guardian/prout
44.8
Weak · 6 October 2026
1.7k
lines of production code
Scala
primary language
1
measurement over time
What this system is
Prout is a deployment monitoring service that tracks pull request merges against external deployment checkpoints to verify release status. It authenticates via GitHub Apps, parses repository configurations to identify deployment targets, and updates GitHub labels and comments based on checkpoint visibility. The system integrates with Sentry for error tracking and provides a web interface for users to inspect repository configuration and deployment health.
Features
Added Sentry error logging integration
The application now integrates Sentry for error tracking. A new SentryLogging component initializes a Logback appender that sends ERROR-level logs to Sentry, tagging them with the current git commit ID. If no Sentry DSN is configured, the system logs a warning and continues without sending errors, allowing for safe operation in development environments.
app/monitoring · high confidence
Introduce checkpoint-based deployment verification with custom reporting
The application now supports verifying deployments against external 'checkpoints' (HTTP endpoints) by reading \.prout.json\ configuration files from any folder in the repository. When a pull request is merged, the system checks if its commits are visible at these configured URLs, updating GitHub labels (Seen, Pending, Overdue) and posting comments accordingly. This change also adds support for custom checkpoint messages, integration with Sentry for release tracking, and reporting deployments to Slack and Librato.
app/lib · high confidence
Removals
Removal of overdue and seen pull request status views
The template files for displaying pull request status updates—specifically the 'overdue' and 'seen' views—have been removed from the application. Users will no longer see the specific messages indicating that a pull request is overdue or has been seen on a site, as these UI components are no longer present in the codebase.
app/views/ghIssues · high confidence
Behavioural changes
Configuration overhaul and logging setup
The application now uses a dedicated Logback configuration (conf/logback.xml) for structured logging, replacing the previous inline logger settings. Application secrets and sensitive credentials (GitHub, Sentry, Librato) are now sourced from environment variables rather than being hardcoded in application.conf. Additionally, the routes file has been reorganized to separate API endpoints (such as GitHub hooks and repo updates) from user-facing pages, and the secret key mechanism was updated to support Play's standard session/CSRF signing.
conf · high confidence
New Play application entry point and configuration structure
The application now uses a custom AppLoader and ApplicationComponents to initialize the Play framework, replacing the previous startup mechanism. This change introduces a ReasonableHttpFilters trait that configures CSRF and security headers while removing the hosts filter, allowing the service to run correctly on dynamically assigned hosts such as autoscaled EC2 instances. The ApplicationComponents class wires up core services including GitHub authentication, Sentry logging, and repository update schedulers, establishing the new foundation for the application's runtime behavior.
app/configuration · high confidence
Prout now requires GitHub App authentication and runs on Java 21
Prout has migrated from using a personal GitHub user account to authenticating as a GitHub App, requiring new environment variables (PROUT\_GITHUB\_APP\_PRIVATE\_KEY, PROUT\_GITHUB\_APP\_CLIENT\_ID, PROUT\_GITHUB\_APP\_CLIENT\_SECRET) instead of the previous access token. This change is accompanied by a runtime upgrade from Java 1.7 to Java 21 (via .tool-versions and system.properties), the removal of Travis CI in favor of other build systems, and the introduction of a new .prout.json configuration format for defining deployment checkpoints. Additionally, Sentry release tracking has been added to the default configuration.
(repo-wide) · high confidence
Rebrand to 'prout' and introduce a new repository configuration overview page
The product has been rebranded from 'pr:guardian' to 'prout', with the index page now providing a clear explanation of its purpose as a deployment tracking bot and a four-step setup guide for users. Additionally, a new repository view (repo.scala.html) has been added, allowing users to inspect their repository's configuration status, including permission checks, validation of .prout.json files, checkpoint deployment status, and merged pull request details.
app/views/userPages · high confidence
Rebrand to Prout and update footer links
The application has been rebranded from 'pr:guardian' to 'prout - pull request deployment monitor', with the page title and navbar brand updated accordingly. The footer now links to the new GitHub repository (guardian/prout) and includes a link to a Guardian blog post about Prout, while removing the link to the BFG repo cleaner. Additionally, a hidden comment containing the git commit ID is added to the page for internal tracking.
app/views · high confidence
Refactored controller architecture and introduced API-specific handling
The controller layer has been restructured to separate concerns: a new Api controller now handles GitHub webhooks and scan requests with specific caching and rate-limiting logic, while a dedicated Auth controller manages authentication. The legacy Application controller has been converted to a class-based structure, integrating with the new RepoAcceptListService for repository validation and adding a diagnostic endpoint that exposes repository configuration status. Additionally, base controller infrastructure (BaseAppController, ControllerAppComponents) has been standardized to support dependency injection and consistent request handling across the application.
app/controllers · high confidence
Removal of Global.scala application settings
The Global.scala file, which previously defined the application's global settings and applied the CSRF filter via WithFilters, has been removed. This change eliminates the legacy Play 2.x GlobalSettings configuration pattern, indicating a shift in how application lifecycle events and global filters are managed within the codebase.
app · high confidence
Test coverage
Added functional tests for PR lifecycle and configuration handling; Added unit and integration tests for lib components.
Dependencies
Upgrade to Scala 3 and modernize dependency stack
The project has been upgraded from Scala 2.11 to Scala 3.3.6, requiring a significant overhaul of the dependency tree. Key library updates include migrating from the legacy \github-api\ and \okhttp\ clients to \play-git-hub\ (v9.0.1), updating \cats-core\ to 2.13.0, \scaffeine\ to 5.3.0, and \nscala-time\ to 3.0.0. The build also introduces \BuildInfoPlugin\ to inject the git commit ID into the application, adds Sentry logging via \raven-logback\, and explicitly overrides transient dependencies for \jackson-core\, \jackson-databind\, and \jquery\ to address security vulnerabilities.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 44 → 45 (+0.4)
- Rubric changed (rubric-2026.09.15 → rubric-2026.10.1) — scores are not directly comparable.
Lenses
- Code Health 34 → 32 (-2.1)
- Architecture 74 → 92 (+18.2)
- Maturity 55 → 55 (+0.0)
- Readiness 55 → 54 (-0.3)
- Security 97 → 76 (-20.7)
- Accessibility 44 → 46 (+2.8)
- Performance 100 (new)
Resolved (2)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
New (8)
- High CVE: [GHSA redacted] (build.sbt)
- Outdated: ch.qos.logback:logback-classic
- Outdated: com.fasterxml.jackson.core:jackson-databind
- Outdated: com.github.nscala-time:nscala-time_3
- Outdated: com.madgag.play-git-hub:core_3
- Outdated: com.typesafe.scala-logging:scala-logging_3
- Outdated: org.webjars:bootstrap
- Outdated: org.webjars:jquery
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
guardian/prout was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 6 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 19f882a1a1c8015784ac643ef81c31b846e5a299 — the exact code this score is about.
- Scored under rubric-2026.10.1 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-1f9c535fa862.