Skip to content
CAI
Software that uses CAICheck a score

boudra/chainsauce

57.8

Adequate · 21 September 2026

2.7k

lines of production code

TypeScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a general-purpose Ethereum blockchain indexing library, now rewritten as Chainsauce v2. It provides tools for creating indexers that subscribe to contract events and process them asynchronously. The architecture supports persistent state management through SQLite or PostgreSQL backends, enabling efficient reindexing and subscription tracking.

Features

Added Postgres and SQLite cache implementations

The cache layer now supports persistent storage via new Postgres and SQLite backends. These implementations store and retrieve event logs and block headers, handling the merging of sequential and overlapping log ranges to maintain a compact history of events per address and chain.

src/cache · high confidence

Complete v2 rewrite of the indexer with async event handling and caching

The indexer has been rewritten in v2, introducing an \AsyncEventEmitter\ for handling events asynchronously and a \Cache\ interface to store and retrieve events, contract reads, and block data. The \processEvents\ function now processes events from a queue, supporting both in-memory and persistent (SQLite/Postgres) storage backends. The \RpcClient\ now supports concurrent requests with configurable retry and delay settings, and handles specific errors like \JsonRpcRangeTooWideError\. The \Indexer\ API has been updated to support these new capabilities, including a \cache\ option for enabling caching and a \subscriptionStore\ for persistent subscription state.

src · high confidence

Introduce subscription store for persisting blockchain indexing state

Added a new subscription store implementation that persists subscription metadata, including block numbers and log indices, to both PostgreSQL and SQLite databases. This enables the system to track and update the indexed state of subscriptions, supporting operations to save, retrieve, update, and delete subscription records.

src/subscriptionStore · high confidence

Behavioural changes

Chainsauce v2 rewrite and general-purpose Ethereum indexing library

The library has been rewritten as Chainsauce v2, a general-purpose Ethereum blockchain indexing tool. Users can now create indexers via \createIndexer\, subscribe to contract events, and perform one-off or continuous indexing. The update introduces a SQLite-based cache for faster reindexing and supports factory contracts. Configuration files for TypeScript, ESLint, and Vite have been updated to support the new structure.

(repo-wide) · low confidence

New JSON and SQLite storage backends with async, cached, and atomic write support

The storage layer has been rewritten to provide new \JsonDatabase\ and \SqliteDatabase\ implementations. The JSON backend now supports asynchronous I/O, cached reads, and delayed/atomic file writes (writing to a temp file and renaming) to prevent corruption. It also exposes a \writeDelay\ option for debouncing writes. The SQLite backend uses \better-sqlite3\ to store documents as JSON in a single table per collection. Both backends implement the standard \Collection\ interface (\insert\, \findById\, \updateById\, \upsertById\, \all\). The previous \JsonStorage\ class, which relied on an in-memory \collections\ object and a GraphQL server, has been removed.

src/storage · high confidence

Dependencies

Major dependency overhaul and version bump to 1.0.20

The project has been upgraded to version 1.0.20, accompanied by a significant overhaul of its dependencies. The codebase has shifted from using \ethers\ and \express\ to a modern stack featuring \viem\, \better-sqlite3\, and \pg\. Additionally, the build and test tooling has been updated to use \vitest\ and \typescript\ 5.1.5, replacing the previous test and linting setup.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 60 → 58 (-2.2)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 91 → 84 (-6.9)
  • Architecture 100 → 100 (-0.1)
  • Maturity 48 → 45 (-2.9)
  • Readiness 59 → 54 (-5.1)
  • Security 68 → 82 (+13.8)

Resolved (28)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: [GHSA redacted] (package-lock.json)
  • …and 8 more

New (60)

  • Coverage not measured — JavaScript/TypeScript suite
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • FunctionTooLong: eventProcessor.processEvents (src/eventProcessor.ts)
  • FunctionTooLong: postgres.createPostgresCache (src/cache/postgres.ts)
  • FunctionTooLong: rpc.createHttpRpcBaseClient (src/rpc.ts)
  • FunctionTooLong: sqlite.createSqliteCache (src/cache/sqlite.ts)
  • FunctionTooLong: subscriptions.getSubscriptionEvents (src/subscriptions.ts)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • …and 40 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

boudra/chainsauce was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 087d040c9397c2e5fa8294491cc05087b1d76d23 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.