EEliberto/Pastel-macOS
40.7
Weak · 1 October 2026
7.8k
lines of production code
Swift
with JavaScript
2
measurements over time
What this system is
Pastel is a macOS application and associated CLI tool designed to manage the acquisition, authentication, and re-signing of Apple App Store IPA files. It provides users with capabilities to search for apps, handle license recovery, and download binaries, while automatically re-signing them with custom metadata. The system integrates a native Node.js runtime for backend operations and supports automatic updates via Sparkle.
Features
Initial macOS project structure and Sparkle integration
The Pastel macOS application project has been established, introducing the core Swift source files for account management, search, version history, downloads, and task logging. The build configuration includes localization support (zh-Hans, zh-HK, zh-Hant, ja, ko, th) and integrates the Sparkle framework to enable automatic software update capabilities for users.
Pastel.xcodeproj · high confidence
Introduce Pastel CLI for Apple App Store acquisition and signing
This release adds a new Node.js-based command-line interface (CLI) for managing Apple App Store interactions. The tool provides commands to search, look up, and list featured apps, as well as to authenticate with Apple ID credentials, retrieve app version history, and download IPA files. It includes built-in logic for handling license acquisition (purchasing or redownloading), recovering from unavailable downloads, and re-signing IPA files with custom metadata and signatures. The CLI supports multi-threaded chunked downloads, respects system proxy settings, and manages persistent login sessions with automatic expiration handling.
NodeProject/src · high confidence
Introduce macOS app with Sparkle auto-updates and new UI features
Pastel is now available as a native macOS application built with SwiftUI and the Observation framework. This release introduces a redesigned user interface featuring a new download library sidebar, version history management with multiple source providers (Timbrd, Agzy, Bilin, Apple), and enhanced search capabilities. The app includes automatic update support via Sparkle, configured with a public ED key and feed URL in the Info.plist, and adds keyboard shortcut handling for row selection across the interface.
Pastel · high confidence
New build scripts for Node runtime bundling, SAP signing, and DMG creation
Added a set of build scripts to the Scripts directory to support the application's internal Node.js runtime and Apple Store authentication. BundleNodeRuntime.sh handles extracting the Node binary, installing dependencies, compiling the SAP signer, and applying necessary codesigning (including a new JIT entitlement for Node). SAPSigner.m implements a subprocess that uses private CommerceKit frameworks to generate SAP action signatures required for Apple authentication. BuildAdHocDMG.sh automates the final build, verification, and DMG packaging process. VerifyDeviceGUIDImplementation.sh ensures the device identifier logic in the app source meets specific safety and implementation constraints.
Scripts · high confidence
Test coverage
Added tests for Apple App Store download, authentication, and session handling
Added comprehensive test coverage for the Apple App Store integration, including fallback logic for current version resolution, parsing of Apple version identifiers, secure credential reading from stdin, device GUID normalization, IPA download completion merging, and redownload recovery mechanisms. The tests also cover session encryption with AES-256-GCM, session expiry detection, StoreServices authentication failure recognition, purchase success validation, storefront version extraction, and platform catalog parsing.
NodeProject/test · high confidence
Dependencies
Add Pastel Node.js client and update macOS update framework
This release adds a new Node.js embedded App Store client (ipatool.js) to the Pastel project, requiring Node.js 24 and bundling dependencies like axios, archiver, and plist. It also updates the Sparkle framework used for macOS application updates to version 2.9.3.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 48 → 41 (-6.8)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 40 → 37 (-3.1)
- Architecture 93 → 96 (+3.7)
- Maturity 54 → 54 (+0.6)
- Readiness 35 → 28 (-7.5)
- Security 96 → 95 (-1.5)
- Performance 60 (new)
Resolved (6)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Hotspot: NodeProject/main.js (NodeProject/main.js)
- Hotspot: NodeProject/src/Signature.js (NodeProject/src/Signature.js)
- Hotspot: NodeProject/src/catalog.js (NodeProject/src/catalog.js)
New (37)
- AccountEditorView.body (cognitive 18) (Pastel/PastelApp.swift)
- ContentView.appHistoryDetailPane (cognitive 29) (Pastel/PastelApp.swift)
- ContentView.versionsWorkspace (cognitive 17) (Pastel/PastelApp.swift)
- Duplicated block (10 lines × 2) (Pastel/PastelApp.swift)
- Duplicated block (10 lines × 2) (Pastel/PastelApp.swift)
- Duplicated block (10 lines × 2) (Pastel/PastelApp.swift)
- Duplicated block (11 lines × 2) (Pastel/PastelApp.swift)
- Duplicated block (11 lines × 2) (Pastel/PastelApp.swift)
- Duplicated block (11 lines × 2) (Pastel/SearchFeatureState.swift)
- Duplicated block (11–12 lines × 2) (Pastel/PastelApp.swift)
- Duplicated block (12 lines × 2) (Pastel/DownloadLibraryFeatureState.swift)
- Duplicated block (12 lines × 2) (Pastel/SearchFeatureState.swift)
- Duplicated block (12–14 lines × 2) (Pastel/PastelApp.swift)
- Duplicated block (14 lines × 2) (Pastel/PastelApp.swift)
- Duplicated block (16 lines × 2) (Pastel/PastelApp.swift)
- Duplicated block (18 lines × 2) (Pastel/PastelApp.swift)
- Duplicated block (18 lines × 2) (Pastel/SearchFeatureState.swift)
- Duplicated block (44 lines × 2) (Pastel/PastelApp.swift)
- Duplicated block (6 lines × 2) (Pastel/DownloadLibraryFeatureState.swift)
- Duplicated block (6 lines × 2) (Pastel/PastelApp.swift)
- …and 17 more
Changes since last survey
- 12 commits — 9 feature/other, 3 fixes
By area
- (root) — 10 commits
- NodeProject/src — 1 commit
- node/lib — 1 commit
Notable commits
- fix: Fix Apple authentication and version lookup
- fix: Fix Apple version history loading
- fix: Fix unavailable historical version downloads
- change: Polish Pastel introduction
- change: Preserve updated README presentation
- change: Refine README product copy
- change: Refine product and release copy
- change: Refresh README with an Apple-inspired presentation
- change: Update README.md
- change: Update README.md
- change: Update README.md
- change: Update README.md
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
EEliberto/Pastel-macOS was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 7087860ae53003bb3c11021b6f166a1632b8144b — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.