Skip to content
CAI
Software that uses CAICheck a score

jpochyla/psst

59.1

Adequate · 29 September 2026

19.9k

lines of production code

Rust

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Psst is a cross-platform Spotify client for Linux, macOS, and Windows that provides a graphical interface and a command-line tool for streaming audio. It handles user authentication, playback of streamed tracks and local files, and podcast episodes, while supporting features like lyrics, track credits, and Last.fm scrobbling. The system manages audio decoding and output through configurable backends and integrates with Spotify's web API for content discovery and metadata.

How it got here

2020 — Core and GUI architecture overhaul

8 changes.

This period focused on a comprehensive restructuring of the project's core library and GUI, introducing a new actor model, modernized authentication flows, and a streamlined audio pipeline. The GUI was significantly refactored to support richer content views, including credits, lyrics, and podcasts, while adopting a new data layer and widget system. These changes were underpinned by a major dependency overhaul, including a switch to Rust 2021 and updated backend libraries.

2021–2025 — Core architecture and packaging overhaul

12 changes.

This period focused on a comprehensive rewrite of the core audio and player subsystems, introducing support for local files, podcasts, and multiple audio backends. It also established robust packaging infrastructure for Linux, macOS, and Windows, alongside significant refactoring of the GUI controller and web API layers to improve modularity and user experience.

Features

Add credits, lyrics, and podcast show/episode views

The UI now supports viewing detailed track credits (roles, artists, and sources), displaying synchronized lyrics for the currently playing track, and browsing podcast content with dedicated pages for show details and episode lists. These new views are integrated into the main navigation and home page sections, allowing users to access richer metadata and audio content directly within the application.

psst-gui/src/ui · high confidence

Added packaging metadata for Linux desktop integration

The Linux packaging structure now includes a standard desktop entry file and a copyright file. The desktop file configures the application to appear in system menus under the Audio/Music categories, sets the executable to psst-gui, and registers the psst URI scheme, while the copyright file formally documents the MIT license and upstream source information for Debian-compliant distribution.

.pkg · high confidence

Automated Homebrew Cask generation for Psst

A new shell script has been added to automatically generate the Homebrew cask definition for the Psst application. This script produces a cask that installs the latest release from the project's GitHub releases page, sets the minimum macOS requirement to Big Sur, and configures the application bundle and cleanup paths, streamlining the maintenance of the Homebrew installation method.

.homebrew · high confidence

Automated platform-specific icon generation for Windows and macOS

The application now automatically generates and embeds native icons during the build process. A new build script handles macOS .icns creation from SVG assets, while a Rust build script generates Windows .ico files and attaches them to the executable, ensuring proper branding on both platforms without manual intervention.

psst-gui · high confidence

Build script captures build time and remote repository URL

The psst-core crate now includes a build script that generates metadata files during compilation. Specifically, it records the local build timestamp and the remote Git repository URL (normalizing SSH-style URLs to HTTPS) into the build output directory, making this information available for runtime inspection or debugging.

psst-core · high confidence

Initial Debian package metadata added

A new DEBIAN control file has been added to define the packaging metadata for the psst-gui application. This establishes the package name, versioning, architecture, and maintainer information, while explicitly declaring runtime dependencies on libssl3 (or libssl1.1), libgtk-3-0, and libcairo2.

.pkg/DEBIAN · high confidence

New UI widget library and icon system

The \psst-gui/src/widget\ module has been introduced, providing a comprehensive set of new UI components and utilities. This includes a \Checkbox\ widget, a \Link\ widget for styled navigation, and layout helpers like \FillBetween\ and \Overlay\. The module also introduces an \Async\ widget for handling deferred, resolved, and rejected promise states, a \ThemeScope\ for applying theme data, and a collection of SF Symbols-based SVG icons (such as \PLAY\, \PAUSE\, \SKIP\_BACK\, \HOME\, and \PODCAST\) to standardize the visual appearance of the interface.

psst-gui/src/widget · high confidence

New WebAPI client with caching and local file support

The webapi module has been rewritten to use the \ureq\ HTTP library instead of the previous async stack, introducing a new \WebApi\ client that manages authentication via OAuth2 and first-party Login5 tokens for partner endpoints. This change adds a \WebApiCache\ component to persist and cache album art images to disk and in memory, and introduces a \LocalTrackManager\ to parse Spotify's local-files.bnk index, enabling the application to discover and play local audio files alongside streaming content.

psst-gui/src/webapi · high confidence

New application icon added

The application now includes a new SVG logo asset (logo.svg) which serves as the primary icon for the GUI. This change updates the visual identity of the application across platforms that utilize this asset.

psst-gui/assets · high confidence

New audio player architecture with local file and podcast support

The player module has been completely rewritten to support a new playback pipeline. This update introduces the ability to play local audio files (MP3 and Ogg Vorbis) alongside streamed tracks, and adds support for playing podcast episodes. The new architecture also includes a reworked queue system with shuffle and loop behaviors, and an optimized streaming storage layer that removes 4-byte alignment requirements for chunk fetching.

psst-core/src/player · high confidence

New data model and state management for the GUI

The application introduces a comprehensive new data layer in \psst-gui/src/data\ to support richer content and improved state handling. This includes new data structures for Albums, Artists, Playlists, Shows, and Tracks, enabling features like artist overviews, album details, and podcast playback. A new \AppState\ centralizes application state, managing navigation history, playback context, and user preferences. The update also adds a \Promise\ type for handling asynchronous operations, a \Finder\ for in-content search, and configuration options for themes, cache, and Last.fm integration.

psst-gui/src/data · high confidence

Optional Cubeb audio backend added alongside existing CPAL support

The audio output module now supports an optional Cubeb backend, providing an alternative to the existing CPAL implementation. Users can choose the audio backend via feature flags, with Cubeb taking precedence as the default when both are enabled. This addition introduces new source files for CPAL and Cubeb implementations, along with a module configuration that selects the default output based on available features.

psst-core/src/audio/output · high confidence

Behavioural changes

CLI now accepts track IDs via command-line arguments and environment variables

The psst-cli entry point has been refactored to accept a track ID as the first command-line argument and retrieve Spotify credentials from the SPOTIFY\_USERNAME and SPOTIFY\_PASSWORD environment variables, replacing the previous hardcoded credentials and fixed track ID. This change also updates the underlying core components, switching from SessionHandle to SessionService, using ItemId instead of SpotifyId, and integrating audio normalization levels into playback items.

psst-cli · high confidence

Major GUI architecture overhaul and Web API integration

The GUI has been significantly refactored to improve performance and reliability. The internal command system has been renamed from \commands\ to \cmd\ and expanded to support new features like track credits, artwork viewing, and queue management. The application now uses a dedicated thread pool for image loading instead of blocking the main thread, and the error handling for Web API calls has been simplified. Additionally, the application now integrates a new \WebApi\ module that handles authentication, caching, and local track management, replacing the previous \aspotify\-based database layer. The main entry point now supports an account setup flow for new users and manages session state more robustly.

psst-gui/src · high confidence

Major core refactoring: new actor model, session service, and OAuth/Last.fm support

The core library has been significantly restructured to improve reliability and add new capabilities. A new \Actor\ trait and \ActorHandle\ system have been introduced to manage background tasks with configurable channel capacities and timeouts. Authentication has been modernized with a new \SessionService\ that manages the session lifecycle, alongside a new \Login5\ implementation for handling Spotify's login challenges and a \ClientTokenProvider\ for managing client tokens. OAuth flows now use PKCE and a dedicated callback listener for secure token exchange. Additionally, Last.fm scrobbling support has been added via a new \LastFmClient\ and OAuth integration. The old audio decoding and output infrastructure (using \lewton\ and \soundio\) has been removed in favor of a new, streamlined audio pipeline.

psst-core/src · high confidence

New audio decoding, resampling, and normalization pipeline

The audio subsystem has been restructured to support MP3 and Ogg Vorbis playback via the Symphonia library, replacing the previous decoder implementation. This change introduces a new modular pipeline in \psst-core/src/audio\ that includes format probing, MP3/Vorbis decoding, sample-rate resampling (using libsamplerate), and ReplayGain normalization. Additionally, the audio decryption module has been refactored to use the \aes\ and \ctr\ crates instead of \aes-ctr\, and a new \StereoMappedSource\ ensures consistent stereo output regardless of the source channel count.

psst-core/src/audio · high confidence

Refactored GUI controller architecture with new utility widgets and improved input handling

The application's controller layer has been restructured to improve modularity and user experience. A new set of reusable Druid controllers has been introduced: \AfterDelay\ for deferred actions, \AlertCleanupController\ for periodic state maintenance, \ExClick\ for custom mouse interaction handling, \ExCursor\ for dynamic cursor changes, \ExScroll\ for configurable scroll scaling, \OnCommand\/\OnCommandAsync\ for command-driven updates, \OnDebounce\ for throttling input, and \OnUpdate\ for data-change reactions. Navigation is now managed by a dedicated \NavController\ that handles route transitions, back-button support (including mouse X1 buttons), and refresh actions (Ctrl+R). The \InputController\ has been moved from widgets to controllers and updated to support standard system shortcuts (Cmd/Ctrl+C/X/V) and Escape to resign focus. Additionally, \SortController\ enables user-configurable sorting of library items, and \SessionController\ manages the connection lifecycle and credential validation.

psst-gui/src/controller · high confidence

Refactored connection module with new authentication flow and access point resolution

The connection module has been refactored to support a new authentication flow, including the ability to store and use access tokens alongside username/password credentials. Access point resolution now returns a list of available points and supports proxy configuration, while the underlying Shannon codec has been renamed and updated to use modern Rust syntax. Additionally, Diffie-Hellman key generation has been updated to use the newer rand crate API.

psst-core/src/connection · high confidence

psst-protocol: Remove custom protobuf definitions and build script

The custom protobuf schema files (authentication, keyexchange, mercury, metadata, playlist, pubsub, spirc) and the build script used to generate Rust bindings from them have been removed from the psst-protocol crate. This change eliminates the local protocol definition and code generation step, aligning with the commit intent to replace these custom handlers with the librespot-protocol library.

psst-protocol · high confidence

Dependencies

Major dependency overhaul and workspace restructuring

The project has performed a comprehensive upgrade of its Rust dependencies, moving the entire workspace to the Rust 2021 edition and Cargo resolver v2. Key library updates include switching the HTTP client from reqwest to ureq (v3.0.11), replacing the custom protobuf implementation with librespot-protocol, and upgrading the Druid GUI framework to a custom 'psst' branch with WebP support. The audio backend was refactored from soundio to CPAL and Symphonia, and the cryptography stack was updated to use the aes and ctr crates. Additionally, the workspace structure was simplified by removing the standalone psst-protocol and psst-bin crates, consolidating functionality into psst-core and the new psst-cli crate.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 55 → 59 (+3.7)
  • Rubric changed (rubric-2026.09.8 → rubric-2026.09.17) — scores are not directly comparable.

Lenses

  • Code Health 93 → 93 (+0.0)
  • Architecture 100 → 86 (-13.8)
  • Maturity 52 → 52 (-0.1)
  • Readiness 57 → 58 (+1.4)
  • Security 43 → 54 (+11.5)
  • Event Sourcing 100 → 100 (+0.0)

Resolved (3)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Off-boarding risk: anonymized user #1

New (26)

  • Documentation: no contributor guidance (README.md)
  • Inconsistent naming for factory methods creating the same type. One uses 'from_...' with descriptive parameters, the other uses 'from_...' but implies a different construction path. More critically, compare with ItemId which has multiple 'from_...' variants (from_base16, from_base62, from_raw, from_uri, from_local). While distinct, the lack of a unified 'parse' or 'try_from' pattern across ID types is a minor stylistic inconsistency, but the real issue is below.
  • Medium advisory (unsound): RUSTSEC-2026-0306 (Cargo.lock)
  • Medium vulnerability: RUSTSEC-2026-0285 (Cargo.lock)
  • Off the main sequence: psst-core
  • Off-boarding risk: anonymized user #1
  • Outdated: crossbeam-channel
  • Outdated: data-encoding
  • Outdated: env_logger
  • Outdated: image
  • Outdated: log
  • Outdated: open
  • Outdated: parking_lot
  • Outdated: rangemap
  • Outdated: regex
  • Outdated: serde
  • Outdated: serde_json
  • Outdated: souvlaki
  • Outdated: tempfile
  • Outdated: time
  • …and 6 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

jpochyla/psst was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 29 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 3c3621aa79f820c737dd899e7e359b1359292466 — the exact code this score is about.
  • Scored under rubric-2026.09.17 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fbec9b1e08c2.