Skip to content
CAI
Software that uses CAICheck a score

brewkits/Grant

71.4

Strong · 22 September 2026

12.2k

lines of production code

Kotlin

primary language

7

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Kotlin Multiplatform library that standardizes the handling of runtime permissions and service status checks across Android, iOS, macOS, desktop, and web environments. It provides a unified API for requesting permissions, managing complex multi-step flows, and displaying platform-specific UI dialogs, while isolating native framework dependencies to prevent App Store rejections. The library includes comprehensive testing utilities and modular components for specialized permissions like Bluetooth, location, and motion, ensuring consistent behavior and state persistence across different platforms and lifecycle events.

Features

Add Motion permission support for iOS

The grant-motion module now includes iOS-specific implementation for handling Motion permissions. This adds a dedicated MotionPermissionHandler that uses CoreMotion's dummy-query pattern to trigger the system permission dialog, with proper handling for hardware unavailability (returning DENIED\_ALWAYS without showing a dialog) and simulator environments. The module also introduces an idempotent initialize() entry point that registers the handler, and comprehensive test coverage including iOS-native tests for the CoreMotion callback behavior, security tests for callback lifecycle, and stress tests for concurrent permission requests.

grant-motion · high confidence

Added macOS camera and microphone permission verification harness

A new standalone desktop-harness application has been added to support Tier 2 manual verification of macOS camera and microphone permissions. This tool allows users to check and request camera and microphone access, as well as open system privacy settings, providing a reliable way to verify permission status mappings without relying on potentially misleading terminal-based execution.

desktop-harness · high confidence

Browser (JS/Wasm) support for grant-core

grant-core now runs in web browsers (JS and Wasm targets), enabling permission and service checks on the web. The implementation maps camera, microphone, location, and notifications to their native browser APIs, while unsupported permissions (e.g., contacts, Bluetooth) consistently return DENIED\_ALWAYS. Service status checks only detect camera hardware presence; all other services report UNKNOWN. Platform-specific features like rationale prompts, foreground signals, and opening system settings are not available in the browser and are handled via no-ops or logging.

grant-core/src/webMain · high confidence

Demo app overhaul: new screens, granular permissions, and improved UI

The demo application has been significantly expanded and refactored to showcase the library's latest capabilities. It now includes dedicated screens for location flow (combining permission and GPS checks) and a minimal grant example, while the main demo screen introduces atomic group grants and granular permission variants like GALLERY\_IMAGES\_ONLY, GALLERY\_VIDEO\_ONLY, READ\_CONTACTS, and BLUETOOTH\_ADVERTISE. The UI has been modernized with a new theme, color-coded status chips, and an OS version banner, and the app now features a splash screen to start the demo. Internally, the demo uses the updated GrantManager API, integrates GrantDialog and GrantGroupDialog for automatic UI handling, and adds a logging toggle to expose internal diagnostics.

demo/src/commonMain/kotlin · high confidence

Initial JVM desktop platform support for grant-core

This change introduces the foundational JVM desktop implementation for the grant library, enabling permission and service status checks on desktop environments. It adds a \DesktopPermissionHandlerRegistry\ to allow opt-in modules (like \grant-desktop\) to register platform-specific handlers, while ensuring that unregistered permissions safely resolve to \DENIED\_ALWAYS\ rather than fabricating a granted status. The implementation includes a \PlatformLock\ using \ReentrantLock\ to handle multi-threaded access safely, a \PlatformGrantDelegate\ that delegates to the registry, and stubs for foreground signals and service checks that report unsupported or unknown states until the specific desktop modules are added.

grant-core/src/jvmMain · high confidence

Initial iOS demo application for Grant library

The iOS demo application has been added to the repository, replacing the previous git submodule reference with a fully integrated Xcode project. This demo provides a SwiftUI interface that embeds the shared Grant library, allowing users to test permission requests for camera, photos, location, contacts, Bluetooth, notifications, calendar, reminders, motion, and local network access. The project includes the necessary Info.plist usage descriptions and build configurations to run the Grant KMP library on iOS devices and simulators.

demo/iosApp · high confidence

Initial public API surface for grant-compose

The public API for the grant-compose module is now established, exposing Compose integration utilities and UI components. This includes extension functions like \collectAsStateWithLifecycle\ and \collectStatusAsState\ for binding grant handlers to Compose state, a \GrantDialogStrings\ class for customizable dialog text, and Compose UI functions such as \GrantDialog\, \GrantGroupDialog\, \GrantAndServiceDialog\, \GrantRationaleDialog\, and \GrantSettingsDialog\. This change locks the ABI for Android and Klib (iOS) targets, ensuring stable public contracts for consumers.

grant-compose/api · high confidence

Introduce opt-in LocationAlways permission module for iOS and Android

The grant-location-always module is now a standalone, opt-in component for handling the 'Always Allow' location permission. On iOS, it provides a native implementation that initializes a CLLocationManager delegate, registers the handler via IosPermissionHandlerRegistry, and correctly maps CoreLocation statuses (including the new iOS 14+ accuracy and authorization states) to the library's GrantStatus enum. On Android, the module exposes a public API surface (GrantLocationAlways.initialize) that acts as a no-op entry point, as Android handles these permissions via Manifest and Intents. The module includes comprehensive test coverage for initialization idempotency, state isolation from foreground location, and security invariants like preventing double-resume crashes on iOS.

grant-location-always · high confidence

New grant-bluetooth module for cross-platform Bluetooth permission handling

The grant-bluetooth module introduces a unified entry point, GrantBluetooth.initialize(), to manage Bluetooth permissions across Android and iOS. On iOS, initialization registers a CoreBluetooth-based handler that covers scan, connect, and advertise operations through a single authorization check, while Android uses a no-op initializer since it relies on Manifest and Intents. The module distinguishes between central (BLUETOOTH) and peripheral (BLUETOOTH\_ADVERTISE) permissions, ensuring they are tracked independently and requested separately. It includes comprehensive test coverage for initialization idempotency, state machine transitions, security invariants (such as preventing callback leaks and ensuring DENIED\_ALWAYS never triggers system dialogs), and stress testing for concurrent operations.

grant-bluetooth · high confidence

New grant-testing module provides official test doubles

The new grant-testing module introduces a set of in-memory test doubles for the grant library, consolidating previously duplicated fake implementations from various modules into a single, official testing artifact. It includes FakeGrantManager for mocking permission checks and requests with configurable statuses and call tracking, FakeGrantStore for simulating grant state persistence, FakeServiceManager for mocking service availability checks, and MultiGrantFakeManager for scenarios where request outcomes must update subsequent status checks. These classes allow developers to write deterministic unit tests for permission handling logic without relying on platform-specific APIs or real permission dialogs.

grant-testing · high confidence

New iOS simulator launch script for the demo app

A new shell script (\.run-ios-from-studio.sh\) has been added to streamline running the Grant demo app on the iOS simulator. The script automates the workflow by building the Kotlin framework, compiling the iOS app via Xcode, and launching it on a specified simulator device (defaulting to iPhone 16). This simplifies the local development and testing process for iOS targets.

(repo-wide) · high confidence

New permission handling APIs: GrantHandler, GrantGroupHandler, and GrantFlow

The library introduces a new set of high-level handlers for managing permission requests. GrantHandler provides a stateful, ViewModel-friendly interface for requesting individual permissions, including support for custom RawPermission definitions and process-death state recovery via SavedStateDelegate. GrantGroupHandler allows requesting multiple permissions as a logical group with sequential rationale handling. GrantFlow enables complex, step-by-step permission logic where the outcome of one request determines the next. These handlers are backed by a new GrantEventListener interface for tracking permission funnel events and utilize a unified GrantStore abstraction for tracking request history.

grant-core/src/commonMain/kotlin/dev/brewkits/grant · high confidence

New public API surface for grant-core on JVM

The \grant-core\ library now exposes a comprehensive public API for the JVM platform, defining the core permission types (such as \AppGrant\ with entries like \BLUETOOTH\_SCAN\, \CAMERA\, and \LOCATION\), status models (\BluetoothReadyStatus\), and handler classes (\GrantAndServiceHandler\, \GrantGroupHandler\) that manage permission requests and UI state. This change establishes the foundational contract for developers to integrate permission granting logic into their JVM-based applications.

grant-core/api/jvm · high confidence

Opt-in App Tracking Transparency module for iOS

A new \grant-tracking\ module has been added to handle iOS App Tracking Transparency (ATT). On iOS, it registers a handler that checks and requests the ATT permission via \ATTrackingManager\, mapping the authorization status to the library's grant states and warning if the request is made while the app is not in the foreground. On Android, the module is a no-op because cross-app tracking does not require a runtime permission prompt. The module is designed as an opt-in isolation to avoid forcing the \AppTrackingTransparency.framework\ and its associated \NSUserTrackingUsageDescription\ plist key on apps that do not track users.

grant-tracking · high confidence

iOS platform support for foreground-aware permission refreshing and state management

This change introduces iOS-specific implementations for the Grant library, enabling automatic permission state refreshes when the app returns to the foreground via \UIApplicationDidBecomeActiveNotification\. It adds \AppForegroundSignal\ to detect these transitions and \PlatformConfig\ to indicate that iOS does not support permission rationale dialogs. Additionally, \GrantFactory\ now accepts a \GrantStore\ to manage permission state (defaulting to in-memory storage), ensuring that permission grants are correctly handled across app lifecycle events without relying on Android-style process-death persistence.

grant-core/src/iosMain/kotlin/dev/brewkits/grant · high confidence

macOS camera, microphone, and privacy settings support added to grant-desktop

The grant-desktop module now supports requesting and checking permissions for the camera and microphone on macOS, as well as opening the system Privacy settings pane. This is achieved via a new Kotlin/Native bridge (CameraBridge and SettingsBridge) that communicates with the JVM side over JNA, handling the native consent dialogs and status checks. The module registers these handlers in the central registry upon initialization, allowing desktop apps to manage these Tier 2 permissions. A test suite verifies the native bridge ABI and correct loading behavior on macOS ARM64.

grant-desktop · high confidence

API

Android permission grant API surface stabilized with Bluetooth and App Tracking support

The public API for the Android grant core has been formalized, introducing specific support for Bluetooth permissions (BLUETOOTH, BLUETOOTH\_CONNECT, BLUETOOTH\_SCAN, BLUETOOTH\_ADVERTISE) and the new Android 14+ special access USE\_FULL\_SCREEN\_INTENT. The API now exposes a comprehensive AppGrant enum covering all supported permissions, including granular gallery access types (IMAGES\_ONLY, VIDEO\_ONLY, ADD\_ONLY), and provides dedicated classes for Bluetooth readiness status and group permission handling. This change stabilizes the interface for developers integrating permission requests, ensuring consistent state management via GrantAndServiceHandler and GrantGroupHandler while explicitly defining the contract for Bluetooth-specific flows.

grant-core/api/android · high confidence

Architecture

Public API surface locked with ABI validation

The grant-core library now enforces a stable public API contract by introducing an ABI validation mechanism and aggregated documentation. This change ensures that the exposed interfaces, such as GrantManager, GrantStore, and the various permission enums, remain consistent across updates, preventing accidental breaking changes for consumers relying on the core grant-checking functionality.

grant-core/api · high confidence

Behavioural changes

Android demo app adds platform-specific utilities and fixes permission request wiring

The Android demo application now includes concrete implementations for platform checks, including a ManifestChecker to validate required permissions, OsInfo to display Android version and API-level specific behavior notes for media and notifications, and a Theme.android file that enables dynamic color schemes on Android 12+. Crucially, the permission request flow is fixed: GrantsBinder now correctly wires the Compose ActivityResultLauncher into the GrantManager using an AtomicReference to handle callbacks, ensuring permission dialogs are properly triggered and results processed, and DemoApplication configures GrantLogger to output to Android Logcat for reliable diagnostics on retail devices.

demo/src/androidMain/kotlin · high confidence

Calendar permission module now supports iOS 17+ write-only access and fixes false denial logs

The grant-calendar module now correctly handles the iOS 17+ 'Add Events Only' (write-only) calendar permission state, mapping it to a new PARTIAL\_GRANTED status instead of incorrectly treating it as denied. This change also fixes a false-alarm logging issue where apps using only the legacy or full-access plist keys were incorrectly reported as missing configuration, and adds comprehensive test coverage for the new state machine behavior, security isolation, and performance stability.

grant-calendar · high confidence

Demo app adds R8 validation and updates documentation

The demo application now includes a proguard-rules.pro file to validate the library's compatibility with aggressive R8 minification, ensuring that no consumer-side keep rules are required for core components. Additionally, the README has been updated with clearer descriptions of the permission handling patterns (sequential, parallel, complex flows), corrected links to the documentation, and added license information.

demo · high confidence

Grant request history now persists on Android and DI graph validation is enforced

On Android, the grant system now uses a persistent store (SharedPreferencesGrantStore) for request history, ensuring that denials and requests survive process death. The iOS implementation continues to use an in-memory store. Additionally, the Koin dependency injection graph is now explicitly validated: loading only the common module without the platform-specific module will now fail at resolution time, preventing silent failures from incomplete wiring. New tests confirm that the DI graph resolves correctly when both modules are provided and fails appropriately when they are not.

grant-core-koin · high confidence

New Compose UI components with centralized string management and dialog precedence fixes

This release introduces the \grant-compose\ module, providing Compose-based UI handlers (\GrantDialog\, \GrantGroupDialog\, \GrantAndServiceDialog\) that replace previous implementations with \BasicAlertDialog\ and optimize recomposition using \derivedStateOf\. It adds a new \GrantDialogStrings\ system via \CompositionLocal\, allowing host apps to provide localized strings once at the root of the composition tree instead of passing them to every dialog call. Additionally, the module introduces convenience extension functions (\collectAsStateWithLifecycle\, \collectStatusAsState\) for easier state observation and fixes a critical behavioral issue where the dialog precedence logic now correctly prioritizes the rationale dialog over settings guides, preventing users from being sent directly to system settings when a permission explanation is still available.

grant-compose/src · high confidence

Renamed grant manager and added multi-permission request support

The core grant management class has been renamed from MyGrantManager to DefaultGrantManager, with the old name retained as a deprecated alias for backward compatibility. The API now supports requesting multiple permissions at once via a new overloaded request method that accepts a list of GrantPermission objects and returns a map of results. Additionally, a setLauncher method has been added to allow custom launcher configuration, and the underlying platform delegate interface has been updated to support these new capabilities.

grant-core/src/commonMain/kotlin/dev/brewkits/grant/impl · high confidence

iOS Contacts permission now supports partial access and is isolated to avoid unnecessary plist requirements

The iOS implementation of the Contacts permission handler now correctly maps the iOS 18 \CNAuthorizationStatusLimited\ state to \PARTIAL\_GRANTED\, ensuring apps can distinguish between full and limited contact access. Additionally, the Contacts framework is now isolated in its own module, which prevents apps that do not use contacts from being forced to include \NSContactsUsageDescription\ in their Info.plist. The module also introduces a dedicated iOS test suite to verify the real permission handler logic, addressing previous gaps where platform-specific code was not exercised by tests.

grant-contacts · high confidence

iOS demo app now supports optional permission modules and platform-specific UI

The iOS demo application has been updated to support optional permission modules (Contacts, Calendar, Motion, Bluetooth, and Always Location) by explicitly initializing them before the dependency injection graph starts, ensuring these permissions are correctly handled rather than returning NOT\_DETERMINED. Additionally, the demo now includes iOS-specific implementations for manifest checking (returning empty lists as iOS validates via Info.plist), OS information (providing iOS version and specific behavior notes for gallery, notification, and motion permissions), and a dedicated Material 3 theme with distinct light and dark color schemes.

demo/src/iosMain · high confidence

iOS location permission handling stabilized and Bluetooth delegate removed

The iOS Bluetooth permission delegate has been removed, isolating Bluetooth handling into its own module. For location permissions, the delegate now prevents a crash on iOS 14+ caused by double-resuming coroutines when both new and legacy callbacks fire, and exposes iOS 14+ accuracy authorization properties to users.

grant-core/src/iosMain/kotlin/dev/brewkits/grant/delegates · high confidence

iOS permission handling is modularized with opt-in framework linking and a custom registry

The iOS permission system has been restructured to isolate native framework dependencies (AVFoundation, CoreLocation, UserNotifications, Photos) into separate handler classes, ensuring that unused frameworks are not statically linked into the app and avoiding mandatory Info.plist keys for permissions the app does not request. This change introduces a new \IosPermissionHandlerRegistry\ that allows developers to register custom handlers for permissions not covered by the standard \AppGrant\ enum, and adds specific handlers for camera/microphone, location (including temporary full accuracy on iOS 14+), push notifications, and photo library access (supporting limited access and add-only modes).

grant-core/src/iosMain/kotlin/dev/brewkits/grant/handlers · high confidence

iOS permission handling refactored into isolated handler modules to prevent App Store rejections

The iOS implementation of the grant library has been restructured to dispatch permission requests to dedicated handler classes (e.g., AVPermissionHandler, LocationPermissionHandler) rather than using a monolithic delegate. This architectural change ensures that native framework imports (such as Photos, Contacts, or CoreLocation) are only statically linked when their specific permissions are actually requested, preventing App Store rejections caused by undeclared usage description keys. Additionally, the service delegate now safely handles App Extension contexts by avoiding direct access to UIApplication.sharedApplication, and Bluetooth service status checks now return UNKNOWN to avoid triggering unintended permission prompts.

grant-core/src/iosMain/kotlin/dev/brewkits/grant/impl · high confidence

iOS permission handling stabilizes with crash prevention and simulator support

This update introduces three key utilities for iOS to improve reliability and developer experience. First, IosUtils now validates that required Info.plist usage description keys are present before requesting permissions, preventing SIGABRT crashes and safely returning a denied status if keys are missing. Second, SimulatorDetector allows the library to detect iOS Simulator environments, enabling mock permission statuses for testing without blocking flows. Third, MainThreadUtils refactors thread-safety mechanisms to use Kotlin Coroutines (GlobalScope and Dispatchers.Main) instead of low-level C interop, ensuring callbacks resume on the main thread more robustly while removing custom dispatcher implementations.

grant-core/src/iosMain/kotlin/dev/brewkits/grant/utils · high confidence

Fixes

Android permission request history now persists across process death

The Android implementation now uses a new \SharedPreferencesGrantStore\ to persist permission request history, ensuring that permanent denials are correctly identified even after the app process is killed and restarted. This prevents the system from treating a previously denied permission as undetermined, which previously caused silent no-ops. The store is automatically applied by default in \GrantFactory.create\ and includes safeguards to discard history from other installations or restores, while offering a \warmUp\ method for apps with strict frame budgets.

grant-core/src/androidMain · high confidence

Increase Mocha test timeout to prevent flaky browser test failures

The browser test suite now uses a 20-second timeout per test instead of the default 2 seconds. This change prevents intermittent failures caused by real browser operations (such as getUserMedia or Notification.requestPermission) taking longer than the previous limit, ensuring that tests relying on async browser APIs complete reliably under load.

grant-core/karma.config.d · high confidence

Introduction of reentrant mutex and improved logging visibility

This change introduces a \ReentrantMutex\ utility to prevent lock contention and deadlocks during nested permission requests, ensuring smoother operation on Android. It also updates \GrantLogger\ to be public and clarifies its behavior: while the default console output is disabled by default, developers can now reliably capture library diagnostics on production devices by installing a custom \logHandler\, addressing previous visibility gaps where logs were silently dropped on retail Android builds.

grant-core/src/commonMain/kotlin/dev/brewkits/grant/utils · high confidence

Test coverage

Added Android instrumented tests for grant-core; Added Android integration and unit tests for permission mapping and request flows; Added Android unit tests for permission store persistence and platform contracts; Added JVM test coverage for AppForegroundSignal, TestPlatform, and JvmGrantDelegate; Added browser-specific tests for permission delegation and foreground signals; Added comprehensive concurrency and safety tests for the permission request handler; Added comprehensive test coverage for grant-core permission handling; Added iOS handler pattern validation tests; Added iOS permission handler tests; Added iOS-specific test coverage for permission handling and foreground signals; Added integration tests for GrantDialog UI state logic; Added integration tests for permission request flows and state persistence; Added performance and system tests for grant-core; Added regression tests for GrantHandler concurrency, state management, and platform-specific edge cases; Added security and privacy tests for the Grant library; Added tests for GrantProperty handler status updates; Added unit tests for Android manifest validation and iOS utility logic; Added unit tests for GrantLogger and ReentrantMutex utilities.

Dependencies

Gradle wrapper updated to version 8.14.4

The Gradle wrapper has been upgraded from version 8.14.3 to 8.14.4. This ensures that builds use the specified Gradle distribution, which may include bug fixes, performance improvements, or new features compared to the previous version.

gradle · high confidence

Initial release of KMP Grant v2.6.0 with macOS support and opt-in permission modules

The library is now available as version 2.6.0, introducing a new \grant-desktop\ module that provides macOS permission handlers via a Compose Desktop harness and a native dylib bridge. This release also adds several new opt-in modules for specific permissions—Bluetooth, Contacts, Calendar, Motion, Location Always, and App Tracking Transparency—allowing consumers to include only the permissions they need. A new \grant-testing\ module is published to provide official test doubles (fakes) for unit testing, and a \grant-bom\ (Bill of Materials) is introduced to ensure all modules are consumed at the same version. Additionally, the \grant-compose\ module has dropped the \iosX64\ target to align with Compose Multiplatform 1.11, and all published modules now enforce explicit API visibility and ABI validation.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 63 → 71 (+8.9)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 91 → 93 (+2.8)
  • Architecture 100 → 99 (-1.2)
  • Maturity 65 → 73 (+8.7)
  • Readiness 58 → 64 (+5.6)
  • Security 56 → 74 (+17.4)

Resolved (50)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (12 lines × 2) (grant-core/src/iosMain/kotlin/dev/brewkits/grant/delegates/LocationManagerDelegate.kt)
  • Duplicated block (13 lines × 2) (demo/src/commonMain/kotlin/dev/brewkits/grant/demo/GrantDemoScreen.kt)
  • Duplicated block (13 lines × 2) (demo/src/commonMain/kotlin/dev/brewkits/grant/demo/GrantDemoScreen.kt)
  • Duplicated block (14 lines × 2) (demo/src/commonMain/kotlin/dev/brewkits/grant/demo/LocationFlowDemoScreen.kt)
  • Duplicated block (14 lines × 2) (grant-compose/src/commonMain/kotlin/dev/brewkits/grant/compose/GrantDialogs.kt)
  • Duplicated block (14 lines × 2) (grant-compose/src/commonMain/kotlin/dev/brewkits/grant/compose/GrantDialogs.kt)
  • Duplicated block (15 lines × 2) (demo/src/commonMain/kotlin/dev/brewkits/grant/demo/DemoApp.kt)
  • Duplicated block (15 lines × 2) (demo/src/commonMain/kotlin/dev/brewkits/grant/demo/GrantDemoScreen.kt)
  • Duplicated block (15 lines × 6) (demo/src/commonMain/kotlin/dev/brewkits/grant/demo/GrantDemoScreen.kt)
  • Duplicated block (18 lines × 2) (demo/src/commonMain/kotlin/dev/brewkits/grant/demo/MinimalGrantDemoScreen.kt)
  • Duplicated block (18 lines × 2) (demo/src/commonMain/kotlin/dev/brewkits/grant/demo/SimpleGrantDemoScreen.kt)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 30 more

New (75)

  • Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
  • Documentation: contradicts the code (docs/ios/APPLE_FRAMEWORK_LINKING_ISSUE.md)
  • Documentation: no installation or build instructions (README.md)
  • Duplicate method names with identical signatures in FakeGrantManager. It is unclear if these have different internal behaviors or if one is a legacy alias.
  • Duplicated block (12 lines × 2) (grant-core/src/iosMain/kotlin/dev/brewkits/grant/delegates/LocationManagerDelegate.kt)
  • Duplicated block (13 lines × 2) (demo/src/commonMain/kotlin/dev/brewkits/grant/demo/LocationFlowDemoScreen.kt)
  • Duplicated block (14 lines × 2) (demo/src/commonMain/kotlin/dev/brewkits/grant/demo/GrantDemoScreen.kt)
  • Duplicated block (16–17 lines × 2) (demo/src/commonMain/kotlin/dev/brewkits/grant/demo/DemoApp.kt)
  • Duplicated block (29 lines × 2) (grant-compose/src/commonMain/kotlin/dev/brewkits/grant/compose/GrantDialogs.kt)
  • Duplicated block (42 lines × 2) (grant-compose/src/commonMain/kotlin/dev/brewkits/grant/compose/GrantDialogs.kt)
  • Duplicated block (6 lines × 2) (grant-core/src/androidMain/kotlin/dev/brewkits/grant/impl/PlatformGrantDelegate.android.kt)
  • Duplicated block (6 lines × 2) (grant-core/src/iosMain/kotlin/dev/brewkits/grant/delegates/LocationManagerDelegate.kt)
  • Duplicated block (7 lines × 2) (grant-core/src/commonMain/kotlin/dev/brewkits/grant/impl/SimpleGrantManager.kt)
  • Duplicated block (8 lines × 2) (grant-core/src/iosMain/kotlin/dev/brewkits/grant/delegates/LocationManagerDelegate.kt)
  • Duplicated block (8 lines × 2) (grant-core/src/iosMain/kotlin/dev/brewkits/grant/delegates/LocationManagerDelegate.kt)
  • Duplicated block (9 lines × 2) (grant-core/src/iosMain/kotlin/dev/brewkits/grant/delegates/LocationManagerDelegate.kt)
  • Extension functions in GrantStoreKt operate on GrantPermission, whereas the core GrantStore interface and its implementations (SharedPreferencesGrantStore, InMemoryGrantStore, FakeGrantStore) operate on AppGrant. This creates a split API surface where the same logical operation (checking/requesting status) has different entry points depending on whether the caller uses the interface or the extension functions, and potentially different underlying types (AppGrant vs GrantPermission).
  • High vulnerability: [GHSA redacted] (kotlin-js-store/yarn.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 55 more

Changes since last survey

  • 67 commits — 49 feature/other, 18 fixes

By area

  • (repo) — 20 commits
  • (root) — 16 commits
  • grant-core/src — 16 commits
  • .github/workflows — 6 commits
  • gradle/libs.versions.toml — 3 commits
  • docs/MIGRATION_GUIDE.md — 1 commit
  • grant-calendar/src — 1 commit
  • grant-compose/src — 1 commit
  • grant-core/build.gradle.kts — 1 commit
  • grant-core/karma.config.d — 1 commit
  • grant-desktop/src — 1 commit

Notable commits

  • fix: Merge main into fix/device-verification-2026-09-04
  • fix: Merge pull request #68 from brewkits/fix/local-network-target-sdk-gating
  • fix: Merge pull request #70 from brewkits/fix/device-verification-2026-09-04
  • fix: Merge pull request #73 from brewkits/fix/android-concurrency-audit
  • fix: Merge pull request #74 from brewkits/fix/exact-alarm-and-calendar-writeonly
  • fix: Merge remote-tracking branch 'origin/main' into fix/local-network-target-sdk-gating
  • fix: ci(coverage): fix stale module list and rationale comment (#79)
  • fix: fix(android): stop injecting permissions into consuming apps; harden store against restore
  • fix: fix(publish): add a real Dokka-based javadoc jar to grant-core's jvm publication
  • fix: fix: AppGrant.STORAGE misclassified Android 14 partial photo access as denied
  • fix: fix: SCHEDULE_EXACT_ALARM was a silent no-op on Android and a fabricated GRANTED on iOS 26
  • fix: fix: accept the iOS 17+ write-only calendar key in the plist gate
  • fix: fix: address real CodeQL findings from the security/code-scanning review
  • fix: fix: apply Kover to grant-core-koin, wire real 50% floor (#80)
  • fix: fix: calendar plist false-alarm + GrantLogger visibility gap, add grant-core test categories
  • fix: fix: correct issues found during full pre-publish diff review
  • fix: fix: owned launch guard, main-thread I/O, cancellation, and lock contention on Android
  • fix: fix: raise Karma/Mocha timeout so the browser suite is not load-dependent
  • change: Merge main into feat/macos-tier2-camera
  • change: Merge pull request #66 from brewkits/chore/v2.4.0-foundation
  • …and 47 more

Architecture

  • Containers 0 added · 0 removed · contexts 4 added · 1 removed · edges 3 added · 0 removed

Added bounded contexts (4)

  • demo
  • grant-compose
  • grant-core
  • repository

Removed bounded contexts (1)

  • grant-motion

Added dependency edges (3)

  • demo → grant-core
  • grant-compose → grant-core (coupling)
  • repository → grant-core

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

brewkits/Grant was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 5b22ca108b06192892e2a78b99c1c884bf2c5251 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.