Skip to content
CAI
Software that uses CAICheck a score

XcodesOrg/XcodesApp

60.8

Adequate · 27 September 2026

8k

lines of production code

Swift

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Xcodes is a macOS application that manages the installation, selection, and configuration of multiple Xcode versions and simulator runtimes. It provides a modern SwiftUI interface for browsing, filtering, and installing Xcode releases while handling complex authentication flows, including Apple ID sign-in and FIDO security keys. The system relies on a privileged helper process to securely perform system-level file operations and integrates Sparkle for automatic application updates.

How it got here

2020 — UI overhaul and native installation backend

16 changes.

The project underwent a significant structural redesign, introducing a dedicated MainWindow with NavigationSplitView and migrating settings to SwiftUI. A major backend feature added native support for downloading, installing, and caching Xcode versions and runtimes, secured by a privileged XPC helper. The release process was also automated with scripts for notarization and build number management.

2021–2024 — UI redesign and security hardening

4 changes.

The project focused on restructuring the user interface, reorganizing preferences into dedicated panes and redesigning the info pane for better data presentation. Concurrently, security was strengthened by implementing strict XPC connection verification in the privileged helper to ensure only the verified application can perform system-level operations.

Features

Add application metadata, licensing, and localization resources

This change introduces the core resource bundle for the Xcodes application, including the Info.plist with configuration for Sparkle auto-updates (feed URL and public key) and privileged helper execution, a comprehensive Localizable.xcstrings catalog supporting 20 languages, and RTF license files for bundled dependencies such as AsyncHTTPNetworkService, SwiftSoup, LibFido2Swift, Yams, and aria2c.

Xcodes/Resources · high confidence

Add custom about window with dependency acknowledgments

The application now features a custom About window that displays the app name, version, and build number, along with direct links to the GitHub repository, the unxip experiment details, and the unxip license. A new 'Acknowledgements' button opens a separate view that renders the third-party dependency licenses from an RTF file in a scrollable text area. The window also includes a 'Support Xcodes' button linking to the Open Collective page and displays the copyright information from the Info.plist.

Xcodes/Frontend/About · high confidence

Introduce native Xcode and runtime installation, update, and caching capabilities

The backend now supports downloading, installing, and managing Xcode versions and simulator runtimes directly within the app. This includes auto-installation of new versions, support for multiple architectures, and the ability to download runtimes via archive or xcodebuild. The update mechanism has been refactored to use a caching system for available Xcodes and runtimes, with configurable data sources (Apple or other) and automatic session validation. File operations for installation (moving apps, creating symlinks, renaming) are routed through a privileged helper when enabled, ensuring proper permissions. The system also handles progress tracking via Dock progress indicators and provides detailed error handling for installation failures, including damaged archives and authentication issues.

Xcodes/Backend · high confidence

Introduces new common UI components and structured error handling

The Xcodes/Frontend/Common module now includes several new reusable components and infrastructure. A \NavigationSplitViewWrapper\ provides a consistent navigation layout with column width constraints for macOS 14+. Progress tracking is enhanced with \ObservingProgressIndicator\ (which ensures main-thread updates for progress changes) and \ProgressButton\ (which disables actions and shows a spinner during in-progress states). Error management is standardized via \View+ErrorHandling\, introducing categorized errors (recoverable, non-recoverable, requires sign-out) and a unified alert system. Additionally, new types like \TagView\, \TrailingIconLabelStyle\, and structured alert/sheet enums (\XcodesAlert\, \XcodesSheet\) support improved UI consistency and authentication flows.

Xcodes/Frontend/Common · high confidence

New AcknowledgementsGenerator tool for compiling dependency licenses

A new command-line utility has been added to scan Xcode projects for Software Package Manager (SPM) dependencies and manually provided license files (including \*.LICENSE files), then combine them into a single RTF file. This tool reads the project's Package.resolved and DerivedData to locate dependencies, supporting standard license filenames (LICENSE, LICENSE.txt, LICENSE.md) as well as custom .LICENSE files, and outputs a formatted acknowledgements document suitable for inclusion in an app's About window.

Xcodes/AcknowledgementsGenerator · high confidence

Privileged XPC helper adds file operation methods

The HelperXPCShared module now exposes new privileged XPC methods for managing Xcode installations, including moving applications, creating symbolic links, renaming, and removing files. These additions complement existing helper capabilities like xcode-select configuration and license acceptance, enabling the main application to perform system-level file operations securely through the privileged helper process.

HelperXPCShared · high confidence

Security

Privileged helper introduces strict XPC connection verification

The privilege helper now enforces strict security checks on incoming XPC connections before accepting them. It validates that the connecting app is signed by the correct team, requires a hardened runtime, and explicitly rejects connections from processes possessing dangerous entitlements like 'get-task-allow' or library validation bypasses. This ensures that only the verified, properly signed main application can execute privileged operations such as managing Xcode paths or modifying system developer settings.

com.xcodesorg.xcodesapp.Helper · high confidence

Behavioural changes

Added Xcode workspace configuration files

The project now includes the standard Xcode workspace data file (contents.xcworkspacedata) and the IDE workspace checks plist (IDEWorkspaceChecks.plist). These files establish the basic workspace structure and suppress the 32-bit warning in Xcode, ensuring the project opens correctly without configuration prompts.

Xcodes.xcodeproj/project.xcworkspace · high confidence

App structure, window management, and settings reorganized

The application now uses a dedicated \MainWindow\ for the primary Xcode list and a separate 'Platforms' window for managing runtime platforms, replacing the previous single-window or grouped approach. The Settings interface has been migrated to use the built-in SwiftUI \Settings\ scene, and the app now supports terminating automatically when the last window is closed (controlled by a new preference). Additionally, the Help menu now includes direct links to the GitHub repository, bug reports, and feature requests, and the About window is managed via the AppDelegate to prevent multiple instances.

Xcodes · high confidence

Appcast now includes Sparkle update signatures

The AppCast directory has been set up as a Jekyll site to generate Sparkle-compatible XML feeds from GitHub releases. A key behavioral change is that the generated appcast entries now include the \sparkle:edSignature\ attribute, which is extracted from the release body comments. This enables the Xcodes.app client to verify the integrity of downloaded updates using the signatures provided in the release notes.

AppCast · high confidence

Automated release packaging, notarization, and build number management

The build process now includes dedicated scripts to streamline the creation of distributable release assets. A new package\_release.sh script automates the clean build, archive, and export steps, utilizing a newly added export\_options.plist configured for 'developer-id' distribution. To ensure macOS security requirements are met, a notarize.sh script handles uploading the app to Apple's notarization service, stapling the ticket, and re-zipping the application. Additionally, an increment\_build\_number.sh script automatically calculates and sets the CFBundleVersion in Info.plist based on the latest git tag, while a fix\_libfido2\_framework.sh script corrects the bundle structure and codesigns related frameworks to resolve library errors.

Scripts · high confidence

Introduce MainWindow as the primary application window with NavigationSplitView

The application now uses a new MainWindow component that serves as the central container for the user interface, replacing the previous window structure. This view implements a NavigationSplitView layout, featuring a sidebar for Xcode selection and filtering (including category, architecture, and installation status) alongside a detail pane that displays the InfoPane or an unselected state. It consolidates authentication flows (sign-in, 2FA, security key, federated login) into a sheet-based system and manages global state such as error handling and bottom status bar updates. Additionally, two new view extensions, View+Conditional and View+IsHidden, are introduced to support cleaner conditional rendering logic within the SwiftUI views.

Xcodes/Frontend · high confidence

Preferences reorganized into dedicated panes with new advanced and experiment options

The Preferences window has been restructured into distinct tabs: General, Updates, Downloads, Advanced, and Experiments. The General pane now includes Apple ID sign-in status, macOS notification management (with a button to open system settings if access was denied), and misc toggles like window closing behavior. The new Advanced pane allows users to change the Xcode installation directory and local cache directory, configure actions on Xcode selection (rename or create symbolic links), toggle the Rosetta option on Apple Silicon, and manage the privileged helper for file operations. The Downloads pane lets users select the data source and downloader engine. The Updates pane handles automatic Xcode installation, prerelease inclusion, and app update checks via Sparkle. The Experiments pane provides a toggle for a faster unxip process.

Xcodes/Frontend/Preferences · high confidence

Redesigned Apple ID sign-in flow with federated and security key support

The sign-in interface has been completely rewritten to support modern authentication methods. Users can now authenticate via federated identity providers (e.g., Microsoft Entra) through a dedicated view that handles IDP redirects, and via FIDO security keys, including support for devices with or without PIN codes. The credential entry experience is improved with a custom multi-field PIN code input component that supports paste operations and auto-advancement, inline error display, and localized strings. The flow also includes dedicated views for selecting trusted phone numbers and entering SMS security codes, replacing the previous simpler login mechanism.

Xcodes/Frontend/SignIn · high confidence

Redesigned Info Pane with dedicated component views

The Info Pane has been completely redesigned to display Xcode details in a structured, two-column layout. The left column now features the Xcode icon, version description, and state-specific controls (Install, Select, Open, Uninstall, or installation progress), while the right column presents detailed information including release date, macOS compatibility requirements, identical builds, SDKs, and compilers. This change introduces several new dedicated views (CompatibilityView, CompilersView, IconView, IdenticalBuildsView, PlatformsView, ReleaseDateView, ReleaseNotesView, SDKsView) to handle specific data displays, and adds support for viewing and downloading iOS/watchOS/tvOS runtimes with architecture filtering.

Xcodes/Frontend/InfoPane · high confidence

Redesigned Xcode list with new filtering, installation controls, and grouped view

The Xcode list interface has been significantly updated to improve usability and visual clarity. Users can now filter the list by release/beta category, installed status, and architecture (Universal or Apple Silicon) via a new toolbar menu. The list supports a grouped view that organizes Xcode versions by major and minor versions, with expandable sections. Each row now displays the Xcode app icon, build identifiers, and an 'Identical Builds' indicator when applicable. Installation and selection states are more prominent, featuring a new AppStore-style button design for Open and Install actions, and a detailed installation progress view with a cancel option. A bottom status bar shows the app version and a link to support the project.

Xcodes/Frontend/XcodeList · high confidence

Updated Xcode schemes for new bundle identifiers and archive cleanup

The project's Xcode schemes have been updated to reflect the rebranding from 'robotsandpencils' to 'xcodesorg', including the addition of a new scheme for the privilege helper (com.xcodesorg.xcodesapp.Helper) and the main app scheme. Additionally, the main app's archive post-action now includes a script to remove duplicate copies of Sparkle.framework, ensuring cleaner app archives.

Xcodes.xcodeproj/xcshareddata · high confidence

Xcodes project configuration updated to support new UI components and dependencies

The Xcodes project file has been updated to include new source files for UI components such as SignInSecurityKeyPinView, SignInSecurityKeyTouchView, and various preference panes (General, Advanced, Updates, Experiments), alongside frameworks like CryptoKit, Sparkle, and XcodesKit. This reflects the integration of security key authentication, enhanced settings interfaces, and updated dependency management within the application.

Xcodes.xcodeproj · medium confidence

Test coverage

Added comprehensive test coverage for AppState, update logic, and sign-in UI

This change introduces a new test suite in XcodesTests to validate core application behaviors. AppStateTests verify the handling of network errors (such as 401 Unauthorized), the correct configuration of PIN code text fields for two-factor authentication, and the logic for preparing users for helper actions. AppStateUpdateTests ensure that the application correctly manages Xcode version states, including merging identical builds based on build metadata, avoiding the replacement of existing install states during updates, and properly handling versions that are installed but not listed in the available data source. NewVersionNotificationTests confirm that the system accurately detects genuinely new Xcode versions by comparing identity sets rather than relying on array count, preventing false negatives when versions are replaced or false positives from duplicates. Finally, SignInCredentialsViewTests verify that the sign-in interface correctly marks username and password fields for autofill support.

XcodesTests · high confidence

Dependencies

New dependency manifests for AppCast and AcknowledgementsGenerator

This change introduces new dependency configuration files for two distinct areas of the project. For the AppCast component, a new Gemfile and Gemfile.lock establish a Jekyll 4.4.1 build environment, including specific versions for plugins like jekyll-github-metadata and kramdown-parser-gfm, as well as platform-specific gems like tzinfo and wdm. For the Xcodes application, a new Package.resolved file pins Swift Package Manager dependencies to specific versions and revisions, notably updating Sparkle to 2.9.6, XcodesKit to 1.1.0, and LibFido2Swift to 0.1.6, while also adding a new AcknowledgementsGenerator tool with its own Package.swift manifest.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 45 → 61 (+15.9)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 96 (-3.6)
  • Architecture 69 → 97 (+27.8)
  • Maturity 52 → 50 (-2.1)
  • Readiness 34 → 58 (+23.1)
  • Security 43 → 71 (+27.8)

Resolved (9)

  • Dimension evaluation failed
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No artifact signing
  • No automated tests
  • No exposed public API
  • No tests found
  • Test reliability not included

New (48)

  • AppState.createSymbolicLink (cognitive 23) (Xcodes/Backend/AppState.swift)
  • AppState.select (cognitive 16) (Xcodes/Backend/AppState.swift)
  • AppStoreButton.background (cognitive 23) (Xcodes/Frontend/XcodeList/AppStoreButtonStyle.swift)
  • AppStoreButton.textColor (cognitive 20) (Xcodes/Frontend/XcodeList/AppStoreButtonStyle.swift)
  • ClassTooLong: AppState (Xcodes/Backend/AppState.swift)
  • Duplicated block (10 lines × 2) (Xcodes/Frontend/SignIn/SignIn2FAView.swift)
  • Duplicated block (11 lines × 2) (Xcodes/Backend/AppState+Update.swift)
  • Duplicated block (12 lines × 2) (Xcodes/Backend/AppState+Runtimes.swift)
  • Duplicated block (12 lines × 2) (Xcodes/Backend/AppState+Runtimes.swift)
  • Duplicated block (12 lines × 2) (Xcodes/Frontend/InfoPane/CompilersView.swift)
  • Duplicated block (12 lines × 2) (Xcodes/Frontend/InfoPane/InstallationStepDetailView.swift)
  • Duplicated block (13 lines × 2) (Xcodes/Backend/AppState.swift)
  • Duplicated block (13 lines × 2) (Xcodes/Frontend/Preferences/AdvancedPreferencePane.swift)
  • Duplicated block (15 lines × 2) (Xcodes/Frontend/Preferences/DownloadPreferencePane.swift)
  • Duplicated block (7 lines × 2) (Xcodes/Backend/AppState.swift)
  • FileTooLong: Backend/AppState.swift (Xcodes/Backend/AppState.swift)
  • Floating branch dependency: asynchttpnetworkservice
  • Floating branch dependency: swift-srp
  • Floating branch dependency: xcodesloginkit
  • Further sole-owners (lower concentration)
  • …and 28 more

Changes since last survey

  • 20 commits — 15 feature/other, 5 fixes

By area

  • (repo) — 7 commits
  • Xcodes.xcodeproj/project.pbxproj — 3 commits
  • Xcodes/Resources — 3 commits
  • Xcodes/Backend — 2 commits
  • Xcodes/Frontend — 2 commits
  • HelperXPCShared/FileOperations.swift — 1 commit
  • Xcodes.xcodeproj/project.xcworkspace — 1 commit
  • XcodesTests/AppStateTests.swift — 1 commit

Notable commits

  • fix: Fix platform architecture picker visibility
  • fix: Merge pull request #840 from YuriNachos/fix/install-notification-title
  • fix: Merge pull request #849 from XcodesOrg/fix/platform-architecture-picker
  • fix: chore: update xcodesKit and LoginKit to latest. minor fixes
  • fix: fix: notify on new Xcode version identity, not array-count growth
  • change: Add localized label for privileged-helper file operations toggle
  • change: Add missing translations for new Uninstalling/UsePrivilegedHelperForFileOperations strings
  • change: Add privileged file-operation XPC methods to the helper
  • change: Mark createSymbolicLink test async to match new async signature
  • change: Merge branch 'main' into signin-autofill
  • change: Merge pull request #839 from zeromhz/signin-autofill
  • change: Merge pull request #842 from YuriNachos/YuriNachos/w9-xcodes
  • change: Merge pull request #847 from abiligiri/feature/privileged-helper-file-ops
  • change: Merge pull request #851 from XcodesOrg/updateXcodesKit+Login
  • change: Route Xcode select/rename/symlink/uninstall file ops through the privileged helper
  • change: Route install-time Xcode.app move through privileged helper
  • change: Show a spinner while an Xcode uninstall is in progress
  • change: better 401 error messages
  • change: v 4.1.1b41
  • change: v4.1 - v2.1 Helper tool

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

XcodesOrg/XcodesApp was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit f9d50b93c7c4fde19ec3033e553471adee762a82 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d00c643c3f66.