Published evidence

Ten read-only pilots. Separate migration proof.

PkgLift tests real project shapes at exact commits, records the classification result, and treats a conservative refusal as useful evidence—not a reason to weaken a safety gate.

Read-only matrix: the ten pinned cases below receive analysis, plan generation, and a migration dry run only in this workflow. This matrix does not run migrate --apply or project scripts, and upstream source is not published as a PkgLift artifact. The separate AWS apply/build qualification is described below.
Upstream pilots

10

Pinned, read-only project shapes.

External migration case

1

Separate AWS single-target partial apply and build.

Mixed-language fixture

1

Repo-owned apply, resolve, and build proof.

Read-only pilot matrix

Each checkout is isolated and pinned to the commit shown. The observed result is an expectation enforced by the pilot harness, not a claim that the whole upstream project can be migrated automatically.

Project shapePinned sourceObserved result
Positive sampleAmazon IVS grid feedSDWebImage is AUTO; AmazonIVSPlayer remains non-automatic.
Mixed catalogLoodosCaseAlamofire, Kingfisher, and lottie-ios 3.2.2 are AUTO; older Firebase and unsupported identities stay non-automatic.
Dynamic RubyV2ex-Swiftpost_install and dynamic Ruby force a mutation-free refusal; no direct entry becomes AUTO.
Broad compatibilityTinode iOSEleven direct identities remain non-automatic because of dynamic Ruby and post_install.
Large dependency setXcodeBenchmarkForty-two identities are classified; MagicalRecord proves unpinned Git provenance and RxBluetoothKit proves that a tag without a full checkout commit remains incomplete. Neither becomes AUTO. The complete pilot result contains no AUTO entries.
Objective-C/macOSHammerspoonTen direct identities are found; CocoaHTTPServer proves unpinned Git provenance and Sentry proves that a tag without a full checkout commit remains incomplete. Neither becomes AUTO. The complete pilot result contains no AUTO entries.
Nested exampleAcknowList exampleThe local AcknowList pod remains BLOCKED.
Parenthesized syntaxfastlane exampleLiteral target and pod calls are attributed exactly; unmapped HexColors remains UNKNOWN.
Project without workspaceFirebaseUI sampleExplicit project selection works; local pods are blocked and Firebase/Auth remains REVIEW.
Legacy FirebaseLegacy Auth QuickstartMappings are found, but attribution and use_frameworks! prevent AUTO.

Separate 1.0 external qualification

In real-project qualification run 36606015426, a disposable copy of the pinned Amazon IVS grid-feed project passed a baseline build, migrated SDWebImage 5.18.1, and passed a fresh build while retaining AmazonIVSPlayer 1.40.0. The positive case exercises one application target.

The same workflow verified conservative refusal for the FirebaseUI project and Hammerspoon workspace: neither produced an AUTO entry or ran apply. These are refusal controls, not positive migration cases.

This source qualification ran on PkgLift commit 70575a9. The 1.0 qualification record separately identifies the signed release candidate and its acceptance results.

Deferred scope: positive external multi-target/workspace qualification remains deferred after 1.0. The AWS single-target result and these refusal controls do not close that case. See the exact environment cells for each recorded workload.

The repository-owned end-to-end fixture

Additional controlled apply and build evidence comes from Fixtures/MixedLanguageSDWebImage, a fixture owned by this repository. It contains one target with both Swift and Objective-C consumers of SDWebImage.

  1. A disposable baseline copy builds with CocoaPods.
  2. A second disposable copy records protected source and resource hashes.
  3. The complete reviewed AUTO set must equal exactly SDWebImage.
  4. The dry run must leave the whole tree unchanged.
  5. This repo-owned copy reaches apply, SwiftPM resolution, and simulator build verification.
  6. The protected hashes must still match afterward.

Audit the evidence

The detailed methodology, licensing notes, pins, and expected outcomes live in Documentation/Pilots.md. The executable definitions are the read-only pilot workflow and the separate repo-owned end-to-end workflow. The real-project qualification workflow owns the separate AWS apply/build and refusal controls.

Have a different project shape?

Turn the unknown into reproducible evidence.

Run analysis on a recoverable copy, remove private identifiers, and share the classification or failure without applying changes.