DigLibrary

Provenance

Built with AI. Check it.

DigLibrary is written with heavy AI assistance. That is said here, at the top, because you would rather know it from the project than work it out later — and because the interesting part is not the admission, it is how much of this you can verify without taking anybody's word.

Who decides what

The division of labour is the reason there is anything to check.

A person

Decides

Every product and architecture decision is made by a person, before the thing is built, and a rule is judged against real music libraries rather than against a fixture written to agree with it.

The AI

Writes, measures, and reports

It writes the code and the tests and measures what a change does. What it is not allowed to do is decide, or claim something it did not measure.

Both

Audit, before each release

A release is preceded by an audit of the code and by a script that checks what a machine can check: that the changelog accounts for every change, that every link names this version, and that the package holds what it should.

Four claims, and the command that settles each

Nothing below asks you to believe anything. Clone the repository and run them.

  1. git clone https://github.com/cankblunt/diglibrary && cd diglibrary
  2. python3 -m venv .venv && .venv/bin/pip install -e ".[dev]"
  3. .venv/bin/python -m pytest -q # 1,997 tests, offline
  4. grep -rniE "telemetry|analytics" src/diglibrary/ # what it sends, which is nothing
Claim

"The tests are real"

They run with no network and no clock of their own — transports, sleeps and clocks are injected. Unplug your network and run the suite; it passes.

They also read the window's own HTML, CSS and JavaScript for the ways those files can disagree without any of them raising an error.

Claim

"Nothing is counted about you"

There is no telemetry, no analytics and no update ping to switch off, because none is present. The only hosts the application reaches are the music catalogues, and the clients that reach them are a short list of files under src/diglibrary/metadata/. If you use Find music, it also reaches the slskd you run yourself, and that client is under src/diglibrary/connectors/slskd/.

Claim

"The quality verdicts are measured"

benchmark/ holds the recipe for a paired benchmark — the same excerpt untouched, filtered, and passed through an encoder at five settings — and the script that scores the shipped rule on it, misses included. Build it from lossless files of your own and read the table.

Claim

"The package is what the repository says"

Releases are published from a tagged commit by a workflow that holds no key at all — the index verifies a short-lived signed identity instead. Every file on PyPI carries an attestation you can fetch and check.

The upload is manual and gated on a human approval, on purpose: a version number can never be reused.

What it is honest about

A project that only publishes its wins is a project you cannot calibrate.

It has been exercised on few machines and few libraries. The test suite proves the code agrees with itself; it does not prove that your library behaves like the ones it was measured on. That is why nothing is written before you approve a plan, and why every write can be reverted.

A 320 kbps transcode passes the spectral rule. The benchmark says so in its own page. The frame-grid measurement reaches nearly every such file; AAC and Opus sources are not detected by it.

It is Beta, and says so in its own metadata. Windows and Linux are intended, with no date; installing on either succeeds and the application then refuses to open and explains why.

Why this is the argument

The fair objection to AI-written software is not that a machine typed it. It is that nobody can tell whether anyone understood it, whether it was checked, or what will happen the first time it meets a case its author never considered.

Those are answerable questions: a suite that runs offline on your machine in about a minute, architecture boundaries asserted by tests rather than promised in a readme, a benchmark you can rebuild, and a plan you read before anything is written.

Judge it on that. If any of it does not hold up, open an issue — a reproducible defect is the most useful thing anybody can send this project.