Skip to content
CAI
Software that uses CAICheck a score

spotiflacapp/SpotiFLAC-Mobile

63.8

Adequate · 23 September 2026

154.1k

lines of production code

Dart

with Go, Kotlin

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a cross-platform Flutter application for downloading and managing high-fidelity audio files from various streaming services. It features a native Go backend that handles complex download queues, format conversion, and metadata processing, ensuring reliable background execution on both Android and iOS. The app provides a rich user interface for browsing music libraries, viewing detailed audio analysis, and managing local collections with extensive customization options.

Features

Expanded model schemas and unified library item for richer metadata and download tracking

The data models in lib/models have been significantly expanded to support new features and improved data fidelity. The Track model now includes fields for artist/album IDs, preview URLs, total discs/tracks, composer, genre, label, copyright, explicit content flags, and UPC, along with a new fromBackendMap factory for parsing extension search results. The DownloadItem model now tracks download speed, byte counts, specific error types (e.g., rate limit, permission), preparation stages, and playlist context (name/position), while also introducing a 'finalizing' status. A new UnifiedLibraryItem model unifies tracks from both download history and local library scans, enabling shared list handling and consistent quality labeling. Additionally, AppSettings and ThemeSettings have been updated with numerous new configuration options, including local library scanning, ReplayGain normalization, extended lyrics provider settings, and an AMOLED theme mode.

lib/models · high confidence

Home-screen download queue widget and download service refactoring

Users can now see the active download status on their home screen via a new DownloadQueueWidgetProvider that updates only on discrete events to respect battery life. The underlying download service has been significantly refactored: network policy (Wi-Fi-only pausing), ReplayGain journaling, and SAF (Storage Access Framework) IO helpers have been extracted into dedicated modules, improving reliability and maintainability. Additionally, FFmpeg execution for native finalization is now sandboxed, and quality-variant filename handling has been hardened to only suffix colliding files.

android/app/src/main/kotlin/com/zarz · high confidence

Introduces structured extension provider metadata and download decryption models

The backend now defines explicit Go structs for extension provider data, including \ExtTrackMetadata\, \ExtAlbumMetadata\, and \ExtArtistMetadata\, which standardize how track, album, and artist information (such as IDs, URLs, and audio quality traits) is passed between providers and the application. Additionally, new \DownloadDecryptionInfo\ and \ExtDownloadResult\ types formalize the handling of decryption strategies (like FFmpeg MOV keys) and download outcomes, providing a consistent interface for processing encrypted audio files and their associated metadata.

_github.com/zarz/spotiflac\_android/go\backend · high confidence

Native support for AC-4, APEv2, and extended metadata in MP4 containers

The Go backend now includes native readers and writers for AC-4 audio inside MP4 containers, APEv2 tags (common in Monkey's Audio), and extended metadata fields (genre, label, copyright) for MP4/M4A files. AC-4 handling specifically rejects truncated sample entries safely to prevent crashes, while APEv2 support enables reading and writing tags for .ape files. These changes allow the app to correctly process, preserve, and edit metadata for these previously unsupported or partially handled formats.

_go\backend · high confidence

New app services and state management infrastructure

The app introduces a suite of new services in lib/services to handle core functionality. APK updates now support resumable downloads with SHA-256 verification and progress tracking. App state (download queue, recent access, playback sessions) is persisted in a new SQLite database with schema migrations. Remote configuration is fetched to display announcements and donation options. Backup and restore capabilities are expanded to include settings, history, collections, and extensions. Batch operations for metadata re-enrichment and track conversion are standardized, and audio metadata mapping is abstracted for consistent tag handling across formats.

lib/services · high confidence

New shared UI components and audio analysis widgets

This change introduces a suite of new shared widgets in the lib/widgets directory to standardize the app's interface and enhance audio metadata capabilities. A new collapsing album-detail header (AlbumDetailHeader) provides a unified, palette-driven background with adaptive title scaling for album screens. Standardized bottom sheets (AppBottomSheet, AppDraggableSheet) and sliver headers (AppSliverHeader) ensure consistent chrome and navigation behavior across the app. A new search field (AppSearchField) and animation utilities (StaggeredListItem, ShimmerLoading) improve input consistency and list transitions. Additionally, a comprehensive audio analysis widget system is added, featuring models, an info card with detailed metric chips (codec, dynamic range, LUFS, spectral cutoff), and an interactive spectrogram view with channel selection.

lib/widgets · high confidence

New shared utility library for layout, metadata, and conversion logic

This change introduces a comprehensive set of new utility modules in lib/utils to centralize and standardize core application logic. For layout, adaptive\_layout.dart and app\_bar\_layout.dart provide responsive scaling, navigation rail breakpoints, and safe-area handling for tablets and desktops. Metadata handling is enhanced via artist\_utils.dart for robust artist name splitting and tag mode support, while audio\_format\_utils.dart and audio\_quality\_badge\_policy.dart standardize format detection, quality label generation, and badge display policies. Audio conversion capabilities are consolidated in audio\_conversion\_utils.dart, defining supported formats, bit depth/sample rate constraints, and dithering/resampler options. Additional utilities include cache\_byte\_budget.dart for managing cache size, chunked\_list.dart for efficient sparse updates, clickable\_metadata.dart for interactive metadata navigation, and extension\_auth\_launcher.dart for managing extension verification flows.

lib/utils · high confidence

Repository initialization with strict linting and toolchain pinning

The repository is initialized with configuration files that enforce consistent code style and development tooling. An \.editorconfig\ defines indentation and line-ending rules for Dart, Go, and other project files. The Flutter SDK version is pinned to 3.47.1 via \.fvmrc\, and the \analysis\_options.yaml\ is updated to enable strict type-safety lints (strict-casts, strict-inference, strict-raw-types) and includes the \riverpod\_lint\ plugin. Additionally, a \.gitattributes\ file ensures correct line endings for scripts and binary files across platforms, and a \cliff.toml\ configures automated changelog generation.

(repo-wide) · high confidence

iOS extension OAuth support and download progress streaming

The iOS app now supports authentication flows for extension providers (such as Spotify) via the custom 'spotiflac://' URL scheme, enabling seamless login and session grants through ASWebAuthenticationSession. Additionally, download progress updates are now streamed to the Flutter layer using a dedicated background subscription mechanism, providing more reliable and performant progress reporting during file operations.

ios/Runner · high confidence

Behavioural changes

App startup, localization, and UI behavior enhancements

The app now includes a tutorial screen that launches for first-time users or those who haven't completed the tutorial, and implements robust locale resolution with English fallback for unsupported languages. UI behavior has been updated to support fluid bouncing scroll physics (iOS-style) and crossfade animations during orientation or layout breakpoint changes, while also introducing runtime profiling to automatically adjust image caching and overscroll effects based on device capabilities like RAM and architecture.

lib · high confidence

Centralized app metadata, language selection, and service identifiers

The app now uses dedicated constant files to manage core configuration. App metadata (version 4.9.6, build 144, author info, and donation links) is centralized in \app\_info.dart\, which also exposes an 'Internal' version string for debug builds and displays a short Git commit hash. Language preferences are defined in \language\_choices.dart\, providing a shared list of supported locales (including system default) for use in onboarding and settings. Service provider identifiers (Spotify, Deezer, Tidal, Qobuz, Amazon, and Local) are standardized in \music\_services.dart\ to ensure consistent dispatching across the app, replacing raw string literals.

lib/constants · high confidence

Download history and queue providers refactored into modular part files

The download history and queue logic has been restructured into distinct, concern-specific part files (models, connectivity, embedding, finalization, and native worker) to improve maintainability. This change introduces extended metadata support (genre, label, copyright) in the history model, adds a one-tap retry prompt for network-failed downloads upon reconnection, and implements startup maintenance tasks such as SAF entry repair, orphan cleanup, and audio metadata backfill.

lib/providers · high confidence

Expanded language support with automatic translation quality filtering

The app now supports 11 languages (English, Korean, French, Spanish, German, Ukrainian, Russian, Turkish, Indonesian, Portuguese (Portugal), and Japanese). To ensure quality, only locales with at least 70% translation completion are enabled by default. Additionally, a new utility extension on BuildContext provides a friendlyError method to display sanitized, user-facing error messages instead of raw technical exceptions.

lib/l10n · high confidence

Expanded localization coverage and corrected locale file naming

The app's localization files in lib/l10n/arb have been significantly expanded with new and updated translations for multiple languages, including Arabic, German, Spanish, and French. Additionally, the locale file naming convention has been standardized to use underscores (e.g., es\_ES) instead of hyphens to ensure compatibility with the framework's localization generation tools.

lib/l10n/arb · high confidence

Native download worker with resilient queue and SAF handling

The Android download pipeline has been refactored to use a native background worker (DownloadService) that manages the download queue, progress snapshots, and finalization independently of the Flutter UI. This change introduces a robust state-snapshotting system (DownloadServiceSnapshot) to persist queue status and item progress, ensuring downloads survive app restarts and background execution limits. It also adds a dedicated SAF (Storage Access Framework) handler (SafDownloadHandler) that stages downloads to prevent data corruption, and a native finalizer (NativeDownloadFinalizer) that handles metadata embedding, format conversion, and history database writes. Additionally, a new policy layer (NativeFinalizationPolicy, NativeWorkerPolicy) centralizes decisions on auto-conversion, rate-limit retries, and verification flows, while a new ForegroundServiceStartPolicy improves compatibility with Android 15+ foreground service restrictions.

app · high confidence

New ProGuard rules to optimize APK size and prevent build warnings

A new proguard-rules.pro file has been added to the Android app to tighten R8 keep rules, enabling better code shrinking and optimization. This change suppresses warnings for unused Play Core and javax.xml.stream classes, preserves necessary Kotlin coroutine internals and native methods, and explicitly keeps only the entry-point classes (MainActivity, DownloadService, etc.) while allowing the rest of the app package to be optimized. This results in a smaller APK size and cleaner release builds without breaking functionality.

android/app · high confidence

Redesigned Settings UI with new About, Donate, and Cache Management pages

The settings interface has been modernized with several new screens. The About page now displays a structured list of contributors, translators, and special thanks, alongside direct links to source repositories and community channels. A dedicated Donate page allows users to support the project via GitHub Sponsors and other methods, with a customizable notice card. Cache Management has been added to let users inspect and clear app, temporary, and cover caches. The Appearance settings now include a live theme preview card, while the App settings page consolidates extension store visibility, update channels, and history management. Download settings have been reorganized to prioritize service selection and quality options, with a new dedicated page for configuring download fallback extensions.

lib/screens/settings · high confidence

Redesigned album and artist detail screens with motion headers and selection mode

The album and artist detail screens have been rebuilt to feature a unified, collapsible header layout that supports motion-artwork banners (video or image) and a sticky app bar title that appears on scroll. Both screens now include a multi-select mode for batch operations, such as adding tracks to playlists or sharing, and integrate with the new extension system to fetch metadata and cover art. The artist screen additionally displays monthly listeners, organizes discography into albums, singles, and compilations, and supports a favorite-artists collection.

lib/screens · high confidence

Removal of legacy Android MainActivity class

The explicit MainActivity class extending FlutterActivity has been removed from the Android application. This change indicates a shift in how the app initializes, likely relying on Flutter's default embedding behavior or a newer configuration method, rather than requiring a custom Kotlin activity entry point.

android/app/src/main/kotlin/com/example · high confidence

Standardized Android ARM release build and refined iOS backend build script

The Android build script now explicitly targets ARM and ARM64 architectures for release APKs and embeds the short Git commit hash into the app via dart-define, ensuring consistent ABI-specific builds. The iOS build script has been updated to use stricter shell safety settings, install gomobile from the version pinned in go.mod rather than the latest, and apply the 'ios' build tag when generating the Go backend XCFramework, improving build reliability and consistency with the project's dependency management.

scripts · high confidence

Unified design tokens, AMOLED dark mode, and Android back-navigation fix

The app now uses a single source of truth for visual scale (radii, spacing, motion durations) via the new AppTokens theme extension, ensuring consistent sizing across components. Dark mode gains an AMOLED option that forces pure black backgrounds and adjusts surface colors for OLED displays. On Android, the predictive-back gesture regression is resolved by overriding page transitions to use standard fade-forward animations, restoring correct modal dismissal order. Additionally, detail screens can now derive their header color scheme dynamically from album cover art.

lib/theme · high confidence

iOS build configuration updated to support local Swift packages and new framework dependencies

The iOS project configuration has been updated to integrate the Gobackend.xcframework and the FlutterGeneratedPluginSwiftPackage. This includes adding the new Swift source files (DownloadProgressSubscription.swift and ExtensionCallbackParser.swift) to the build, linking the required frameworks, and configuring the Xcode scheme to run the Flutter preparation script before building. These changes ensure the app correctly embeds and links the new backend framework and manages plugin dependencies via Swift Package Manager.

ios/Runner.xcodeproj · high confidence

iOS minimum version raised to 16 and Go backend framework integration added

The iOS deployment target has been updated from 13.0 to 16.0, meaning the app now requires iOS 16 or later to run. Additionally, the build configuration now includes the local 'Gobackend' framework (Gobackend.xcframework) by adding its search paths and linking flags, and the workspace has been updated to include the CocoaPods project, enabling the app to utilize this native Go backend component.

ios/Flutter · high confidence

Test coverage

Added tests for download progress subscription isolation and extension callback parsing; Added unit tests for native download and finalization policies; Expanded test coverage for UI, audio, and download features.

Dependencies

Gradle wrapper upgraded to version 9.7.1 with enhanced network resilience

The Android build system now uses Gradle 9.7.1 instead of 8.14. This update includes configuration for improved network stability, specifically adding a 10-second timeout, retry logic with a 500ms backoff, and strict distribution URL validation to ensure build integrity.

android/gradle · high confidence

Major dependency and build system upgrades across Android, iOS, and Go

This release upgrades the underlying build infrastructure and dependencies to support newer platform versions and improve stability. On Android, the project migrates from Groovy to Kotlin DSL (build.gradle.kts), upgrades the Android Gradle Plugin to v9.3.2 and Kotlin to v2.4.10, and targets Android SDK 37 with Java/Kotlin 25. It also enables ProGuard shrinking, splits APKs by ABI to reduce size, and updates core libraries like coroutines and lifecycle components. On iOS, the minimum deployment target is raised to iOS 16, and a patch is added to support older Xcode SDKs for device info. The Go backend is upgraded to Go 1.26.6 to fix ARM32 crashes, and the Flutter app updates numerous packages including FFmpeg, audio services, and navigation libraries, while also adding monochrome icon support and localization assets.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 60 → 64 (+3.6)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 92 → 72 (-19.9)
  • Architecture 96 → 97 (+0.9)
  • Maturity 54 → 55 (+0.9)
  • Readiness 59 → 61 (+1.4)
  • Security 53 → 82 (+28.8)
  • Domain Modelling 100 → 100 (+0.0)

Resolved (60)

  • Boundary-crossing change coupling: download_queue_provider.dart ↔ downloaded_embedded_cover_resolver.dart (lib/providers/download_queue_provider.dart)
  • Boundary-crossing change coupling: downloaded_album_screen.dart ↔ audio_conversion_utils.dart (lib/screens/downloaded_album_screen.dart)
  • Boundary-crossing change coupling: exports.go ↔ download_item.dart (go_backend/exports.go)
  • Boundary-crossing change coupling: local_album_screen.dart ↔ audio_conversion_utils.dart (lib/screens/local_album_screen.dart)
  • Boundary-crossing change coupling: queue_tab.dart ↔ audio_conversion_utils.dart (lib/screens/queue_tab.dart)
  • Boundary-crossing change coupling: queue_tab.dart ↔ batch_convert_sheet.dart (lib/screens/queue_tab.dart)
  • Change coupling: exports.go ↔ extension_timeout.go (go_backend/exports.go)
  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • FileTooLong: screens/local_album_screen.dart (lib/screens/local_album_screen.dart)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 40 more

New (940)

  • ApkDownloader.downloadApk (cognitive 56) (lib/services/apk_downloader.dart)
  • ApkDownloader.downloadApk (cyclomatic 30) (lib/services/apk_downloader.dart)
  • AppDelegate.invokeGoMethod (cognitive 168) (ios/Runner/AppDelegate.swift)
  • AppDelegate.invokeGoMethod (cyclomatic 193) (ios/Runner/AppDelegate.swift)
  • AppStateDatabase.migrateQueueFromSharedPreferences (cognitive 19) (lib/services/app_state_database.dart)
  • AppStateDatabase.migrateRecentAccessFromSharedPreferences (cognitive 34) (lib/services/app_state_database.dart)
  • AppStateDatabase.migrateRecentAccessFromSharedPreferences (cyclomatic 19) (lib/services/app_state_database.dart)
  • AudioMetadataMapper.convertToId3Tags (cyclomatic 30) (lib/services/audio_metadata_mapper.dart)
  • AudioMetadataMapper.normalizeToVorbisComments (cognitive 18) (lib/services/audio_metadata_mapper.dart)
  • AudioMetadataMapper.normalizeToVorbisComments (cyclomatic 40) (lib/services/audio_metadata_mapper.dart)
  • AudioMetadataMapper.vorbisToNativeChunkFields (cognitive 21) (lib/services/audio_metadata_mapper.dart)
  • AudioMetadataMapper.vorbisToNativeChunkFields (cyclomatic 45) (lib/services/audio_metadata_mapper.dart)
  • BackupService._parseArchive (cognitive 47) (lib/services/backup_service.dart)
  • BackupService._parseArchive (cyclomatic 22) (lib/services/backup_service.dart)
  • BackupService.writeBackupArchive (cognitive 39) (lib/services/backup_service.dart)
  • BackupService.writeBackupArchive (cyclomatic 16) (lib/services/backup_service.dart)
  • BatchReEnrichRunner.preview (cognitive 20) (lib/services/local_track_batch_actions.dart)
  • Boundary-crossing change coupling: exports.go ↔ explore_provider.dart (go_backend/exports.go)
  • Change coupling: downloaded_album_screen.dart ↔ local_album_screen.dart (lib/screens/downloaded_album_screen.dart)
  • Change coupling: extension_runtime_auth.go ↔ extension_runtime_file.go (go_backend/extension_runtime_auth.go)
  • …and 920 more

Changes since last survey

  • 248 commits — 134 feature/other, 114 fixes

By area

  • lib/l10n — 59 commits
  • lib/screens — 43 commits
  • android/app — 25 commits
  • lib/services — 20 commits
  • lib/providers — 19 commits
  • (root) — 17 commits
  • lib/widgets — 10 commits
  • (repo) — 4 commits
  • lib/utils — 4 commits
  • .github/workflows — 3 commits
  • go_backend/extension_fallback.go — 3 commits
  • go_backend/title_match_utils.go — 3 commits
  • ios/Runner — 3 commits
  • docs/EXTENSION_DEVELOPMENT.md — 2 commits
  • go_backend/audio_metadata.go — 2 commits
  • go_backend/coverage_test_helpers_test.go — 2 commits
  • go_backend/download_comment_test.go — 2 commits
  • go_backend/extension_availability_verification_test.go — 2 commits
  • lib/models — 2 commits
  • go_backend/cover.go — 1 commit

Notable commits

  • fix: fix(altstore): match source bundle ID to released IPA
  • fix: fix(analysis): bound spectrogram memory for large files
  • fix: fix(analysis): reject false low spectral cutoffs
  • fix: fix(analysis): reject false spectral rolloff cutoffs
  • fix: fix(android): scope SAF read failures to each descriptor
  • fix: fix(audio): preserve Opus codec in M4A scans
  • fix: fix(audio-analysis): avoid spectrogram splice noise
  • fix: fix(auth): preserve shared signed-session challenge identity
  • fix: fix(backup): allow selecting SFLB archives for restore
  • fix: fix(backup): use compact sflb file extension
  • fix: fix(build): hide unexported lyrics search results from gomobile
  • fix: fix(ci): harden release workflow inputs and actions
  • fix: fix(ci): standardize Android ARM release build
  • fix: fix(conversion): preserve Unicode SAF document names
  • fix: fix(conversion): reserve FLAC outputs without overwriting files
  • fix: fix(cover): preserve best max-quality candidate #511
  • fix: fix(cover): preserve provider high-resolution artwork
  • fix: fix(database): cache unavailable FTS5 capability
  • fix: fix(db): prevent concurrent startup locks
  • fix: fix(download): accept matching tracks across releases
  • …and 228 more

Architecture

  • Containers 0 added · 0 removed · contexts 1 added · 1 removed · edges 0 added · 0 removed

Added bounded contexts (1)

  • app

Removed bounded contexts (1)

  • android

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

spotiflacapp/SpotiFLAC-Mobile was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit a34e2935442e7ec661c539ab3c2df8fc0b23b1ff — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.