Skip to content
CAI
Software that uses CAICheck a score

FiloSottile/mkcert

49.2

Weak · 24 September 2026

1.2k

lines of production code

Go

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a cross-platform utility for managing trust stores and certificates, with specific implementations for Linux, Java, Windows, and macOS. It provides a command-line interface for installing, uninstalling, and configuring certificate authorities and client certificates. The codebase has been refactored to separate platform-specific logic and migrated to Go modules, though it no longer supports Apple property list encoding or decoding.

Removals

Removed go-plist vendor dependency

The \github.com/DHowett/go-plist\ library has been removed from the vendor directory. This eliminates the ability to encode and decode Apple property lists (XML, binary, and text formats) within the application.

vendor · high confidence

Behavioural changes

Major refactoring: modular trust store implementations and unified CLI

The codebase has been restructured to separate platform-specific trust store logic into dedicated files (truststore\_linux.go, truststore\_java.go, truststore\_nss.go, truststore\_windows.go, truststore\_darwin.go), each handling installation and removal for their respective systems. The command-line interface has been updated to support new flags (-uninstall, -CAROOT, -help, -version) and advanced options like -client, -ecdsa, -pkcs12, and -csr. Additionally, the project has migrated from the 'dep' dependency manager to Go modules, removing Gopkg.toml and Gopkg.lock, and updated the import path for the plist library.

(repo-wide) · high confidence

Dependencies

Migrated to Go modules and updated dependencies

The project has switched to Go modules, introducing a go.mod and go.sum file to manage dependencies. This includes adding the howett.net/plist package and updating the import path for filippo.io/mkcert. Indirect dependencies such as golang.org/x/crypto, golang.org/x/net, and software.sslmate.com/src/go-pkcs12 are also included in the new module graph.

(dependencies) · medium confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 48 → 49 (+1.1)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 87 → 92 (+4.6)
  • Architecture 69 → 69 (+0.0)
  • Maturity 39 → 39 (+0.0)
  • Readiness 47 → 47 (-0.1)
  • Security 56 → 63 (+6.5)

Resolved (16)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Medium CVE: GO-2023-1568 (go.mod)
  • No exposed public API
  • dormant codebase — no living knowledge left to concentrate

New (35)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency pinned to a stale untagged commit: golang.org/x/net
  • Documentation: no architecture or design documentation (README.md)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Medium CVE: GO-2023-1568 (go.mod)
  • Medium: security finding (details withheld)
  • …and 15 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

FiloSottile/mkcert was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 1c1dc4ed27ed5936046b6398d39cab4d657a2d8e — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-923689c465cf.