gabriel-TheCode/Infotify
64.8
Adequate · 21 September 2026
6.6k
lines of production code
Kotlin
with PHP
4
measurements over time
What this system is
This system is a privacy-focused news aggregation application for Android that delivers daily briefings and subject-specific feeds. It features a Compose-only user interface with offline caching capabilities and relies on a dedicated PHP proxy server to manage API access, enforce input validation, and reduce upstream costs. The infrastructure includes a separate static website for public information and is built using modern Kotlin and Gradle tooling.
Features
New Play Store listing assets and copy
The Play Store listing now includes a complete set of assets and localized copy. A new Python script generates store-ready images from real application captures, ensuring the app icon matches the installed launcher icon and screenshots are framed in a device chassis without distortion. The listing copy is provided in both English and French, detailing features like subject selection, daily briefings, and privacy guarantees, and is verified against the app's actual code and permissions.
playstore · high confidence
New server-side news proxy with caching and strict input validation
A new PHP-based proxy service has been deployed at infotify-api.nativia.co to centralize access to the NewsData.io API. This change introduces server-side caching (10-minute TTL) to significantly reduce API credit consumption by serving repeated queries from cache rather than the upstream provider. The proxy enforces strict input validation using allowlists for categories, languages, and countries, and normalizes the API response into a consistent envelope for the client. Security measures include forcing HTTPS, denying direct access to configuration files, and implementing rate limiting.
server · high confidence
Public site launch with dedicated server configuration
The public website for infotify.nativia.co is now live, featuring a static brochure site (home, privacy, support) that is deliberately separated from the API host to prevent deployment conflicts. The site includes a new SVG favicon, a privacy policy detailing data handling, and a support page. Server configuration is handled by a new .htaccess file that enforces HTTPS, serves static HTML, denies PHP execution, sets security headers (X-Content-Type-Options, Referrer-Policy, X-Frame-Options), and manages caching for assets.
site · high confidence
Behavioural changes
Enable R8 code shrinking and obfuscation with specific keep rules
The app now enables R8 for release builds to reduce size and obfuscate code. To prevent runtime crashes caused by reflection, specific ProGuard rules have been added to preserve Gson DTOs (specifically in the \com.thecode.infotify.data.remote.infotify\ package), Room entities, Retrofit interfaces, kotlinx.serialization navigation routes, and the DailyBriefingWorker.
app · high confidence
News feed now available offline with improved error messaging
The app now caches news articles locally, allowing users to read previously loaded feeds even without an internet connection. When offline, a banner indicates the age of the cached content rather than showing a generic error. Additionally, error handling has been refined to distinguish between specific failure modes, such as provider quota exhaustion or invalid credentials, providing clearer feedback to the user instead of generic connection errors.
app/src · high confidence
Dependencies
Gradle wrapper updated to version 9.7.1
The project now uses Gradle wrapper version 9.7.1 for builds, ensuring consistent build environments across development and CI systems by downloading this specific distribution from the official Gradle services.
gradle · high confidence
Migrate to Android Gradle Plugin 9, Kotlin 2.3, and Compose-only architecture
The project has been rebuilt on Android Gradle Plugin 9.2.1 and Kotlin 2.3.21, introducing a version catalog (libs.versions.toml) to centralize dependency management. The build now uses KSP instead of kapt for annotation processing (Room, Hilt) and relies on AGP's built-in Kotlin support. The application targets API 26+ (minSdk 26, compileSdk 17) and has shifted to a Compose-only UI, removing the View system, ViewBinding, and legacy libraries like Glide, Lottie, and ViewPager2. Key dependencies include Hilt 2.60.1 for DI, Room 2.8.4, Retrofit 3.0.0, OkHttp 5.5.0, and Coil 2.7.0 for image loading. The release build enables R8 minification and resource shrinking, with a dedicated 'releaseTest' build type for local verification.
(dependencies) · high confidence
Housekeeping
Initial project scaffolding and documentation
The repository is initialized with the core project structure, including the Gradle wrapper scripts for build automation, a CONTRIBUTING guide for external collaborators, and an updated README that outlines the app's features, architecture, and setup requirements. The .gitignore is also configured to properly exclude IDE-specific files, build outputs, and platform-specific artifacts.
(repo-wide) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 52 → 65 (+12.6)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 99 → 100 (+0.4)
- Architecture 100 → 93 (-7.4)
- Maturity 55 → 63 (+8.0)
- Readiness 24 → 57 (+32.4)
- Security 90 → 83 (-7.2)
- Domain Modelling 100 → 70 (-30.3)
Resolved (11)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (12 lines × 2) (app/src/main/java/com/thecode/infotify/presentation/main/headline/HeadlineFragment.kt)
- Duplicated block (12 lines × 2) (app/src/main/java/com/thecode/infotify/presentation/main/headline/HeadlineFragment.kt)
- Duplicated block (20 lines × 2) (app/src/main/java/com/thecode/infotify/presentation/main/headline/HeadlineFragment.kt)
- Further orphaned files (smaller)
- No exposed public API
- Secret: generic-api-key (app/src/main/java/com/thecode/infotify/utils/AppConstants.kt)
- Secret: generic-api-key (app/src/main/java/com/thecode/infotify/utils/AppConstants.kt)
- Test reliability not included
- dormant codebase — no living knowledge left to concentrate
New (18)
- Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
- Duplicated block (12 lines × 2) (app/src/main/java/com/thecode/infotify/presentation/feed/FeedScreen.kt)
- Duplicated block (15 lines × 2) (app/src/main/java/com/thecode/infotify/presentation/feed/FeedViewModel.kt)
- Duplicated block (15 lines × 2) (app/src/main/java/com/thecode/infotify/presentation/settings/SettingsScreen.kt)
- Duplicated block (7 lines × 2) (app/src/main/java/com/thecode/infotify/presentation/feed/FeedViewModel.kt)
- Duplicated block (8 lines × 2) (app/src/main/java/com/thecode/infotify/data/local/bookmark/BookmarkMapper.kt)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- No ADRs found
- No dependency advisory monitoring
- Secret: generic-api-key (app/src/main/java/com/thecode/infotify/utils/AppConstants.kt)
- Secret: generic-api-key (app/src/main/java/com/thecode/infotify/utils/AppConstants.kt)
- Small-team knowledge concentration
- Workflow token permissions not restricted
Changes since last survey
- 26 commits — 19 feature/other, 7 fixes
By area
- app/src — 8 commits
- (root) — 5 commits
- (repo) — 2 commits
- site/img — 2 commits
- .github/workflows — 1 commit
- .kotlin/sessions — 1 commit
- docs/ARCHITECTURE.md — 1 commit
- playstore/README.md — 1 commit
- playstore/captures — 1 commit
- playstore/feature-graphic-1024x500.png — 1 commit
- playstore/listing.md — 1 commit
- server/.gitignore — 1 commit
- server/test_proxy.py — 1 commit
Notable commits
- fix: fix(playstore): actually commit the captures the generator reads
- fix: fix(site): favicons, undistorted screenshots, and list cards that drop a dead thumbnail
- fix: fix(site): the stretch was a declared aspect-ratio, plus a phone frame
- fix: fix: drop the Terms link from About — the page cannot exist
- fix: fix: splash invisible in dark, onboarding under the navigation bar
- fix: fix: update infotify website/playstore assets and fix images ratio
- fix: fix: wordmark dot placement and cards that survive a failed image
- change: Merge pull request #16 from gabriel-TheCode/main
- change: Merge: NewsData.io proxy, Compose rewrite, interests and daily briefing
- change: build: AGP 9, KSP, a version catalog, and no unused dependencies
- change: build: enable R8 and verify the minified build actually runs
- change: chore: drop declared-but-unused dependencies
- change: chore: untrack a per-developer IDE file, and stop ignoring playstore/captures
- change: ci: build on main, and stop injecting a key the build no longer reads
- change: docs(playstore): listing copy for both locales, checked against the code
- change: docs: add architecture reference
- change: docs: point the README screenshots at the generated Play Store tiles
- change: docs: rewrite the README and architecture notes for what the app now is
- change: feat(playstore): a full listing asset set, generated from real captures
- change: feat(server): add caching news proxy at infotify.nativia.co
- …and 6 more
Architecture
- Containers 0 added · 0 removed · contexts 1 added · 0 removed · edges 0 added · 0 removed
Added bounded contexts (1)
- app
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
gabriel-TheCode/Infotify was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit e1a0a51c7e0a8d4814447cf812a1667c125eba4c — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.