Skip to content
CAI
Software that uses CAICheck a score

guardian/prout

44.8

Weak · 6 October 2026

1.7k

lines of production code

Scala

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

Prout is a deployment monitoring service that tracks pull request merges against external deployment checkpoints to verify release status. It authenticates via GitHub Apps, parses repository configurations to identify deployment targets, and updates GitHub labels and comments based on checkpoint visibility. The system integrates with Sentry for error tracking and provides a web interface for users to inspect repository configuration and deployment health.

Features

Added Sentry error logging integration

The application now integrates Sentry for error tracking. A new SentryLogging component initializes a Logback appender that sends ERROR-level logs to Sentry, tagging them with the current git commit ID. If no Sentry DSN is configured, the system logs a warning and continues without sending errors, allowing for safe operation in development environments.

app/monitoring · high confidence

Introduce checkpoint-based deployment verification with custom reporting

The application now supports verifying deployments against external 'checkpoints' (HTTP endpoints) by reading \.prout.json\ configuration files from any folder in the repository. When a pull request is merged, the system checks if its commits are visible at these configured URLs, updating GitHub labels (Seen, Pending, Overdue) and posting comments accordingly. This change also adds support for custom checkpoint messages, integration with Sentry for release tracking, and reporting deployments to Slack and Librato.

app/lib · high confidence

Removals

Removal of overdue and seen pull request status views

The template files for displaying pull request status updates—specifically the 'overdue' and 'seen' views—have been removed from the application. Users will no longer see the specific messages indicating that a pull request is overdue or has been seen on a site, as these UI components are no longer present in the codebase.

app/views/ghIssues · high confidence

Behavioural changes

Configuration overhaul and logging setup

The application now uses a dedicated Logback configuration (conf/logback.xml) for structured logging, replacing the previous inline logger settings. Application secrets and sensitive credentials (GitHub, Sentry, Librato) are now sourced from environment variables rather than being hardcoded in application.conf. Additionally, the routes file has been reorganized to separate API endpoints (such as GitHub hooks and repo updates) from user-facing pages, and the secret key mechanism was updated to support Play's standard session/CSRF signing.

conf · high confidence

New Play application entry point and configuration structure

The application now uses a custom AppLoader and ApplicationComponents to initialize the Play framework, replacing the previous startup mechanism. This change introduces a ReasonableHttpFilters trait that configures CSRF and security headers while removing the hosts filter, allowing the service to run correctly on dynamically assigned hosts such as autoscaled EC2 instances. The ApplicationComponents class wires up core services including GitHub authentication, Sentry logging, and repository update schedulers, establishing the new foundation for the application's runtime behavior.

app/configuration · high confidence

Prout now requires GitHub App authentication and runs on Java 21

Prout has migrated from using a personal GitHub user account to authenticating as a GitHub App, requiring new environment variables (PROUT\_GITHUB\_APP\_PRIVATE\_KEY, PROUT\_GITHUB\_APP\_CLIENT\_ID, PROUT\_GITHUB\_APP\_CLIENT\_SECRET) instead of the previous access token. This change is accompanied by a runtime upgrade from Java 1.7 to Java 21 (via .tool-versions and system.properties), the removal of Travis CI in favor of other build systems, and the introduction of a new .prout.json configuration format for defining deployment checkpoints. Additionally, Sentry release tracking has been added to the default configuration.

(repo-wide) · high confidence

Rebrand to 'prout' and introduce a new repository configuration overview page

The product has been rebranded from 'pr:guardian' to 'prout', with the index page now providing a clear explanation of its purpose as a deployment tracking bot and a four-step setup guide for users. Additionally, a new repository view (repo.scala.html) has been added, allowing users to inspect their repository's configuration status, including permission checks, validation of .prout.json files, checkpoint deployment status, and merged pull request details.

app/views/userPages · high confidence

The application has been rebranded from 'pr:guardian' to 'prout - pull request deployment monitor', with the page title and navbar brand updated accordingly. The footer now links to the new GitHub repository (guardian/prout) and includes a link to a Guardian blog post about Prout, while removing the link to the BFG repo cleaner. Additionally, a hidden comment containing the git commit ID is added to the page for internal tracking.

app/views · high confidence

Refactored controller architecture and introduced API-specific handling

The controller layer has been restructured to separate concerns: a new Api controller now handles GitHub webhooks and scan requests with specific caching and rate-limiting logic, while a dedicated Auth controller manages authentication. The legacy Application controller has been converted to a class-based structure, integrating with the new RepoAcceptListService for repository validation and adding a diagnostic endpoint that exposes repository configuration status. Additionally, base controller infrastructure (BaseAppController, ControllerAppComponents) has been standardized to support dependency injection and consistent request handling across the application.

app/controllers · high confidence

Removal of Global.scala application settings

The Global.scala file, which previously defined the application's global settings and applied the CSRF filter via WithFilters, has been removed. This change eliminates the legacy Play 2.x GlobalSettings configuration pattern, indicating a shift in how application lifecycle events and global filters are managed within the codebase.

app · high confidence

Test coverage

Added functional tests for PR lifecycle and configuration handling; Added unit and integration tests for lib components.

Dependencies

Upgrade to Scala 3 and modernize dependency stack

The project has been upgraded from Scala 2.11 to Scala 3.3.6, requiring a significant overhaul of the dependency tree. Key library updates include migrating from the legacy \github-api\ and \okhttp\ clients to \play-git-hub\ (v9.0.1), updating \cats-core\ to 2.13.0, \scaffeine\ to 5.3.0, and \nscala-time\ to 3.0.0. The build also introduces \BuildInfoPlugin\ to inject the git commit ID into the application, adds Sentry logging via \raven-logback\, and explicitly overrides transient dependencies for \jackson-core\, \jackson-databind\, and \jquery\ to address security vulnerabilities.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 44 → 45 (+0.4)
  • Rubric changed (rubric-2026.09.15 → rubric-2026.10.1) — scores are not directly comparable.

Lenses

  • Code Health 34 → 32 (-2.1)
  • Architecture 74 → 92 (+18.2)
  • Maturity 55 → 55 (+0.0)
  • Readiness 55 → 54 (-0.3)
  • Security 97 → 76 (-20.7)
  • Accessibility 44 → 46 (+2.8)
  • Performance 100 (new)

Resolved (2)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)

New (8)

  • High CVE: [GHSA redacted] (build.sbt)
  • Outdated: ch.qos.logback:logback-classic
  • Outdated: com.fasterxml.jackson.core:jackson-databind
  • Outdated: com.github.nscala-time:nscala-time_3
  • Outdated: com.madgag.play-git-hub:core_3
  • Outdated: com.typesafe.scala-logging:scala-logging_3
  • Outdated: org.webjars:bootstrap
  • Outdated: org.webjars:jquery

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

guardian/prout was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 6 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 19f882a1a1c8015784ac643ef81c31b846e5a299 — the exact code this score is about.
  • Scored under rubric-2026.10.1 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-1f9c535fa862.