assayxport
A codebase's API composition as deterministic JSON
Assaying analyzes a metal to report its exact composition. assayxport analyzes a codebase to report its exact API composition — where each symbol lives, what package it belongs to, its signature, its docs, whether it is a runnable entrypoint, and who it calls — as a deterministic JSON manifest at the project root. An LLM, docgen, or downstream tool reads one map instead of reparsing everything.
One scan produces a single manifest covering every supported language found in
the tree: Go, Python, Java, TypeScript, and JavaScript. The binary is ax —
short for assayxport, and short to type.
v0.19.3 — Validated Cadence execution plans
ax serve renders a large repository’s tree quickly, extracts the packages a
reader is looking at first, and fills the rest progressively. Streaming
extractors bound memory, while the explorer’s monoidal summary tree merges
package results incrementally without reallocating the accumulated index.
Version-gated reconciliation prevents stale background work from overwriting a
newer scan.
The explorer now expresses loading decisions as Cadence v0.4 validated plans. Viewport intent maps to explicit activation values, and scheduler priority is derived from that axis rather than from legacy strategy variants.
Use
ax scan . # writes assayxport.json + .assayxport/ shards
ax scan ./pkg --stdout # print combined JSON, write nothing
ax scan . --lang java # restrict to one language (repeatable)
Languages
By default scan runs every registered extractor (Go, Python, Java,
TypeScript, and JavaScript) and merges the results into one manifest whose
languages field lists what was found.
--lang restricts the run and is repeatable, so --lang python --lang go runs
only those two. An unregistered language name is an error that lists the
available ones.
- Go extraction is fully semantic via
go/packages. - Python, Java, TypeScript, and JavaScript extraction is syntactic, via a pure-Go, cgo-free tree-sitter parser: names, kinds, visibility, signatures as written, doc comments, decorators/annotations, and entrypoints are reliable; imported-name resolution and inferred types are not.
Java visibility is the 4-way access modifier
(public/protected/private/package-private). Consumers read the
per-symbol visibility_idiom to interpret the visibility field across
languages.
Output
assayxport.json— root index: project metadata plus one entry per package..assayxport/<package-dir>.json— per-package shard with the full symbol list.
Output is deterministic: relative paths, no timestamps, stable ordering. Equal inputs produce byte-identical files.
Call graph
Every function-like symbol carries a calls list: its distinct callees, each
with a call-site count, stored as edges-at-the-symbol so the whole-program
graph assembles by following ref links from shard to shard. The graph runs
all the way down to language primitives — or as far as the project’s semantics
allow — and each edge says which: internal (in this manifest, linked),
builtin (the language floor: Go len, Python print), external (stdlib
or a dependency — the scan boundary), dynamic (func values and interface
dispatch, where a static target does not exist), or unresolved (the honest
answer when syntax runs out, recorded as written).
Go edges are fully semantic via go/types; syntactic-language edges resolve as
far as local definitions, imports, and the language’s builtin floor reach, and
refuse to guess past that.
Java edges also record the call site as written — arity plus a per-position
arg_types evidence vector (literals, casts, new T(...), this), null
where the source doesn’t say — so overloaded calls can be drawn exactly when
the evidence distinguishes them and as an honest fan-out when it doesn’t.
Edges are deduplicated on the full vector, and a call whose arity matches no
locally declared overload is reported unresolved rather than linked to the
wrong method.
License
MIT. Third-party components (the tree-sitter runtime and language grammars, all
MIT) are attributed in the repo’s NOTICE.
Built as part of the GoForge suite, in Go.