Skip to content
CAI
Software that uses CAICheck a score

square/picasso

53.9

Adequate · 25 September 2026

6.8k

lines of production code

Kotlin

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Add Kotlin-based stats event listener for memory, network, and bitmap metrics

The Picasso stats module now provides a new \StatsEventListener\ implementation in Kotlin that tracks cache hits/misses, download sizes, and bitmap decoding/transformation statistics. Users can access a \Snapshot\ of these metrics via \getSnapshot()\ and log them using \dump()\, enabling deeper insight into image loading performance and memory usage.

picasso-stats/src · high confidence

Add PollexorRequestTransformer for Thumbor image transformations

The Picasso library now includes a new PollexorRequestTransformer that integrates with the Thumbor image processing service. This transformer intercepts image requests and converts them into Thumbor URLs, applying server-side transformations such as resizing, center-cropping, and format conversion (WebP). Users can configure the transformer with a Thumbor host, optional encryption keys, and a callback to apply custom filters, enabling seamless offloading of image processing to Thumbor.

picasso-pollexor/src · high confidence

New Picasso Compose integration for image loading

The Picasso library now includes a new \picasso-compose\ module that provides a \rememberPainter\ extension function, allowing developers to load images as Compose \Painter\ objects. This feature enables dynamic image loading in Jetpack Compose UIs, with the implementation ensuring that requests are aware of state changes and avoiding redundant network calls when the request configuration remains unchanged.

picasso-compose · high confidence

Picasso 3.0 public API surface defined

The public API for Picasso 3.0 is now explicitly defined, introducing a new package structure under com.squareup.picasso3. This includes the main Picasso class and its Builder, along with supporting interfaces and classes such as BitmapTarget, Callback, DrawableTarget, EventListener, MemoryPolicy, NetworkPolicy, and Request. The API exposes lifecycle observer capabilities, custom HTTP header support via Request headers, and coroutine-based dispatchers for internal threading control.

picasso/api · high confidence

API

Introduce Picasso Stats API for monitoring image loading

A new API contract file (picasso-stats.api) is added to the picasso-stats/api location, defining the public interface for the StatsEventListener and its nested Snapshot class. This establishes the stable API surface for accessing image loading statistics, including cache metrics, download counts, and bitmap size data, enabling users to programmatically monitor Picasso's internal performance and state.

picasso-stats/api · high confidence

Behavioural changes

Added API signature file for Picasso Pollexor

A new API signature file (picasso-pollexor.api) was added to define the public surface of the Picasso Pollexor module. This establishes the ABI contract for the PollexorRequestTransformer class and its associated Callback interface, enabling ABI validation to ensure future changes remain compatible with existing users.

picasso-pollexor/api · high confidence

New website layout and theme

The website received a new layout and visual theme. A new \app-theme.css\ file defines a red color scheme (primary color \#b94948) for headers, links, and syntax highlighting. A new \app.css\ file provides the structural styles, including a fixed header, sidebar navigation, and responsive breakpoints for mobile and tablet views. Additionally, the site now includes \bootstrap-combined.min.css\ (v2.3.1) to provide base styling for grid, forms, and components.

website/static · high confidence

Picasso core library converted to Kotlin

The Picasso core library has been converted from Java to Kotlin. This change affects the internal implementation of the image loading and caching logic, including the dispatcher, bitmap handling, and request processing. Users of the library will not see changes to the public API, but the internal codebase is now written in Kotlin.

picasso/src/main · high confidence

Picasso library is deprecated and no longer receiving public releases

The README has been updated to announce that Picasso is deprecated and users should migrate to alternatives like Coil. The project will no longer publish new public releases to Maven Central, though existing versions will continue to function. The release process has been formalized in a new RELEASING.md file, and the CHANGELOG has been updated to include version 2.71828. Additionally, the project migrated its CI from Travis to GitHub Actions, and updated the Gradle wrapper and build configuration.

(repo-wide) · high confidence

Picasso website receives a complete layout overhaul

The website's index page has been completely redesigned with a new layout, updated navigation, and refreshed content structure. The page now features a more modern header, improved sidebar navigation, and updated code examples. Links to the Javadoc and community resources have been updated to point to the new locations.

website · high confidence

Rewrite the Picasso sample app in Kotlin with a Compose UI

The sample application has been converted from Java to Kotlin and now features a new Compose-based UI for browsing images. The app initializes Picasso using AndroidX Startup, and the sample activities (GridView, List/Detail, Gallery, Contacts, and Compose) are all implemented in Kotlin, providing a modern, idiomatic example of using the library.

picasso-sample/src/main/java · high confidence

Test coverage

Add Paparazzi snapshot test for Picasso image loading; Added Robolectric configuration for Android tests; Converted core Picasso test classes to Kotlin; Ported unit tests to Android instrumentation; Updated Mockito configuration for inline mocking.

Dependencies

Migrate build system from Maven to Gradle with updated dependencies

The project has been migrated from a Maven-based build system to Gradle, utilizing a version catalog (gradle/libs.versions.toml) to manage dependencies. Key library updates include OkHttp 4.12.0, Okio 3.9.0, Kotlin 2.0.0, and AndroidX components such as Fragment 1.8.1 and Core 1.13.1. The build configuration now enforces strict null checking with Nullaway and uses Spotless for code formatting. Additionally, the project has been updated to compile against Android SDK 34 and targets a minimum SDK of 21.

(dependencies) · high confidence

Upgraded Gradle wrapper to version 8.10.2

The project's Gradle wrapper has been updated to version 8.10.2, ensuring that builds use this specific distribution. This change affects the build environment and may introduce new build behaviors or compatibility requirements associated with the Gradle 8.x series.

gradle/wrapper · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 41 → 54 (+13.3)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 97 → 91 (-5.5)
  • Architecture 96 → 100 (+4.1)
  • Maturity 32 → 31 (-0.9)
  • Readiness 32 → 67 (+35.2)
  • Security 37 → 70 (+32.7)

Resolved (27)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • Duplicated block (12 lines × 2) (picasso-sample/src/main/java/com/example/picasso/SampleComposeActivity.kt)
  • Duplicated block (6 lines × 2) (picasso/src/main/java/com/squareup/picasso3/MatrixTransformation.kt)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • …and 7 more

New (46)

  • BaseDispatcher.performPauseTag (cognitive 29) (picasso/src/main/java/com/squareup/picasso3/BaseDispatcher.kt)
  • Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no licence statement (README.md)
  • Dormant codebase
  • Duplicated block (10 lines × 2) (picasso-sample/src/main/java/com/example/picasso/SampleComposeActivity.kt)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • …and 26 more

Architecture

  • Containers 0 added · 0 removed · contexts 3 added · 0 removed · edges 2 added · 0 removed

Added bounded contexts (3)

  • picasso
  • picasso-compose
  • picasso-stats

Added dependency edges (2)

  • picasso-compose → picasso
  • picasso-stats → picasso

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

square/picasso was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit e94d6116e3fff99b3932103e0ab22ff5b44a1273 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-dd72cc24c749.