Overview of OpenRewrite and Moderne
Contents
- OpenRewrite started at Netflix as a way to automate the code changes nobody had time for.
- What is OpenRewrite?
- OpenRewrite works on Lossless Semantic Trees and applies recipes to them.
- Moderne runs OpenRewrite recipes across thousands of repositories at once.
- Can AI coding agents use OpenRewrite recipes?
- Moderne turns code impact analysis into a job that takes minutes.
- The Moderne CLI brings multi-repo refactoring to a developer’s machine.
- DevCenter shows the whole organization the state of its codebase.
- What does Moderne add to OpenRewrite?
- Moderne adds scale, proprietary recipes, and agent tools to OpenRewrite.
- Is Moderne an alternative to OpenRewrite?
OpenRewrite is an open source framework for automated code refactoring. It migrates frameworks and patches vulnerabilities by running recipes, one repository at a time. Recipes are deterministic programs that search and change code.
Moderne is the enterprise platform from the team that created OpenRewrite. It runs recipes across thousands of repositories at once, so a migration or security fix reaches the whole codebase in one run.
OpenRewrite started at Netflix as a way to automate the code changes nobody had time for.
Jonathan Schneider created OpenRewrite while working in engineering tools at Netflix. Netflix’s culture of freedom and responsibility led to code that didn’t conform to any single style. The same culture meant the central team couldn’t gate product engineers by breaking their builds over a pattern it didn’t like.
Requests from the central team were too often met with: “I do not have time to deal with this, but if you do it for me, I’ll merge in the changes.” So eventually, Jonathan built a tool to automate key changes. Prior to OpenRewrite, Jonathan created the Gradle Lint plugin, a popular plugin that manipulates Groovy build files and upgrades dependencies. The plugin already rewrote the Groovy code behind build configuration, so source code was the next step.
OpenRewrite reached Java when the central team wanted to retire an internal logging library that predated SLF4J and replace it with SLF4J. The internal library had been deprecated for six years. Nobody could be forced to migrate off it, so references to it were still all over the Netflix codebase. With OpenRewrite, the central team was able to remove them at scale.
The internal logger took a %s format string with the exception first:
class MyService {
Logger logger = Logger.getLogger(MyService.class);
void streamMovie(Movie movie) {
try {
movie.start();
} catch (StreamingException e) {
logger.error("streaming %s",
e,
movie.getTitle()
);
}
}
}The recipe moved each call to SLF4J, with a {} placeholder and the exception last:
class MyService {
Logger logger = LoggerFactory.getLogger(MyService.class);
void streamMovie(Movie movie) {
try {
movie.start();
} catch (StreamingException e) {
logger.error("streaming {}",
movie.getTitle(),
e
);
}
}
}In the years since, OpenRewrite’s capabilities have expanded from simple API changes to complex framework migrations and CVE patching. Coverage has grown from Java to the rest of the enterprise stack: JVM languages, JavaScript and TypeScript, C#, Python, and the build and configuration files around them. Anyone can use OpenRewrite and contribute to it, and it runs from Maven and Gradle plugins or inside a CI pipeline.
What is OpenRewrite?
OpenRewrite is an open source engine that changes code with recipes. It parses code into a Lossless Semantic Tree (LST) that keeps type information and formatting, so a recipe changes only what it targets. Jonathan Schneider created it at Netflix, and it now runs framework migrations and vulnerability fixes from Maven and Gradle plugins.
OpenRewrite works on Lossless Semantic Trees and applies recipes to them.
A Lossless Semantic Tree (LST) goes beyond an abstract syntax tree (AST). It’s type-attributed, so recipes can find and change code accurately with no false positives. It also preserves formatting, so changes match the style of the surrounding code.
The smallest recipes do one search or one transformation, such as “find method,” “change method,” “find transitive dependency,” “upgrade dependency,” or “exclude dependency.” Composite recipes group these building blocks to do larger jobs.
When the building blocks aren’t enough, developers can customize and write their own recipes. They can then share that recipe with others so other people can run it against their code.
There are thousands of recipes in the OpenRewrite catalog, both free and proprietary. Many recipes are available for individual users and companies to openly consume and customize for their own code. Moderne creates and maintains a commercial set covering security remediation, technology insights, major migrations, and AI-enabled recipes.
OpenRewrite recipes were initially focused on code transformations. Users asked for a way to find issues before refactoring, so a search function was added. A search is a special kind of transformation: OpenRewrite adds markers to the LST elements that match. From there, the markers can be translated into text based on the developer’s wishes (usually as comments that contain TODOs, Jira issue numbers, etc.).
To identify every method invocation in a whole package of Google’s Guava library, we can instruct the recipe to perform this search:

The results show the recipe isn’t matching method names. Type attribution confirms that each call comes from the com.google.common.collect package:

This recipe in plain OpenRewrite YAML looks like:
type: specs.openrewrite.org/v1beta/recipe
name: com.yourorg.FindGuavaCollectUsages
displayName: Find Guava collect method calls
recipeList:
- org.openrewrite.java.search.FindMethods:
methodPattern: com.google.common.collect.* *(..)Give this a try by following the OpenRewrite Quickstart Guide or one of the tutorials, such as “Automatically fix Checkstyle violations” or “Migrate to Java 21.”
Moderne runs OpenRewrite recipes across thousands of repositories at once.
OpenRewrite on its own works one repository at a time, and Moderne removes that limit for organizations with large codebases. Teams use it to run a recipe across the whole codebase in a single run.
The Moderne Platform is not built directly on top of OpenRewrite. It uses proprietary technology to apply OpenRewrite recipes at scale, and the biggest difference is how it handles LSTs.
OpenRewrite is computationally expensive. It takes source code as text, produces LSTs for it using the compiler, applies the recipe, and then produces new source code as text. For each recipe run, the OpenRewrite build tools start from scratch.
The Moderne Platform batch-builds and serializes LSTs and stores them on disk, so recipes and analysis run against your codebase without a rebuild. LSTs are built once and shared across teams for whatever work they are doing, which saves both time and infrastructure cost.
See the difference here:
Central teams within companies, such as platform teams, are typically responsible for managing the Moderne Platform. They configure Moderne ingest for their organization’s codebase to produce LSTs at scale.
Because the LSTs already exist, recipe results come back within minutes. Developers can search and transform code, then open pull requests across every affected repository and send them through the usual CI/CD review.
Testing matters more at this scale. A recipe bug in one repository is a quick fix, but the same bug run across every repository in an organization means a pull request to reject in each of them. Moderne develops and tests recipes on open source repositories, and runs and compiles them to catch regressions. Teams building their own custom migrations do that work on the platform too. Moderne also runs a free community tenant where anyone can run recipes across popular open source projects.
The same LSTs now serve coding agents, which otherwise read files one at a time to work out how a codebase fits together. Trigrep gives agents type-aware code search. Prethink gives them codebase context that recipes resolve ahead of time. Through Moderne, agents such as Claude Code, Cursor, and GitHub Copilot can use both and run recipes as ordinary tools. The platform already holds more than 30 billion lines of code as LSTs.
Can AI coding agents use OpenRewrite recipes?
Yes. Moderne gives agents such as Claude Code, Cursor, and GitHub Copilot recipes as tools, so the agent plans the change and a deterministic recipe makes the edits. In a Java 25 migration benchmark test, an agent working alone used more than 65 million tokens over 45 minutes and finished about a quarter of the migration. An agent calling recipes used about 30,000 tokens, took 3 minutes, and completed it.
Moderne turns code impact analysis into a job that takes minutes.
On the Moderne Platform, impact analysis runs across any number of repositories and millions or billions of lines of code in the time it takes a recipe to run. By hand, the same analysis takes weeks or months of several engineers’ time, and the code keeps moving while it happens, so the results are out of date before they’re finished. Many migration and modernization efforts stall at this stage.
Because ingest keeps the LSTs up to date as the code changes, a new run reflects today’s code, and teams can act on the results immediately.
Two features of the Moderne Platform do most of this work:
- Data tables collect real-time data about dependencies, CVEs, licenses, version numbers, API usage, and other facts about your source code. You can learn more about data tables in our documentation, our blog, and our demo video.
- Code visualizations turn recipe data into charts, such as where a dependency is used, which languages make up a codebase, or which OWASP categories show up most across an organization. Developers use them to plan the work, and leaders read them at a glance. The visualizations docs list what’s available, and there’s a blog post and a demo video too.
The Moderne CLI brings multi-repo refactoring to a developer’s machine.
With the Moderne CLI (command line interface), a developer can examine and fix code across as many repositories as their machine has the computing power for.
Many of the CLI commands are optimized for parallel execution across multiple repos. For example, it can run recipes on pre-built LSTs simultaneously, so one recipe run can cover a whole business unit.
The Moderne CLI is also used to batch-build LSTs for mass ingestion into the platform.

Used with the Moderne Platform, the CLI lets multiple teams and business units operate on the same codebase together.
Learn more about the Moderne CLI in our documentation and blog.
DevCenter shows the whole organization the state of its codebase.
Two features let developers, central teams, and business leaders track the codebase and move it forward together:
- Moderne DevCenter is the platform’s dashboard for tracking change across an organization, from a single team up to the whole company. Upgrade cards show each repository’s migration status, and security cards show the most common vulnerabilities. From either card, you can run the fixing recipe and follow the pull requests it opens. The dashboards are defined as recipes themselves, so they’re version-controlled and reusable. Read the DevCenter documentation or the relaunch post.
- Activity View tracks recipe runs, commits, and visualizations produced over time, so engineering teams can see what is happening across the organization without asking around. To find out more about the Activity View, check out our documentation and demo video.
Moderne is available three ways. The Moderne Platform is the SaaS platform, used with the Moderne CLI, for mass code refactoring and analysis across an organization’s codebase. Moderne DX delivers the same capabilities in a fully air-gapped environment, with an on-premises central service that integrates with local Moderne CLI instances. With the Managed Service, Moderne’s team runs the migration and security remediation work on your behalf, with outcomes backed by SLAs.
To get started with Moderne, you can try the platform on open source code.
What does Moderne add to OpenRewrite?
Scale. Moderne builds every repository’s LST ahead of time, so one recipe run covers thousands of repositories. On top of that come mass pull requests, DevCenter dashboards, proprietary remediation and migration recipes, and agent tools like Trigrep and Prethink.
Moderne adds scale, proprietary recipes, and agent tools to OpenRewrite.
| Capability | Moderne | OpenRewrite |
|---|---|---|
| Multi-repository runs | Yes, thousands of repositories at once | No, one repository at a time |
| Mass pull requests | Yes | No |
| Collaboration (Activity View, recipe marketplace, Recipe Builder) | Yes | No |
| DevCenter dashboards for upgrades and security | Yes | No |
| Security remediation recipes (SAST, SCA, OWASP top 10), Moderne proprietary license | Moderne customers | Not available |
| Technology insight recipes (SQL and API usage), Moderne proprietary license | Moderne customers | Not available |
| Major migration recipes (for example, Spring Boot 4), Moderne proprietary license | Moderne customers | Not available |
| AI-enabled recipes, Moderne proprietary license | Moderne customers | Not available |
| Open source recipes (Apache License 2.0) | Yes | Yes |
| Source-available recipes (Moderne Source Available License) | Yes | Yes |
| Agent tools | Trigrep, Prethink, and recipe runs from coding agents | Not included |
| Management reports | Yes | No |
| Audit logs | Yes | No |
| Recipe languages | Java, JavaScript, Python, Go, C#, and YAML | Java and YAML |
| Infrastructure cost | LSTs built once and reused; included in the platform | LSTs rebuilt on every recipe run |
| Time to remediate across an estate | Minutes across many repositories | Days to weeks, one repository at a time |
| Where it runs | SaaS platform, Moderne DX (air-gapped), or Managed Service | Your machine or CI |
Is Moderne an alternative to OpenRewrite?
No. Moderne extends OpenRewrite. The team that created OpenRewrite builds Moderne and still maintains the open source project, and any OpenRewrite recipe runs on it. Start with the plugin on one repository, and move to Moderne when the change has to reach thousands.


