Skip to content

Releases: codellm-devkit/codeanalyzer-java

v3.3.4

Choose a tag to compare

@github-actions github-actions released this 29 Sep 18:36

Install

pip install codeanalyzer-java==3.3.4   # bundles a JVM; installs the canjv launcher

Or the jar with a codeanalyzer launcher (requires Java 11+):

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/codellm-devkit/codeanalyzer-java/releases/download/v3.3.4/codeanalyzer-installer.sh | sh

Or run the JAR directly (requires Java 11+):

# JSON output, at the analysis level you ask for
java -jar codeanalyzer.jar -i /path/to/project -a 4 -o ./out          # writes out/analysis.json

# Neo4j projection - always full depth, so it takes no --analysis-level
java -jar codeanalyzer.jar -i /path/to/project --emit neo4j -o ./out  # writes out/graph.cypher

Downloads

Asset Description
codeanalyzer.jar Self-contained analyzer (run with java -jar)
codeanalyzer-installer.sh Installer that fetches the jar and adds a codeanalyzer launcher
schema.neo4j.json Neo4j graph schema contract (node labels, relationships, DDL)

📦 Other Changes

  • fix(artifacts): a non-identifier view-dispatch target is not a dataflow variable, not a NullPointerException

v3.3.3

Choose a tag to compare

@github-actions github-actions released this 11 Sep 16:08
2c8deb1

Install

pip install codeanalyzer-java==3.3.3   # bundles a JVM; installs the canjv launcher

Or the jar with a codeanalyzer launcher (requires Java 11+):

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/codellm-devkit/codeanalyzer-java/releases/download/v3.3.3/codeanalyzer-installer.sh | sh

Or run the JAR directly (requires Java 11+):

# JSON output, at the analysis level you ask for
java -jar codeanalyzer.jar -i /path/to/project -a 4 -o ./out          # writes out/analysis.json

# Neo4j projection - always full depth, so it takes no --analysis-level
java -jar codeanalyzer.jar -i /path/to/project --emit neo4j -o ./out  # writes out/graph.cypher

Downloads

Asset Description
codeanalyzer.jar Self-contained analyzer (run with java -jar)
codeanalyzer-installer.sh Installer that fetches the jar and adds a codeanalyzer launcher
schema.neo4j.json Neo4j graph schema contract (node labels, relationships, DDL)

📦 Other Changes

  • fix(artifacts): an unresolved receiver type is not a dispatch site, not a NullPointerException

v3.3.2

Choose a tag to compare

@github-actions github-actions released this 11 Sep 15:28
08860ae

Install

pip install codeanalyzer-java==3.3.2   # bundles a JVM; installs the canjv launcher

Or the jar with a codeanalyzer launcher (requires Java 11+):

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/codellm-devkit/codeanalyzer-java/releases/download/v3.3.2/codeanalyzer-installer.sh | sh

Or run the JAR directly (requires Java 11+):

# JSON output, at the analysis level you ask for
java -jar codeanalyzer.jar -i /path/to/project -a 4 -o ./out          # writes out/analysis.json

# Neo4j projection - always full depth, so it takes no --analysis-level
java -jar codeanalyzer.jar -i /path/to/project --emit neo4j -o ./out  # writes out/graph.cypher

Downloads

Asset Description
codeanalyzer.jar Self-contained analyzer (run with java -jar)
codeanalyzer-installer.sh Installer that fetches the jar and adds a codeanalyzer launcher
schema.neo4j.json Neo4j graph schema contract (node labels, relationships, DDL)

📦 Other Changes

  • fix(entrypoints): Jakarta finder marks lifecycle methods, not any method with a servlet parameter

v3.3.1

Choose a tag to compare

@github-actions github-actions released this 11 Sep 15:17
c95fcf7

Install

pip install codeanalyzer-java==3.3.1   # bundles a JVM; installs the canjv launcher

Or the jar with a codeanalyzer launcher (requires Java 11+):

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/codellm-devkit/codeanalyzer-java/releases/download/v3.3.1/codeanalyzer-installer.sh | sh

Or run the JAR directly (requires Java 11+):

# JSON output, at the analysis level you ask for
java -jar codeanalyzer.jar -i /path/to/project -a 4 -o ./out          # writes out/analysis.json

# Neo4j projection - always full depth, so it takes no --analysis-level
java -jar codeanalyzer.jar -i /path/to/project --emit neo4j -o ./out  # writes out/graph.cypher

Downloads

Asset Description
codeanalyzer.jar Self-contained analyzer (run with java -jar)
codeanalyzer-installer.sh Installer that fetches the jar and adds a codeanalyzer launcher
schema.neo4j.json Neo4j graph schema contract (node labels, relationships, DDL)

📦 Other Changes

  • feat(artifacts): may-dispatch over a static string table — J_DISPATCHES_TO with prov: [table]

v3.3.0

Choose a tag to compare

@github-actions github-actions released this 11 Sep 14:03
d7f12ed

Install

pip install codeanalyzer-java==3.3.0   # bundles a JVM; installs the canjv launcher

Or the jar with a codeanalyzer launcher (requires Java 11+):

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/codellm-devkit/codeanalyzer-java/releases/download/v3.3.0/codeanalyzer-installer.sh | sh

Or run the JAR directly (requires Java 11+):

# JSON output, at the analysis level you ask for
java -jar codeanalyzer.jar -i /path/to/project -a 4 -o ./out          # writes out/analysis.json

# Neo4j projection - always full depth, so it takes no --analysis-level
java -jar codeanalyzer.jar -i /path/to/project --emit neo4j -o ./out  # writes out/graph.cypher

Downloads

Asset Description
codeanalyzer.jar Self-contained analyzer (run with java -jar)
codeanalyzer-installer.sh Installer that fetches the jar and adds a codeanalyzer launcher
schema.neo4j.json Neo4j graph schema contract (node labels, relationships, DDL)

📦 Other Changes

  • feat(artifacts): view-template role and J_DISPATCHES_TO from dispatch sites to the Artifact they reach

v3.2.0

Choose a tag to compare

@github-actions github-actions released this 10 Sep 15:13
fbaf800

Install

pip install codeanalyzer-java==3.2.0   # bundles a JVM; installs the canjv launcher

Or the jar with a codeanalyzer launcher (requires Java 11+):

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/codellm-devkit/codeanalyzer-java/releases/download/v3.2.0/codeanalyzer-installer.sh | sh

Or run the JAR directly (requires Java 11+):

# JSON output, at the analysis level you ask for
java -jar codeanalyzer.jar -i /path/to/project -a 4 -o ./out          # writes out/analysis.json

# Neo4j projection - always full depth, so it takes no --analysis-level
java -jar codeanalyzer.jar -i /path/to/project --emit neo4j -o ./out  # writes out/graph.cypher

Downloads

Asset Description
codeanalyzer.jar Self-contained analyzer (run with java -jar)
codeanalyzer-installer.sh Installer that fetches the jar and adds a codeanalyzer launcher
schema.neo4j.json Neo4j graph schema contract (node labels, relationships, DDL)

🐛 Fixes

  • fix(neo4j): carry module.source and span byte offsets so the graph can resolve text
  • fix(neo4j): carry body_span, type parameters, leaf spans and call-site facts

📦 Other Changes

v3.1.2

Choose a tag to compare

@github-actions github-actions released this 09 Sep 14:07
c3d0b68

Install

pip install codeanalyzer-java==3.1.2   # bundles a JVM; installs the canjv launcher

Or the jar with a codeanalyzer launcher (requires Java 11+):

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/codellm-devkit/codeanalyzer-java/releases/download/v3.1.2/codeanalyzer-installer.sh | sh

Or run the JAR directly (requires Java 11+):

# JSON output, at the analysis level you ask for
java -jar codeanalyzer.jar -i /path/to/project -a 4 -o ./out          # writes out/analysis.json

# Neo4j projection - always full depth, so it takes no --analysis-level
java -jar codeanalyzer.jar -i /path/to/project --emit neo4j -o ./out  # writes out/graph.cypher

Downloads

Asset Description
codeanalyzer.jar Self-contained analyzer (run with java -jar)
codeanalyzer-installer.sh Installer that fetches the jar and adds a codeanalyzer launcher
schema.neo4j.json Neo4j graph schema contract (node labels, relationships, DDL)

📦 Other Changes

  • fix(sdg): param_in/param_out carry the bound formal's var in JSON and on J_PARAM_IN/OUT

v3.1.1

Choose a tag to compare

@github-actions github-actions released this 08 Sep 10:39
fdab050

Install

pip install codeanalyzer-java==3.1.1   # bundles a JVM; installs the canjv launcher

Or the jar with a codeanalyzer launcher (requires Java 11+):

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/codellm-devkit/codeanalyzer-java/releases/download/v3.1.1/codeanalyzer-installer.sh | sh

Or run the JAR directly (requires Java 11+):

# JSON output, at the analysis level you ask for
java -jar codeanalyzer.jar -i /path/to/project -a 4 -o ./out          # writes out/analysis.json

# Neo4j projection - always full depth, so it takes no --analysis-level
java -jar codeanalyzer.jar -i /path/to/project --emit neo4j -o ./out  # writes out/graph.cypher

Downloads

Asset Description
codeanalyzer.jar Self-contained analyzer (run with java -jar)
codeanalyzer-installer.sh Installer that fetches the jar and adds a codeanalyzer launcher
schema.neo4j.json Neo4j graph schema contract (node labels, relationships, DDL)

📦 Other Changes

  • docs: the PyPI install needs a real JDK from -a 2 onwards
  • feat(cli): --strict fails a run whose analysis degraded
  • chore(release): 3.1.1
  • feat(id): can:///java/… — the app becomes the outermost segment, and the graph root gets its id
  • docs(plan): can:///java/… identity migration
  • feat(ids): @external drops the language segment; document the polyglot rule

⚠️ Breaking: the can:// id grammar changed

Every durable id moved. The application is now the outermost segment:

before   can://java/<app>/<file>/<type>/<signature>
after    can://<app>/java/<file>/<type>/<signature>

before   can://artifact/<app>/<path>            after   can://<app>/artifact/<path>
before   can://java/<app>/@external/<type>/<sig> after   can://<app>/@external/<type>/<sig>

@external and artifact deliberately omit the language segment: they are language-neutral shared merge targets, so codeanalyzer-python and codeanalyzer-typescript mint byte-identical ids for the same file or library symbol. This release converges Java onto the shape those two already use.

schema_version remains 2.0.0, so this change is NOT detectable from the payload. A stored analysis.json or Neo4j graph written by 3.1.0 or earlier holds old-shape ids that will no longer join against 3.1.1 output. The analyzer version is the only signal. If you have persisted ids, re-analyze.

Neo4j: existing databases need one upgrade push, and it is handled. :JApplication now merges on its can://<app> id rather than the free-text --app-name, and the legacy j_application_name uniqueness constraint is dropped before any load — without that, the first push against a pre-3.1.1 database would fail with ConstraintValidationFailed. Verified end to end against Neo4j 5.

The Cypher wipe now covers the whole can://<app>/ prefix, which brings :Artifact and :ConfigKey inside it. They are rebuilt by every snapshot instead of accumulating forever. One deliberate consequence: a cross-language edge into a shared :Artifact is dropped by one analyzer's snapshot and restored on the other's next push. :Package (pkg: purls) sits under no application and is never wiped.

What this does not do: the app id is derived from --app-name, so two services analyzed under the same name still merge onto one root. Give each service its own --app-name.

New: --strict

A degraded run — the RTA overlay or the L4 semantic ddg unavailable — previously exited 0 with only a WARN on stderr. --strict turns any such degradation into a non-zero exit that names what was lost, and writes no analysis.json, so a pipeline cannot mistake a thin payload for a complete one. Opt-in: degrading remains a supported mode.

Relevant if you install from PyPI: the bundled jdk4py runtime is a JRE with no javac, so -a 2 and above need a real JDK on JAVA_HOME. Without one, RTA and the semantic ddg silently drop — which is exactly what --strict surfaces.

v3.1.0

Choose a tag to compare

@github-actions github-actions released this 07 Sep 22:48
21cc730

Install

pip install codeanalyzer-java==3.1.0   # bundles a JVM; installs the canjv launcher

Or the jar with a codeanalyzer launcher (requires Java 11+):

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/codellm-devkit/codeanalyzer-java/releases/download/v3.1.0/codeanalyzer-installer.sh | sh

Or run the JAR directly (requires Java 11+):

# JSON output, at the analysis level you ask for
java -jar codeanalyzer.jar -i /path/to/project -a 4 -o ./out          # writes out/analysis.json

# Neo4j projection - always full depth, so it takes no --analysis-level
java -jar codeanalyzer.jar -i /path/to/project --emit neo4j -o ./out  # writes out/graph.cypher

Downloads

Asset Description
codeanalyzer.jar Self-contained analyzer (run with java -jar)
codeanalyzer-installer.sh Installer that fetches the jar and adds a codeanalyzer launcher
schema.neo4j.json Neo4j graph schema contract (node labels, relationships, DDL)

📦 Other Changes

  • feat(config): config-read literal tier — J_USES_CONFIG and J_READS_CONFIG_UNRESOLVED
  • feat(entrypoints): report on the application root, framework attribution on the node
  • feat(config): dataflow tiers — close non-literal keys over the L3 DDG and L4 call graph
  • docs(schema): stop calling the graph contract 2.2.0
  • chore(release): 3.1.0

v3.0.3

Choose a tag to compare

@github-actions github-actions released this 07 Sep 04:52
e6082ed

Install

pip install codeanalyzer-java==3.0.3   # bundles a JVM; installs the canjv launcher

Or the jar with a codeanalyzer launcher (requires Java 11+):

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/codellm-devkit/codeanalyzer-java/releases/download/v3.0.3/codeanalyzer-installer.sh | sh

Or run the JAR directly (requires Java 11+):

# JSON output, at the analysis level you ask for
java -jar codeanalyzer.jar -i /path/to/project -a 4 -o ./out          # writes out/analysis.json

# Neo4j projection - always full depth, so it takes no --analysis-level
java -jar codeanalyzer.jar -i /path/to/project --emit neo4j -o ./out  # writes out/graph.cypher

Downloads

Asset Description
codeanalyzer.jar Self-contained analyzer (run with java -jar)
codeanalyzer-installer.sh Installer that fetches the jar and adds a codeanalyzer launcher
schema.neo4j.json Neo4j graph schema contract (node labels, relationships, DDL)

📦 Other Changes

  • fix(ddg): drop dependence edges whose endpoint is not a body node
  • fix(l4): join the SDG port lattice to the statement ddg