Skip to content
CAI
Software that uses CAICheck a score

mxcl/PromiseKit

57.6

Adequate · 27 September 2026

2.7k

lines of production code

Swift

with Objective-C, C

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Added example scripts and documentation for image caching, error handling, and Twitter automation

New examples have been added to the documentation to demonstrate practical usage patterns. This includes an image cache implementation using promises for thread-safe caching and cleanup, a Swift extension for handling bad HTTP responses from URLSession, and a script for automating the deletion of old tweets and favorites via the Twitter API.

Documentation/Examples · high confidence

Initial project scaffolding and configuration

The repository is initialized with essential configuration files: a \.gitignore\ to exclude build artifacts and IDE files, a \.gitmodules\ file defining numerous extension submodules (including Foundation, UIKit, and various Apple platform extensions), a \.travis.yml\ for CI builds across multiple Xcode and Swift versions, a \LICENSE\ file, and Swift Package Manager manifests (\[e-mail redacted]\, \[e-mail redacted]\, \[e-mail redacted]\) that configure the library and its tests. Additionally, a \README.md\ provides documentation and installation instructions, and a \.tidelift.yml\ file is added for security support information.

(repo-wide) · high confidence

Introduce Swift concurrency and Combine integration for promises and guarantees

Adds support for Swift 5.5+ structured concurrency by providing \async\ methods on \Promise\ and \Guarantee\ that wrap the asynchronous operations in \CheckedContinuation\ continuations, allowing promises to be used in \async\/\await\ contexts. Additionally, the library now exposes \Combine\ interoperability, adding \future()\ methods to convert \Promise\ and \Guarantee\ into Combine \Future\ publishers, and provides a \promise()\ method to convert Combine \Future\s back into PromiseKit promises. These additions are implemented in new \Async.swift\ and \Combine.swift\ files within the Sources directory.

Sources · high confidence

Behavioural changes

Added privacy manifest for App Store compliance

A new PrivacyInfo.xcprivacy file has been added to the project, declaring that no data is being tracked and no data is being collected. This ensures the app meets Apple's privacy manifest requirements.

Sources/Resources · high confidence

Fixes broken PromiseKit Playground

The PromiseKit playground has been repaired so it can be opened and run in Xcode without errors. A new Contents.swift file was added to replace the missing file, and the playground configuration was updated to reference the correct source file, allowing users to execute the example code and see the expected output.

PromiseKit.playground · high confidence

Updated Xcode project configuration for the latest Swift and iOS versions

The Xcode project file (project.pbxproj) has been updated to support the latest Swift and iOS versions, ensuring compatibility with modern development environments. This update includes adjustments to build settings and file references to align with current Apple platform standards.

PromiseKit.xcodeproj · high confidence

Updated Xcode project scheme configuration for test parallelization and code coverage

The Xcode project scheme for PromiseKit has been updated to enable parallel test execution and code coverage collection. Specifically, the test action now includes PMKCoreTests, PMKA+Tests, PMKBridgeTests, PMKDeprecatedTests, and PMKJSA+Tests as parallelizable test targets, and code coverage is enabled for the main framework. This change improves the speed and depth of the testing process during development and CI runs.

PromiseKit.xcodeproj/xcshareddata · high confidence

Updated Xcode workspace configuration

The Xcode workspace configuration has been updated to include a new workspace data file, workspace checks plist, and workspace settings file. These changes ensure proper workspace setup and configuration for the project, including disabling automatic context creation and enabling 32-bit build warnings.

PromiseKit.xcodeproj/project.xcworkspace · medium confidence

Updated all extension submodules to their latest versions

All extension submodules (AVFoundation, Accounts, AddressBook, Alamofire, AssetsLibrary, Bolts, CloudKit, CoreBluetooth, CoreLocation, EventKit, Foundation, HealthKit, HomeKit, MapKit, MessagesUI, OMGHTTPURLRQ, Photos, QuartzCore, Social, StoreKit, SystemConfiguration, UIKit, and WatchConnectivity) have been updated to their latest commits. This brings the extensions up to date with upstream changes, ensuring compatibility and incorporating any fixes or improvements from the respective libraries.

Extensions · high confidence

Test coverage

Added Promises A+ specification tests; Added Promises/A+ compliance test suite; Added comprehensive test coverage for CorePromise components; Added deprecation and Linux test coverage; Added tests for AnyPromise bridging between Swift and Objective-C; Adds comprehensive test coverage for PromiseKit CoreObjC components.

Dependencies

PromiseKit 8.2.0 release with Swift Package Manager and CocoaPods support

The release introduces Swift Package Manager support via a new Package.swift file, enabling native Swift package integration. The CocoaPods specification (PromiseKit.podspec) is updated to version 8.2.0, adding support for visionOS 1.0, updating deployment targets for iOS (10.0), macOS (10.13), watchOS (4.0), and tvOS (10.0), and defining various subspecs for different platform frameworks. Additionally, the test suite for JS-A+ compliance is updated with a new package.json and package-lock.json, incorporating dependencies like lodash 4.17.21 and other testing tools.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 40 → 58 (+17.5)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 99 (-1.2)
  • Architecture 95 (new)
  • Maturity 57 → 60 (+2.8)
  • Readiness 26 → 45 (+19.5)
  • Security 38 → 60 (+21.8)

Resolved (79)

  • Critical CVE: [GHSA redacted] (Tests/JS-A+/package-lock.json)
  • Critical CVE: [GHSA redacted] (Tests/JS-A+/package-lock.json)
  • Critical CVE: [GHSA redacted] (Tests/JS-A+/package-lock.json)
  • Critical CVE: [GHSA redacted] (Tests/JS-A+/package-lock.json)
  • Critical CVE: [GHSA redacted] (Tests/JS-A+/package-lock.json)
  • Critical CVE: [GHSA redacted] (Tests/JS-A+/package-lock.json)
  • Critical CVE: [GHSA redacted] (Tests/JS-A+/package-lock.json)
  • Critical CVE: [GHSA redacted] (Tests/JS-A+/package-lock.json)
  • Critical CVE: [GHSA redacted] (Tests/JS-A+/package-lock.json)
  • Critical CVE: [GHSA redacted] (Tests/JS-A+/package-lock.json)
  • Critical CVE: [GHSA redacted] (Tests/JS-A+/package-lock.json)
  • Critical CVE: [GHSA redacted] (Tests/JS-A+/package-lock.json)
  • Critical CVE: [GHSA redacted] (Tests/JS-A+/package-lock.json)
  • Critical CVE: [GHSA redacted] (Tests/JS-A+/package-lock.json)
  • Critical CVE: [GHSA redacted] (Tests/JS-A+/package-lock.json)
  • Critical CVE: [GHSA redacted] (Tests/JS-A+/package-lock.json)
  • Critical CVE: [GHSA redacted] (Tests/JS-A+/package-lock.json)
  • Critical CVE: [GHSA redacted] (Tests/JS-A+/package-lock.json)
  • Critical CVE: [GHSA redacted] (Tests/JS-A+/package-lock.json)
  • Critical CVE: [GHSA redacted] (Tests/JS-A+/package-lock.json)
  • …and 59 more

New (79)

  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (the committed lockfile is in a format this engine cannot resolve)
  • Duplicated block (14 lines × 2) (Sources/Guarantee.swift)
  • Duplicated block (14 lines × 2) (Sources/Thenable.swift)
  • FixmeComment (Sources/Box.swift)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 59 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

mxcl/PromiseKit was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 96cd3bdedf944c1606ad1fa7e32418ce0cd7ff68 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d00c643c3f66.