Borehole · Project · free tier
crystal-lang/crystal
Free reading: not for reliance
99e34e9 · 17,055 commits · 2,746 files
Read 2026-10-04

crystal-lang/crystal: technical due diligence, read from its repository

What Borehole read in crystal-lang/crystal's code and history at 99e34e9: its licence, security advisories, releases, review practice, tests, dependencies and operations. Every finding cites the file and line it rests on. The full report also covers the team and asks the questions the code cannot answer.

DimensionRating
Architecture & Codebase — including AI provenancestrong
Engineering Process & SDLC Maturitystrong
Product & Engineering Maturitystrong
Security & Reliability Postureadequate
Observability & Operationsnot assessable
Fit with the Acquirernot assessable

What the repository says

  • Releases are cut from another branch than the one surveyed

Architecture & Codebase — including AI provenance

strong
01.6

src/compiler/crystal/syntax/parser.cr is 6,622 lines, 100× this codebase's median file

adequate

The median source file here is 66 lines. 38 files exceed 1,000 lines, the largest being 6,622. Size is not a defect on its own — some problems genuinely live in one place — but these are where merge conflicts, review fatigue and single-owner knowledge concentrate, and they are the first thing that slows an inheriting engineer down.

Evidence
src/compiler/crystal/syntax/parser.cr:1 — 6,622 lines (100× median)
src/string.cr:1 — 5,930 lines (89× median)
src/float/printer/ryu_printf_table.cr:1 — 4,946 lines (74× median)
src/compiler/crystal/semantic/main_visitor.cr:1 — 3,674 lines (55× median)
src/compiler/crystal/types.cr:1 — 3,634 lines (55× median)

Engineering Process & SDLC Maturity

strong

No finding.

Product & Engineering Maturity

strong
04.62

Releases are cut from another branch than the one surveyed

adequate

The newest release, 1.21.1, is not on the branch this survey read; the newest release on it is 1.21.0. The shipped product may differ from what this report describes. Survey the release branch too.

Evidence
tag 1.21.1

Security & Reliability Posture

adequate
05.1

1 credential-shaped string committed to the tree

adequate

Matches for AWS access key appear in tracked files outside test and fixture paths. They stay in the history even after they leave the tree, so what matters is whether each was rotated. The code cannot tell whether any of them is live, and that decides whether this matters: none sits in production configuration, and none is in a format its provider keeps for live keys. Is any of these live? Show that each was rotated after it was committed, and when. Every match is in CI configuration, where the usual reason is a throwaway service container's credential. Worth confirming; not a leak on its own.

Evidence
AWS access key pattern matched
05.27

The build runs third-party code it does not pin

adequate

1 third-party CI action is referenced by a tag or branch rather than a commit, so they run whatever that tag points to on the day; 1 step pipes a download straight into a shell. Tags have been moved to malicious commits in real supply-chain attacks, and a piped script is whatever the server returns that minute. Pinning to a commit is the fix, and it is small.

Evidence
.github/workflows/llvm.yml:72 — action pinned by tag
lib/sanitize/.circleci/config.yml:48 — download piped into a shell
05.65

2 advisories against this project in the last 24 months

adequate

The newest was published on 2026-10-05. A project that publishes advisories is telling its users about its fixes, and the count and pace say how much security work it carries. Whether 1 of them are fixed in the code you ship could not be told from this history: its version is only known to be at least 1.21.0. Answer lives in: the release you run, set against each fixed version. The record is incomplete: NVD: 29 records name crystal with nothing tying them to this repository (CVE-2001-1464, CVE-2004-0204, CVE-2004-1327, …).

Evidence
2026-10-05: GHSA-jfq5-c3x6-w7jj (moderate), fixed in 1.21.1: Implicit HTTP request body decompression
2026-04-16: GHSA-wqh5-7w63-pm68 (low), fixed in 1.20.0: Crystal HTTP::Server is prone to request smuggling

Observability & Operations

not assessable

Not rated: only 4 of 16 checks could reach a conclusion here; the rest do not apply to this repository or could not read it.

Fit with the Acquirer

not assessable

Not rated: structurally not assessable from a repository.

Read more, or read your own

The full report on crystal-lang/crystal: every dimension, the questions for the room, and the audit log.

Survey a repository: free on public repositories. Private code is read on your own machine by a collector whose source you can read first.