Skip to content
CAI
Software that uses CAICheck a score

square/Valet

63.8

Adequate · 30 September 2026

3.1k

lines of production code

Swift

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Valet is a Swift library for secure keychain storage on Apple platforms, providing APIs for local, iCloud-synced, and Secure Enclave-protected data access. It supports iOS, macOS, tvOS, and watchOS, featuring modern concurrency safety and biometric authentication controls. The system includes comprehensive test suites and build automation to ensure cross-platform compatibility and data integrity.

How it got here

2015 — Swift migration and Secure Enclave adoption

6 changes.

The Valet library was rewritten from Objective-C to Swift, shifting its primary keychain security implementation to use the Secure Enclave for biometric authentication. This period involved migrating the project structure, updating build configurations, and rewriting sample applications to align with modern Xcode standards and Swift 6 requirements.

2017–2018 — multi-platform test host scaffolding

7 changes.

The project established dedicated test host applications for iOS, macOS, tvOS, and watchOS to enable comprehensive keychain testing across all Apple platforms. This work involved creating the necessary application structures, entitlements, and asset catalogs while aligning the test bundle configuration with Swift Package Manager conventions.

2019–2024 — Valet 4.0 concurrency and Secure Enclave support

7 changes.

The project advanced to version 4.0, adopting Swift 6 concurrency with full Sendable conformance and introducing new Secure Enclave classes for biometric-protected data storage. Internal keychain logic was refactored for cross-platform safety and migration support, while comprehensive integration and unit tests were added to validate these new features across iOS, macOS, tvOS, and watchOS.

Features

Add Valet iOS Test Host App scaffolding

The Valet iOS Test Host App is introduced as a new test target, providing the necessary iOS application structure to exercise the Valet library. This includes standard project assets such as the app icon set, launch screen, and main storyboard, along with configuration files like Info.plist and entitlements. The entitlements specifically configure access to the 'group.valet.test' application group and keychain access groups, enabling the test host to interact with shared keychain storage for testing purposes.

Valet iOS Test Host App · high confidence

Add signed macOS test host app for keychain testing

A new macOS test host application has been added to enable testing of signed keychain code. The app includes a standard Cocoa interface (AppDelegate, ViewController, and Main storyboard) and is configured with entitlements for app sandboxing, application groups, and specific keychain access groups, allowing the test suite to verify behavior with properly signed binaries.

Valet macOS Test Host App · high confidence

Add tvOS test host application

A new test host application for tvOS has been added to support testing the Valet library on Apple TV. This includes the standard iOS application structure (AppDelegate, ViewController, Main storyboard) along with tvOS-specific asset catalogs for app icons and top-shelf images, and an entitlements file configured with the necessary keychain access groups for the test environment.

Valet tvOS Test Host App · high confidence

Added TouchID test storyboard for secure element operations

A new storyboard file (ValetSecureElementTestMain.storyboard) has been added to the ValetTouchIDTest localization bundle. This UI provides a test interface for the Valet TouchID feature, allowing users to perform secure element operations such as setting, getting, and removing items, checking for item existence, and requiring a biometric prompt.

ValetTouchIDTest/en.lproj · high confidence

Added watchOS test host app configuration and assets

A new watchOS test host application has been added to support running the full XCTest suite on watchOS devices. This includes the necessary app icon assets for various watch sizes and roles, an Info.plist defining the app bundle and its companion iOS app, entitlements for shared application groups, and a basic Interface.storyboard for the watch interface controller.

Valet watchOS Test Host App · high confidence

Added watchOS test host app structure

A new watchOS test host application has been added to support running tests on the watchOS platform. This includes the necessary SwiftUI app entry point, a basic content view, and associated asset catalogs for icons and colors, enabling the Valet library's test suite to execute in a watchOS environment.

Valet watchOS Test Host App Watch App · high confidence

Behavioural changes

Added Info.plist for Sources module

A new Info.plist file has been added to the Sources directory, establishing the standard metadata configuration (such as bundle identifier, version, and copyright) required for the module under the adopted SPM file structure.

Sources · high confidence

Automated multi-platform build and coverage reporting

The project now includes a Swift-based build script that automates compilation and testing across iOS 18, tvOS 18, macOS 15, and watchOS 11, supporting both Swift Package Manager and Xcode build systems. A companion shell script handles uploading code coverage reports to Codecov for the generated derived data, streamlining the CI process for these specific platform configurations.

Scripts · high confidence

Internal keychain access logic restructured for platform safety and migration support

The internal implementation of keychain operations has been refactored to improve cross-platform compatibility and data integrity. The new \Service\ configuration now applies the \kSecUseDataProtectionKeychain\ attribute to the base query on all platforms, addressing previous inconsistencies where it was only applied on macOS. Additionally, the \Keychain\ class now includes a dedicated \migrateObjects\ method, enabling the safe transformation and migration of existing keychain values. These changes are part of a broader internal restructuring that also introduces thread-safe wrappers for SecItem calls and centralized configuration enums.

Sources/Valet/Internal · high confidence

Updated Xcode project schemes for modern build configurations

The shared Xcode project schemes (including Valet Mac, iOS, tvOS, watchOS, and their respective test hosts) have been regenerated to version 1.3/1.7 with a LastUpgradeVersion of 1600. This update standardizes build settings across all targets, enabling parallel builds, implicit dependency building, and code coverage for test actions, while ensuring consistent debugger and launcher identifiers for reliable debugging and testing workflows.

Valet.xcodeproj/xcshareddata · high confidence

Valet 4.0 introduces Swift 6 concurrency, new Secure Enclave types, and explicit identifiers

Valet has been updated to version 4.0, adopting Swift 6 and Xcode 16 with full Sendable conformance across core types to support modern concurrency. The library now exposes new \SecureEnclaveValet\ and \SinglePromptSecureEnclaveValet\ classes for storing data on the Secure Enclave with configurable biometric access controls, alongside new \Identifier\ and \SharedGroupIdentifier\ structs that allow explicit, user-defined keychain service identifiers. Existing APIs have been refactored to use these new types, and \CloudAccessibility\ has been separated from \Accessibility\ to distinguish iCloud-synced items from local-only ones.

Sources/Valet · high confidence

Valet API refactored to use Secure Enclave

The Valet library has been updated to replace the previous SecureElement implementation with SecureEnclave. This change involves removing the legacy Valet.h and Valet.m interface files and introducing the new VALSinglePromptSecureEnclaveValet component, which alters how user presence authentication is handled for keychain operations.

Valet · high confidence

Valet project structure migrated to Swift and modern Xcode standards

The Valet iOS/macOS library has been rewritten in Swift, replacing the previous Objective-C implementation. This change introduces a new project structure with Swift-based source files (such as Valet.swift, SecureEnclave.swift, and Configuration.swift) and updates the Xcode project file to reflect modern build settings and object versions. The migration includes the addition of new test suites for Swift components and the integration of legacy Objective-C support via a separate LegacyValet framework, ensuring backward compatibility while shifting the primary development focus to Swift.

Valet.xcodeproj · high confidence

ValetTouchIDTest app rewritten in Swift with Secure Enclave support

The ValetTouchIDTest sample application has been rewritten in Swift to demonstrate the SinglePromptSecureEnclaveValet class. This update introduces a new launch screen and configures the app to request Face ID usage permissions. The test interface now allows users to store, retrieve, remove, and check for the existence of keychain items protected by the Secure Enclave, including a new 'Require Prompt' button that forces biometric authentication on the next access attempt.

ValetTouchIDTest · high confidence

Test coverage

Added unit tests for Valet configuration, keychain errors, and valet initialization; Added watchOS test host app extension scaffolding; Adopt SPM file structure for test bundle; Expanded integration test coverage for Valet keychain operations; Removed legacy Objective-C test suite.

Dependencies

Valet 5.1.0 release with Swift 6 and platform updates

This update releases Valet version 5.1.0, adopting Swift 6 and requiring Swift 6.0 for both CocoaPods and Swift Package Manager builds. The library now supports iOS 12+, tvOS 12+, watchOS 5+, and macOS 10.13+. The CocoaPods dependency for CI has been updated to version 1.16.0, and the Gemfile.lock reflects updated transitive dependencies including activesupport 7.2.3.1, addressable 2.9.0, and rexml 3.4.2.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 70 → 64 (-5.9)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 92 → 92 (+0.0)
  • Architecture 100 → 99 (-0.8)
  • Maturity 53 → 53 (+0.0)
  • Readiness 70 → 52 (-18.4)
  • Security 100 → 100 (+0.0)

New (5)

  • Coverage not measured — Swift suite
  • Duplicate factory methods with inconsistent naming and parameter types. The public API exposes both valet/sharedGroupValet (taking typed Identifier/SharedGroupIdentifier) and 🚫swift_valet/🚫swift_sharedGroupValet (taking raw Strings). The 🚫 prefix suggests these are deprecated or internal, but they are exposed in the public surface. Furthermore, the sharedGroupValet variants have inconsistent parameter orders and types (e.g., appIDPrefix vs groupPrefix vs SharedGroupIdentifier).
  • Duplicate factory methods with subtle naming differences (with vs withExplicitlySet). The distinction between these methods is not clear from the signatures alone. It is likely that withExplicitlySet is for cases where the identifier is already fully formed, while with might involve some generation or lookup, but this is not obvious.
  • Inconsistent migration API signatures. The migrateObjects method has two distinct overloads for the same operation (matching and from) that differ only in the second parameter (compactMap vs removeOnCompletion). This is confusing because compactMap implies a transformation/filtering step, while removeOnCompletion implies a side effect. It is unclear if these are mutually exclusive options or if one is deprecated.
  • Redundant objc_ prefixed methods that duplicate functionality of non-prefixed methods. The objc_ methods appear to be identical in signature and intent to their non-prefixed counterparts (e.g., objc_setObject vs setObject). This creates confusion about which method to use and violates the principle of least surprise.

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

square/Valet was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 43f517941ced37752c0cd5e2b53a3c9d021c848b — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-cb25ca4feafa.