maxgoedjen/secretive
63.2
Adequate · 27 September 2026
7.2k
lines of production code
Swift
primary language
4
measurements over time
What this system is
This system is a macOS-native SSH key management application that acts as a secure agent for cryptographic signing operations. It manages secrets stored in the macOS Keychain, Secure Enclave, and smart cards, exposing them via a standard SSH agent protocol to host applications. The architecture isolates sensitive parsing and network tasks into hardened, code-signed XPC services to ensure security and stability.
How it got here
2020–2022 — Open-source release and modular architecture
17 changes.
The project was opened to the public with comprehensive documentation and build configurations, while simultaneously restructuring its codebase into distinct Swift packages like SecretKit and SecretAgentKit. This period focused on enforcing strict concurrency, migrating to CryptoKit, and introducing modular XPC services to enhance security and maintainability.
2025 — UI overhaul and security hardening
11 changes.
This period focused on a comprehensive redesign of the user interface, introducing guided setup flows, certificate management, and a new main app layout with agent status controls. Concurrently, the codebase underwent significant security hardening by implementing strict code-signing enforcement for XPC communication and introducing a hardened updater service. These changes were supported by the development of reusable UI components and robust OpenSSH protocol parsing libraries.
2026 — SSH certificate management and security hardening
4 changes.
This period focused on introducing the CertificateKit package to handle SSH certificate storage, parsing, and migration via the macOS Keychain. It also enhanced security by migrating application settings to the Keychain and added formatting utilities for cryptographic data, alongside a project infrastructure update to the Xcode 27 JSON format.
Features
Add Xcode scheme and localization resources for SecretAgentKit
This change introduces the build scheme configuration for the SecretAgentKit package, enabling it to be built, tested, and launched within Xcode. Additionally, it adds the Localizable.xcstrings file containing the base localization structure and initial string entries for SecretAgentKit, supporting a wide range of languages including English, Portuguese (Brazil), Russian, and others, which prepares the package for internationalization.
Sources/Packages/Resources · high confidence
Added hex and base64 formatting styles for cryptographic data
Introduced new \FormatStyle\ conformances for converting binary data and cryptographic digests into human-readable strings. Users can now format \Data\, \MD5Digest\, and \SHA256Digest\ objects using customizable hex representations (with optional separators) and base64 representations (with optional padding stripping), simplifying the display of certificate and hash information in the UI.
Sources/Packages/Sources/Formatters · high confidence
Added preview assets and mock services for SwiftUI previews
New preview content files have been added to the Secretive target to support SwiftUI canvas previews. This includes a \PreviewAgentStatusChecker\ that mocks the agent launch controller, a \PreviewStore\ and \PreviewUpdater\ that provide mock implementations of the secret store and update logic, and a \Contents.json\ asset catalog. These changes enable developers to preview UI components without needing a live agent or real secrets.
Sources/Secretive/Preview Content · high confidence
Added type-erased wrappers for Secret and SecretStore
SecretKit now provides \AnySecret\ and \AnySecretStore\ type-erasers, allowing users to store and pass heterogeneous secret implementations and store instances through a unified, type-erased interface. These wrappers enable generic storage of secrets and stores without exposing their concrete types, while preserving access to core properties like ID, name, and public key, as well as operations such as signing, creating, deleting, and updating secrets.
Sources/Packages/Sources/SecretKit/Erasers · high confidence
Initial open-source release with documentation and build configuration
This release makes the project open source by adding comprehensive documentation (README, FAQ, CONTRIBUTING, SECURITY, CODE\_OF\_CONDUCT, LOCALIZING) and a build helper script (configure\_team\_id.sh) that allows users to generate an OpenSource.xcconfig file with their Apple Developer Team ID for local builds. The .gitignore is updated to exclude the generated configuration file and build artifacts.
(repo-wide) · high confidence
Introduces SecretKit type definitions and protocols for key management and signing
This change adds the foundational type definitions and protocols for the SecretKit package, enabling users to manage secrets and perform cryptographic operations. It defines the \Secret\ and \SecretStore\ protocols for accessing and modifying keys, including support for creating, deleting, and updating secrets with specific attributes like key type (ECDSA, RSA, MLDSA) and authentication requirements (biometric, password, or none). The update also introduces \SigningRequestProvenance\ to track the chain of processes requesting a signature and \SigningRequestTarget\ to distinguish between SSH connection and direct signature payloads, providing better context and security validation for signing operations.
Sources/Packages/Sources/SecretKit/Types · high confidence
Introduction of SecretKit package with keychain error handling and store management
This change introduces the SecretKit package, adding new files for keychain error handling (KeychainTypes.swift) and secret store management (SecretStoreList.swift). KeychainTypes.swift defines error types like KeychainError and SigningError, and provides a helper to map SecretType to SecKeyAlgorithm for signing operations. SecretStoreList.swift introduces an observable, main-actor class to manage a list of secret stores, including methods to add stores, track modifiable stores, and retrieve all secrets or secrets paired with their stores.
Sources/Packages/Sources/SecretKit · high confidence
New CertificateKit package for SSH certificate management
This change introduces the CertificateKit package, providing the core infrastructure for managing SSH certificates. It includes data models for certificates and OpenSSH certificate structures, a CertificateStore class that handles persisting, loading, and syncing certificates via the macOS Keychain, and a CertificateMigrator to import existing certificate files from the user's home directory. Additionally, an XPCCertificateParser is added to delegate certificate parsing to a background XPC service, ensuring the UI remains responsive during import operations.
Sources/Packages/Sources/CertificateKit · high confidence
New OpenSSH protocol parsing and serialization components
The SSHProtocolKit package now includes a suite of new types to handle OpenSSH-specific data formats. This adds an OpenSSHReader for parsing length-prefixed data chunks, and dedicated writers (OpenSSHPublicKeyWriter, OpenSSHCertificateWriter, OpenSSHSignatureWriter) to generate OpenSSH-style representations for public keys, certificates, and signatures, including SHA256 fingerprint generation. It also introduces an OpenSSHCertificateParser to decode OpenSSH certificate data into structured objects, and extends the SSHAgent protocol support with an SSHAgentInputParser to handle agent requests, including signature contexts and OpenSSH protocol extensions like session binding.
Sources/Packages/Sources/SSHProtocolKit · high confidence
New Smart Card secret store implementation
This change introduces a new \SmartCardStore\ and \SmartCard.Secret\ implementation within the \SmartCardSecretKit\ package, enabling the application to manage cryptographic secrets stored on smart card tokens. The store monitors for smart card insertion and removal events, automatically loading available secrets and exposing them through the standard \SecretStore\ API for signing operations.
Sources/Packages/Sources/SmartCardSecretKit · high confidence
New SwiftUI view modifiers and toolbar button styles
Added three new SwiftUI modifiers and styles to the application's view layer: \BoxBackgroundStyle\ for applying rounded, stroked backgrounds; \ErrorStyle\ for formatting error text in red callout font; and \ToolbarButtonStyle\ which provides a \PrimitiveButtonStyle\ for toolbar buttons that uses macOS 26's glass effect when available, falling back to a bordered style on earlier versions.
Sources/Secretive/Views/Modifiers · high confidence
New app interface with setup flow, agent status, and update management
The application now features a new main interface that guides users through an initial setup process and displays the status of the background agent. Users can view detailed agent information, including its location and version, and manage its lifecycle by starting, restarting, or disabling it directly from the UI. The interface also includes an 'About' screen with version details and contributor acknowledgments, an 'Updater' view to manage software updates, and a reusable 'Copyable' component that allows users to easily copy text or reveal file paths in Finder.
Sources/Secretive/Views/Views · high confidence
New certificate management interface and refined secret editing
The Secrets view now includes a dedicated interface for managing SSH certificates, allowing users to view certificate details (such as key ID, serial number, fingerprints, validity range, and principals) and rename or delete them via list context menus. The secret editing experience has been refined: the edit screen now supports updating the public key attribution alongside the name, and the creation flow exposes advanced options for selecting key types (including ML-DSA) and setting authentication requirements like biometry. Additionally, the main list view now displays a lock icon for secrets requiring authentication, and empty-state views provide clearer guidance for both modifiable and immutable stores.
Sources/Secretive/Views/Secrets · high confidence
New common UI components and shared configuration utilities
This update introduces a set of reusable SwiftUI view modifiers and views to the Common package, including \ActionButtonStyle\ (with variants for primary, toolbar circle, normal, and danger buttons), \MultilineInfoView\ for displaying structured lists with hover interactions, and helper views like \FixedTitleView\. It also adds shared configuration utilities: \BundleIDs.swift\ provides dynamic bundle identifier resolution for agent/host switching, and \URLs.swift\ defines standard paths for the SSH agent home, socket (with a separate debug socket for debug builds), public keys, and certificates, along with path normalization helpers.
Sources/Packages/Sources/Common · high confidence
New guided setup and integration configuration interface
The Configuration area now includes a new SetupView that guides users through installing the agent, confirming updates, and configuring integrations. A new IntegrationsView provides a structured list of supported tools (SSH, Git, shells like zsh/bash/fish) with detailed, copyable configuration instructions. Users can now copy SSH agent socket paths or Git allowed-signers entries directly to the clipboard and reveal configuration file locations in Finder, simplifying the process of connecting Secretive to other applications.
Sources/Secretive/Views/Configuration · high confidence
SecretiveUpdater introduced as a hardened XPC service for version checking
A new background XPC service (SecretiveUpdater) has been added to handle version checks against GitHub. This service is configured with strict hardened-process entitlements and an Internet Access Policy that explicitly permits TCP connections to api.github.com on port 443 for checking new versions and security updates. The implementation uses URLSession to fetch and decode release data, ensuring the updater runs with enhanced security constraints.
Sources/SecretiveUpdater · high confidence
Architecture
SecretAgent now uses dedicated XPC services for SSH parsing and hosts file reading
The SecretAgent helper process has been refactored to offload SSH input parsing and hosts file reading to separate, hardened XPC services (SecretAgentInputParser, SecretiveCertificateParser, and SecretAgentHostsfileReader). This architectural change isolates potentially untrusted OpenSSH data parsing from the main agent process, improving security and stability. The main agent now communicates with these services via XPC sessions to parse requests and read known\_hosts, while also introducing a new PendingRequestsView for managing batch authentication requests and a CertificateMigrator to handle legacy certificate imports.
Sources/SecretAgent · high confidence
Behavioural changes
Added build configuration and test plan for the Config module
The Config module now includes a dedicated xcconfig file to manage build settings, specifically defining CI versioning variables and allowing the bundle ID and development team to be overridden for Open Source builds. Additionally, a new test plan has been introduced to explicitly run tests for the BriefTests, SecretKitTests, and SecretAgentKit targets.
Sources/Config · high confidence
App relaunches agent after updates and applies enhanced security entitlements
The Secretive app now automatically relaunches its background agent after an update to ensure the latest code is running, while also respecting user-disabled states to prevent unwanted restarts. Additionally, the application now enforces enhanced security entitlements, including hardened process protections and Smart Card access, to improve the overall security posture of the key management system.
Sources/Secretive · high confidence
Migration to CryptoKit and support for MLDSA keys
The Secure Enclave implementation has been migrated from the legacy Security framework keychain API to Apple's CryptoKit, introducing a new migration path that automatically converts existing ECDSA keys to the new format while preserving compatibility with older versions. This change also adds support for MLDSA (Post-Quantum) key types (MLDSA65 and MLDSA87) on macOS 26.0 and later, allowing users to generate and use these newer algorithms alongside existing ECDSA keys.
Sources/Packages/Sources/SecureEnclaveSecretKit · high confidence
New XPC wrapper package with strict code-signing enforcement
A new \XPCWrappers\ package has been introduced, providing a typed, async/await-based interface for XPC communication that automatically handles JSON encoding/decoding and error serialization. In non-debug builds, the package enforces strict code-signing requirements on both the client and server sides, restricting connections to binaries signed with the specific Apple Developer ID 'Z72PRUAWF6'. This change replaces lower-level XPC handling with a safer, higher-level abstraction that ensures memory safety and restricts inter-process communication to trusted, signed executables.
Sources/Packages/Sources/XPCWrappers · high confidence
New agent launch and update-checking controllers
The application now uses dedicated controllers to manage the background agent lifecycle and detect recent updates. AgentStatusChecker handles installing, uninstalling, and force-launching the SecretAgent login item, including logic to identify the correct process instance and support for development builds. JustUpdatedChecker monitors user defaults to determine if the app or macOS has just been updated, allowing the UI to potentially show relevant notices. ApplicationDirectoryController provides a utility to check if the app is running from the Applications directory or Xcode.
Sources/Secretive/Controllers · high confidence
New modular update system with strict concurrency and semantic versioning
The Brief package has been restructured into a standalone Swift package, introducing a new \Updater\ class that manages application updates via XPC services. This change enforces Swift 6 strict concurrency by marking core types like \Release\ and \SemVer\ as \Sendable\ and \Hashable\. Users benefit from a more robust update mechanism that parses semantic versions, respects minimum OS version requirements, and prevents dismissal of critical security updates. The system also supports ignoring specific releases while maintaining a clean, protocol-based architecture for future extensibility.
Sources/Packages/Sources/Brief · high confidence
Project migrated to Xcode 27 JSON project format
The Secretive Xcode project file has been converted from the legacy XML-based format to the new JSON-based project format (Xcode 27). This change updates the underlying build system representation for the Secretive and SecretAgent targets, along with their associated resources, configurations, and localizations, ensuring compatibility with newer Xcode versions while preserving the existing project structure and file references.
Sources/Secretive.xcodeproj · high confidence
SecretAgentKit restructured into a new modular package with concurrency-safe agent and authentication logic
The SSH agent core has been moved into a new \SecretAgentKit\ package, introducing a concurrency-safe \Agent\ class that manages socket connections, identity listing, and signing requests. This update adds support for SSH certificates by including both keys and certificates in identity responses, and implements a new \AuthenticationHandler\ that supports persistent authentication contexts (time-based or request-ID-based) and handles concurrent signing requests via a pending-requests view. Socket communication is now managed by a \SocketController\ using \AsyncStream\ for session and message handling, and a \SigningRequestTracer\ provides detailed provenance (including app icons and signature validity) for incoming requests. Additionally, a \PublicKeyFileStoreController\ writes public keys and certificates to disk for script accessibility.
Sources/Packages/Sources/SecretAgentKit · high confidence
Settings storage migrated to macOS Keychain
The SettingsKit package now persists application settings in the macOS Keychain instead of UserDefaults. This change enhances security by leveraging the system keychain's protections against other-process modification and ensures settings are tied to device-only access when unlocked, providing stronger guarantees for sensitive configuration data.
Sources/Packages/Sources/SettingsKit · high confidence
Updated English localization strings for SecretAgent
The English localization strings for the SecretAgent application have been updated, including the main storyboard interface. This ensures that menu items, dialogs, and other UI elements display the correct English text for users.
Sources/SecretAgent/en.lproj · high confidence
Updated Xcode project schemes for Xcode 26.4
The Xcode project schemes for the Secretive, SecretAgent, and PackageTests targets have been updated to version 1.7 with a LastUpgradeVersion of 2640, reflecting compatibility with Xcode 26.4. This change ensures that build, test, launch, and archive configurations are correctly structured for the newer IDE version.
Sources/Secretive.xcodeproj/xcshareddata · high confidence
Updated workspace settings to enable ARM64e builds
The Xcode workspace configuration has been updated to explicitly enable ARM64e architecture support for both iOS and macOS packages. This change ensures that the build system correctly targets the newer Apple Silicon instruction sets, which is necessary for compatibility with modern devices and to resolve archiving issues in recent Xcode versions.
Sources/Secretive.xcodeproj/project.xcworkspace · high confidence
Test coverage
Added test suites for release parsing, versioning, and SSH agent operations; Added tests for OpenSSH public key and signature handling.
Dependencies
Swift 6 migration and package structure updates
The project has updated its Swift tools version to 6.2 in the root Package.swift and 6.4 in the internal packages manifest, targeting macOS 14 and macOS 15 respectively. This change introduces Swift 6 language mode and strict memory safety settings to the build configuration, alongside structural adjustments to the SPM package definitions, including the addition of new targets like SettingsKit, SecretAgentKit, Common, SharedXPCServices, Brief, and XPCWrappers in the internal package manifest.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 42 → 63 (+21.1)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 96 (-4.0)
- Architecture 94 (new)
- Maturity 39 → 49 (+9.9)
- Readiness 29 → 61 (+32.2)
- Security 58 → 88 (+29.1)
Resolved (20)
- Dimension evaluation failed
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- No artifact signing
- No automated tests
- No exposed public API
- No tests found
- Test reliability not included
- The 'Getting Started' section ends mid-sentence with an unexplained clip marker, so the remaining sections (A Note Around Code Signing and Keychains; Backups and Transfers to New Machines; Security; Acknowledgements; sekey; Localization) are present in the outline but not visible. (README.md)
New (34)
- Agent.handle (cognitive 17) (Sources/Packages/Sources/SecretAgentKit/Agent.swift)
- BackgroundViewModifier.backgroundColor (cognitive 22) (Sources/Packages/Sources/Common/MultilineInfoView.swift)
- BackgroundViewModifier.backgroundColor (cognitive 22) (Sources/Secretive/Views/Views/CopyableView.swift)
- Change coupling: AnySecretStore.swift ↔ SecureEnclaveStore.swift (Sources/Packages/Sources/SecretKit/Erasers/AnySecretStore.swift)
- Coverage not measured — Swift suite
- Dependency hygiene PARTLY measured — SwiftPM pinning read, dependency currency NOT established
- Duplicated block (11 lines × 2) (Sources/Packages/Sources/CertificateKit/CertificateStore.swift)
- Duplicated block (11–12 lines × 2) (Sources/Packages/Sources/Common/MultilineInfoView.swift)
- Duplicated block (12 lines × 2) (Sources/SecretAgent/App.swift)
- Duplicated block (16 lines × 2) (Sources/Packages/Sources/SharedXPCServices/CertificateMigrator.swift)
- Duplicated block (21 lines × 2) (Sources/Secretive/Views/Secrets/EditCertificateView.swift)
- Duplicated block (5 lines × 3) (Sources/Packages/Sources/SharedXPCServices/XPCCertificateParser.swift)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 14 more
Changes since last survey
- 13 commits — 10 feature/other, 3 fixes
By area
- Sources/Packages — 8 commits
- .github/workflows — 2 commits
- Sources/Secretive.xcodeproj — 2 commits
- Sources/SecretAgent — 1 commit
Notable commits
- fix: Fix Xcode 27 archiving (#829)
- fix: Fix hosts xpc service signing settings (#828)
- fix: Fix keyType constants being Data instead of String, specify in update calls (#830)
- change: Add host lookup xpc service (#826)
- change: Make enhanced security entitlements uniform (#833)
- change: Parsing OpenSSH extensions (#823)
- change: Pending request view (#821)
- change: Remove broken task entitlement lookup and only enforce on release builds. (#824)
- change: Secure Settings store (#831)
- change: Set Xcode 27 builder (#822)
- change: Switch to glorious new Xcode 27 JSON project format (#837)
- change: import os -> import OSLog (#832)
- change: improved localization for pt-BR (#804)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
maxgoedjen/secretive was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 54e0d00d87e207377101b0ea6ddfa624cd1a1c16 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-d00c643c3f66.