Skip to content
CAI
Software that uses CAICheck a score

commanded/commanded-audit-middleware

52.6

Weak · 21 September 2026

338

lines of production code

Elixir

primary language

7

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is an Elixir-based application that implements a command auditing middleware to automatically record the execution details of dispatched commands. It persists command metadata, success status, and error information to a database, supporting environment-specific configurations and JSONB storage for optimized querying. The system includes comprehensive tests and SQL scripts to verify middleware behavior and inspect audit logs.

Features

Added command auditing middleware to record command execution details

A new auditing middleware has been introduced to the Commanded framework, enabling automatic recording of every dispatched command to a database. This feature captures command metadata, execution success or failure, error details, and execution duration, while allowing sensitive fields like passwords to be filtered from the stored data.

lib/commanded · high confidence

Configure environment-specific database connections for command auditing

The application now supports environment-specific database configurations for the \commanded\_audit\_middleware\. A new \config/config.exs\ file centralizes common settings like the Ecto repository and serializer, while separate files (\dev.exs\, \jsonb.exs\, \prod.exs\, \test.exs\) define environment-specific database connection details (e.g., \commanded\_audit\_middleware\_dev\, \commanded\_audit\_middleware\_jsonb\_test\). This allows the audit middleware to connect to different databases depending on the environment, with \jsonb.exs\ specifically configuring JSONB column schemas for testing.

config · medium confidence

Behavioural changes

Add SQL script to query command audit logs

A new SQL script, scripts/command\_audit.sql, has been added to query the command\_audit table. It retrieves key audit fields including causation\_id, correlation\_id, command\_type, success status, and error details. The script also calculates and displays execution duration in milliseconds and seconds, providing a ready-to-use query for inspecting the last 50 dispatched commands.

scripts · high confidence

Audit table schema and indexing for command tracking

The system now persists dispatched commands to a new \command\_audit\ table, capturing details such as command type, execution duration, and success status. The schema includes \causation\_id\ and \correlation\_id\ fields to support distributed tracing. Additionally, GIN indexes are created on the \data\ and \metadata\ columns (when configured as JSONB) to optimize query performance on these fields.

priv · high confidence

Removed Commanded auditing middleware

The Commanded.Middleware.Auditing module, which previously handled auditing of dispatched commands to the database, has been removed from the codebase.

lib · medium confidence

Update installation and configuration instructions for v1.0.0

The README has been updated to reflect the v1.0.0 release, including new configuration options for serializing audit data as JSONB in PostgreSQL. Users are now instructed to configure the \serializer\, \data\_column\_schema\_type\, and \metadata\_column\_schema\_type\ to enable JSONB support, alongside updated dependency and environment setup steps.

(repo-wide) · high confidence

Test coverage

Added tests for the Commanded auditing middleware

Added comprehensive unit tests for the Commanded auditing middleware, covering scenarios for recording command dispatches, tracking success and failure states, capturing error details, and verifying that sensitive fields are filtered from audit records. The previous placeholder test file was removed and replaced with a full test suite in \test/auditing\_test.exs\ that validates the middleware's behavior across various command execution outcomes.

test · high confidence

Dependencies

Upgrade to Commanded 1.0.0 and Ecto 3.3

The project has been updated to support Commanded 1.0.0 and Ecto 3.3, requiring Elixir 1.7 or later. This upgrade aligns the middleware with the latest stable releases of these core libraries, ensuring compatibility with modern Elixir ecosystems and providing access to new features and bug fixes in the underlying frameworks.

(dependencies) · medium confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 48 → 53 (+4.9)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 (new)
  • Architecture 69 → 69 (+0.0)
  • Maturity 34 → 34 (+0.0)
  • Readiness 46 → 62 (+16.2)
  • Security 99 → 79 (-19.5)

Resolved (9)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • No exposed public API
  • Test reliability not included
  • The document links only to CHANGELOG.md (one line) and no architecture or contribution docs; the outline lists Contributing and Contributors sections. (README.md)
  • complexity unreadable for .exs — churn × complexity hotspots could not be measured
  • dormant codebase — no living knowledge left to concentrate

New (14)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • No SBOM
  • No artifact signing
  • No build provenance
  • No dependency advisory monitoring
  • Outdated: commanded
  • Outdated: ecto
  • Outdated: ecto_sql
  • Outdated: ex_doc
  • Outdated: jason
  • Outdated: postgrex

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

commanded/commanded-audit-middleware was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 488b77bac82ac795206a589276391108c4cd9264 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.