mas-cli/mas
68.1
Adequate · 27 September 2026
3.5k
lines of production code
Swift
with C
4
measurements over time
What this system is
This system is a command-line interface tool for managing the Mac App Store, enabling users to search for, install, update, and uninstall applications. It provides structured output options, including JSON, and supports shell auto-completion for enhanced usability. The tool handles app identification via both bundle and ADAM IDs, manages privileged operations securely, and maintains compatibility with modern macOS versions through rigorous code quality standards and testing.
How it got here
2015–2021 — Tooling standardization and Swift 6 migration
5 changes.
The project modernized its development infrastructure by removing legacy Xcode project files and standardizing code quality tooling, including SwiftLint and SwiftFormat. It upgraded to Swift 6.2 with a macOS 13 minimum requirement and refreshed dependencies to ensure compatibility with new language features. Additionally, shell completion scripts were added for Bash and Fish to improve the user experience.
2024–2025 — CLI modernization and async migration
8 changes.
The project modernized its command-line interface by rewriting commands in Swift with async support and restructuring option groups for better usability. This period also included significant infrastructure updates, such as migrating build scripts to zsh, adding a build tool plugin for metadata generation, and updating private framework headers to match current Apple APIs.
2026 — utility refactoring and test coverage
7 changes.
This period focused on refactoring core utilities to improve code safety, concurrency, and testability, including the introduction of a structured Printer, thread-safe process execution, and robust version comparison logic. Comprehensive test coverage was added for CLI commands and testing infrastructure to ensure reliability across these changes.
Features
Add shell completion scripts for Bash and Fish
Users can now enable command-line auto-completion for the \mas\ tool in both Bash and Fish shells. The new \contrib/completion/mas.bash\ and \contrib/completion/mas.fish\ files provide completions for subcommands (such as \install\, \search\, \list\, \lookup\, and \outdated\) and their associated flags (like \--json\, \--force\, and \--verbose\). The Fish script also offers dynamic completions for app IDs by querying the App Store or local installation lists, improving the interactive experience for shell users.
contrib · high confidence
Introduce structured Printer utility for formatted output
A new \Printer\ struct has been added to \Sources/mas/Utilities/Output\ to handle console output with ANSI color support and structured formatting. This component provides dedicated methods for informational, notice, warning, and error messages, automatically applying appropriate prefixes and colors when connected to a terminal, and includes an atomic error counter to track failure counts across operations.
Sources/mas/Utilities/Output · high confidence
New build tool plugin to generate build information
A new Swift build tool plugin (MASBuildToolPlugin) has been added to the project. When building the package, this plugin automatically runs a prebuild script to generate the MAS+BuildInformation.swift file, ensuring that build-time metadata is available to the application without manual intervention.
Plugins/MASBuildToolPlugin · high confidence
Removals
Remove Xcode project and workspace files
The \mas-cli.xcodeproj\ directory, including the \project.pbxproj\ project file and the \project.xcworkspace\ workspace configuration, has been deleted from the repository. This change removes the legacy Xcode build configuration, indicating a shift away from Xcode-native project management for this location.
mas-cli.xcodeproj · high confidence
Behavioural changes
Command-line interface commands rewritten in Swift with async support
The \mas\ command-line interface commands (Config, Get, Home, Install, List, Lookup, Lucky, Open, Outdated, Reset, Search, Seller, SignOut, Uninstall, Update, Version) have been rewritten in Swift using the ArgumentParser framework. This change introduces asynchronous execution for most commands (e.g., Search, Lookup, Home, Seller, Open, Get, Install, Update, Uninstall, Lucky) to improve responsiveness, particularly for network operations like searching and installing apps. The command structure is now defined via Swift structs conforming to \AsyncParsableCommand\ or \ParsableCommand\, replacing previous implementations. The \Lookup\ command is now the primary command for retrieving app information, with \info\ retained as an alias. The \Update\ command retains \upgrade\ as an alias. The \Seller\ command retains \vendor\ as an alias. The \Get\ command retains \purchase\ as an alias. The \SignOut\ command is now explicitly named \signout\. The \Uninstall\ command now supports a \--dry-run\ flag and uses \sudo\ for moving apps to the trash. The \Reset\ command now terminates App Store-related processes and clears the download folder. The \Config\ command outputs detailed system and mas configuration information. The main entry point (\MAS.swift\) now handles async command execution and root privilege dropping.
Sources/mas/Commands · high confidence
Introduces Environment abstraction and URL utility extensions
This change introduces a new \Environment\ struct to centralize configuration for iTunes Store lookups and searches, replacing direct dependencies with injectable closures for better testability and flexibility. Additionally, it adds utility extensions to \URL\ that provide a \filePath\ property for reliable path resolution, convenience initializers for folder paths, and an asynchronous \open\ method that returns the \NSRunningApplication\ instance, simplifying app launching workflows.
Sources/mas/Utilities/Resources · high confidence
New utility extensions and internal JSON parsing support
This update introduces a suite of new Swift standard-library extensions to improve code safety, concurrency, and performance, alongside new internal infrastructure for JSON handling. Key additions include a thread-safe \Lazy\ property wrapper, \concurrentMap\ and \concurrentCompactMap\ methods for \Collection\ to enable safe parallel processing, and a \priorityMerge\ function for \Sequence\ to combine results based on relevance scores. String utilities have been enhanced with a \similarity(to:)\ method using an optimized Damerau-Levenshtein algorithm, an \uppercasingFirst\ property, and \padding\ support for collections. Additionally, a new \Required\ property wrapper enforces non-nil values with custom error messages, and internal \JSON.Object\ subscripting is added to support optional JSON output for commands like \config\, \list\, and \search\.
Sources/mas/Utilities/Swift · high confidence
Refactored command-line option groups and added new flags for outdated checks
The \mas\ tool's command-line interface has been restructured by consolidating options into dedicated \OptionGroup\ structs (such as \CatalogAppsOptionGroup\, \ForceOptionGroup\, and \OutdatedAppsOptionGroup\). This change introduces new flags for the \outdated\ and \update\ commands: \--check-min-os\ (defaulting to enabled) to verify macOS version compatibility before reporting updates, and \--verbose\ to warn about app IDs unknown to the App Store. The previous \--accurate-ignore-unknown-apps\ flag has been removed. Additionally, a new \--bundle\ flag allows users to force the interpretation of app IDs as bundle IDs, and the internal logic for detecting outdated apps now uses \OSAllocatedUnfairLock\ for thread safety.
Sources/mas/Commands/OptionGroups · high confidence
Refactored privilege management and subprocess execution
The application now executes privileged commands in external processes using the Subprocess library, improving stability and security. User and group identity resolution has been updated to use thread-safe functions (\getpwuid\_r\ and \getgrgid\_r\), and privilege dropping logic has been refined to correctly handle \sudo\ environment variables when elevating or demoting permissions.
Sources/mas/Utilities/Processes · high confidence
Refactored version comparison logic to fix UniversalSemVer behavior
The version comparison utilities in \Sources/mas/Utilities/Versions\ have been refactored to correct \UniversalSemVer\ comparisons. This change decomposes the previous implementation into new modular protocols (\CoreIntegerVersion\, \MajorMinorPatch\, \SemVerSyntax\) and introduces \UniversalSemVer\ and \UniversalSemVerInt\ structs that conform to \ExpressibleByStringLiteral\. Users will benefit from more robust and accurate semantic version parsing and comparison, particularly for complex version strings involving major, minor, patch, prerelease, and build metadata.
Sources/mas/Utilities/Versions · high confidence
Removal of the main entry point file
The \main.swift\ file, which previously served as the application's entry point and printed a "Hello, World!" message, has been deleted from the mas-cli project. This change removes the default startup code, indicating that the application's entry logic has been moved or restructured elsewhere in the codebase.
mas-cli · high confidence
Scripts directory restructured and rewritten in zsh
The project's build and maintenance scripts have been completely rewritten in zsh and reorganized into a new \Scripts/\ directory. This change introduces a shared setup script (\\_setup\_script\) to standardize environment configuration and utility functions like \print\_notice\ and \ensure\_command\available\ across all scripts. Key operational scripts such as \bootstrap\, \build\, \lint\, \format\, \test\, and \package\ have been updated to use this new structure, with \lint\ and \format\ now utilizing \\\\\ globs to traverse symlinked folders and \package\ generating separate installers per architecture. The \mas\ wrapper script has also been enhanced to support optional JSON output formatting for commands like \list\, \lookup\, and \config\.
Scripts · high confidence
Standardize development environment and code quality tooling
The project now enforces consistent coding standards and development workflows through a comprehensive set of configuration files. EditorConfig, .gitattributes, and .gitignore are introduced to standardize line endings, whitespace, and build artifacts. Code quality is managed via SwiftFormat 0.62.1, SwiftLint 0.65.0, markdownlint-cli2 0.23.2, yamllint 1.38.0, and periphery 3.8.0, with specific rules enabled for Swift 6.3 compatibility and stricter linting. The minimum supported macOS version is explicitly set to 13 Ventura in both the deployment target and documentation, and the project is declared as a Swift Package with a Brewfile specifying required Homebrew dependencies.
(repo-wide) · high confidence
Support for bundle IDs alongside ADAM IDs in app identification
The app identification model now accepts both ADAM IDs and bundle IDs. The \AppID\ enum distinguishes between the two, and the \InstalledApp.matches(\_:)\ method checks against either identifier. This change allows the tool to identify and manage apps using their bundle identifiers, improving compatibility and future support for iOS and iPadOS apps.
Sources/mas/Models · high confidence
Updated private framework headers for CommerceKit and StoreFoundation
The private framework headers in Sources/PrivateFrameworks have been regenerated using ipsw version 3.1.707, updating the declarations for CommerceKit and StoreFoundation. This includes new or refreshed interface definitions for classes such as CKDownloadQueue, CKPurchaseController, ISStoreAccount, and SSDownload, reflecting the current API surface of these Apple frameworks. The update also adds a C source file to ensure proper compilation and updates module maps for the new headers.
Sources/PrivateFrameworks · high confidence
Test coverage
Added serialized test suite for MAS; Added test coverage for MAS CLI commands; Added test utilities for stream capture and resource decoding; Added tests for CatalogApp and CatalogAppResults parsing.
Dependencies
Swift 6.2 upgrade and dependency refresh
The project has been upgraded to Swift 6.2 (language mode 6) and sets the minimum deployment target to macOS 13 Ventura. This update refreshes the dependency graph, pinning packages such as SwiftSoup to 2.13.7, Swift Argument Parser to 1.8.2, and Swift Collections to 1.6.0, while enabling several upcoming Swift features like ExistentialAny and MemberImportVisibility to ensure compatibility with the new language version.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 49 → 68 (+19.2)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 91 (-8.8)
- Architecture 87 (new)
- Maturity 55 → 59 (+3.6)
- Readiness 33 → 70 (+36.8)
- Security 61 → 77 (+15.9)
Resolved (7)
- Dimension evaluation failed
- High: security finding (details withheld)
- No automated tests
- No exposed public API
- No tests found
- Rotate the exposed credentials — git history can't be un-committed
- Test reliability not included
New (30)
- AppStoreAction.app (cognitive 70) (Sources/mas/Models/AppStoreAction.swift)
- AppStoreAction.app (cyclomatic 25) (Sources/mas/Models/AppStoreAction.swift)
- Change coupling: MAS.Get.swift ↔ MAS.Update.swift (Sources/mas/Commands/MAS.Get.swift)
- Coverage not measured — Swift suite
- Documentation: no project overview (README.md)
- Duplicated block (13 lines × 2) (Sources/mas/Utilities/Swift/Collection.swift)
- Duplicated block (16 lines × 2) (Sources/mas/Models/CatalogApp.swift)
- Duplicated block (5 lines × 2) (Sources/mas/Utilities/Processes/Group.swift)
- Duplicated block (6 lines × 2) (Sources/mas/Models/CatalogApp.swift)
- Duplicated block (7 lines × 2) (Sources/mas/Models/CatalogApp.swift)
- Duplicated block (9 lines × 2) (Sources/mas/Models/CatalogApp.swift)
- Hotspot: Sources/mas/Commands/OptionGroups/OutdatedAppsOptionGroup.swift (Sources/mas/Commands/OptionGroups/OutdatedAppsOptionGroup.swift)
- Hotspot: Sources/mas/Models/AppStoreAction.swift (Sources/mas/Models/AppStoreAction.swift)
- Hotspot: Sources/mas/Models/CatalogApp.swift (Sources/mas/Models/CatalogApp.swift)
- Job token omits the contents scope its checkout needs
- Key.normalized (cognitive 23) (Sources/mas/Models/CatalogApp.swift)
- Key.normalized (cyclomatic 52) (Sources/mas/Models/CatalogApp.swift)
- Low cohesion: String (LCOM4 6) (Sources/mas/Utilities/Output/Printer.swift)
- MethodTooLong: AppStoreAction.app (Sources/mas/Models/AppStoreAction.swift)
- MethodTooLong: Key.normalized (Sources/mas/Models/CatalogApp.swift)
- …and 10 more
Changes since last survey
- 14 commits — 14 feature/other, 0 fixes
By area
- Sources/mas — 7 commits
- (root) — 4 commits
- (repo) — 2 commits
- Sources/PrivateFrameworks — 1 commit
Notable commits
- change: Elide local constant, map(…) & compactMap(…) calls.
- change: Improve String.similarity(to:) performance.
- change: Lazier OutdatedApp.lazyJSON.
- change: Make some SAP properties private(set).
- change: Merge pull request #1297 from rgoldberg/1296-7.1.0
- change: Merge pull request #1312 from phorcys420-contrib/phorcys/nixpkgs-reference
- change: Refactor code to be functional.
- change: Reformat.
- change: Standardize error messages.
- change: Transpose editorconfig & markdownlint ignore comments.
- change: Update README.md
- change: Update AGENTS.md. Remove GEMINI.md.
- change: Update dependencies.
- change: chore: add nixpkgs to README
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
mas-cli/mas was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 6c5032dc8da74668c407b76d02463eea20b732a5 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-d00c643c3f66.