CocoaPods → Swift Package Manager

Move dependencies.
Keep the certainty.

PkgLift analyzes native Xcode projects, creates a reviewable migration plan, and applies only dependency changes backed by exact evidence.

Apple Silicon · macOS 14 distribution minimum · MIT licensed. See the verified environments.

1. Install PkgLift:

brew install Alexsvensson99/tap/pkglift

2. Open Terminal in your project's folder and run:

pkglift analyze

Analysis prints its findings in Terminal. Your Xcode project and Podfile stay unchanged.

migration — zsh
$ pkglift analyze
Scanning MyApp.xcworkspace…
Found 3 direct CocoaPods dependencies.

$ pkglift plan
AUTO     Alamofire 5.9.1
         exact mapping + supported lockfile version
REVIEW   LegacyAnalytics
         external source requires human review
UNKNOWN  InternalUI
         no exact registry evidence

Plan saved to .pkglift/plan.json

$ pkglift migrate
Dry run complete. No project files changed.

$ pkglift migrate --apply
Applied 1 reviewed AUTO migration.
Preserved 2 CocoaPods dependencies.

$ pkglift verify --build --scheme MyApp
✓ package linkage
✓ SwiftPM resolution
✓ Xcode build
Dry-run firstPreview and prove a clean diff before apply.
Fail closedAmbiguity becomes review—not a guessed edit.
Mixed-language proofSwift and Objective-C consumers verified together.
Signed & notarizedDeveloper ID distribution for macOS.
Stable releases

Install the latest signed release

Use the CLI to analyze, plan, apply, and verify supported migrations while uncertain dependencies stay under CocoaPods.

PkgLift 1.0.1, published 2026-10-02 Europe/Stockholm, retains the stable 1.x public CLI, JSON, and Swift library contracts within its documented compatibility scope. Exact dependency and project evidence still governs every AUTO decision.

Version 1.0.1 fails closed on unsupported .xcproj definitions before analysis or migration, including bundles with both PBX and JSON definitions. It does not add JSON-project migration. Read the release notes and qualification record.

Install through Homebrew or download the latest signed, notarized macOS release. Already using PkgLift? Run brew update && brew upgrade pkglift to update a Homebrew installation.

Regenerate saved migration plans after upgrading to 1.0.1. Executable plans are bound to the exact PkgLift version that created them.

The signed CLI runtime was verified on macOS 14.8.9 without a consumer build. Hosted consumer acceptance used macOS 15.7.9/Xcode 16.4; separate local validation used macOS 27.0/Xcode 27.0. These are independent observations, not a continuous support range. See the exact environment cells. Positive external multi-target/workspace qualification remains deferred.

Evidence-backed migration

Review a plan, preview the changes, and apply only entries backed by exact registry, version, target, and language evidence.

Build verification checks the resulting package linkage before you accept the migration.

Conservative boundaries

Uncertain dependencies stay with CocoaPods, and unsupported project shapes—including unsupported .xcproj definitions—are refused instead of guessed.

Dry run remains the default so you can inspect the proposed change first.

Workflow

Four deliberate steps

PkgLift separates discovery, decision-making, mutation, and verification so every risky transition remains visible.

1

Analyze

Discover nested projects, workspaces, Podfiles, targets, and locked dependency versions.

2

Plan

Classify every direct dependency and save a reviewable, typed migration plan.

3

Migrate

Dry-run by default. Apply only the reviewed entries classified as AUTO.

4

Verify

Check package-product-target linkage, resolve SwiftPM, and optionally run an Xcode build.

Real-project evidence

The refusals are part of the proof.

Ten public projects are pinned and exercised through read-only analysis, planning, and dry run. A separate qualification run proves one AWS single-target partial migration and build; repository-owned fixtures provide additional controlled migration evidence.

Explore all pilot outcomes
3 AUTO

Positive mixed case

Known dependencies move only when project context preserves the full evidence chain.

REVIEW

Hooks stay visible

Dynamic Ruby and install hooks stop otherwise plausible mappings.

BLOCKED

Local pod

A nested local dependency is detected and deliberately preserved.

UNKNOWN

No invented mapping

An exact literal declaration still stays put when registry evidence is absent.

Safety model

Not every dependency should move automatically

AUTO

Evidence is complete

Exact mapping, supported locked version, verified product and target, plus complete consumer-language evidence.

REVIEW

Human context matters

A plausible path exists, but unsupported project context or judgment is required.

BLOCKED

Known unsafe shape

The project contains a construct that prevents a safe automatic migration.

UNKNOWN

No exact evidence

PkgLift does not invent a repository URL, product, target, or compatible version.

A refusal is a successful safety outcome. Dynamic Ruby, install hooks, external pod sources, incomplete source profiles, ambiguous targets, and Carthage or cross-platform integration remain visible instead of being forced into an automatic conversion.
Verified case study

Swift and Objective-C consumed the same migrated package.

In the repo-owned mixed-language fixture, PkgLift migrated exactly SDWebImage, resolved SwiftPM, built for the simulator, and preserved every source and resource hash.

Read the end-to-end evidence

CocoaPods baseline

The mixed Swift and Objective-C target built before migration.

Reviewed plan

The complete AUTO set was exactly SDWebImage.

Controlled apply

Only the disposable repo-owned fixture was mutated.

Verification

SwiftPM resolution, simulator build, and protected hashes passed.

Ready to inspect your project?

See what PkgLift finds in your project

Run pkglift analyze from your project's folder. It prints a report without modifying your Xcode project or Podfile. Review the findings before creating a migration plan.