permissionlesstech/bitchat
56.2
Adequate · 22 September 2026
74.5k
lines of production code
Swift
primary language
5
measurements over time
What this system is
BitChat is a secure, cross-platform messaging application for iOS and macOS that enables private communication over Bluetooth mesh networks and the Nostr protocol. It provides end-to-end encrypted direct messages and location-based public channels, supporting features like live voice streaming, file sharing, and mesh bridging to extend range over the internet. The system prioritizes privacy through metadata stripping, transitive identity verification, and Tor integration, while maintaining robust performance via deterministic testing and modular architecture.
How it got here
2025 — Hybrid mesh architecture and security hardening
36 changes.
The project implemented a hybrid BLE/Nostr architecture, introducing native Nostr transport, mesh bridging, and end-to-end encryption via the Noise Protocol Framework. Significant architectural shifts included modularizing the codebase into coordinators and frameworks, integrating local Tor connectivity, and establishing a robust three-layer identity model with transitive verification. The period also focused on comprehensive testing, privacy compliance, and expanding features like live voice streaming and location-based channels.
2026 — Mesh protocol foundation and architecture unification
11 changes.
This period focused on establishing the core mesh networking infrastructure by introducing the BitFoundation library and unifying the conversation architecture into a centralized state management system. Significant effort was also directed toward replacing the legacy Tor implementation with the Rust-based Arti client and expanding comprehensive test coverage for protocol primitives, security logic, and deterministic mesh simulations.
Features
Add iOS share extension for staging links and text
Users can now share URLs and text from other apps directly into bitchat via the new iOS share extension. The extension extracts shared links or plain text, stages the content in a shared container for review, and displays a status message (e.g., "Saved for review") before dismissing, allowing the main app to later process the staged content.
bitchatShareExtension · high confidence
Add shared Xcode schemes for iOS and macOS
Shared Xcode schemes for the iOS and macOS targets have been added to the project, ensuring consistent build, test, and launch configurations across the team. The iOS scheme includes the share extension and enables code coverage and parallel test execution, while the macOS scheme mirrors the iOS configuration for its respective target. Both schemes are configured to run with the BITCHAT\_LOG\_LEVEL environment variable set to debug by default.
bitchat.xcodeproj/xcshareddata · high confidence
Added geographic location data for online relays
The relays directory now includes a new CSV file, \online\_relays\_gps.csv\, which maps online relay URLs to their geographic coordinates (latitude and longitude). This addition provides location context for the list of active relays, enabling features such as geographic filtering or proximity-based selection for users.
relays · high confidence
Introduce Noise Protocol Framework for end-to-end encrypted messaging
BitChat now uses the Noise Protocol Framework (XX pattern with Curve25519, ChaCha20-Poly1305, and SHA-256) to provide mutual authentication, forward secrecy, and replay protection for peer-to-peer messages. This change adds a complete cryptographic handshake and session management layer, including rate limiting, session expiration/rekeying, and strict message-size bounds, replacing the previous transport encryption approach.
bitchat/Noise · high confidence
Introduce SecureLogger with hot-path performance and data sanitization
BitLogger now includes a new SecureLogger module that provides centralized, security-aware logging. It introduces automatic sanitization of sensitive data in log messages, redacting 64-character cryptographic fingerprints, long base64-encoded keys, passwords, and truncating peer IDs. To ensure performance on hot paths, the logger uses autoclosures to avoid evaluating message strings when they are filtered out by the log level, and it compiles all debug logging out of release builds entirely. A configurable minimum log level (defaulting to info) can be set via the BITCHAT\_LOG\_LEVEL environment variable.
localPackages/BitLogger · high confidence
Introduce live push-to-talk voice streaming for direct messages
Voice messages now support live streaming: when you hold the microphone button, your voice is encoded and sent to the recipient in real-time, while simultaneously recording a standard voice note as a fallback. This feature uses a centralized audio session coordinator to manage capture and playback conflicts (talk-over) and employs AAC-LC encoding at 16 kHz to ensure compatibility with existing voice note playback. Users can enable or disable this live streaming behavior via a new setting.
bitchat/Features/voice · high confidence
Introduce mesh bridging to extend chat range over the internet
Users can now connect to other mesh islands beyond local radio range by enabling the mesh bridge in the App Info settings. This feature stitches nearby mesh groups together over the internet, allowing messages to reach people who are not in direct Bluetooth proximity. The People sheet now displays a dedicated "across the bridge" section for these remote participants, and the message composer includes a toggle to scope outgoing messages to either the local mesh or the bridged network.
bitchat/Views · high confidence
Introduce native Nostr transport with geohash routing and proof-of-work
This change adds a complete Nostr transport layer to BitChat, enabling private messaging and location-based communication over Nostr relays. It introduces a new identity system using Schnorr keys (npub) and derives stable, unlinkable per-geohash identities for location channels. The implementation includes a GeoRelayDirectory to discover nearby relays via GPS coordinates, NIP-13 proof-of-work mining for geohash messages to manage rate limits, and a proprietary private-envelope protocol (using XChaCha20-Poly1305) for end-to-end encrypted DMs. Relay connections are managed with support for Tor, custom relay lists, and robust reconnection logic, while identity persistence is handled via the Keychain with specific accessibility attributes to ensure stability across device lock states.
bitchat/Nostr · high confidence
Introduces BitFoundation library with core mesh protocol primitives
The BitFoundation library has been added to centralize shared components, introducing the core data models and binary encoding logic for the mesh network. This includes the new AnnounceV2Packet for identity-free presence announcements that support peer ID rotation, the CourierEnvelope for store-and-forward messaging with rotating recipient tags, and the BitchatPacket/BitchatMessage structures for the v1 and v2 binary protocol. The update also brings in essential utilities for binary encoding, zlib compression, and SHA256 hashing, alongside a new DeliveryStatus enum to track message delivery states.
localPackages/BitFoundation/Sources · high confidence
Introduces Gossip Sync Manager with persistent public message history
The sync subsystem now includes a new GossipSyncManager that manages periodic, type-aware sync rounds for public messages, fragments, file transfers, board posts, and prekey bundles. This change adds a GCSFilter for efficient, size-constrained peer state comparison and a GossipMessageArchive to persist recent public messages to disk, enabling devices to act as a town crier and recover room history after app restarts or mesh partition reconnections. A RequestSyncManager and SyncResponseRateLimiter are also introduced to handle on-demand sync requests and prevent airtime/battery drain from excessive sync responses.
bitchat/Sync · high confidence
Introduces binary protocol packets for location channels, mesh bridging, and voice bursts
The protocol layer now supports location-based channels via new \Geohash\ and \LocationChannel\ types that map geohash precisions to channel levels (building through region). Mesh bridging is enabled by \NostrCarrierPacket\ for ferrying signed Nostr events between mesh and internet gateways, and \MeshMessageIdentity\ for content-derived deduplication. Public mesh communication is enhanced with \VoiceBurstPacket\ and \VoiceBurstPacketizer\ for live push-to-talk audio, while \BoardPackets\ provides signed bulletin-board posts and tombstones. File transfer capabilities are defined in \BitchatFilePacket\ for voice notes and images, and peer discovery is updated with \AnnouncementPacket\ and \AuthenticatedPeerStatePacket\ to advertise capabilities like vouching and private media.
bitchat/Protocols · high confidence
New Autocomplete Service for Mentions
A new \AutocompleteService\ has been added to the Services layer to handle autocomplete suggestions for chat mentions. The service scans input text for the \@\ symbol and matches it against known peer nicknames, returning a list of up to five matching suggestions along with the text range to replace. This enables users to quickly mention other peers in the chat without typing full names.
bitchat/Services · high confidence
New UI components for slash commands, connectivity, and message delivery
This update introduces several new view components to improve the user interface and feedback. CommandSuggestionsView provides dynamic slash-command suggestions as you type, filtering by context and showing usage hints. ConnectivityStatusBanner displays persistent, actionable alerts for Bluetooth or Tor connectivity issues, helping users understand why mesh or internet features may be unavailable. DeliveryStatusView and its integration into TextMessageView now provide clear, localized visual indicators and tap-to-reveal details for private message delivery states (sending, sent, delivered, read, failed), with snapshots ensuring SwiftUI correctly re-renders status changes. Additional components include MeshEmptyStateView and MeshRadarView to visualize mesh scanning activity and nearby conversations on an empty timeline, PanicWipeBlockedBanner to alert users when a panic wipe is incomplete, PaymentChipView for rendering and redeeming Cashu and Lightning payment links, IRCToggleStyle for consistent settings toggles, and SheetCloseButton for standardized sheet dismissal.
bitchat/Views/Components · high confidence
New model types for media, peer status, read receipts, and sync protocols
The app introduces several new data models to support richer messaging and network features. BitchatMessage now includes a Media extension to handle voice and image attachments, caching file directory lookups for performance. BitchatPeer is a new struct representing network peers with detailed connection states (Bluetooth, mesh, Nostr, offline) and support for local petnames and favorite relationships. ReadReceipt models enable read confirmation tracking with binary encoding. RequestSyncPacket implements a TLV-based protocol for targeted message synchronization, including fragment ID filtering for stalled reassemblies. CommandInfo centralizes slash-command definitions and suggestions, while NoisePayload provides typed encoding for network messages.
bitchat/Models · high confidence
New safety, performance, and validation tooling for scripts
This change introduces several new scripts to enforce safety and performance standards. A new \check-just-clean-safety.sh\ script ensures the Justfile's clean recipe is restricted to removing local build artifacts and does not mutate tracked source files. A \check-perf-floors.sh\ gate monitors benchmark throughput against defined floors, retrying on noise to catch algorithmic regressions. Additionally, a \generate-mac-appicon.swift\ script creates macOS-specific app icons with proper rounded corners and shadows, and new Python tests validate the GeoRelay update workflow and data validation logic to ensure secure and correct relay processing.
scripts · high confidence
New utility modules for theming, localization, and input validation
This change introduces a suite of new utility components in the Utils module. It adds AppLanguageSettings to allow users to override the app language via an in-app picker, persisting the choice for the next launch. A new Theme system supports switching between 'Matrix' and 'Liquid Glass' visual styles, including dynamic color palettes and font designs. Input handling is enhanced with InputValidator for strict string sanitization and nickname normalization (Unicode NFC), a SafeRegex helper to prevent crashes from invalid patterns, and a MessageDeduplicator for efficient ID tracking. Additional utilities include PeerDisplayNameResolver for handling nickname collisions, QuickJoinRegions for locale-based channel suggestions, and Dynamic Type support via Font+Bitchat.
bitchat/Utils · high confidence
Strict validation for georelay CSV updates
A new script, scripts/validate\_georelays.py, has been added to enforce strict validation rules for the georelay data update workflow. This tool validates that uploaded CSV files adhere to a specific schema (relay URL, latitude, longitude), ensuring data integrity by checking for allowed URL schemes (wss/https), rejecting local or non-ASCII hostnames, validating coordinate ranges, and enforcing limits on file size, row count, and unique relay entries. This change ensures that only reviewed and correctly formatted data is accepted into the system.
python · high confidence
Architecture
ChatViewModel logic modularized into domain-specific extensions
The ChatViewModel's implementation has been reorganized into separate extension files to improve maintainability and separation of concerns. Nostr integration, geohash channel management, and identity handling are now isolated in ChatViewModel+Nostr.swift. Private chat operations, including direct messages, group chat broadcasting, media transfers (images, voice notes), and live push-to-talk voice streaming, are handled in ChatViewModel+PrivateChat.swift. Tor lifecycle events, status announcements, and bootstrap stall detection are managed in ChatViewModel+Tor.swift. This refactoring keeps the main ChatViewModel focused on core state and coordination while delegating specific domain logic to these dedicated extensions.
bitchat/ViewModels/Extensions · high confidence
Migrate Xcode project to modern build system and modularize targets
The Xcode project has been upgraded to object version 90 and restructured to use modern build-system features, including file-system synchronization for source groups and explicit exception sets for target-specific files like Info.plist. The project now explicitly defines and links modular frameworks (BitFoundation, BitLogger, Tor, P256K) and adds a share extension target (bitchatShareExtension.appex) with proper embedding and container item proxies, replacing the previous flat source-file references with a more organized, modular architecture.
bitchat.xcodeproj · high confidence
Refactor ChatViewModel into modular, testable coordinators
The monolithic ChatViewModel has been decomposed into a set of focused coordinator classes (ChatBluetoothAlertPolicy, ChatComposerCoordinator, ChatDeliveryCoordinator, ChatFavoriteTogglePolicy, ChatGroupCoordinator, ChatLifecycleCoordinator, ChatLiveVoiceCoordinator, ChatMediaPreparation, and ChatMediaTransferCoordinator). Each coordinator now depends on a narrow protocol-defined context rather than holding a back-reference to the entire ChatViewModel, which makes the components independently testable and clarifies their specific responsibilities—such as handling Bluetooth alerts, managing autocomplete, coordinating delivery statuses, and processing live voice bursts.
bitchat/ViewModels · high confidence
Unified conversation architecture with centralized state management
The app introduces a new single-writer ConversationStore that serves as the central source of truth for all conversation message state, replacing the previous distributed stores (PublicTimelineStore, legacy private message path). This change consolidates public and private message handling, delivery status tracking, and conversation selection into a unified model, improving consistency and performance by avoiding unnecessary index rebuilds. The new architecture also introduces a RecentChats section to ensure DM conversations remain accessible even when peers go offline, and integrates verification seals for private message senders based on transitive trust relationships.
bitchat/App · high confidence
Behavioural changes
Added preview helpers for deterministic keychain and message mocking
The app now includes a \PreviewKeychainManager\ and \BitchatMessage\ preview extensions to support SwiftUI previews and isolated testing. The keychain manager provides a thread-safe, in-memory implementation of \KeychainManagerProtocol\ that replaces real device storage with local dictionaries, ensuring that previews and tests do not interact with the developer's real login keychain. It also introduces specific error-handling methods (\getIdentityKeyWithResult\, \saveIdentityKeyWithResult\) that return typed results (\KeychainReadResult\, \KeychainSaveResult\) instead of booleans, improving error classification during preview rendering.
_bitchat/\PreviewHelpers · high confidence
App runtime, localization, and privacy compliance overhaul
The app now uses a centralized AppRuntime to manage core models and lifecycle events, replacing the previous single ChatViewModel approach. A new LaunchScreen storyboard provides a branded startup view, and the app has migrated to Swift String Catalogs (.xcstrings) for localization, filling locale gaps so strings no longer fall back to English. To meet App Store requirements, a PrivacyInfo.xcprivacy file has been added, and usage descriptions for Bluetooth, camera, location, microphone, and photo library have been added to Info.plist.
bitchat · high confidence
Extracted dedicated image picker and preview views for iOS and macOS
The image viewing and selection logic has been refactored into three new, platform-specific SwiftUI components within the Image Viewers module. On iOS, \ImagePickerView\ now wraps the native \UIImagePickerController\ to handle camera and photo library access, while \ImagePreviewView\ manages fullscreen image display and export via \UIDocumentPickerViewController\. On macOS, \MacImagePickerView\ provides a localized \NSOpenPanel\ for selecting images, and \ImagePreviewView\ handles display and saving via \NSSavePanel\. This change isolates the platform-specific UI implementations for image selection and previewing.
bitchat/Views/Image Viewers · high confidence
Image processing now strips metadata and enforces size limits
The media feature now includes a new ImageUtils module that processes images by scaling them to a maximum dimension of 448 pixels and compressing them to a target size of 45,000 bytes. This process explicitly strips all metadata (including EXIF, GPS, TIFF, IPTC, and XMP) to prevent privacy leaks, and validates that source images do not exceed 10 MB before processing.
bitchat/Features/media · high confidence
Introduce Xcode configuration files and remove xcodegen
The project now uses standard Xcode .xcconfig files (Debug.xcconfig, Release.xcconfig, and Local.xcconfig.example) to manage build settings, replacing the previous xcodegen-based configuration. This change simplifies local development setup by allowing developers to copy the example local config file to define their own team ID, bundle identifier, and app group, while the release configuration sets the deployment targets to iOS 16.0 and macOS 13.0, uses Swift 5.0, and hardcodes the production bundle identifier and team ID.
Configs · high confidence
Introduces three-layer identity model with transitive verification and encrypted persistence
BitChat now uses a three-layer identity architecture separating network peer IDs, cryptographic Noise keys, and social mappings (petnames, trust). This change adds transitive verification, allowing users to trust peers vouched for by already-verified contacts, and introduces a new 'vouched' trust level. Identity data is now persisted in an encrypted cache stored in the device Keychain, managed by a new SecureIdentityStateManager that handles thread-safe, synchronous saves to prevent CI hangs. The system also supports blocking Nostr pubkeys for geohash chats and tracks private media capabilities.
bitchat/Identity · high confidence
New media message views with image reveal, voice notes, and delivery status
The media message rows now use dedicated SwiftUI views that enhance how images and voice notes are displayed and interacted with. Incoming images are initially blurred with a 'tap to reveal' overlay, and deleting received images now requires a confirmation dialog. Voice messages display a waveform, playback controls, and a pulsing 'LIVE' badge for streaming audio, with the ability to cancel in-flight sends. Delivery status for private messages is now explicitly shown and tappable to reveal details, ensuring read receipts and send progress are visible immediately.
bitchat/Views/Media · high confidence
Replace C Tor with Rust Arti for Tor integration
The app now uses the Rust-based Arti client instead of the previous C Tor implementation for Tor connectivity. This change introduces a new local package containing the Arti xcframework and a Swift TorManager that boots a local Arti instance, exposing a SOCKS5 proxy on 127.0.0.1:39050. The TorManager tracks bootstrap progress and stalls, enforces Tor for all connections by default (fail-closed), and provides a TorURLSession to route app traffic through the proxy or directly when Tor is disabled. The underlying Rust FFI wrapper handles the lifecycle of the Arti client, including start, stop, and dormant mode signals.
localPackages/Arti · high confidence
Repository configuration and documentation overhaul
The project has replaced the XcodeGen-based \project.yml\ and \setup.sh\ with a native Xcode project structure managed via \.xcconfigs\ and a \Justfile\ for developer commands. To improve repository hygiene and CI, \.gitattributes\ is now used to prevent GitHub language stats skewing, a \.periphery.yml\ configuration with a baseline is added for dead-code scanning, and SwiftLint is configured with an advisory-only CI job. Documentation has been significantly expanded with a new \WHITEPAPER.md\ detailing the hybrid BLE/Nostr architecture, a \PRIVACY\_POLICY.md\, a \SECURITY.md\ for vulnerability reporting, and a \BRING\_THE\_NOISE.md\ explaining the Noise Protocol implementation. The repository license is explicitly set to Public Domain (Unlicense), and the \README.md\ has been updated to reflect the new setup process and features.
(repo-wide) · high confidence
Share extension localization migrated to Swift String Catalogs
The share extension's localization files have been converted from the legacy format to Swift String Catalogs (.xcstrings). This change updates the underlying storage format for translations, ensuring that the share extension's UI strings are managed through the modern Xcode localization system while preserving existing translations for multiple languages.
bitchatShareExtension/Localization · high confidence
Test coverage
Added comprehensive test coverage for the Noise protocol implementation; Added integration tests for mesh network topology and message delivery; Added performance baseline tests and CI floor gates; Added test coverage for image processing, autocomplete, and BLE services; Added test coverage for prekey-based encryption and sync protocol logic; Added tests for BLE packet fragmentation and reassembly; Added unit tests for hex string parsing utility; Deterministic mesh simulation for testing link and identity behavior; Expanded test coverage for BitFoundation protocol and security primitives; Expanded test coverage for Nostr components; Expanded test coverage for core architecture, BLE, and chat components; Expanded test coverage for mesh protocol packets and utilities; New end-to-end test suite for courier, prekey, and chat flows; New mock infrastructure for BLE, identity, and transport testing; Test suite hygiene: robust async waits and timing constraints.
Dependencies
Introduces local Arti Tor integration and modularizes dependencies
The project now integrates the Arti Tor client (version 0.38) as a local Rust package, replacing previous implementations to provide Tor connectivity via a new 'Tor' Swift module. This change introduces several new local Swift packages—BitLogger, BitFoundation, and Arti—to modularize shared components and dependencies. Additionally, the main package now depends on swift-secp256k1 (version 0.21.1) for cryptographic operations and adopts Swift String Catalogs (.xcstrings) for localization, setting 'en' as the default localization.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 66 → 56 (-9.4)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 93 → 81 (-12.7)
- Architecture 93 → 97 (+3.8)
- Maturity 67 → 68 (+1.3)
- Readiness 55 → 69 (+13.3)
- Security 69 → 68 (-1.1)
- Event-Driven 40 (new)
Resolved (29)
- Change coupling: BLEOutboundPacketPolicy.swift ↔ SyncTypeFlags.swift (bitchat/Services/BLE/BLEOutboundPacketPolicy.swift)
- Change coupling: BLEService.swift ↔ RelayController.swift (bitchat/Services/BLE/BLEService.swift)
- Change coupling: BLEService.swift ↔ SyncTypeFlags.swift (bitchat/Services/BLE/BLEService.swift)
- Change coupling: LocationChannel.swift ↔ ContentView.swift (bitchat/Protocols/LocationChannel.swift)
- Change coupling: TextMessageView.swift ↔ MediaMessageView.swift (bitchat/Views/Components/TextMessageView.swift)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High vulnerability: [GHSA redacted] (localPackages/Arti/Cargo.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- LLM evaluation failed
- Medium CVE: [GHSA redacted] (localPackages/Arti/Cargo.lock)
- Medium CVE: [GHSA redacted] (localPackages/Arti/Cargo.lock)
- Medium CVE: RUSTSEC-2023-0071 (localPackages/Arti/Cargo.lock)
- Medium advisory (unmaintained): RUSTSEC-2024-0436 (localPackages/Arti/Cargo.lock)
- Medium advisory (unmaintained): RUSTSEC-2025-0141 (localPackages/Arti/Cargo.lock)
- Medium advisory (unmaintained): RUSTSEC-2026-0173 (localPackages/Arti/Cargo.lock)
- Medium advisory (unsound): RUSTSEC-2026-0012 (localPackages/Arti/Cargo.lock)
- Medium advisory (unsound): RUSTSEC-2026-0097 (localPackages/Arti/Cargo.lock)
- …and 9 more
New (510)
- AnnounceV2Packet.decode (cognitive 22) (localPackages/BitFoundation/Sources/BitFoundation/AnnounceV2Packet.swift)
- AnnounceV2Packet.decode (cyclomatic 16) (localPackages/BitFoundation/Sources/BitFoundation/AnnounceV2Packet.swift)
- AnnouncementPacket.decode (cognitive 26) (bitchat/Protocols/Packets.swift)
- AnnouncementPacket.decode (cyclomatic 17) (bitchat/Protocols/Packets.swift)
- AnnouncementPacket.encode (cognitive 16) (bitchat/Protocols/Packets.swift)
- AppRuntime.handleScenePhaseChange (cognitive 16) (bitchat/App/AppRuntime.swift)
- AuthenticatedPeerStatePacket.decode (cognitive 24) (bitchat/Protocols/Packets.swift)
- AuthenticatedPeerStatePacket.decode (cyclomatic 16) (bitchat/Protocols/Packets.swift)
- BLEAnnounceHandler.handle (cognitive 33) (bitchat/Services/BLE/BLEAnnounceHandler.swift)
- BLEAnnounceHandler.handle (cyclomatic 33) (bitchat/Services/BLE/BLEAnnounceHandler.swift)
- BLEConnectionScheduler.handleDiscovery (cognitive 16) (bitchat/Services/BLE/BLEConnectionScheduler.swift)
- BLEConnectionScheduler.handleDiscovery (cyclomatic 16) (bitchat/Services/BLE/BLEConnectionScheduler.swift)
- BLEFanoutSelector.collapseDuplicateLinksPerPeer (cognitive 20) (bitchat/Services/BLE/BLEFanoutSelector.swift)
- BLEFileTransferHandler.storeIncomingPayload (cognitive 17) (bitchat/Services/BLE/BLEFileTransferHandler.swift)
- BLEFileTransferHandler.storeIncomingPayload (cyclomatic 22) (bitchat/Services/BLE/BLEFileTransferHandler.swift)
- BLEIncomingFileStore.enforceQuota (cognitive 33) (bitchat/Services/BLE/BLEIncomingFileStore.swift)
- BLEIncomingFileStore.expireAgedMedia (cognitive 34) (bitchat/Services/BLE/BLEIncomingFileStore.swift)
- BLENoisePacketHandler.handleEncrypted (cognitive 29) (bitchat/Services/BLE/BLENoisePacketHandler.swift)
- BLENoisePacketHandler.handleEncrypted (cyclomatic 17) (bitchat/Services/BLE/BLENoisePacketHandler.swift)
- BLEPrivateMediaReceiptStore.commitAccepted (cognitive 20) (bitchat/Services/BLE/BLEPrivateMediaReceiptStore.swift)
- …and 490 more
Changes since last survey
- 14 commits — 14 feature/other, 0 fixes
By area
- bitchat/Views — 5 commits
- bitchat/Localizable.xcstrings — 2 commits
- .github/workflows — 1 commit
- bitchat/App — 1 commit
- bitchat/Services — 1 commit
- bitchatTests/AppArchitectureTests.swift — 1 commit
- bitchatTests/ChatNostrCoordinatorContextTests.swift — 1 commit
- bitchatTests/Integration — 1 commit
- localPackages/BitFoundation — 1 commit
Notable commits
- change: Add 26 code-referenced keys to the catalog + a test that closes the gap (#1654)
- change: Add a persistent connectivity banner and stop the radar lying (#1597)
- change: Add a recent-chats section so DM conversations can't become unreachable (#1598)
- change: Deflake AppArchitectureTests: raise the local waitUntil to settleTimeout (#1653)
- change: Deflake gift-wrap tests: settle deadlines, not latency budgets (#1651)
- change: Fail closed on unverifiable handshake peer IDs + check SecRandomCopyBytes results (#1645)
- change: Localize CommandProcessor: all 48 command strings, 30 locales (#1657)
- change: Localize the last hardcoded UI strings; wire up two dead translations (#1656)
- change: Make SwiftLint blocking in CI now that the violation backlog is zero (#1646)
- change: Make the Periphery scan blocking (#1648)
- change: Make the panic wipe confirmable and its outcome visible (#1588)
- change: Remove the public-channel screenshot broadcast (#1596)
- change: Stop claiming encryption and privacy properties that aren't live (#1595)
- change: Timestamp sanity windows: future-dated QR codes and implausible Nostr DM rumors (#1647)
Architecture
- Unchanged — 0 containers · 1 contexts · 0 edges
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
permissionlesstech/bitchat was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 9b84b361225facd8e623f25d76f889d3dc54a879 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-be726e82e277.