cognitive_complexity
Algorithmic Cognitive Complexity calculation and Data-Flow analysis library and CLI tools for Dart and Flutter.
0.2.4
4.2K downloads/mo
#4088 most downloaded on pub.dev
kevmoo/analytica.dart
What this package is like to depend on
Last release today
23 Aug 2026
Ships on a steady schedule
a new release about every 1 weeks
Nearly every release is documented
notes for 10 of 10 stable releases
Nothing withdrawn
no release was ever pulled
0 months old
10 releases · first in 2026
10 releases in the last 12 months
see the full history below
Release timeline
10 releases · Aug 2026 to Aug 2026Releases
latest 10-
0.2.423 Aug 2026Release notes
Open source →- Fix
action.ymlmonorepo auto-detection to evaluate defaultlibvs
packagesexistence against the caller's$GITHUB_WORKSPACEinstead of
$ACTION_PATH(#76). - Fix
action.ymlto run the scanner from the caller's$GITHUB_WORKSPACE
rather than$ACTION_PATH, so relativetargetsand--git-diffresolve
against the repository under audit when the action is used from another
repository (#76). - Add
--comment-outputand--max-comment-rowsCLI options: with
--format=github, write a second report capped to the most significant rows
(violations, then increases, then additions) for posting as a PR comment,
while the step summary keeps the full table (#49). - Add
commentFileandmaxCommentRowsparameters toGitHubReporter. - Add
max-comment-rowsinput to the GitHub Action (default0= unlimited)
to keep sticky comments under GitHub's 65536-character body limit. - Anchor GitHub annotations to the declaration line only, so they render
under the function signature instead of after the closing brace (#55). - Move package into pub workspace monorepo layout under
packages/cognitive_complexity. - Restore root
action.ymlandskills/structure for monorepo workspace.
Release notes
Open source →- Fix
action.ymlmonorepo auto-detection to evaluate defaultlibvspackagesexistence against the caller's$GITHUB_WORKSPACEinstead of$ACTION_PATH(#76). - Fix
action.ymlto run the scanner from the caller's$GITHUB_WORKSPACErather than$ACTION_PATH, so relativetargetsand--git-diffresolve against the repository under audit when the action is used from another repository (#76). - Add
--comment-outputand--max-comment-rowsCLI options: with--format=github, write a second report capped to the most significant rows (violations, then increases, then additions) for posting as a PR comment, while the step summary keeps the full table (#49). - Add
commentFileandmaxCommentRowsparameters toGitHubReporter. - Add
max-comment-rowsinput to the GitHub Action (default0= unlimited) to keep sticky comments under GitHub's 65536-character body limit. - Anchor GitHub annotations to the declaration line only, so they render under the function signature instead of after the closing brace (#55).
- Move package into pub workspace monorepo layout under
packages/cognitive_complexity. - Restore root
action.ymlandskills/structure for monorepo workspace.
- Fix
-
0.2.310 Aug 2026Release notes
Open source →- Fix
data_flowcrashing withPathNotFoundExceptionwhen run as a
standalone AOT executable (dart run cognitive_complexity:data_flow@/
dart install), where SDK auto-discovery resolved to the app bundle
(#21):- Fail fast with an actionable error (pass
--sdk-path, setDART_SDK,
or put an SDK onPATH) instead of handing the analyzer an unresolved
SDK location. - Teach
PATH-based discovery the Flutter checkout layout: a
flutter/bin/dartwrapper script now resolves to
flutter/bin/cache/dart-sdk. - Add a
FLUTTER_ROOTdiscovery fallback. - Add a
--sdk-pathoption to thedata_flowCLI (plumbed to the
existingDataFlowAnalyzer.sdkPathparameter); invalid explicit paths
are rejected with a clear error.
- Fail fast with an actionable error (pass
- Fix
--fail-on-increaseignoring--fail-threshold: when both are set,
an increase now only fails the run if the new score exceeds the
threshold. Sub-threshold increases are still reported (delta table, PR
comment) but no longer block healthy changes such as added error
handling. Without--fail-threshold, the strict any-increase ratchet is
unchanged. - Update the
dart-cognitive-complexityagent skill:- Add explicit rule under Tier 1/2 prescribing that extracted private helper
routines that do not read or mutate class instance state (this) must be
declared as private top-level functions (orstaticmethods) rather than
instance methods.
- Add explicit rule under Tier 1/2 prescribing that extracted private helper
Release notes
Open source →- Replace table truncation notice with inline summary comment linking to step summary.
Release notes
Open source →- Fix
data_flowcrashing withPathNotFoundExceptionwhen run as a standalone AOT executable (dart run cognitive_complexity:data_flow@/dart install), where SDK auto-discovery resolved to the app bundle (#21):- Fail fast with an actionable error (pass
--sdk-path, setDART_SDK, or put an SDK onPATH) instead of handing the analyzer an unresolved SDK location. - Teach
PATH-based discovery the Flutter checkout layout: aflutter/bin/dartwrapper script now resolves toflutter/bin/cache/dart-sdk. - Add a
FLUTTER_ROOTdiscovery fallback. - Add a
--sdk-pathoption to thedata_flowCLI (plumbed to the existingDataFlowAnalyzer.sdkPathparameter); invalid explicit paths are rejected with a clear error.
- Fail fast with an actionable error (pass
- Fix
--fail-on-increaseignoring--fail-threshold: when both are set, an increase now only fails the run if the new score exceeds the threshold. Sub-threshold increases are still reported (delta table, PR comment) but no longer block healthy changes such as added error handling. Without--fail-threshold, the strict any-increase ratchet is unchanged. - Update the
dart-cognitive-complexityagent skill:- Add explicit rule under Tier 1/2 prescribing that extracted private helper
routines that do not read or mutate class instance state (
this) must be declared as private top-level functions (orstaticmethods) rather than instance methods.
- Add explicit rule under Tier 1/2 prescribing that extracted private helper
routines that do not read or mutate class instance state (
- Fix
-
0.2.3+111 Aug 2026Release notes
Open source →- Add an example.
- Remove accidental export of internal
CognitiveComplexityVisitorfrom
package:cognitive_complexity/cognitive_complexity.dart.
Release notes
Open source →- Add an example.
- Remove accidental export of internal
CognitiveComplexityVisitorfrompackage:cognitive_complexity/cognitive_complexity.dart.
-
0.2.3+211 Aug 2026Release notes
Open source →- Streamline
README.mdinto a focused, scannable TL;DR. - Extract deep-dive reference documentation into modular guides under
doc/:doc/scoring.md: Scoring matrix, nesting multipliers, and Dart 3 AST rules.doc/cli.md: Command-line options, git diff delta evaluation, and CI ratcheting.doc/data_flow.md: Statement data-flow analysis, method extraction theory, and programmatic API.doc/github_actions.md: Complete GitHub Action workflow setup, parameters, and fork security permissions.
Release notes
Open source →- Streamline
README.mdinto a focused, scannable TL;DR. - Extract deep-dive reference documentation into modular guides under
doc/:doc/scoring.md: Scoring matrix, nesting multipliers, and Dart 3 AST rules.doc/cli.md: Command-line options, git diff delta evaluation, and CI ratcheting.doc/data_flow.md: Statement data-flow analysis, method extraction theory, and programmatic API.doc/github_actions.md: Complete GitHub Action workflow setup, parameters, and fork security permissions.
- Streamline
-
0.2.210 Aug 2026Release notes
Open source →- Introduce
data_flowanalysis tool and library (package:cognitive_complexity/data_flow.dart):- Added
DataFlowAnalyzerto extract reaching definitions (inputs), variable mutations, and live outputs for arbitrary statement slices. - Added
SignatureSynthesizerto automatically generate Dart 3 Record method signatures (({TypeA a, TypeB b})). - Added
data_flowCLI with agent-first JSON formatting by default and formatted text reports. - Hardened slice analysis: pattern assignments (
(a, b) = (b, a)), pattern variable declarations, labeledbreak/continuetargeting outside the slice,rethrowwhosecatchlies outside the slice, mutations of captured variables inside nested closures, and constructor initializers. - Added
ControlFlowEscapeType.closureEscape,rethrowEscape, andconstructorInitializerEscape. - Signatures now propagate
await forasync-ness, use use-site static types (preserving promotion), include enclosing type parameters with their bounds, and sanitize/deduplicate record field names. - Liveness now follows loop back edges: a variable mutated in a slice inside a loop is reported as an output when it is read anywhere in that loop, even textually before the slice.
- Added
- Introduce
-
0.2.2+110 Aug 2026Release notes
Open source →- Update the
dart-cognitive-complexityagent skill: anti-goodhart 3-tier decomposition rubric with deterministic tier selection via thedata_flowCLI, and a gated Tier 3 method-object reference (references/method-object.md) absorbed fromkevmoo/kevmoo_skills. - No library or CLI code changes.
- Update the
-
0.2.2+210 Aug 2026Release notes
Open source →- Refine the skill's 3-Tier Decomposition Rubric per empirical feedback
(#19):- "Slice at natural seams" rule: enlarge slices to whole loops/state
machines before classifying; solves coupled 2-variable state
(queue+visited) without weakening the Tier 3 gate (stays at >= 3
with recorded evidence). - Named records for private/file-local slices at any output count;
dedicatedResultdataclasses reserved for public API boundaries
(aligns the rubric with thedata_flowsignature synthesizer). - Pattern E: loop-body extraction with explicit signal returns
(enum/sealed) instead of boolean control-flow flags; ordered
dispositions for control-flow escapes. - Domain-modeling exit: promoting coupled state to a real named, tested
domain class is out of rubric scope — the gate bans_Runnerfacades,
not real abstractions.
- "Slice at natural seams" rule: enlarge slices to whole loops/state
- No library or CLI code changes.
Release notes
Open source →- Refine the skill's 3-Tier Decomposition Rubric per empirical feedback
(#19):
- "Slice at natural seams" rule: enlarge slices to whole loops/state
machines before classifying; solves coupled 2-variable state
(
queue+visited) without weakening the Tier 3 gate (stays at >= 3 with recorded evidence). - Named records for private/file-local slices at any output count;
dedicated
Resultdataclasses reserved for public API boundaries (aligns the rubric with thedata_flowsignature synthesizer). - Pattern E: loop-body extraction with explicit signal returns
(
enum/sealed) instead of boolean control-flow flags; ordered dispositions for control-flow escapes. - Domain-modeling exit: promoting coupled state to a real named, tested
domain class is out of rubric scope — the gate bans
_Runnerfacades, not real abstractions.
- "Slice at natural seams" rule: enlarge slices to whole loops/state
machines before classifying; solves coupled 2-variable state
(
- No library or CLI code changes.
- Refine the skill's 3-Tier Decomposition Rubric per empirical feedback
-
0.2.104 Aug 2026 -
0.2.003 Aug 2026Release notes
Open source →Scoring fixes aligning with the SonarSource Cognitive Complexity whitepaper (v1.7) and its reference implementation (sonar-java):
else ifchains no longer deepen nesting: branch contents sit one level below the headif(previously each chain link added an extra level).switchstatements/expressions andcatchclauses now receive the standard nesting increment when nested (previously flat +1).- Local function declarations no longer add a structural +1; like lambdas, they only deepen nesting.
Analyzer coverage and CLI fixes:
- Constructor initializers and parameter default values are now scored.
- Top-level functions named with pseudo-keywords (
show,on, ...) are no longer skipped. - Top-level getters/setters are reported with a
get/setprefix, matching class members. --fail-on-increaseno longer flags newly added declarations (they have no baseline); they are governed by--fail-thresholdalone.- Directory exclusion (
.git,.dart_tool,build) now matches whole path segments, so.github/and similar directories are scanned correctly.
-
0.1.003 Aug 2026Release notes
Open source →- Initial release of reachability and dead/unused declaration analyzer.
- Support for CLI execution, package entrypoint harvesting, and Flutter/test
framework adapters. - Deterministic analysis modes: open-world (libraries) and closed-app
(standalone/executables). - Custom suppression directives:
// undead:ignoreand
// undead:ignore_for_file.
Release notes
Open source →- Initial release of core utilities, SDK discovery, Git integration, and CI reporting.
Release notes
Open source →- Initial release of
pkg:dedupe:- Token-level and structural clone detection across Dart and Flutter codebases.
- Polynomial rolling hash k-gram indexing and maximal clone extension.
- Granular normalization filters (
--ignore-comments,--ignore-literals,--ignore-identifiers). - Persistent content-hashed disk caching (
--cache,--cache-dir,--clear-cache). - Exact line-union overlapping clone cluster deduplication and net lines saved analysis.
- Linear adjacent chaining and MinHash token verification for large-scale clone clusters (>50 instances).
- Git diff integration and PR delta scanning (
--git-diff,--only-changed). - Multi-format report generation: Markdown, JSON, GitHub Actions annotations/summaries, and terminal text.
- Per-file duplication metrics, cluster classification, and estimated lines saved analysis.
- Value-semantic, immutable report models (
CloneInstance,DuplicateCluster,DedupeReport) with full JSON serialization. - CLI binary entrypoint (
bin/dedupe.dart).
Release notes
Open source →- Initial release of Cognitive Complexity calculation engine and CLI tool.