tryzealot/zealot
52.2
Adequate · 19 September 2026
12.5k
lines of production code
Ruby
with JavaScript
1
measurement over time
What this system is
Zealot is a self-hosted application distribution and management platform that handles the ingestion, parsing, and delivery of mobile and desktop app builds. It provides a comprehensive admin interface for managing Apple developer credentials, system backups, and user collaboration, while offering public-facing APIs and web interfaces for release uploads, debug file management, and OTA installation. The system supports granular access control, real-time monitoring, and multi-platform metadata extraction to streamline the software release lifecycle.
How it got here
2014–2019 — Rails 7/8 modernization and feature expansion
52 changes.
The project underwent a comprehensive modernization, upgrading the backend to Rails 7 and 8 while migrating the frontend to Vite, Hotwire, and Bootstrap 5. This period established a robust foundation with granular Pundit-based authorization, Apple developer integration, and a complete GraphQL API. It also introduced critical operational features including app archiving, debug file management, and a redesigned admin panel for system configuration.
2020–2024 — Admin interface modernization and backup infrastructure
31 changes.
This period focused on overhauling the admin panel with a modern, responsive UI using Turbo streams, dark mode, and modular styling, while introducing comprehensive backup management capabilities. Significant work also went into expanding the API surface with new debug file and release download endpoints, alongside establishing robust test coverage via Swagger/OpenAPI specifications.
2025–2026 — Frontend modernization and admin enhancements
13 changes.
This period focused on modernizing the frontend architecture by migrating to Vite, Tailwind CSS, and DaisyUI, while restructuring JavaScript with Stimulus controllers for dynamic UI behaviors. It also introduced new administrative tools, including real-time service management, log viewing, and configuration validation, alongside enhanced security through GraphQL field-level validators and Gitea OAuth integration.
Features
Add ActionCable channel infrastructure and log channel
The application now includes the base ActionCable channel and connection classes, enabling real-time WebSocket communication. The connection class identifies users via Warden and tags logs with the user ID, while a new LogChannel is added to handle logging events, addressing previous missing log channel issues.
app/channels · high confidence
Add Gitea OAuth strategy
Users can now authenticate with Gitea accounts. This change introduces a new OmniAuth strategy for Gitea, enabling single sign-on integration with Gitea instances using the default Gitea.com endpoints.
_lib/omni\auth · high confidence
Add GraphQL field-level authentication and authorization validators
New validators have been added to the GraphQL layer to enforce access control at the field level. The \AuthenticatedValidator\ ensures that a user is logged in before accessing specific fields, raising an error if the current user is missing. Additionally, the \AdminOnlyValidator\ restricts access to fields requiring administrative privileges, checking for the admin role on the current user. These validators can be attached to GraphQL fields to automatically enforce these security constraints during query execution.
app/graphql/validators · high confidence
Added Docker build rake task
A new rake task \docker:build\ has been added to the application, allowing users to build the Docker image using the \tryzealot/zealot:dev\ tag directly from the command line.
lib/tasks · high confidence
Added Slim template for scaffold forms
A new Slim template for scaffold forms has been added to the library, providing a structured form layout that iterates over model attributes to generate input fields and includes error notifications and submission buttons.
lib/templates · high confidence
Added custom 50x server error pages
New custom error pages have been added for HTTP 500 (Internal Server Error), 502 (Bad Gateway), 503 (Service Unavailable), 504 (Gateway Timeout), and 505 (HTTP Version Not Supported). These pages provide a consistent, branded user experience with clear status descriptions and actionable guidance, replacing any default server error responses.
public/errors · high confidence
Admin web hooks management interface added
The admin panel now includes a dedicated interface for managing web hooks, allowing administrators to view, edit, and delete hook configurations. The new index page lists existing web hooks with their associated channel counts and provides links to edit or remove them, while the edit page enables modification of the hook URL, payload body, and specific event triggers (upload, download, changelog). A new console view has also been added to test web hook payloads directly from the admin interface.
_app/views/admin/web\_hooks, app/views/web\hooks · high confidence
Bulk delete capability for channel releases
Users can now select and delete multiple releases at once from a channel's filter list. The new interface includes a bulk selection checkbox, a 'Delete All' button for the current view, and a confirmation modal to prevent accidental data loss, streamlining the management of release versions.
app/views/channels/filters · high confidence
Custom user authentication controllers for passwordless login and OAuth integration
The application now uses custom Devise controllers in the users namespace to support passwordless (magic link) authentication, third-party OAuth logins (including GitHub organization validation), and passwordless profile updates. Users can now log in via magic links without a password, connect or sign in using external providers like GitHub, GitLab, and Feishu, and update their profile information without re-entering their current password. The system also handles OAuth callback routing, organization membership checks for GitHub, and redirects appropriately after successful authentication or account linking.
app/controllers/users · high confidence
Database schema initialization and admin setup automation
The database schema is now defined in \db/schema.rb\ (version 2025\_12\_18\_081921), establishing the core data model including tables for apps, users, devices, debug files, and background job processing via \good\_job\. The \seeds.rb\ script has been updated to automatically create a default admin account and populate example application data during initialization, configurable via the \ZEALOT\_SKIP\_SAMPLE\_DATE\ environment variable.
db · high confidence
First-time third-party login now emails a default password
When a user logs in via a third-party provider for the first time, they now receive a welcome email containing a generated default password. This new email template displays the user's name and the password in a success-styled badge, ensuring users have initial access credentials when linking an external account.
_app/views/user\mailer · high confidence
GraphQL API scaffolding with Pundit authorization and App/User types
The GraphQL layer in app/graphql/types has been initialized with a new schema structure, introducing base type classes (Object, InputObject, Argument, etc.) and specific types for App, User, and Release. This change integrates Pundit for authorization, enforcing access controls on fields such as User email and token, and requiring explicit authorization checks in QueryType methods for fetching User and App records. The API now exposes root-level query fields for users, apps, and a test echo endpoint, establishing the foundation for data retrieval and permission enforcement.
app/graphql/types · high confidence
Initial project scaffolding and configuration
The repository has been initialized with the core configuration files required to run the Zealot application. This includes a multi-stage Dockerfile targeting Ruby 3.4.8 and Node.js 24.12.0, a \.mise.toml\ file for managing development tasks (web, worker, vite, caddy), and a \vite.config.mts\ file configuring the Vite asset pipeline with Tailwind CSS. The project also introduces a \Procfile\ for defining web and worker processes, a \render.yaml\ for deployment on Render, and a \crowdin.yml\ for localization management. Additionally, standard project files such as \README.md\, \LICENSE\, \SECURITY.md\, and \.rubocop.yml\ have been added to establish the project's structure and coding standards.
(repo-wide) · high confidence
Introduce VS Code Dev Container for local development
Developers can now use a pre-configured VS Code Dev Container to run the application locally. The setup includes a base image built on Debian Trixie with mise for managing Ruby and Node.js versions, along with tools like lazygit, tig, and tmux. The environment is configured with specific VS Code extensions (Ruby LSP, Tailwind CSS, etc.) and mounts SSH keys. It uses Docker Compose to spin up a PostgreSQL 18 database and a pgweb 0.17.0 UI service, automatically creating the necessary development and test databases on startup.
.devcontainer · high confidence
Introduce database and uploads backup logic
The \lib/zealot/backup\ directory now contains the core implementation for creating and restoring backups. This includes a new \Database\ class that handles PostgreSQL dumps and restores using \pg\_dump\ and \psql\, an \Uploads\ class for archiving and restoring application file uploads, and a \Manager\ class that orchestrates the process, generates a SHA256 checksum for integrity verification, and manages backup retention.
lib/zealot/backup · high confidence
Introduce new data models for app collaboration, Apple developer integration, and system configuration
The application now supports app-level collaboration through a new \Collaborator\ model, allowing users to be assigned roles (member, developer, admin) and ownership on apps. Apple developer integration is handled by new \AppleKey\, \AppleTeam\, and \AppleKeyDevice\ models, which manage API keys, teams, and device synchronization with Apple's services. System configuration is centralized in a new \Setting\ model backed by \rails-settings-cached\, supporting dynamic fields for site appearance, third-party authentication (OIDC, GitHub, GitLab, etc.), and analytics. Additional models include \Backup\ and \BackupScope\ for scheduled database and app backups, \DebugFile\ and \DebugFileMetadatum\ for managing dSYM and ProGuard mapping files, and updates to \App\, \Channel\, \Scheme\, \Release\, and \User\ to support these new capabilities.
app/models · high confidence
New API controllers for apps, schemes, channels, collaborators, debug files, devices, releases, users, and version
The API layer now includes dedicated controllers for managing apps, schemes, channels, collaborators, debug files, devices, releases, users, and version information. Apps, schemes, and channels are now protected by an archived-app check that blocks updates and deletions when an app is archived, and apps can be filtered by scope (active, archived, or all). Collaborators can be added, updated, and removed per app, with duplicate creation prevented. Debug files can be uploaded, listed, updated, and deleted, with uploads tied to a channel and triggering a teardown job. Devices can be updated by UDID (creating them if they do not exist), and releases can be updated or deleted. Users can be listed, searched by email, created, updated, destroyed, and locked or unlocked. The base API controller enforces token validation, provides standardized error responses (including debug details in development), sets cache-control headers, and handles common exceptions. A version endpoint returns the application version, VCS reference, and build date.
app/controllers/api · high confidence
New API endpoints for downloading and checking debug files
Added two new API controllers to handle debug file operations. The \DownloadController\ exposes a GET endpoint that allows users to retrieve debug files by searching via release/build versions, device type, or upload order, returning a redirect to the actual file URL. The \ExistsController\ provides three new GET endpoints to verify the presence of debug files: one by version metadata, one by binary checksum, and one by UUID, returning the file metadata if found.
_app/controllers/api/debug\files · high confidence
New Apple Key management interface
Administrators can now create, view, and manage Apple Developer API keys through a dedicated admin section. The new interface allows users to register keys by uploading private key files, view key and associated team metadata, and see a list of linked devices with their UDIDs and details. Key actions include downloading the private key file, syncing device information, and deleting keys via a confirmation modal.
_app/views/admin/apple\keys · high confidence
New JSON and Jinja2 validators for structured data validation
Added two new ActiveModel validators to enforce stricter validation on JSON and Jinja2 template fields. The JsonValidator allows configuration to require specific JSON structures (arrays or hashes) and control whether empty values are permitted, while the JbValidator validates Jinja2 template syntax by rendering the content and ensuring the resulting output is a valid JSON object. These changes improve data integrity for webhook bodies and settings that rely on JSON or template-based configurations.
app/validators · high confidence
New Puma control client for external management
A new \PumaControlClient\ class has been added to the library, enabling external clients to interact with the Puma control interface. It uses the Faraday HTTP library to send requests for retrieving server statistics and triggering restarts, defaulting to the \0.0.0.0:9293\ endpoint and a token from the \PUMA\_CONTROL\_URL\_TOKEN\ environment variable if not explicitly provided.
lib · high confidence
New Rake tasks for database management, demo data generation, and API documentation
This change introduces three new Rake task files in the \lib/tasks/zealot\ directory. The \zealot.rake\ file adds tasks for upgrading the database (handling setup vs. migration based on current version), checking SMTP configuration, resetting the system to demo mode, and generating Swagger API documentation files for all available locales. The \demo.rake\ file provides tasks to generate fake demo data, including creating a sample app with enterprise schemes and channels, and generating fake user accounts with specific roles. The \backup.rake\ file is added but contains only commented-out code, indicating that backup functionality is not yet active in this location.
lib/tasks/zealot · high confidence
New System Information page in admin panel
A new System Information page has been added to the admin interface, providing a comprehensive overview of the server environment. Users can now view the application version with an asynchronous new-release check, VCS reference, build date, OS, database (PostgreSQL), and Ruby versions, as well as CPU, memory, and disk usage with progress indicators. The page also displays file permission health checks, mounted volume details, a collapsible section for system environment variables (with secure masking for sensitive keys), and a list of installed Ruby gems.
_app/views/admin/system\info · high confidence
New admin interface controllers for service management, logging, and configuration
This change introduces a suite of new Stimulus controllers in the admin frontend to enhance the administrative user experience. The ServiceController allows users to restart services with automatic health-check polling and visual status feedback. The LogsController provides real-time log viewing with configurable refresh intervals and auto-scrolling. The CronController enables live validation of cron schedule expressions via an API endpoint. The SMTPVerifyController facilitates testing SMTP configurations with loading states, and the NewReleaseController checks for and displays available software updates. These controllers are registered in the admin index and rely on shared utilities like Zealot for logging and turboStream for form submissions.
app/frontend/javascript/controllers/admin · high confidence
New admin log viewer with real-time updates and multi-file support
A new log viewing interface has been added to the admin panel, allowing administrators to view and switch between multiple log files via tabs. The viewer supports real-time log streaming with configurable refresh intervals (1, 2, 5, or 10 seconds) and includes loading and error state messages. The interface is localized and uses a responsive card-based layout with tab navigation for selecting different log sources.
app/views/admin/logs · high confidence
New admin panel controllers for system management
The application introduces a dedicated admin panel by adding a set of new controllers in the app/controllers/admin directory. These controllers provide the backend logic for managing Apple developer credentials (keys and teams), configuring and executing database backups with scheduling and download capabilities, viewing and streaming server logs, monitoring system health and disk usage, managing user accounts (including lock/unlock and confirmation resending), editing global system settings, and configuring webhooks. This establishes the core administrative interface for system configuration and maintenance.
app/controllers/admin · high confidence
New controllers for filtering and managing channel releases by branch, type, and version
Three new controllers—Branches, ReleaseTypes, and Versions—have been added to the channels area, enabling users to view and bulk-delete releases filtered by specific branches, release types, or version numbers. Each controller implements pagination for the release lists and enforces authorization checks (e.g., :branches?, :release\_types?, :versions?, :destroy\_releases?) before allowing access or deletion, ensuring that users can only manage releases they are permitted to see or remove.
app/controllers/channels · high confidence
New database analytics dashboard view
A new view for the database analytics section has been added to the admin panel. This page displays an embedded iframe that loads the PgHero analytics interface, providing administrators with a dedicated space to view database performance metrics.
_app/views/admin/database\analytics · high confidence
New debug file management interface for iOS and Android
The application now includes a dedicated debug file management section, allowing users to upload and view debug symbols for both iOS (dSYM) and Android (ProGuard mapping) platforms. The new interface features an app-centric index page that displays counts for iOS and Android debug files per application, a device-specific list view showing file versions, processing status, and metadata, and detailed show pages that present architecture/UUID information for iOS and file details for Android. Users can upload new debug files via a form that supports pre-filled parameters, download processed files, re-trigger background parsing tasks, and delete entries, with access controlled by app-level management permissions.
_app/views/debug\files · high confidence
New device detection and native confirmation dialog utilities
Added new JavaScript utility modules in the frontend utils directory to enhance user interaction and environment detection. The helpers module introduces functions to detect specific operating systems (iOS, macOS, non-Apple) and devices using ua-parser-js, alongside a generic polling mechanism and Turbo Stream integration. The modal module replaces previous dialog implementations with a native HTML \<dialog\>-based confirmation system that supports customizable titles, messages, and button labels, featuring distinct visual styles for confirm and alert variants.
app/frontend/javascript/utils · high confidence
New download controllers for debug files and app releases
The application introduces two new controllers under the download namespace: DebugFilesController and ReleasesController. DebugFilesController handles the retrieval and attachment of debug files, ensuring they exist before serving. ReleasesController manages app release downloads, adding a password verification step for protected releases and triggering a webhook event upon successful download to notify the system of the action.
app/controllers/download · high confidence
New model concerns for backup verification, release parsing, and user authentication
This change introduces a suite of new model concerns in the \app/models/concerns\ directory to support recent feature additions. \BackupFile\ adds SHA256 checksum verification for backup integrity. \ReleaseParser\ handles app metadata extraction and icon fetching for iOS, Android, macOS, Windows, and HarmonyOS. \ReleaseAuth\ manages cookie-based password authentication for app releases. \UserOmniauth\ implements the core logic for third-party logins (Google, LDAP, OpenID Connect, Feishu, GitLab, GitHub, Gitea), while \UserRoles\ and \UserSettings\ define role scopes and user preference enums. Additional concerns include \SettingHelper\, \SettingSuger\, and \SettingValidate\ for configuration management, \VersionCompare\ for semver handling, \RecentlyReleasesCacheable\ for cache invalidation, and \ReleaseUrl\ for generating download and install links.
app/models/concerns · high confidence
New reusable UI components for modals, flash notifications, and release activity
This change introduces several new ViewComponent-based UI elements to the application. The new ModalComponent provides a standardized, configurable dialog wrapper with support for various sizes, positioning, and custom footers, replacing ad-hoc modal implementations. The FlashComponent standardizes system notifications, adding support for optional titles, specific icons based on message type (success, warning, error), and configurable auto-dismiss delays. Additionally, the AppReleaseActivityComponent offers a structured timeline view for app releases, displaying version details, changelogs, and metadata with pagination. A SwapIconComponent is also added to handle toggle-style icon interactions with preset styles for switches and hamburger menus.
app/components · high confidence
New services for admin/demo data seeding and app teardown parsing
The application introduces dedicated service classes to handle initial data setup and file analysis. \CreateAdminService\ now manages the creation of the default admin account and demo users, configuring their locale, timezone, and appearance settings based on system settings. \CreateSampleDataService\ generates sample application and device data for demonstration purposes. Additionally, \TeardownService\ centralizes the logic for parsing uploaded application files (including Android, iOS, macOS, Windows, and HarmonyOS formats), extracting metadata such as bundle IDs, permissions, URL schemes, and developer certificates, and storing this information in the database.
app/services · high confidence
New shared partials for form errors and limited install prompts
Added two new shared view partials: \_form\_errors.html.slim, which displays validation error messages for objects, and \_install\_limited.html.slim, which renders a hidden UI component for guiding users through limited app installation steps using the install-limited controller and Vite image tags.
app/views/shared · high confidence
New sponsor donation modal and Turbo Stream rendering
Users can now access a dedicated sponsor modal that displays an introduction and links to multiple donation channels, including GitHub Sponsors, Buy Me a Coffee, Afdian, and a general donation page. This modal is rendered via a new Turbo Stream template that dynamically replaces the modal content, supporting both the new sponsor view and standard body content based on configuration options.
app/views/modals · high confidence
New theme selection input component for admin settings
A new \ThemeSelectInput\ component has been added to the application inputs, providing a user interface for selecting and previewing themes within admin settings. This component renders a list of available themes, allowing users to click or use keyboard navigation to select a theme, which immediately updates the page's visual appearance by setting the \data-theme\ attribute on the document and body elements.
app/inputs · high confidence
Standardized development environment with new bin scripts
The repository now includes a standardized set of executable scripts in the \bin/\ directory to streamline local development and deployment. This adds a \bin/dev\ script that utilizes \mprocs\ to manage concurrent processes, alongside new binstubs for \puma\ (web server), \good\_job\ (background jobs), \vite\ (asset pipeline), and \yarn\ (package manager). Standard Rails utilities like \rails\, \rake\, \rubocop\, and \setup\ are also provided to ensure consistent execution environments for database preparation, server startup, and code linting.
bin · high confidence
Architecture
Extracted view logic into dedicated helper modules
The application's view logic has been refactored by extracting specific rendering and utility methods from the monolithic ApplicationHelper into dedicated helper modules (AdminHelper, AppsHelper, ChannelsHelper, CollaboratorsHelper, DashboardHelper, DebugFilesHelper, DemomodeHelper, DeviseHelper, TeardownHelper, UdidsHelper, UsersHelper, and ViewComponentHelper). This change improves code organization and maintainability by grouping related functionality—such as app icon rendering, device type styling, secure data masking in demo mode, and QR code generation—into their respective domains, while the ApplicationHelper now focuses on global layout and navigation utilities.
app/helpers · high confidence
Behavioural changes
Admin background jobs view now loads via iframe
The admin background jobs interface has been refactored to load the job management UI inside an iframe, passing the current locale to the embedded page. This change shifts the rendering responsibility for the actual job list and controls to a separate endpoint, while the admin panel now serves as a container that respects system locale settings with English as the fallback.
_app/views/admin/background\jobs · high confidence
Admin interface styling overhaul and dark mode support
The admin interface styles have been restructured into modular SCSS files (backups, logs, settings, system\_info, web\_hooks) and consolidated via an index file. This change introduces specific styling for backup forms, log viewers, and system info displays, including dedicated dark mode support for the system info and backup sections. Additionally, custom CSS for toggle switches in the settings page and layout adjustments for the iframe wrapper and web hooks list have been added to improve the visual consistency and usability of the admin panel.
app/assets/stylesheets/admin · high confidence
Admin settings page rewritten with Turbo and dynamic form handling
The admin settings interface has been completely refactored to use Turbo streams for asynchronous updates, replacing the previous implementation. The new system provides a dynamic form that adapts its input type based on the setting's data type: boolean settings use a toggle switch, hash and array settings use a JSON text editor, and inclusion-based settings use radio buttons or a theme selector. The interface now supports resetting settings to their default values, displays validation errors inline, and includes specific features like SMTP verification for mailer options and a service restart button that appears when changes require a restart. The layout is organized into a grid of cards grouped by scope, with each setting displaying its current value, hints, and edit links.
app/views/admin/settings · high confidence
Admin user management rewritten with Turbo and new UI components
The admin users interface has been completely rewritten to use the Hotwire/Turbo stack, replacing the previous implementation with new Slim templates for the user list, edit form, and detail views. This change introduces a modern grid-based layout for the user list and detail pages, adds copy-to-clipboard functionality for user tokens and confirmation URLs, and enables inline editing via modals. The update also integrates new features such as user lock/unlock controls, collaborator management, and demo-mode restrictions, while ensuring all interactions are handled via Turbo streams for a smoother, asynchronous user experience.
app/views/admin/users · high confidence
Apple Team management now uses Turbo-driven modal editing
The Apple Team editing interface has been rewritten to use Turbo Streams instead of traditional page reloads. The edit action now opens a modal form (via \render\_modal\) that submits via Turbo, automatically closing the modal on success and updating the team metadata in place without a full page refresh. This change improves the responsiveness of the admin interface for managing Apple Developer teams.
_app/views/admin/apple\teams · high confidence
Apps list and detail pages rewritten with Hotwire and dark mode support
The app list and detail views have been completely rewritten to use the Hotwire stack (Turbo Frames and Turbo Streams) for faster, partial-page interactions, replacing the previous implementation. This update introduces a new card-based layout for the app list and detail pages, featuring dark mode styling, app icons, and summary badges for schemes, channels, and uploads. It also adds a dedicated collaborators section to the app detail page, allowing owners to manage team members and transfer ownership, and implements archive/unarchive functionality with corresponding Turbo Stream updates to the UI.
app/views/apps · high confidence
Channel detail page rewritten with Hotwire and new component structure
The channel detail view has been completely refactored to use the Hotwire stack (Turbo and Turbo Streams) for a more dynamic, single-page-like experience. The previous layout has been replaced with a modular set of partials (\_activity, \_channel, \_channels, \_form, \_metadata, \_mobile\_menu, \_schemes, \_versions, \_web\_hooks) that render specific sections like release activity, metadata, and bulk operations. Turbo Stream responses now handle create, update, and destroy actions, updating the UI in-place without full page reloads. Additionally, a new mobile-friendly dropdown menu has been introduced to improve navigation on smaller screens, and the channel overview path has been standardized.
app/views/channels · high confidence
Collaborator management now uses Turbo Streams for instant updates
The collaborator interface has been migrated to use Hotwire's Turbo Streams, replacing previous JavaScript-based interactions. Adding, editing, or removing a collaborator now updates the page instantly without a full reload, and the form is rendered within a modal component. This change improves the responsiveness of the app collaboration settings, allowing users to manage team members and roles with immediate visual feedback.
app/views/collaborators · high confidence
Consolidated frontend JavaScript entry point
The frontend JavaScript entry point has been moved to the new \app/frontend/javascript\ directory. The new \application.js\ file serves as the central entry, explicitly importing the \controllers\ and \channels\ modules to initialize the frontend application.
app/frontend/javascript · high confidence
Database schema updates for user settings, app archiving, and background jobs
This update modifies the database schema to support new user preferences and application management features. Users can now customize their interface with language, appearance, and timezone settings, and the system supports distinct light and dark theme configurations. Application management is enhanced with the ability to archive apps and define specific download file types for channels. Additionally, the schema introduces support for app collaborators with owner roles and integrates the GoodJob gem for background job processing, alongside tables for Solid Cache and Solid Cable to improve performance and real-time capabilities.
db/migrate · high confidence
Docker container now uses Caddy as the default reverse proxy with improved error handling
The Docker image has switched its external-facing web server from the previous configuration to Caddy, managed via s6-overlay. This change introduces a new Caddyfile that serves static assets and proxies requests to the Rails application, while implementing specific error handling: it displays a loading page when the backend is unreachable and serves generic 50x error pages for server errors. Additionally, the container now includes built-in log rotation for Caddy, application, and job logs, and initializes necessary directories and crontabs for temporary file cleanup.
docker · high confidence
GoodJob health check and scheduler extension extracted
The GoodJob integration now includes a dedicated health check class that verifies the gem is loaded and monitors active process counts, alongside a new scheduler extension module that manages cron job storage. These changes restructure how GoodJob's operational status and scheduling logic are implemented within the library.
_lib/good\job · high confidence
Introduce GoodJob-based background job processing with Turbo Stream notifications
The application has migrated its background task infrastructure to use GoodJob (a pure database-driven scheduler) and ActiveJob, replacing the previous Redis-based system. This change introduces a new \ApplicationJob\ base class that leverages Turbo Streams to broadcast real-time job status updates and notifications (success or failure) directly to the user's browser. The \app/jobs\ directory now contains specific job implementations for core workflows: \AppWebHookJob\ for sending release notifications via webhooks with retry logic, \BackupJob\ for managing database and app backups with progress tracking, \DebugFileTeardownJob\ for parsing dSYM and ProGuard files, \CleanOldReleasesJob\ and \RetainedBuildsJob\ for automated version cleanup, \ResetForDemoModeJob\ for periodic demo data initialization, and \TeardownJob\ for general release metadata parsing. Users will experience real-time feedback on long-running tasks like backups and file parsing, as well as reliable webhook delivery and automated maintenance of old release versions.
app/jobs · high confidence
Introduce app archiving and granular Pundit-based authorization
Users can now archive and unarchive applications via a dedicated controller, with the app list and dashboard filtering active versus archived apps based on the user's role. The entire application hierarchy (Apps, Schemes, Channels, Releases, Debug Files, Collaborators, Web Hooks) now enforces strict authorization using Pundit policies, ensuring that actions like editing, deleting, or uploading are permitted only for authorized users or in guest mode. Archived apps are explicitly blocked from receiving new releases or being modified, and the GraphQL API now requires a valid Bearer token for authentication.
app/controllers · high confidence
Introduce custom mailer classes for Devise and user notifications
The application now includes dedicated mailer classes to handle email delivery. A new ApplicationMailer base class sets default sender and reply-to addresses from application settings and applies a shared mailer layout. DeviseMailer is introduced to customize Devise's email behavior, also using the shared layout. Additionally, a UserMailer class has been added to send a welcome email containing a temporary password to users during their first third-party authentication login.
app/mailers · high confidence
Introduces new API serializers for core entities
The application now uses a dedicated set of serializers (extending ApplicationSerializer) to structure API responses for Apps, Channels, Collaborators, Debug Files, Releases, Schemes, and Users. This change standardizes the output format, exposing specific fields such as platform and device\_type on releases, conditional debug file metadata, and user role information for admins, ensuring consistent data presentation across the API.
app/serializers · high confidence
Introduction of Pundit-based role and guest-mode access control
The application now enforces granular permissions across all resources (apps, channels, releases, debug files, backups, webhooks, users, and settings) using the Pundit gem. Access is determined by user roles (admin, developer, member) and app-specific collaboration status, with a new guest mode allowing unauthenticated users to perform read-only operations where permitted. Administrative actions, such as managing settings, locking users, or performing backups, remain restricted to admins, while collaborative features like editing app details or managing collaborators require appropriate app-level permissions.
app/policies · high confidence
Migrate frontend controllers to Stimulus and implement dynamic UI behaviors
The application's frontend JavaScript has been restructured to use the Stimulus framework, introducing a new \application.js\ entry point and a suite of dedicated controllers. This change enables dynamic user interface features, including a responsive breadcrumb system that automatically hides items in an overflow menu when space is constrained, and a global theme manager that supports light/dark modes with auto-detection and preview capabilities. Additionally, the update adds a skeleton loading state for QR code images to improve perceived performance, implements a responsive drawer that toggles based on device width, and introduces new controllers for clipboard copying, bulk selection operations, and tab-based URL state management.
app/frontend/javascript/controllers · high confidence
Migrate styling to Bootstrap 5 and AdminLTE 4 with SCSS architecture
The application's styling system has been upgraded from the legacy CSS/SASS setup to a modern SCSS architecture based on Bootstrap 5 and AdminLTE 4. This change introduces a new modular structure with dedicated SCSS files for components like buttons, dashboards, and app details, replacing the old \application.css\ manifest. Users will experience improved dark mode support across the interface, including specific color adjustments for buttons, cards, and timeline elements, as well as updated font families and icon handling via FontAwesome 6. The migration also resolves previous visual inconsistencies, such as missing fonts and incorrect border colors in dark mode, ensuring a more consistent and polished appearance across all pages.
app/assets/stylesheets · high confidence
Migration to DaisyUI with dynamic theme support
The frontend styling system has been restructured to use DaisyUI, configured with a 'd-' prefix and all themes enabled. This change introduces dynamic theme switching capabilities, allowing users to select from various color themes (including dark modes like synthwave, night, and dracula) and automatically adapt to system preferences. The layout styles now handle theme-aware branding images and update global anchor link colors, while breadcrumb separators and app-specific components like tooltips and teardown pages are restyled to align with the new design system.
app/frontend/stylesheets · high confidence
New API endpoints for app version management and upload
The API now exposes dedicated controllers for managing app versions and handling uploads. Users can retrieve the latest app version via GET /api/apps/latest, check if a specific version exists via GET /api/apps/version\_exist, and list all versions via GET /api/apps/versions. The upload endpoint POST /api/apps/upload has been refactored to support creating or updating app builds, handling channel and scheme creation, and triggering webhooks and teardown jobs upon successful upload.
app/controllers/api/apps · high confidence
New admin helper modules for backup, settings, system info, and user status
The application now includes dedicated helper modules in the admin area to support new and refactored UI features. Admin::BackupHelper provides logic for displaying backup schedules, job progress percentages, and status icons, enabling the display of real-time backup execution progress and checksum-based verification details. Admin::SettingHelper formats setting values for display and generates version reference links that now support Docker tags. Admin::SystemInfoHelper defines color coding for progress bars, and Admin::UserHelper determines user account status (locked, activated, or inactive) for the users page.
app/helpers/admin · high confidence
New card and property component styles with collapse support
The frontend now includes dedicated CSS styles for card and property UI components. The new card component supports multiple color variants (primary, secondary, neutral, info, success, warning, error) and outline modes, with specific styling for headers, bodies, and footers. It also introduces a collapse functionality using CSS grid and checkbox inputs, allowing cards to expand and contract smoothly. The property component provides a styled layout for key-value pairs, featuring a distinct background for values and hover effects for links.
app/frontend/stylesheets/components · high confidence
New controller concerns for localization, breadcrumbs, and error handling
This change introduces several new controller concerns in the \app/controllers/concerns\ directory to standardize and enhance core application behaviors. The \Customize\ concern adds support for user-specific locale and timezone settings, including header-based locale detection and fallbacks for demo mode. \Breadcrumbable\ provides a reusable method for constructing navigation trails for apps, schemes, and channels. \ExceptionHandler\ centralizes error handling, mapping specific exceptions (such as \AppArchivedDeny\, \Faraday::Error\, and \Pundit::NotAuthorizedError\) to appropriate HTTP status codes and rendering consistent error pages for both HTML and JSON responses. Additionally, \AppArchived\ enforces restrictions on actions for archived apps, \Qrcode\ standardizes QR code generation with theme and size options, \DeviceAttributes\ handles iOS certificate generation logic, and \UserRole\ simplifies user permission checks.
app/controllers/concerns · high confidence
New dedicated controllers for release installation and QR code generation
The app now uses dedicated controllers for handling release installation and QR code generation. The new \Releases::InstallController\ serves an XML response for installation requests, resolving releases by channel and ID, and returns a localized 'not found' error if the release is missing. The new \Releases::QrcodeController\ generates QR codes containing the friendly URL for a specific release, using the \Qrcode\ module to render the image. These changes refactor the previous logic into separate, focused components for better maintainability and clarity.
app/controllers/releases · high confidence
New error handling and SMTP validation infrastructure
This change introduces the Zealot library's core error handling and mail verification capabilities. It adds a structured error class hierarchy (Zealot::Error) with specific subclasses for record existence, record not found (including specific handling for Users), API not found, and denied actions on archived apps, all providing localized error messages. Additionally, it adds a SmtpValidator class that checks SMTP configuration settings and attempts to authenticate with the mail server, ignoring signal exceptions during the verification process to ensure robustness.
lib/zealot · high confidence
New frontend entrypoints for Tailwind and Vite integration
The application now uses new entrypoint files to initialize the frontend build system. The CSS entrypoint imports the Tailwind configuration, and the JavaScript entrypoint imports the main application script, enabling the integration of Vite, Tailwind CSS, and DaisyUI as indicated by the commit history.
app/frontend/entrypoints · medium confidence
New loading page and updated error handling
A new loading page (public/loading.html) is now displayed while the application starts, featuring a health check that polls the /api/version endpoint with a 5-second timeout and automatically refreshes the browser once the service is ready. The default 404, 422, and 500 error pages have been removed, and the robots.txt file has been updated to disallow all search engine crawlers.
public · high confidence
New sidebar components for QR codes and major versions
The release detail page now includes dedicated sidebar partials for displaying QR codes and major version history. The new \_qrcode.html.slim partial renders a card with a QR code for the current release and a footer instruction, while \_version.html.slim displays a table of major versions linked via the new friendly routing helpers, ensuring proper Turbo navigation.
app/views/releases/sidebar · high confidence
Pagination UI updated to use DaisyUI styling
The Kaminari pagination components have been rewritten to use DaisyUI CSS classes (prefixed with 'd-') for styling. This change updates the appearance of pagination controls, including first, last, next, previous, and page buttons, as well as the gap indicator, to align with the DaisyUI design system. The paginator template now uses a 'd-join' container for button grouping and applies 'd-btn' and 'd-btn-sm' classes for consistent button styling.
app/views/kaminari · high confidence
Rails 7 upgrade and infrastructure modernization
The application has been upgraded to Rails 7.0, introducing several backend infrastructure changes: Action Cable now uses the solid\_cable adapter, caching is handled by solid\_cache, and background jobs use the good\_job adapter. The database configuration has been standardized to use the ZEALOT\_DATABASE\_URL environment variable with PostgreSQL as the default adapter. The Puma web server configuration has been updated to support control URLs and better worker management. Additionally, the application now supports Chinese and English language switching, and the Vite asset pipeline is configured for frontend development.
config · high confidence
Rails 8.0 framework defaults and configuration overhaul
The application now includes the \new\_framework\_defaults\_8\_0.rb\ initializer, enabling the \to\_time\_preserves\_timezone\ setting to preserve the timezone of receivers (previously defaulting to UTC offset). This is part of a broader configuration update in \config/initializers\ that also introduces \new\_framework\_defaults\_7\_0.rb\ to ease the transition to Rails 7.0 defaults, updates the session cookie key to \\_zealot\_session\, and configures new MIME types for iOS and Android installers (\.plist\, \.ipa\, \.apk\).
config/initializers · high confidence
Redesign of application layout and navigation structure
The application layout has been completely rewritten to introduce a modern, responsive design with a collapsible sidebar drawer, dynamic breadcrumbs, and a structured content area. The new layout supports a light/dark theme system, displays a configurable announcement bar in demo mode, and integrates multiple analytics providers (Google Analytics, Umami, Microsoft Clarity) via settings. The navigation now includes a user profile dropdown, a donate button, and role-based sidebar links (e.g., admin tools, monitors). Email templates have also been updated to use the new Vite asset pipeline and consistent branding.
app/views/layouts · high confidence
Redesigned admin backup management interface
The admin backup management views have been completely rewritten to provide a modern, responsive interface for managing backup schedules and jobs. The new design features a dedicated index page for listing backup schedules with details like key, scopes, and next scheduled time, and a show page that displays both completed backup files (with SHA256 checksums and download links) and in-progress jobs with real-time status updates. The interface now supports creating, editing, and deleting backup schedules via Turbo-driven modals, as well as running, disabling, and deleting individual backups and jobs directly from the UI.
app/views/admin/backups · high confidence
Redesigned dashboard with role-based analytics and componentized UI
The dashboard view has been rewritten to use a new component-based structure, introducing a dedicated analytics section that displays counts for apps, debug files, teardowns, and uploads. This section adapts its layout and content based on user permissions: non-admin users see a four-column grid of general metrics, while administrators see an eight-column grid that additionally exposes web hooks, users, background jobs, and disk usage. The recent upload timeline is now rendered via the AppReleaseActivityComponent, and the overall layout utilizes Tailwind CSS grid utilities for responsive styling.
app/views/dashboards · high confidence
Redesigned email confirmation page with split layout
The email confirmation view has been rewritten to use a modern split layout. On larger screens, the left side displays a shared introduction component, while the right side presents the confirmation form in a tabbed container. The form now pre-fills the email field with the unconfirmed address if a reconfirmation is pending, and includes a link to other authentication actions.
app/views/devise/confirmations · high confidence
Redesigned error pages with localized content and development debugging
The error pages have been completely rewritten to use a card-based layout with distinct styling for client errors (4xx) versus server errors (5xx). Users now see localized error messages and content pulled from translation keys, along with convenient 'Go Back' and 'Return to Homepage' links. Additionally, in development mode, a debug section is displayed showing the exception class, message, and full stack trace to aid developers.
app/views/errors · high confidence
Redesigned login interface with tabbed authentication modes
The login view has been rewritten to support a tabbed interface allowing users to switch between normal email/password, LDAP, and passwordless login methods. The layout now conditionally renders these tabs based on system settings (e.g., \Setting.login\_enabled\, \Setting.passwordless\_login\_enabled\) and displays third-party OAuth providers separately. A new 'disabled login' partial is shown when authentication is globally disabled, and error messages are now displayed in a dismissible alert component.
app/views/devise/shared · high confidence
Redesigned login page with tabbed authentication options and passwordless email support
The login interface has been completely rewritten to support multiple authentication methods via a tabbed layout. Users can now switch between standard sign-in, passwordless login (magic link), and LDAP authentication directly on the sessions page. A new passwordless flow has been introduced, allowing users to receive a time-limited login link via email, supported by a new magic link email template. The UI has also been updated to include an introductory section and utilizes a new tab-switching component for seamless navigation between these methods.
app/views/devise/sessions · high confidence
Redesigned password reset pages with layout and conditional logic
The password reset views (forgot password and change password) have been rewritten to use a new grid-based layout with a shared intro section and tabbed content styling. Additionally, the 'forgot password' page now respects the global login setting: if user login is disabled, it displays a 'disabled login' message instead of the reset form.
app/views/devise/passwords · high confidence
Redesigned release detail page with modular components
The release detail view has been restructured into distinct, reusable partials (\_activity, \_changelog, \_debug\_file, \_devices, \_install\_app, \_metadata, \_new\_release\_callout, \_password\_auth) to improve maintainability and user experience. Users now see a richer metadata display including device types, native codes, and custom fields with icons, while changelogs support markdown formatting with author and date badges. The install flow includes password authentication, iOS certificate expiration warnings, and platform-specific install/download buttons. Debug files display proguard mappings and metadata, and the page highlights archived apps and new release notifications.
app/views/releases/body · high confidence
Redesigned release upload and detail views with guest access and Turbo integration
The release views have been rewritten to support web-based app uploads and improved guest access. The new upload form allows users to manually specify version and build details for apps that cannot be auto-detected. Release detail pages now use Turbo frames for dynamic updates and display debug file information alongside standard metadata. Guest users can now view application details and download links, while authenticated users with manage permissions see an upload button (hidden for archived apps). A dedicated 'not found' page handles missing releases with clear error messages and navigation options.
app/views/releases · high confidence
Redesigned user registration and profile management with theme settings
The Devise registration and profile edit views have been rewritten to support customizable user settings, including language, timezone, and appearance (light/dark themes). The new registration page allows users to sign up with username, email, and password, and respects a global setting to enable or disable registration. The profile edit page now includes sections for updating personal details, changing appearance preferences, managing API tokens, and a danger zone for account cancellation, with specific restrictions applied in demo mode.
app/views/devise/registrations · high confidence
Refactored API response structures for apps, versions, and uploads
The API serializers for app details, version lists, debug files, and upload responses have been restructured to provide more granular and consistent data. App listings now explicitly include an 'archived' status and associated schemes/collaborators. Version and latest-app endpoints are now channel-based, allowing filtering by bundle\_id and specific version constraints. Upload responses now include platform and device\_type metadata, and changelogs are returned in both markdown and plain-text formats via the new 'text\_changelog' field.
app/serializers/api · high confidence
Removal of legacy Sprockets JavaScript manifest
The \app/assets/javascripts/application.js\ manifest file has been deleted. This file previously served as the entry point for the Sprockets asset pipeline, explicitly requiring jQuery, jQuery UJS, Turbolinks, and all other JavaScript files in the directory. Its removal indicates a shift away from the traditional Sprockets-based asset compilation for this manifest, likely as part of a migration to a different bundling system (such as Webpacker) or a restructuring of how frontend assets are loaded.
app/assets/javascripts · high confidence
Restructured file storage paths for apps, icons, and debug files
The application uploaders have been refactored to use a new, hierarchical directory structure for storing uploaded assets. App binaries are now saved under \apps/a{app\_id}/r{revision\_id}/binary\, icons under \apps/a{app\_id}/r{revision\_id}/icons\, and debug files under \debug\_files/a{app\_id}/d{debug\_id}\. This change also introduces automatic cleanup of empty upstream directories upon file removal and enforces stricter extension allowlists (e.g., PNG, WebP, JPEG, JPG, BMP for icons; ZIP for debug files).
app/uploaders · high confidence
Schemes management migrated to Turbo and modal-based interaction
The scheme creation and editing workflows now use Turbo Streams for asynchronous updates and render forms within a modal dialog. This change introduces a new form partial that supports configuring retained builds and a new boolean option to enable a callout for new builds, along with channel selection during creation. Upon saving or deleting a scheme, the interface updates the list and displays notifications without a full page reload, ensuring the list correctly reflects empty states when all schemes are removed.
app/views/schemes · high confidence
Standardized app icon styling and layout
A new global stylesheet for the apps section defines consistent visual rules for application icons. App icons are now rendered with rounded corners and a uniform size (18 units), with specific overrides for the channel activity section to ensure icons remain smaller (10 units) in that context. Empty icon placeholders are also styled with borders and background colors to maintain visual consistency across light and dark modes.
app/frontend/stylesheets/apps · high confidence
Teardown views rewritten with platform-specific detail cards
The teardown result pages have been completely rewritten to display structured, platform-specific metadata for Android, iOS, macOS, tvOS, Windows, and HarmonyOS apps. Each platform now uses a dedicated partial (e.g., \_android.html.slim, \_ios.html.slim) that renders a consistent card layout showing app name, version, package/bundle ID, supported devices, file size, and uploader. Platform-specific details are now prominently displayed: Android shows min/target SDK versions, native codes, deep links, URL schemes, features, permissions, and services; iOS/macOS/tvOS show release type, minimum OS version, capabilities, entitlements, and URL schemes; Windows shows file description, architecture, version info, and company details; HarmonyOS shows supported devices and native codes. Developer certificates and signatures are now rendered in collapsible sections with detailed certificate information (serial, issuer, subject, fingerprints, expiration) and signature scheme verification status. Mobile provisioning profiles are displayed with UUID, team info, and expiration status. The index page now shows a clean history list with metadata columns, and the new upload form is simplified. All views use consistent i18n keys and modern card-collapse components.
app/views/teardowns · high confidence
UDID management page redesigned with new device registration and Apple key integration
The UDID management interface has been completely rewritten to support a streamlined workflow for registering and managing devices. Users can now register new devices directly from the UDID page, including the ability to associate them with Apple Developer accounts via the new Apple Keys section. The updated view displays comprehensive device metadata, associated application releases with changelogs, and statistics for channels, releases, and keys. It also introduces a dedicated installation profile view for fetching UDIDs and improves the overall layout with better mobile responsiveness and dark mode support.
app/views/udid · high confidence
Updated Rails environment configurations for modernized defaults and improved diagnostics
The development, production, and test environment configurations have been updated to align with newer Rails conventions. In development, code reloading is now controlled via \enable\_reloading\ instead of \cache\_classes\, and server timing, verbose query logging, and conditional caching toggles have been added to aid debugging. Production now uses \public\_file\_server\ instead of the deprecated \serve\_static\_assets\, configures NGINX's \X-Accel-Redirect\ header for static files, and sets a custom \Server\ header ('Zealot') along with standard security headers (X-Frame-Options, X-Content-Type-Options, X-XSS-Protection). Test environment caching behavior has been adjusted to support CI environments, and deprecated asset server settings have been replaced with \public\_file\_server\. These changes improve diagnostic visibility, security posture, and compatibility with current Rails standards.
config/environments · high confidence
iOS app installation plist now includes app icon
The iOS app installation page now generates a plist file that includes the app's icon URL (display-image) alongside the software package URL. This allows users to see the app icon when installing via iOS's native 'Add to Home Screen' or OTA installation flow, provided the icon file exists.
app/views/releases/install · high confidence
Test coverage
Added RSpec test infrastructure and Swagger/OpenAPI specification helpers; Added Swagger API specifications for Apps, Channels, Collaborators, Debug Files, Health, Releases, Schemes, Users, and Version endpoints; Added shared Swagger test helpers for API parameter and response validation; Added test factories for App and User models.
Dependencies
Routine dependency updates across Ruby and JavaScript ecosystems
This release updates a wide range of production and development dependencies to their latest versions. Key Ruby gems updated include Rails (across 6.1, 7.0, 7.1, and 8.1 minor/patch lines), Puma, Sidekiq, Good Job, GraphQL, and Sentry integrations. JavaScript dependencies such as esbuild, @hotwired/turbo-rails, @rails/actioncable, and Tailwind CSS plugins have also been upgraded. These changes primarily address bug fixes, security patches, and compatibility improvements without introducing new user-facing features.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 52.
Lenses
- Code Health 68
- Architecture 78
- Maturity 56
- Readiness 48
- Security 65
- Domain Modelling 52
- Accessibility 57
Changes since last survey
- 300 commits — 280 feature/other, 20 fixes
By area
- (repo) — 139 commits
- (root) — 131 commits
- .github/workflows — 11 commits
- .devcontainer/Dockerfile.base — 4 commits
- app/graphql — 3 commits
- app/views — 2 commits
- .devcontainer/Dockerfile — 1 commit
- .devcontainer/docker-compose.yml — 1 commit
- app/controllers — 1 commit
- app/frontend — 1 commit
- app/inputs — 1 commit
- config/application.rb — 1 commit
- config/cable.yml — 1 commit
- config/locales — 1 commit
- docker/rootfs — 1 commit
- lib/zealot — 1 commit
Notable commits
- fix: Merge pull request #2412 from tryzealot/copilot/fix-push-docker-image-job
- fix: Merge pull request #2459 from tryzealot/fix/rails-multi-database-schema-backup-invalid
- fix: Merge pull request #2474 from CherryLover/fix/arm64-native-build
- fix: Potential fix for code scanning alert no. 18: Workflow does not contain permissions
- fix: Potential fix for code scanning alert no. 19: Workflow does not contain permissions
- fix: Potential fix for code scanning alert no. 2: Workflow does not contain permissions
- fix: Revert "chore(deps-dev): bump @tailwindcss/vite from 4.2.2 to 4.2.4"
- fix: chore: fix devcontainer build pnpm error
- fix: chore: fix docker build pnpm error
- fix: chore: fix postgres 18 volume path
- fix: fix(api): require valid bearer token before executing queries
- fix: fix(database): restore single database configuration and support engine migrations in zealot:upgrade
- fix: fix(docker): build arm64 images natively instead of pinning FROM to $BUILDPLATFORM
- fix: fix(job): backup with empty database sql file
- fix: fix(web): create and destry backup turbo load view
- fix: fix: correct namespace for GraphQL validators to match Zeitwerk autoloading
- fix: fix: correct namespace for GraphQL validators to match Zeitwerk autoloading
- fix: fix: pnpm lock
- fix: fix: restore release publish workflow permissions
- fix: fix: restore release publish workflow permissions
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
tryzealot/zealot was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 93ee7d3f821f50987b32ec112f6e206cdacceeb9 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.