nenadvulic/solid-like-a-rock
70.2
Strong · 21 September 2026
3k
lines of production code
Swift
primary language
4
measurements over time
What this system is
SolidLikeARock is a static analysis tool for Swift projects that enforces architectural boundaries and security policies. It provides a command-line interface and SPM plugins to lint code against configurable rules, such as layering, peer isolation, and sensitive data handling. The system generates architecture graphs, detects violations, and integrates with CI/CD workflows to maintain codebase integrity.
Features
Add Swift Package Manager command plugin for SolidLint
Users can now run \swift package solid-lint\ to lint their package's Sources directory using a \.solid.yml\ configuration file at the package root. This new command plugin wraps the \solid-like-a-rock\ executable, forwarding arguments and defaulting to linting the \Sources\ directory when no arguments are provided.
Plugins/SolidLint · high confidence
Add automated architecture linting for Swift code in Claude Code sessions
Added a PostToolUse hook in .claude that automatically runs the solid-like-a-rock linter after every Swift edit, ensuring that architecture boundary violations are caught and reported to the AI agent in the same turn. The setup includes a shell script (.claude/hooks/solid-lint-changed.sh) that detects Swift file changes, locates the project's .solid.yml configuration, and runs the linter, exiting with a non-zero status to force the agent to fix the issue. A settings.json file wires this hook to Edit, Write, and MultiEdit tool calls, and a README explains the integration and configuration options.
.claude · high confidence
Added benchmark and artifact-bundle scripts
Two new shell scripts were added to the repository. The first, scripts/benchmark.sh, provides a reproducible benchmarking tool that clones the isowords project at a pinned SHA, generates a configuration, and times the linting process (median of 3 runs). The second, scripts/make-artifactbundle.sh, assembles a SwiftPM .artifactbundle containing a universal binary (arm64 + x86\_64) built via lipo, enabling prebuilt executable usage for the build-tool plugin.
scripts · high confidence
Enable Swift Package Manager build-tool plugin for SolidLikeARock
The SolidLintBuildTool plugin is added to the Swift Package Manager (SPM) build system. This integrates the SolidLikeARock linter as a prebuild step that runs automatically on every \swift build\ or Xcode build. The plugin detects Swift source modules and executes the linter against them, using a \.solid.yml\ configuration file if present at the package root. This allows import violations to be reported inline without requiring a separate script execution.
Plugins/SolidLintBuildTool · high confidence
Introduce architectural linting, security rules, and graph visualization
SolidCore now provides comprehensive static analysis for Swift projects. The \init\ subcommand generates a \.solid.yml\ configuration from the project's import graph, supporting \freeze\, \layered\, and \tca\ (TCA 1.x) modes. The linter enforces layering rules (e.g., \isolatePeers\, \dependencyOrder\), visibility rules (flagging \public\ in leaf modules), and 14 security rules (e.g., disabled TLS validation, hardcoded secrets). Results can be reported as JSON, GitHub Actions annotations, or rendered as Mermaid/DOT architecture graphs.
Sources/SolidCore · high confidence
Introduce init, graph, and lint subcommands for architectural enforcement
The SolidLikeARock CLI now provides three distinct subcommands: 'init' generates a .solid.yml configuration file from the project's import graph, with options for TCA presets, freeze mode, and security checks; 'graph' outputs the layer-level architecture diagram in Mermaid or DOT format; and 'lint' (the default) checks imports against the architecture rules, supporting JSON/GitHub reporters, baseline files, and visibility/security rule enforcement.
Sources/SolidCLI · medium confidence
New demo tapes and fixtures for vhs recordings
Added four new VHS demo tapes (demo, init-freeze, baseline, tca) and their associated fixture directories (fixture, fixture-init, fixture-tca) to the demo folder. These provide reproducible, automated recordings that demonstrate the tool's core capabilities: detecting and fixing architecture violations, freezing existing dependencies, establishing baselines for legacy code, and enforcing the Composable Architecture's peer-isolation rules.
demo · high confidence
New example templates for Swift linting, security rules, and TCA architecture
Added three new example files to demonstrate usage: a Swift Dangerfile for integrating the linter with CI, a security-focused configuration file with 14 rules for sensitive data and crypto checks, and a preset template for The Composable Architecture (TCA) to enforce inward dependency ordering and module isolation.
examples · high confidence
Test coverage
Added comprehensive test coverage for SolidCore's linting, security, and configuration logic; Added test fixtures for Clean Architecture and TCA dependency rules.
Dependencies
Initial release of SolidLikeARock CLI and linting plugins
This change introduces the initial release of the SolidLikeARock project, establishing the Swift Package Manager configuration for the CLI tool and its associated linting plugins. The package defines dependencies on swift-argument-parser (v1.3.0+), swift-syntax (v600.0.0–602.0.0), and Yams (v5.1.0+). It also includes a prebuilt binary target for the CLI, ensuring the \solid-lint\ command plugin and build-tool plugin can function correctly.
(dependencies) · medium confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 55 → 70 (+15.4)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 92 (-7.9)
- Architecture 100 → 97 (-3.0)
- Maturity 77 → 82 (+4.7)
- Readiness 46 → 69 (+23.2)
- Security 39 → 61 (+22.1)
Resolved (18)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- LLM evaluation failed
- No exposed public API
- Scanner failed to run — not a clean result
- Test reliability not included
- complexity unreadable for .swift — churn × complexity hotspots could not be measured
- single-maintainer — knowledge-concentration (bus factor) risk
New (37)
- Coverage not measured — Swift suite
- Documentation: no architecture or design documentation (README.md)
- Duplicated block (10–11 lines × 2) (Sources/SolidCLI/GraphCommand.swift)
- Duplicated block (20–22 lines × 2) (Sources/SolidCLI/GraphCommand.swift)
- Duplicated block (9 lines × 10) (Sources/SolidCore/Security/Rules/BiometryNoErrorHandlingRule.swift)
- GraphBuilder.build (cognitive 21) (Sources/SolidCore/GraphBuilder.swift)
- HardcodedSecretRule.check (cognitive 36) (Sources/SolidCore/Security/Rules/HardcodedSecretRule.swift)
- HardcodedSecretRule.check (cyclomatic 36) (Sources/SolidCore/Security/Rules/HardcodedSecretRule.swift)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Hotspot: Sources/SolidCLI/SolidCommand.swift (Sources/SolidCLI/SolidCommand.swift)
- …and 17 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
nenadvulic/solid-like-a-rock was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 90a27a72153fba14284fe766889c6c0252ecef2d — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.