GoForge — Build | Test | Ship | Collaborate GoForge — Build | Test | Ship | Collaborate
v0.23.0

assayxport

A codebase's API composition as deterministic JSON

$ go install goforge.dev/assayxport/cmd/ax@latest

Assaying analyzes a metal to report its exact composition. assayxport analyzes a codebase to report its exact API composition — where each symbol lives, what package it belongs to, its signature, its docs, whether it is a runnable entrypoint, and who it calls — as a deterministic JSON manifest at the project root. An LLM, docgen, or downstream tool reads one map instead of reparsing everything.

One scan produces a single manifest covering every supported language found in the tree: Go, Python, Java, TypeScript, and JavaScript. The binary is ax — short for assayxport, and short to type.

v0.19.3 — Validated Cadence execution plans

ax serve renders a large repository’s tree quickly, extracts the packages a reader is looking at first, and fills the rest progressively. Streaming extractors bound memory, while the explorer’s monoidal summary tree merges package results incrementally without reallocating the accumulated index. Version-gated reconciliation prevents stale background work from overwriting a newer scan.

The explorer now expresses loading decisions as Cadence v0.4 validated plans. Viewport intent maps to explicit activation values, and scheduler priority is derived from that axis rather than from legacy strategy variants.

Use

ax scan .                # writes assayxport.json + .assayxport/ shards
ax scan ./pkg --stdout   # print combined JSON, write nothing
ax scan . --lang java    # restrict to one language (repeatable)

Languages

By default scan runs every registered extractor (Go, Python, Java, TypeScript, and JavaScript) and merges the results into one manifest whose languages field lists what was found. --lang restricts the run and is repeatable, so --lang python --lang go runs only those two. An unregistered language name is an error that lists the available ones.

  • Go extraction is fully semantic via go/packages.
  • Python, Java, TypeScript, and JavaScript extraction is syntactic, via a pure-Go, cgo-free tree-sitter parser: names, kinds, visibility, signatures as written, doc comments, decorators/annotations, and entrypoints are reliable; imported-name resolution and inferred types are not.

Java visibility is the 4-way access modifier (public/protected/private/package-private). Consumers read the per-symbol visibility_idiom to interpret the visibility field across languages.

Output

  • assayxport.json — root index: project metadata plus one entry per package.
  • .assayxport/<package-dir>.json — per-package shard with the full symbol list.

Output is deterministic: relative paths, no timestamps, stable ordering. Equal inputs produce byte-identical files.

Call graph

Every function-like symbol carries a calls list: its distinct callees, each with a call-site count, stored as edges-at-the-symbol so the whole-program graph assembles by following ref links from shard to shard. The graph runs all the way down to language primitives — or as far as the project’s semantics allow — and each edge says which: internal (in this manifest, linked), builtin (the language floor: Go len, Python print), external (stdlib or a dependency — the scan boundary), dynamic (func values and interface dispatch, where a static target does not exist), or unresolved (the honest answer when syntax runs out, recorded as written).

Go edges are fully semantic via go/types; syntactic-language edges resolve as far as local definitions, imports, and the language’s builtin floor reach, and refuse to guess past that.

Java edges also record the call site as written — arity plus a per-position arg_types evidence vector (literals, casts, new T(...), this), null where the source doesn’t say — so overloaded calls can be drawn exactly when the evidence distinguishes them and as an honest fan-out when it doesn’t. Edges are deduplicated on the full vector, and a call whose arity matches no locally declared overload is reported unresolved rather than linked to the wrong method.

License

MIT. Third-party components (the tree-sitter runtime and language grammars, all MIT) are attributed in the repo’s NOTICE.

Built as part of the GoForge suite, in Go.