JavaScript: calls through a CommonJS destructured require are never resolved (express: 63 call edges from 11,733 call sites)
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 55/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Stack tecnologico
- javascript
- Ambito
- devtools
Direzione di ricerca
Reproduce the issue with graphify <path> --code-only, followed by cluster-only --no-label, using the CommonJS example in expressjs/express (lib/utils.js and lib/response.js). Start by tracing how the resolved import binding is handled at the plain identifier call site; done means the graph includes a calls edge from the calling function to normalizeType(), with coverage for this destructured require form.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
For CommonJS code, graphify resolves the import of a function but not calls through the imported binding. The result is that JavaScript projects get almost no calls edges, while the same analysis on other languages produces one to two orders of magnitude more.
Measurement
Same command on eight well-known repos (graphify <path> --code-only, then cluster-only --no-label). Call sites counted by walking each file's tree-sitter AST for the language's own call node type; call edges counted from graph.json:
| Repo | Language | Call sites | calls edges |
ratio |
|---|---|---|---|---|
| JamesNK/Newtonsoft.Json | C# | 48,070 | 13,487 | 28% |
| google/gson | Java | 23,468 | 5,337 | 23% |
| spf13/cobra | Go | 4,430 | 934 | 21% |
| BurntSushi/ripgrep | Rust | 17,103 | 3,270 | 19% |
| psf/requests | Python | 2,687 | 453 | 17% |
| gin-gonic/gin | Go | 9,414 | 1,346 | 14% |
| pallets/flask | Python | 3,963 | 386 | 10% |
| expressjs/express | JavaScript | 11,733 | 63 | 1% |
express's whole graph contains 11 calls and 52 indirect_call edges across 404 nodes and 119 callable nodes.
Concrete case
expressjs/express at current HEAD:
// lib/utils.js:61
exports.normalizeType = function(type){ ... };
// lib/response.js:27
var normalizeType = require('./utils').normalizeType;
// lib/response.js:587
this.set('Content-Type', normalizeType(key).value);
Everything here is literal: a literal require path, a literal property, and a plain identifier call.
In the resulting graph.json, the node lib_utils_normalizetype has exactly two incoming edges:
response.js --imports--> normalizeType()
lib/utils.js --contains--> normalizeType()
There is no calls edge from lib/response.js to normalizeType(), even though the import was resolved correctly — so the resolver clearly knows where the symbol lives.
Expected
A calls edge from the calling function in lib/response.js to normalizeType() in lib/utils.js.
Why it matters
The import edge being present while the call edge is missing means the information needed to resolve the call is already available; only the call-site binding is not being made. Any consumer doing reachability or call-graph work on JavaScript gets a graph that is essentially call-free — a "no path found" result on a JS project currently means very little.
The var x = require('./m').x destructuring form is extremely common in CommonJS, so this is likely not an edge case.
Environment
- graphify
0.9.65(PyPIgraphifyy) - Python 3.14, Windows 10
expressjs/expressdefault branch, shallow clone 2026-09-22
- Lingua principale
- Python
- Stelle
- 124k
- Fork
- 11.9k
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di Graphify-Labs/graphify
-
[Bug]: `graphify export svg` writes a graph.svg that is not well-formed XML when a label contains a control characterForse già presa Una pull request collegata a questa issue è aperta o già unita. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
Graphify-Labs/graphify#4241 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
Graphify-Labs/graphify#3763 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
Graphify-Labs/graphify#3611 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Nix supportAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
Graphify-Labs/graphify#3193 · 2 reazioni ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 92/100
Graphify-Labs/graphify#2871 · 2 commenti ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di Graphify-Labs/graphify
Issue simili
-
first
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
AcademySoftwareFoundation/rmtc#54 · 1 commento ·
-
feature/cohorts feature/feature-flags team/feature-flags
Difficoltà 2/5 1-3 ore Idoneità per principianti 74/100
I maintainer di solito rispondono entro 1 giorno
-
License examples/ as MITForse già presa @PGrayCS l’ha presa oggi. Apertadocumentation enhancement example good first issue
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
speedyk-005/yasbd-lib#383 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
interactions-py/interactions.py#1827 ·
-
Managed start can fail when OpenVMM reads its control capability before NVX writes itForse già presa @ppenna l’ha presa oggi. Apertabug
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
I maintainer di solito rispondono entro 1 giorno