lethen 3.8.1-dev.1
Pre-releaselethen 3.8.1-dev.1
The first lethen development prerelease establishes reliable scanning on Swift 6.4 / Xcode 27. Distribution is source-only. Tags through 3.8.0 retain upstream Periphery history and attribution; they are not lethen releases.
Changes
- Resolve the active SwiftPM binary directory and explicitly enable indexing, including release builds. Custom scratch roots, default/native builds, and explicit external stores remain distinct; missing stores fail with actionable errors.
- Restore the working directory after thrown errors and report fixture setup/indexing failures through XCTest instead of crashing.
- Update the four incompatible iOS fixture settings to 15.0 while preserving the other targets and assertions.
- Connect generated SwiftUI state projections to source properties and model missing synthesized equality reads. Explicit custom equality and unused controls remain covered.
- Require the exact-commit
Swift 6.4 / Xcode 27CI check, retaining the existing stable macOS/Linux and Bazel jobs.
Existing .periphery.yml settings, // periphery:ignore comments, library names, and attribution are preserved. No broad dependency upgrade or baseline suppression was used.
Verification and limits
The verified baseline passes 322 tests across all four targets, with no failures or compatibility skips. Clean, warm reused-index (--skip-build), and native fixture scans agree on 423 findings; strict clean self-scan passes. All 12 non-optional CI jobs pass on the code baseline, including macOS/Linux Swift 6.1–6.3 and Bazel 8.x/9.x. The exact versioned commit passed its final CI gate; evidence is recorded below.
The private-project audit reviewed a deterministic sample of 30 findings, fixed seven sampled false positives, verified 11 retained controls, and passed 60 tests after temporary removals. Restored clean/warm scans agree on 154 findings. This sample does not establish that every finding is correct or every unused declaration is found. Assign-only storage may intentionally control object lifetime or support external tooling; package APIs may have consumers outside the scanned scheme.
Automatic synthesized-equality modeling is conservative and relies on indexed source callers and visible custom witnesses. Broader --retain-equatable-properties / --retain-hashable-properties options remain available. Externally built automatic swiftbuild indexes require explicit --index-store-path; --skip-build discovery expects explicitly enabled indexes. Managed SwiftPM discovery builds rebuild existing products to prevent stale stores after external unindexed builds. This adds build time; use --skip-build only when the index is known to be current.
The compatibility table separates toolchain, project/build engine, host, and evidence. The local source-install baseline is Apple Swift 6.4 / Xcode 27.0 on arm64 macOS 27. Intel macOS, universal/signed binaries, and running a Swift 6.4-built binary on macOS 15 are unverified. The package minimum alone does not prove runtime compatibility. Snapshot jobs are not support promises.
Source installation
Select a full Xcode installation on macOS, for example:
sudo xcode-select -s /Applications/Xcode.app/Contents/DeveloperThen install the explicit tag:
git clone --branch 3.8.1-dev.1 --depth 1 https://github.com/albovsky/lethen.git
cd lethen
swift build -c release --product lethen
lethen_bin_dir="$(swift build -c release --show-bin-path)"
"$lethen_bin_dir/lethen" version
"$lethen_bin_dir/lethen" scan --help
mkdir -p "$HOME/.local/bin"
install -m 755 "$lethen_bin_dir/lethen" "$HOME/.local/bin/lethen"
export PATH="$HOME/.local/bin:$PATH"
lethen scan --project-root /path/to/your/project --disable-update-checkKeep the PATH export in your shell profile. Build paths are queried because swiftbuild and native layouts differ. The optional update checker uses GitHub's stable /releases/latest endpoint and does not discover prereleases; install development tags manually.
Release gates include a clean detached candidate build, a real fixture scan with the installed release binary, exact-commit CI, and a fresh public-tag installation. The GitHub release records the final commit, CI link, and installation outcome. Binary signing/publishing automation remains disabled.
Final release evidence
- Verified commit and annotated tag target:
04c6965c8a1f99d34a2ee71da20b0dbc6df4b031. - All 12 non-optional jobs passed in the final matrix run. The required exact-commit Xcode 27 check records 322 passing tests, 423 matching clean/reused/native findings, strict self-scan, and version
3.8.1-dev.1. Itsswift-6.4-evidenceartifact contains the logs and full comparison sets. - A separate full local suite passed all 322 tests on that exact commit. Final analysis preserved all 154 restored private-project findings.
- A clean detached candidate and a fresh clone of the public
3.8.1-dev.1tag each built withswift build -c release --product lethen. Each executable was located through--show-bin-path, checked withversionandscan --help, installed, and used for a real default fixture scan matching all 423 findings. External fixture locations were compared by absolute identity across checkout depths; no findings were discarded. - Both installation checks ran on arm64 macOS 27.0 (26A428), Xcode 27.0 (27A266a), Apple Swift 6.4 (
swiftlang-6.4.0.34.1). Public-tag release binary SHA-256:3d311da45fc2f36898cebd1f1322c36f1c645777e6f23cd8be3b75f15a29d702. This is verification metadata, not a distributed binary asset. - The optional Linux main-snapshot job failed. Snapshot jobs are outside the release gate and support claims.
- Final review was performed locally by the author as required by the implementation plan; no independent review is claimed. The pull request remains available for review.