Skip to content
CAI
Software that uses CAICheck a score

caezium/burrow

53.9

Adequate · 1 October 2026

64.4k

lines of production code

Swift

with C#, TypeScript

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Burrow is a cross-platform system maintenance and optimization utility that provides native desktop applications for macOS and Windows. It leverages bundled engine binaries and privileged helpers to perform deep cleaning, disk optimization, and anomaly detection while ensuring safety through auditable deletion workflows and strict security models. The system also includes a web landing site and comprehensive tooling for reproducible builds, telemetry, and automated code review.

Features

Added Windows publish profiles for ARM64, x64, and x86

New MSBuild publish profiles have been added for Windows on ARM64, x64, and x86 architectures. These profiles configure the application to publish as a self-contained deployment to a file system, enabling users to generate standalone executables for these specific Windows platforms.

Properties · high confidence

Initial repository scaffolding and documentation for Burrow

This change establishes the foundational structure for the Burrow project, introducing the initial README, SECURITY, TELEMETRY, and RELEASES documentation, along with the NOTICE file for third-party attribution. It configures the development environment with .gitignore and .gitmodules for vendored submodules (burrow-engine, burrow-cli), sets up the Cloudflare Workers configuration for the landing site, and adds a .coderabbit.yaml file to define automated code review rules for the Swift and C\# codebases.

(repo-wide) · high confidence

New build, release, and site deployment tooling

The repository now includes a comprehensive suite of scripts to manage the macOS build pipeline, release process, and website deployment. This includes checksum-pinned fetchers for third-party frameworks (Sentry, Sparkle) and tools (XcodeGen, sentry-cli) to ensure reproducible builds, alongside a dedicated script to build the universal fclones sidecar. Release workflows are supported by scripts for ad-hoc and Developer ID code signing, Homebrew tap updates, and Sentry crash-reporting integration (including a public summary sanitizer). The site deployment is now handled by scripts that prepare assets, inject PostHog analytics keys, and generate localized pages and release content from JSON sources.

scripts · high confidence

New data models for CLI integration, safe deletion, and system telemetry

The BurrowWin application introduces several new model classes to support core functionality. BurrowEnvelope and BurrowError define the unified JSON contract for parsing output from the burrow-cli tool, enabling consistent handling of success and failure states. DestructiveDeletionModels introduces a robust framework for safe file and directory deletion, including candidate descriptors, authorization tokens, and receipts to ensure destructive operations are validated and auditable. Additionally, GpuTelemetrySample and SystemTelemetrySnapshot provide structured data models for capturing and reporting system resource usage, including CPU, memory, disk, network, and GPU metrics.

BurrowWin · high confidence

New macOS application source files for Burrow

The macos/Sources directory now contains the initial implementation of the Burrow application, including the main entry point, app delegate, and core UI components like the Activity and Analyze panes. It also introduces foundational services for AI configuration, anomaly detection, alerting, and system state monitoring, along with localization support and branding assets.

macos/Sources · high confidence

Privileged helper daemon with hardened security and improved reliability

The macOS privileged helper daemon has been implemented with a strict five-gate security model (connection, shape, freshness, authorization, execution) to prevent command injection and ensure only signed, authorized operations are performed. To improve reliability and debuggability, the daemon now retries account lookups to handle transient system states and writes diagnostic logs to a local file in addition to the unified log, ensuring visibility even if system logging fails.

macos/HelperSources · high confidence

Windows desktop preview with system maintenance and telemetry

This release introduces a new Windows desktop application (BurrowWin) built on WinUI 3 and .NET 8, providing a native UI for system maintenance tasks including deep cleaning, app uninstallation, disk optimization, and analysis. The app bundles the Mole engine (a PowerShell-based toolkit for Windows maintenance) and integrates it via a local MCP server. It includes a comprehensive dependency injection setup, telemetry collection (Sentry and PostHog) with user opt-in, and safety features like recycle bin integration and path validation to prevent accidental system damage.

windows · high confidence

macOS app resource bundle and localization assets added

The macOS application now includes its core resource bundle, providing the app icon set, a defined accent color, and localized interface strings for German, Spanish, French, Japanese, and Korean. The Info.plist declares the app as a menu-bar-only utility (LSUIElement) and configures Sparkle for automatic update checks with signed feeds. A privileged helper launch daemon is registered to support admin operations, and the app is configured without sandboxing to allow necessary filesystem and network access. Privacy and entitlements are explicitly declared to comply with macOS requirements.

macos/Resources · high confidence

Behavioural changes

Mac build process now bundles and seals the engine and fclones sidecar

The macOS build scripts now automatically compile and bundle the \burrow-engine\ binary (as a universal arm64/x86\_64 executable) and the \fclones\ sidecar into the app's Resources directory. A new \build.sh\ script handles the final code-signing seal after the Xcode build to ensure the bundled engine retains Full Disk Access permissions. This allows the Duplicates feature to function with zero user installation of external tools, and the app now runs on a single bundled engine binary rather than relying on a separate system or conductor process.

macos/scripts · high confidence

Permanently redirects legacy hostnames to burrow.computer

The worker now serves the landing site and automatically performs a permanent 301 redirect for requests arriving at legacy hostnames (burrow.henryzh.dev and www.burrow.computer) to the new canonical domain burrow.computer, preserving the original path to maintain SEO ranking signals.

worker · high confidence

Updated bundled burrow-engine submodule

The macOS application now uses a newer version of the bundled burrow-engine submodule (commit d3f65b2). This update incorporates recent fixes and improvements from the engine repository, ensuring the macOS client benefits from the latest engine capabilities and stability enhancements.

macos/vendor · high confidence

Test coverage

Added test coverage for release, security, and analytics workflows; Added tests for macOS core logic and engine contracts.

Dependencies

Introduces Windows desktop preview and native tooling dependencies

Adds a new TypeScript-based desktop preview for Windows (built with Electron, React 19, and Vite) alongside native Windows tooling dependencies. The Go module for the Mole shim introduces bubbletea, lipgloss, and gopsutil, while the .NET projects (BurrowWin, MoShim, McpStdioBridge, and tests) target .NET 8 and reference CommunityToolkit.Mvvm, Microsoft.Extensions.Hosting, Sentry, and the Windows App SDK.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 55 → 54 (-0.8)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 55 → 55 (-0.0)
  • Architecture 85 → 85 (+0.0)
  • Maturity 69 → 68 (-0.1)
  • Readiness 43 → 42 (-0.7)
  • Security 79 → 83 (+3.6)
  • Performance 71 → 71 (+0.0)

Resolved (31)

  • Documentation: no architecture or design documentation (docs/compare.html)
  • Documentation: no installation or build instructions (docs/install.html)
  • Documentation: no installation or build instructions (docs/zh-Hans/index.html)
  • Documentation: no project overview (docs/compare.html)
  • Documentation: no usage examples (docs/zh-Hans/index.html)
  • Duplicated block (5 lines × 2) (macos/Sources/PopupView.swift)
  • Hotspot: macos/Sources/BurrowStreamReport.swift (macos/Sources/BurrowStreamReport.swift)
  • Hotspot: macos/Sources/CleanList.swift (macos/Sources/CleanList.swift)
  • Hotspot: macos/Sources/CleanupAuthorization.swift (macos/Sources/CleanupAuthorization.swift)
  • Hotspot: macos/Sources/Connectivity.swift (macos/Sources/Connectivity.swift)
  • Hotspot: macos/Sources/HotKey.swift (macos/Sources/HotKey.swift)
  • Hotspot: macos/Sources/MCPServer.swift (macos/Sources/MCPServer.swift)
  • Hotspot: macos/Sources/MetricsCore.swift (macos/Sources/MetricsCore.swift)
  • Hotspot: macos/Sources/MetricsStore.swift (macos/Sources/MetricsStore.swift)
  • Hotspot: macos/Sources/MoActions.swift (macos/Sources/MoActions.swift)
  • Hotspot: macos/Sources/PortEnumerator.swift (macos/Sources/PortEnumerator.swift)
  • Hotspot: macos/Sources/PrivilegedExecution.swift (macos/Sources/PrivilegedExecution.swift)
  • Hotspot: macos/Sources/PrivilegedHelper/HelperCodeRequirement.swift (macos/Sources/PrivilegedHelper/HelperCodeRequirement.swift)
  • Hotspot: macos/Sources/QueryServer.swift (macos/Sources/QueryServer.swift)
  • Hotspot: macos/Sources/UninstallGuard.swift (macos/Sources/UninstallGuard.swift)
  • …and 11 more

New (69)

  • CleanView.body (cognitive 17) (macos/Sources/CleanView.swift)
  • Documentation: no architecture or design documentation (docs/localization.md)
  • Documentation: no project overview (docs/es/releases.html)
  • Documentation: no project overview (docs/releases.html)
  • Duplicated block (10 lines × 3) (macos/Sources/DupesView.swift)
  • Duplicated block (10–11 lines × 3) (macos/Sources/HistoryView.swift)
  • Duplicated block (11 lines × 3) (macos/Sources/DupesView.swift)
  • Duplicated block (12 lines × 4) (macos/Sources/AnalyzeView.swift)
  • Duplicated block (12 lines × 4) (macos/Sources/DupesView.swift)
  • Duplicated block (14 lines × 2) (macos/Sources/MenuBarWidgets.swift)
  • Duplicated block (18 lines × 3) (macos/Sources/DupesView.swift)
  • Duplicated block (1–8 lines × 6) (macos/Sources/CleanHub.swift)
  • Duplicated block (3–7 lines × 3) (macos/Sources/PopupView.swift)
  • Duplicated block (4–5 lines × 3) (macos/Sources/Components/ShortcutRecorder.swift)
  • Duplicated block (4–5 lines × 4) (macos/Sources/ProcessInspectorView.swift)
  • Duplicated block (5 lines × 2) (macos/Sources/CleanView.swift)
  • Duplicated block (5 lines × 2) (macos/Sources/ConnectivityView.swift)
  • Duplicated block (5 lines × 2) (macos/Sources/HistoryView.swift)
  • Duplicated block (5 lines × 2) (macos/Sources/InstallerView.swift)
  • Duplicated block (5 lines × 2) (macos/Sources/SettingsView.swift)
  • …and 49 more

Changes since last survey

  • 17 commits — 16 feature/other, 1 fixes

By area

  • docs/de — 15 commits
  • docs/blog — 1 commit
  • docs/ko — 1 commit

Notable commits

  • fix: fix(l18n): refine Korean translations (#446)
  • change: site: refresh download and star counts
  • change: site: refresh download and star counts
  • change: site: refresh download and star counts
  • change: site: refresh download and star counts
  • change: site: refresh download and star counts
  • change: site: refresh download and star counts
  • change: site: refresh download and star counts
  • change: site: refresh download and star counts
  • change: site: refresh download and star counts
  • change: site: refresh download and star counts
  • change: site: refresh download and star counts
  • change: site: refresh download and star counts
  • change: site: refresh download and star counts
  • change: site: refresh download and star counts
  • change: site: refresh download and star counts
  • change: site: refresh download and star counts

Architecture

  • Unchanged — 1 containers · 1 contexts · 0 edges

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

caezium/burrow was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit eff3d7b7e8a77c34d84421834d9ce7d5dc743e40 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.