Skip to content
CAI
Software that uses CAICheck a score

KrishKrosh/TrackWeight

44.5

Weak · 27 September 2026

1.3k

lines of production code

Swift

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Added scripts to automate code signing, notarization, and local build testing

The repository now includes helper scripts to streamline the macOS build process. The new \scripts/setup-signing.sh\ script guides users through exporting their Apple Developer ID Application certificate and encoding it for GitHub Secrets, while also providing instructions for adding Apple ID, password, and Team ID secrets required for automated notarization. Additionally, \scripts/test-build-locally.sh\ allows developers to locally reproduce the GitHub Actions workflow, including building a universal binary (arm64 and x86\_64), performing code signing, verifying binary architectures, and optionally running the notarization step. A \scripts/README.md\ documents the purpose and usage of these scripts.

scripts · high confidence

New Settings page and device selection for trackpad input

A new Settings view has been added to the app, allowing users to select which trackpad device to use for input. This replaces the previous Debug tab with a dedicated Settings tab. The ContentViewModel now manages a list of available devices and the currently selected device, enabling multi-device support. Additionally, the entitlements file has been updated to include permissions for USB and serial device access, which are required for trackpad communication.

TrackWeight · high confidence

Behavioural changes

Add MIT license and update installation instructions

The repository now includes an MIT license file, clarifying the software's usage rights. Additionally, the README has been updated to provide clearer installation instructions, including options for downloading a DMG, using Homebrew, or building from source, and references to the Open Multi-Touch Support library have been updated to point to the project's custom fork.

(repo-wide) · high confidence

Removed local OpenMT bridge classes

The local OpenMT bridge classes, specifically OMSManager and OMSTouchData, have been removed from the Sources directory. This indicates a shift away from the previous local implementation, likely in favor of a remote or external package for handling multitouch support.

Sources · high confidence

Updated OpenMultitouchSupport dependency and added SettingsView

The project now references the OpenMultitouchSupport framework via a remote Swift package (https://github.com/KrishKrosh/OpenMultitouchSupport.git) instead of a local path, and includes the new SettingsView in the build and framework dependencies. Additionally, the macOS deployment target has been lowered from 13.5/14.6 to 13.0 across build configurations.

TrackWeight.xcodeproj · medium confidence

Dependencies

Migrated to remote Swift Package Manager for OpenMultitouchSupport

The project has switched from a local binary target to a remote Swift Package Manager dependency for OpenMultitouchSupport, resolving the dependency via GitHub revision fb6991fa1ece8c5faa8eef49190beb2baf071694 on the main branch. This change updates how the OpenMultitouchSupport framework is fetched and integrated into the build.

(dependencies) · medium confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 37 → 45 (+7.7)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 98 (-2.2)
  • Architecture 69 (new)
  • Maturity 40 → 50 (+10.7)
  • Readiness 22 → 30 (+8.2)
  • Security 45 → 51 (+5.9)

Resolved (11)

  • Dimension evaluation failed
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No artifact signing
  • No exposed public API
  • early-stage repository — too few commits for a meaningful bus factor
  • early-stage repository — too little history to judge knowledge freshness
  • git history depth insufficient

New (19)

  • Dependency hygiene PARTLY measured — SwiftPM pinning read, dependency currency NOT established
  • Floating branch dependency: openmultitouchsupport
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No ADRs found
  • Secret passed as a command-line argument
  • WeighingViewModel.processTouchData (cognitive 39) (TrackWeight/WeighingViewModel.swift)
  • WeighingViewModel.processTouchData (cyclomatic 22) (TrackWeight/WeighingViewModel.swift)
  • Workflow token permissions not restricted

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

KrishKrosh/TrackWeight was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit e322cae241d29afbee2860a6b585e9fe3974bd0c — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d00c643c3f66.