12 lines × 2) (deply/collectors/directory_collector.py)
- Duplicated block (12 lines × 2) (deply/collectors/directory_collector.py)
- Duplicated block (12 lines × 2) (deply/utils/dependency_visitor.py)
- Duplicated block (13 lines × 2) (deply/collectors/directory_collector.py)
- Duplicated block (13 lines × 2) (deply/collectors/directory_collector.py)
- Duplicated block (14 lines × 2) (deply/collectors/class_name_regex_collector.py)
- Duplicated block (14 lines × 2) (deply/collectors/file_regex_collector.py)
- Duplicated block (5 lines × 2) (deply/collectors/class_name_regex_collector.py)
- Duplicated block (8 lines × 2) (deply/collectors/decorator_usage_collector.py)
- Duplicated block (8 lines × 2) (deply/utils/ast_utils.py)
- Duplicated block (9 lines × 2) (deply/collectors/directory_collector.py)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 37 more
New (80)
- ConfigValidator._validate_collector (cyclomatic 19) (deply/config_validator.py)
- Dependency advisory scan runs only on code events
- Dependency hygiene PARTLY measured — Python dependencies read, no exact pin to grade for currency
- Documentation: no architecture or design documentation (README.md)
- Duplicated block (11 lines × 2) (deply/collectors/directory_collector.py)
- Duplicated block (11 lines × 2) (deply/utils/dependency_visitor.py)
- Duplicated block (11–15 lines × 3) (deply/collectors/class_inherits_collector.py)
- Duplicated block (12 lines × 2) (deply/utils/dependency_visitor.py)
- Duplicated block (13 lines × 2) (deply/collectors/directory_collector.py)
- Duplicated block (13 lines × 2) (deply/utils/dependency_visitor.py)
- Duplicated block (13–14 lines × 3) (deply/collectors/class_inherits_collector.py)
- Duplicated block (15 lines × 2) (deply/collectors/directory_collector.py)
- Duplicated block (15–19 lines × 2) (deply/collectors/directory_collector.py)
- Duplicated block (16 lines × 2) (deply/rules/class_decorator_rule.py)
- Duplicated block (17 lines × 2) (deply/collectors/file_regex_collector.py)
- Duplicated block (18 lines × 2) (deply/collectors/class_inherits_collector.py)
- Duplicated block (28–31 lines × 2) (deply/collectors/decorator_usage_collector.py)
- Duplicated block (31 lines × 2) (deply/collectors/directory_collector.py)
- Duplicated block (5 lines × 2) (deply/collectors/class_name_regex_collector.py)
- Duplicated block (6 lines × 2) (deply/collectors/class_inherits_collector.py)
- …and 60 more
Changes since last survey
- 24 commits — 16 feature/other, 8 fixes
By area
- (root) — 8 commits
- (repo) — 6 commits
- skills/deply-config — 3 commits
- deply/deply_runner.py — 2 commits
- deply/reports — 2 commits
- deply/code_analyzer.py — 1 commit
- deply/utils — 1 commit
- doc/features.md — 1 commit
Notable commits
- fix: Fix async and nested scope tracking (#14)
- fix: Fix overlapping layer ownership
- fix: Merge pull request #16 from Vashkatsi/fix/fail-incomplete-analysis
- fix: Merge pull request #19 from Vashkatsi/fix/layer-ownership-contract
- fix: fix: canonicalize completeness metrics
- fix: fix: fail incomplete analysis
- fix: fix: scope local import dependencies
- fix: fix: support Python source encodings
- change: Add Full Stack FastAPI Template config (#18)
- change: Add SARIF architecture reports (#25)
- change: Merge pull request #17 from Vashkatsi/chore/release-v1.0.0
- change: Merge pull request #21 from Vashkatsi/feat/analysis-completeness-metrics
- change: Merge pull request #22 from Vashkatsi/chore/release-v1.1.0
- change: Merge pull request #26 from Vashkatsi/plan/module-aware-resolution
- change: Validate configuration before analysis (#15)
- change: chore: release 1.0.0
- change: chore: release 1.1.0
- change: chore: release 1.1.1 (#24)
- change: chore: release 1.1.2
- change: docs: describe local import ownership
- …and 4 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
Vashkatsi/deply was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 25a4bc6c4dbeef0c7e4913d826fffc1be68e126f — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.