migrate --apply or project scripts, and upstream source is not published as a PkgLift artifact. The separate AWS apply/build qualification is described below.10
Pinned, read-only project shapes.
1
Separate AWS single-target partial apply and build.
1
Repo-owned apply, resolve, and build proof.
Read-only pilot matrix
Each checkout is isolated and pinned to the commit shown. The observed result is an expectation enforced by the pilot harness, not a claim that the whole upstream project can be migrated automatically.
| Project shape | Pinned source | Observed result |
|---|---|---|
| Positive sample | Amazon IVS grid feed | SDWebImage is AUTO; AmazonIVSPlayer remains non-automatic. |
| Mixed catalog | LoodosCase | Alamofire, Kingfisher, and lottie-ios 3.2.2 are AUTO; older Firebase and unsupported identities stay non-automatic. |
| Dynamic Ruby | V2ex-Swift | post_install and dynamic Ruby force a mutation-free refusal; no direct entry becomes AUTO. |
| Broad compatibility | Tinode iOS | Eleven direct identities remain non-automatic because of dynamic Ruby and post_install. |
| Large dependency set | XcodeBenchmark | Forty-two identities are classified; MagicalRecord proves unpinned Git provenance and RxBluetoothKit proves that a tag without a full checkout commit remains incomplete. Neither becomes AUTO. The complete pilot result contains no AUTO entries. |
| Objective-C/macOS | Hammerspoon | Ten direct identities are found; CocoaHTTPServer proves unpinned Git provenance and Sentry proves that a tag without a full checkout commit remains incomplete. Neither becomes AUTO. The complete pilot result contains no AUTO entries. |
| Nested example | AcknowList example | The local AcknowList pod remains BLOCKED. |
| Parenthesized syntax | fastlane example | Literal target and pod calls are attributed exactly; unmapped HexColors remains UNKNOWN. |
| Project without workspace | FirebaseUI sample | Explicit project selection works; local pods are blocked and Firebase/Auth remains REVIEW. |
| Legacy Firebase | Legacy Auth Quickstart | Mappings are found, but attribution and use_frameworks! prevent AUTO. |
Separate 1.0 external qualification
In real-project qualification run 36606015426, a disposable copy of the pinned Amazon IVS grid-feed project passed a baseline build, migrated SDWebImage 5.18.1, and passed a fresh build while retaining AmazonIVSPlayer 1.40.0. The positive case exercises one application target.
The same workflow verified conservative refusal for the FirebaseUI project and Hammerspoon workspace: neither produced an AUTO entry or ran apply. These are refusal controls, not positive migration cases.
This source qualification ran on PkgLift commit 70575a9. The 1.0 qualification record separately identifies the signed release candidate and its acceptance results.
The repository-owned end-to-end fixture
Additional controlled apply and build evidence comes from Fixtures/MixedLanguageSDWebImage, a fixture owned by this repository. It contains one target with both Swift and Objective-C consumers of SDWebImage.
- A disposable baseline copy builds with CocoaPods.
- A second disposable copy records protected source and resource hashes.
- The complete reviewed
AUTOset must equal exactlySDWebImage. - The dry run must leave the whole tree unchanged.
- This repo-owned copy reaches apply, SwiftPM resolution, and simulator build verification.
- The protected hashes must still match afterward.
Audit the evidence
The detailed methodology, licensing notes, pins, and expected outcomes live in Documentation/Pilots.md. The executable definitions are the read-only pilot workflow and the separate repo-owned end-to-end workflow. The real-project qualification workflow owns the separate AWS apply/build and refusal controls.
Turn the unknown into reproducible evidence.
Run analysis on a recoverable copy, remove private identifiers, and share the classification or failure without applying changes.