xtool-org/xtool
58.5
Adequate · 30 September 2026
10.9k
lines of production code
Swift
primary language
2
measurements over time
What this system is
xtool is a cross-platform command-line interface and library that enables iOS app development, signing, and deployment on non-macOS hosts like Linux. It provides a comprehensive suite of tools for managing Apple Developer resources, handling code signing artifacts, and orchestrating device installations via a unified API. The system supports building iOS applications and extensions using Swift Build, while offering native macOS packaging and authentication workflows for seamless integration into existing development environments.
Features
Automated documentation build script added
A new build script (build.sh) has been added to the Documentation directory to streamline the generation of DocC documentation. This script automatically locates the DocC tool, cleans the output directory, and supports two modes: 'convert' to generate static documentation and 'preview' for local development. It enables experimental features such as code block annotations and custom templates to enhance the documentation output.
Documentation · high confidence
Automated macOS build, signing, and notarization pipeline
A new Fastlane configuration has been added for the macOS platform, enabling an automated pipeline to build, sign, and notarize the XTool application. The setup defines the app identifier (sh.xtool.XToolMac) and implements a 'package' lane that handles code generation, keychain management, certificate import, and provisioning profile generation. It specifically configures the build for 'developer-id' distribution, performs Apple notarization on the resulting .app bundle, and re-packages the application using 'ditto' to ensure resource forks are handled correctly for codesigning compliance.
macOS/fastlane · high confidence
Initial Linux AppImage build support
Added a new Linux build pipeline that packages the xtool CLI as an AppImage. This includes a build script (build.sh) that compiles the Swift binary, integrates linuxdeploy for packaging, and supports building natively or via Docker. The entry also adds necessary configuration files such as a .gitignore, a desktop entry file for Linux integration, and documentation explaining the setup and usage.
Linux · high confidence
Interactive code-signing identity selection script
Added a new shell script that helps developers select a valid Apple Development code-signing identity from the system keychain. The script lists available identities, extracts the associated team name from the certificate's Organizational Unit, and prompts the user to choose one if multiple options are found, outputting the selected identity and team name.
scripts · high confidence
Introduce IntegratedInstaller and Superconfig for device pairing and installation
Added the IntegratedInstaller actor and Superconfig struct to the XKit integration layer. IntegratedInstaller manages the device pairing workflow (including wireless lockdown and certificate handling) and installation stages, exposing progress updates and user prompts (pair/unlock) via a delegate. Superconfig provides a serializable container for device UDID, pairing keys, device info, team/signing details, and developer tokens, saved as a plist to support the installer's configuration needs.
Sources/XKit/Integration · high confidence
Introduce XKit Signer for app provisioning and code signing
The \Sources/XKit/Signer\ module now provides the core logic for provisioning and codesigning iOS applications. \AutoSigner\ handles the end-to-end workflow, including fetching provisioning profiles, updating bundle identifiers and entitlements in Info.plist files, and installing the mobile provision. \SignerImpl\ wraps the underlying native signing library to perform the actual code signing with support for real certificates or ad-hoc identities, while \SigningContext\ manages the authentication and target device configuration required for these operations.
Sources/XKit/Signer · high confidence
Introduce XKit library with mobileprovision parsing and version reporting
The Sources/CXKit directory now contains the XKit library (renamed from libSupersign), providing a C API for parsing mobile provisioning profiles and reporting the tool version. Users can now create, inspect, and free mobileprovision objects via mobileprovision\_create\_from\_data, mobileprovision\_get\_digest, and mobileprovision\_free, while xtl\_version() exposes the current xtool version string.
Sources/CXKit · high confidence
Introduce macOS .app bundle with CLI and UI support
xtool is now packaged as a macOS .app bundle, enabling the use of macOS-specific features like entitlements and the keychain for credential storage. The application supports both command-line usage (via an embedded shell script wrapper) and a native SwiftUI interface that guides users through the initial setup, including copying the binary to their PATH.
macOS · high confidence
Introduce modular utility library with dependency-injected storage and signing managers
The XKit utilities module adds a suite of foundational components for the application, including a dependency-injected key-value storage system (supporting memory, directory, and keychain backends), a signing information manager for handling private keys and certificates, and a ZIP compressor/decompressor for app payload handling. It also provides helper utilities for safe stdout access, task sleeping, provisioning identifier sanitization, and error grouping, all structured to allow easy testing and backend swapping via the Dependencies framework.
Sources/XKit/Utilities · high confidence
Introduce xtool CLI for cross-platform iOS development
This change adds the \xtool\ command-line interface, enabling iOS app development on non-macOS hosts (such as Linux). It provides commands for authentication (\xtool auth\), SDK management (\xtool sdk\), project scaffolding (\xtool new\), and building/packing apps (\xtool dev build\). The tool supports two authentication modes: Apple ID password login and App Store Connect API keys. It includes a Darwin SDK builder that extracts and configures iOS/macOS SDKs from Xcode archives for use with SwiftPM, and handles device communication for installation and launching.
Sources/XToolSupport · high confidence
New DeveloperServices API client and provisioning operations
This change introduces a new \DeveloperServices\ module that provides a modern, async-first client for interacting with Apple's Developer Portal. It adds support for managing App Groups (creating, listing, and assigning them to apps), handling App ID registration with capability synchronization, and fetching/replacing development certificates with revocation confirmation. The implementation includes a new \DeveloperServicesClient\ for HTTP requests, a legacy API version handler for older endpoints, and an OpenAPI-based client for paginated requests. It also introduces entitlement mapping to capabilities and a \DeveloperServicesProvisioningOperation\ that orchestrates device addition, certificate fetching, and app registration in a single workflow.
Sources/XKit/DeveloperServices · high confidence
New GrandSlam Apple ID authentication and Anisette data subsystem
The XKit/GrandSlam module introduces a complete implementation for Apple ID authentication (GrandSlam) and Anisette data generation. Users can now authenticate via SRP with support for secondary (2FA) flows, fetch app tokens, and retrieve device-specific Anisette headers. The Anisette provider is pluggable: it defaults to an external Omnisette server but can use the local XADI library (via subprocess) when available, and includes logic to fetch and cache the necessary Android libraries for XADI on first use.
Sources/XKit/GrandSlam · high confidence
New XKit Model layer for certificates, entitlements, and provisioning profiles
This change introduces the core data models for the XKit library, enabling the application to handle iOS code-signing artifacts. It adds a Certificate model for parsing and inspecting DER-encoded certificates (extracting developer identity, team ID, and serial number), a Keypair model for generating RSA-2048 private keys and Certificate Signing Requests (CSRs), and a Mobileprovision model for parsing \.mobileprovision\ profiles into structured digests containing devices, certificates, and entitlements. Additionally, it defines a comprehensive Entitlements system with a container for managing lists of entitlements and specific types for supported features such as WiFi-Aware, HomeKit, HealthKit, and various networking and security capabilities.
Sources/XKit/Model · high confidence
New XKit installation subsystem for iOS device management
This change introduces the XKit installation module, providing a complete set of components for managing iOS devices and installing applications. It includes AppInstaller for orchestrating IPA uploads and installations with progress reporting, Connection and ConnectionManager for establishing and pooling device connections (with heartbeat handling on iOS), and utilities for managing provisioning profiles, debugging processes, and mounting developer disk images. The implementation uses the SwiftyMobileDevice framework and is structured as a public actor-based API for concurrent, safe device interaction.
Sources/XKit/Installation · high confidence
New developer services CLI commands for listing resources
The XToolSupport module now includes a new \ds\ command group that allows users to list Apple Developer resources directly from the terminal. This adds subcommands for listing development teams, certificates, devices, bundle identifiers, and provisioning profiles. Each list command paginates through the Developer API to retrieve all items and prints their key attributes (such as names, IDs, platforms, and expiration dates) to the console, providing a quick way to inspect account assets without using the web portal.
Sources/XToolSupport/DSCommands · high confidence
New documentation for creating iOS app extensions
Added a new guide, Appex.md, that walks users through adding a Widget Extension to an xtool-based iOS app. The documentation covers the necessary configuration steps, including defining the extension product in Package.swift, linking it in xtool.yml, creating the required Info.plist with the correct extension point identifier, and writing the WidgetKit code.
Documentation/xtool.docc · high confidence
PackLib now supports building with Swift Build and packaging iOS app extensions
The PackLib library has been refactored to support the new Swift Build system alongside the existing SwiftPM, automatically selecting Swift Build for Swift 6.4+ toolchains and configuring the necessary Darwin SDK toolsets on non-macOS hosts. Additionally, the library now supports packaging iOS app extensions, allowing users to define extension targets in their configuration that are built, signed, and bundled alongside the main application.
Sources/PackLib · high confidence
macOS app packaging and hardened runtime configuration
The macOS build now packages the application as a .app bundle with a hardened runtime enabled. This includes specific entitlements for keychain access and unsigned executable memory, along with an automatic code signing style and a defined app category (developer-tools) in the generated Info.plist.
macOS/Support · high confidence
Behavioural changes
Developer API code generation now uses idiomatic naming and public access
The generated Swift client for the Developer API now exposes types and clients with public access modifiers and applies an idiomatic naming strategy, improving visibility and consistency for consumers. The underlying OpenAPI schema is patched to make response enums extensible (allowing unknown values rather than failing on strict parsing) and to correct the BundleId capability creation request structure, ensuring the generated code accurately reflects the API's actual behavior and requirements.
Sources/DeveloperAPI · high confidence
Improved temporary directory management and cross-platform file operations
The XUtils module now provides more robust handling of temporary directories and file copying across platforms. On Linux, temporary directories are stored in the user's cache directory (e.g., \~/.cache/xtool) instead of /tmp to avoid EINVAL errors when copying between tmpfs and ext4 filesystems during SDK installation. The module also introduces a new \copyItem\ method that can bypass owner preservation by using the \subprocess\ library on Darwin, and includes a \TemporaryDirectory\ struct with locking mechanisms to prevent race conditions and cleanup of orphaned directories.
Sources/XUtils · high confidence
Introduce XTool as a standalone macOS application entry point
The xtool source location now defines a concrete entry point via the XToolMain enum, which initializes dependencies and invokes the core XTool.run() logic. This change establishes the executable structure for packaging xtool as a .app on macOS, replacing previous naming or structural conventions with a clear, Swift-based main function that handles async execution and dependency preparation.
Sources/xtool · high confidence
Introduce platform-specific HTTP client implementations with unified protocol
The HTTP client layer now uses a unified \HTTPClientProtocol\ that provides OpenAPI transport, WebSocket support, and HTTP request handling with error reporting. On Linux, the implementation uses \AsyncHTTPClient\ with a 60-second connect timeout, custom Apple root CA trust configuration, and optional proxy support via the \XTL\_HTTP\_PROXY\ environment variable. On non-Linux platforms, it uses \URLSession\ with ephemeral sessions and similar WebSocket and TLS validation behaviors. Both implementations support disabling TLS validation via the \XTL\_DISABLE\_TLS\_VALIDATION\ environment variable and expose dependency injection keys for testing.
Sources/XKit/HTTPClientProtocol · high confidence
Regenerated Developer API client and types from OpenAPI spec
The generated Swift source files for the Developer API client (Client.swift) and associated types (Types.swift) have been regenerated. This update refreshes the API surface to align with the latest OpenAPI specification, ensuring that the generated client code, including operation definitions and data models, reflects the current state of the Developer API endpoints.
Sources/DeveloperAPI/Generated · high confidence
Removal of user-specific Xcode scheme file
The user-specific Xcode scheme file (Supercharge.xcscheme) has been deleted from the project. This file contained configuration for build, test, launch, profile, analyze, and archive actions, including debugger settings and working directory options. Its removal means that this specific user's custom scheme configuration is no longer tracked in version control, and other developers will rely on the default or shared scheme settings for running and testing the application.
Supercharge.xcodeproj · high confidence
Test coverage
Added integration test suite for xtool; Added integration tests for XTool and XKit components.
Dependencies
Updated Swift Package dependencies and resolved lockfile
The project's Swift Package Manager dependencies have been updated, with the \Package.swift\ manifest now specifying minimum versions for key libraries such as \xtool-core\ (1.5.0), \SwiftyMobileDevice\ (1.7.0), \zsign\ (1.9.0), and \xadi\ (0.4.1). A new \Package.resolved\ lockfile has been added to pin these dependencies, ensuring consistent builds across environments. Additionally, the macOS build configuration now includes a \Gemfile\ and \Gemfile.lock\ to manage Ruby dependencies like \fastlane\ and \fastlane-plugin-xcodegen\.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 62 → 58 (-3.3)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 95 → 94 (-1.4)
- Architecture 100 → 92 (-7.9)
- Maturity 49 → 49 (-0.1)
- Readiness 58 → 56 (-2.3)
- Security 76 → 81 (+5.1)
- Performance 67 (new)
Resolved (15)
- Documentation: no licence statement (Documentation/Contributing/README.md)
- High CVE: [GHSA redacted] (macOS/Gemfile.lock)
- High CVE: [GHSA redacted] (macOS/Gemfile.lock)
- High IaC: WD-DOCKER-0001 (Dockerfile)
- Low CVE: [GHSA redacted] (macOS/Gemfile.lock)
- Medium CVE: [GHSA redacted] (macOS/Gemfile.lock)
- Medium IaC: CKV_DOCKER_4 (Dockerfile)
- Medium IaC: DS-0013 (Dockerfile)
- Medium IaC: WD-DOCKER-0003 (Dockerfile)
- Medium IaC: WD-DOCKER-0003 (Dockerfile)
- Members sharing a duplicated core (4 members, 50+ identical tokens) (Sources/XToolSupport/DSCommands/DSCertificatesCommand.swift)
- Outdated: fastlane
- TodoComment (Sources/XToolSupport/DevCommand.swift)
- TodoComment (Sources/XToolSupport/SDKBuilder.swift)
- TodoComment (Sources/XToolSupport/SDKBuilder.swift)
New (22)
- ClassTooLong: SDKBuilder (Sources/XToolSupport/SDKBuilder.swift)
- Coverage not measured — Swift suite
- Duplicated block (5 lines × 2) (Sources/XToolSupport/SDKBuilder.swift)
- FileTooLong: XToolSupport/SDKBuilder.swift (Sources/XToolSupport/SDKBuilder.swift)
- High: security finding (details withheld)
- Hotspot: Sources/XToolSupport/SDKBuilder.swift (Sources/XToolSupport/SDKBuilder.swift)
- Inconsistent initialization patterns for configuration. Preferences offers three distinct initializers that seem to overlap in intent (configuring how lookups are performed), whereas other similar configuration types (like DeviceInfoProvider or ZIPCompressor) use a single initializer accepting a closure/protocol property. This creates cognitive load regarding which initializer to use.
- Inconsistent naming convention for storage operations. KeyValueStorage uses string/setString (verb-noun), while MemoryKeyValueStorage, DirectoryStorage, and KeychainStorage use data/setData (noun-verb or just noun). This inconsistency extends to the property names (string vs data) and method names (setString vs setData), making the API surface feel disjointed.
- Medium IaC: WD-DOCKER-0003 (Dockerfile)
- Medium IaC: WD-DOCKER-0003 (Dockerfile)
- Members sharing a duplicated core (4 members, 50+ identical tokens) (Sources/XToolSupport/DSCommands/DSCertificatesCommand.swift)
- MethodTooLong: SDKBuilder.installDeveloper (Sources/XToolSupport/SDKBuilder.swift)
- MethodTooLong: SDKBuilder.installToolset (Sources/XToolSupport/SDKBuilder.swift)
- Off the main sequence: XUtils
- Outdated: async-http-client
- Outdated: swift-collections
- Outdated: swift-openapi-runtime
- Projects may be oversized for their cohesion
- Redundant HTTP client abstractions. DeveloperServicesClient exposes a high-level send method, but the underlying infrastructure exposes two distinct methods on HTTPClientProtocol (send and makeRequest) with different signatures and responsibilities. This forces implementers to choose between two inconsistent low-level entry points.
- TodoComment (Sources/XToolSupport/DevCommand.swift)
- …and 2 more
Changes since last survey
- 20 commits — 20 feature/other, 0 fixes
By area
- (root) — 8 commits
- Documentation/xtool.docc — 3 commits
- Sources/PackLib — 3 commits
- Sources/XToolSupport — 3 commits
- .sourcekit-lsp/config.json — 1 commit
- Sources/XKit — 1 commit
- macOS/.ruby-version — 1 commit
Notable commits
- change: Bump xadi to 0.4.1 (#265)
- change: anisette: use XADI Swift Package (#258)
- change: anisette: use XADI on macOS (#259)
- change: build: use SwiftBuild for xtool workspace LSP (#282)
- change: build: use automatic library type (#266)
- change: docker: add SWIFT_VERSION arg (#276)
- change: docs: recommend Xcode 27 and Swift 6.4 (#267)
- change: docs: update remaining reference of Xcode 26 -> 27 (#275)
- change: fastlane: update Ruby and gems (#278)
- change: package: bump Darwin deployment targets to Fall2023 (#277)
- change: package: bump deps (#281)
- change: packer: keep swift build stdout on stdout (#261)
- change: sdk: SwiftBuild support (#229)
- change: sdk: get clang resources from swift toolchain (#274)
- change: sdk: integrate OpenAppleMacros (#101)
- change: sdk: prune Xcode when installing from xip (#280)
- change: sdk: self-updating darwin tools (#110)
- change: sdk: update darwin-tools and OAM (#270)
- change: tests: add integration tests (#252)
- change: zsign: update to v1.9.0 (#271)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
xtool-org/xtool was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 4d0c4298f9ec728168d841d365ca2d4aa0d41f3a — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-cb25ca4feafa.