Skip to content
CAI
Software that uses CAICheck a score

wouterdebie/davit

56.2

Weak · 1 October 2026

14.4k

lines of production code

Swift

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Davit is a native macOS application designed to manage Docker containers and container-based virtual machines. It provides capabilities for building images from Dockerfiles, importing and orchestrating multi-service stacks via Docker Compose, and browsing files within running containers. The system also handles registry authentication, credential management, and includes a marketing website for distribution.

Features

Added Davit brand icons and menu bar assets

The application now includes a new set of brand assets for the Davit product. This adds the main application icon (both with a transparent background and a solid dark background) featuring a 3D-stacked container design with gradients and glow effects. It also adds macOS menu bar template images (monochrome outlines) designed to adapt to light and dark system themes, along with a Python script to regenerate the main icon SVG from geometric definitions.

icon · high confidence

Introduce native Dockerfile builds, Docker Compose orchestration, and credential helper support

Davit now supports building images directly from Dockerfiles via the BuildKit shim, allowing users to specify build arguments, labels, and target stages. It also introduces Docker Compose import, parsing compose files to create and manage multi-service stacks with support for profiles, healthchecks, and dependency conditions. Additionally, the app now supports Docker credential helpers, resolving short-lived tokens from helpers like docker-credential-gcloud and staging them in the keychain for pull operations.

Sources/ContainerStack · high confidence

Launch of the Davit marketing site and automated GCS deployment

The project now includes a public-facing marketing website (site/index.html) and an automated deployment script (site/deploy.sh) for Google Cloud Storage. The site introduces Davit as a native macOS app for Apple's container platform, highlighting features such as container management, file browsing, Compose import, and registry logins, along with Homebrew installation instructions. The deployment script ensures that the release-managed appcast file is excluded from site uploads to prevent overwrites, and configures cache headers so that HTML files are revalidated on every visit for instant deployment updates while images are cached for 24 hours.

site · high confidence

New container management features and UI refinements

This update introduces several new capabilities and interface improvements. Users can now build images directly from Dockerfiles via a new BuildImageSheet, import Docker Compose files with a preview of services and volumes, and browse, upload, and download files inside running containers using the new Files tab. A global command palette (Cmd-K) allows quick navigation across all resources. The UI has been refined with thin, self-hiding scrollbars, a new memory input control with unit selection, and a more efficient pulsing animation for status dots that reduces CPU usage. Additionally, a new Machines section allows users to create and manage container-based virtual machines, and registry login management has been added to Settings for accessing private images.

Sources/ContainerStack/Views · high confidence

Behavioural changes

Release pipeline overhaul: Sparkle updates, notarization, and signing safeguards

The release process now uses Sparkle for automatic updates, embedding the framework and configuring the appcast URL and public key in the bundle. To ensure release integrity, a new signing script pins the expected Developer ID certificate fingerprint and refuses to sign if it mismatches, while a separate check script verifies that the signing key matches the bundle's trusted public key before release. The pipeline also supports Apple notarization and produces a styled drag-to-Applications DMG (falling back to a plain image if tools are missing). Additionally, the internal container dependency version has been bumped to 1.3.1.

scripts · high confidence

Dependencies

Upgrade container dependencies and add Sparkle for auto-updates

The application now relies on Apple's container and containerization libraries (upgraded to versions 1.3.1 and 0.42.0 respectively) and introduces Sparkle 2.10.0 to handle automatic application updates. Additionally, new dependencies including Yams, Swift NIO, and specific container modules (ContainerBuild, ContainerCommands, ContainerImagesService, MachineAPIClient) have been added to support expanded functionality, with linker settings adjusted to ensure Sparkle loads correctly at runtime.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 57 → 56 (-0.8)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 80 → 80 (-0.1)
  • Architecture 100 → 100 (+0.0)
  • Maturity 53 → 53 (-0.6)
  • Readiness 43 → 45 (+1.7)
  • Security 77 → 74 (-2.6)

Resolved (7)

  • Dependency hygiene PARTLY measured — SwiftPM pinning read, dependency currency NOT established
  • Documentation: contradicts the code (docs/compose-parity-plan.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (16 lines × 2) (Sources/ContainerStack/Main.swift)
  • Hotspot: Sources/ContainerStack/Backend.swift (Sources/ContainerStack/Backend.swift)
  • Off-boarding risk: anonymized user #1

New (21)

  • ContainerOverviewTab.content (cognitive 28) (Sources/ContainerStack/Views/ContainerDetail.swift)
  • ContainerOverviewTab.content (cyclomatic 24) (Sources/ContainerStack/Views/ContainerDetail.swift)
  • ContainersView.body (cognitive 25) (Sources/ContainerStack/Views/Containers.swift)
  • ContainersView.body (cyclomatic 21) (Sources/ContainerStack/Views/Containers.swift)
  • Duplicated block (10 lines × 2) (Sources/ContainerStack/Views/Machines.swift)
  • Duplicated block (11–13 lines × 2) (Sources/ContainerStack/Views/Machines.swift)
  • Duplicated block (15 lines × 2) (Sources/ContainerStack/Views/VolumesNetworks.swift)
  • Hotspot: Sources/ContainerStack/Views/ContainerDetail.swift (Sources/ContainerStack/Views/ContainerDetail.swift)
  • Hotspot: Sources/ContainerStack/Views/Containers.swift (Sources/ContainerStack/Views/Containers.swift)
  • Hotspot: Sources/ContainerStack/Views/Sheets.swift (Sources/ContainerStack/Views/Sheets.swift)
  • Hotspot: Sources/ContainerStack/Views/Shell.swift (Sources/ContainerStack/Views/Shell.swift)
  • MainWindow.body (cognitive 17) (Sources/ContainerStack/Views/Shell.swift)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Off-boarding risk: anonymized user #1
  • Outdated: container
  • Outdated: containerization
  • Outdated: swift-log
  • Outdated: swift-nio
  • PullImageSheet.body (cognitive 48) (Sources/ContainerStack/Views/Sheets.swift)
  • …and 1 more

Changes since last survey

  • 6 commits — 6 feature/other, 0 fixes

By area

  • .github/workflows — 3 commits
  • Sources/ContainerStack — 3 commits

Notable commits

  • change: Bump the artifact actions off Node 20
  • change: Move updating to Sparkle
  • change: Refuse to sign a release with the wrong Sparkle key (#23)
  • change: Require notarization before installing an update
  • change: Thin, self-hiding scrollbars in the main window
  • change: Verify the artifact handoff on every push, not just at release (#22)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

wouterdebie/davit was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 30784fc27e9a947fa12adee596e6c2cd477010cd — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.