Skip to content
CAI
Software that uses CAICheck a score

commanded/eventstore

69.2

Adequate · 21 September 2026

6.6k

lines of production code

Elixir

primary language

7

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is an Elixir-based event sourcing library backed by PostgreSQL, designed to manage event streams and subscriptions. It provides core capabilities for appending, reading, and subscribing to events, along with snapshot management and multi-node cluster support. The system includes comprehensive tooling for database migrations, performance benchmarking, and extensive test coverage for its storage and notification layers.

How it got here

2016 — Initial release and core feature implementation

18 changes.

This period marks the initial release of the EventStore library for Elixir, establishing the foundational structure for an event sourcing system backed by PostgreSQL. The work focused on implementing core features including the event store macro, SQL schema initialization, and the complete storage layer for event persistence and subscription management. Comprehensive test coverage was added to validate the new functionality across streams, subscriptions, and storage operations.

2017–2020 — multi-node cluster and notification subsystem

11 changes.

This period focused on enabling multi-node cluster configurations and implementing a PostgreSQL-based notification system for low-latency event propagation. The work included adding cluster node configuration files, database schema migrations, and a GenStage-based listener/publisher architecture for handling stream changes. Additionally, the codebase was refactored to support multiple event stores and included comprehensive testing for the new notification and subscription systems.

Features

Add Mix task utilities for managing multiple event stores

A new \Mix.EventStore\ module was added to provide conveniences for writing EventStore-related Mix tasks. This includes a \parse\_event\_store/1\ function that parses command-line arguments (e.g., \-e\ or \--eventstore\) and falls back to reading the \event\_stores\ key from the application environment, supporting multiple event stores. Additionally, \ensure\_event\_store!/2\ was updated to support runtime configuration by running \app.config\ (for Elixir v1.11+) or falling back to \loadpaths\/\compile\ for older versions, ensuring the specified module is a valid EventStore implementation.

lib/mix · medium confidence

Add advisory lock management and serialization infrastructure

The event store now includes a new \EventStore.AdvisoryLocks\ module to manage PostgreSQL advisory locks, ensuring exclusive access to resources. A \MonitoredServer\ helper is introduced to manage and restart database connections with exponential backoff. Serialization is expanded with new modules: \JsonSerializer\ (using Jason), \JsonbSerializer\, and \TermSerializer\ (using Erlang's external term format). The \RecordedEvent\ struct is updated to include \stream\_uuid\ and \created\_at\ (as \DateTime\). Configuration is centralized in \EventStore.Config\ and \EventStore.Config.Parser\, supporting options like \column\_data\_type\, \correlation\_id\_type\, and \causation\_id\_type\. The \Page\ struct supports pagination metadata.

_lib/event\store · high confidence

Add cluster node configuration files for multi-node setup

Added sys.config files for three cluster nodes (node1, node2, node3) that configure kernel-level settings for inter-node communication. Each node is configured to optionally sync with the other two nodes on localhost (127.0.0.1) with a 30-second timeout, enabling a basic multi-node cluster topology.

cluster · high confidence

Added SQL scripts for data access and management

New SQL scripts have been added to the project to support querying and managing event data. The 'all\_events' script retrieves event details from the stream, 'snapshots' queries snapshot data, 'subscriptions' lists subscription status with pending event counts, and 'truncate' clears all relevant tables. These scripts provide the necessary database operations for handling snapshots, subscriptions, and general event data.

scripts · high confidence

Added benchmarking seed script for the event store

A new Elixir script (bench/seed\_eventstore.exs) has been added to populate the event store with 1 million events for benchmarking purposes. This script initializes the test event store and generates events using the EventFactory, enabling performance testing workflows.

bench · high confidence

Added storage benchmarks for append, read, and subscribe operations

Added three new benchmark suites in the bench/storage directory to measure the performance of the event store's core operations. AppendEventsBench tests concurrent event writes with 1, 10, 20, and 50 concurrent writers. ReadEventsBench measures read performance with 1, 10, 20, and 50 concurrent readers. SubscribeToStreamBench evaluates stream subscription throughput with 1, 10, 20, and 50 concurrent subscriptions, including a specific test for checkpoint threshold configuration.

bench/storage · high confidence

Implement PostgreSQL LISTEN/NOTIFY-based event notification system

Added a new notification subsystem that uses PostgreSQL's LISTEN/NOTIFY mechanism to listen for event stream changes and broadcast them to subscribers. The system consists of a Listener (GenStage producer) that receives notifications, a Publisher (GenStage consumer) that reads the affected events from storage, and a Supervisor to manage the lifecycle of these processes. The notification payload now includes the stream UUID, stream ID, and version range, enabling efficient, low-latency event propagation.

_lib/event\store/notifications · high confidence

Initial release of EventStore for Elixir

This entry marks the initial commit of the EventStore project, establishing the foundational structure for an Elixir-based event sourcing library backed by PostgreSQL. The diff introduces core configuration files (\.formatter.exs\, \.tool-versions\ specifying Elixir 1.16.0 and Erlang 26.2.1), a \.dialyzer\_ignore.exs\ to suppress specific type warnings, and a comprehensive \README.md\ that documents installation, usage examples, and performance benchmarks. It also includes a \docker-compose.yml\ for local development, a \LICENSE\ file, and a \docker-compose.yml\ for standing up a suitable database for testing.

(repo-wide) · high confidence

Introduce EventStore macro and module for defining event stores

The library now provides a macro to define an event store module, allowing users to configure and start event stores with support for dynamic named instances, custom Postgres schemas, and shared database connection pools. The previous \EventStore\ module has been replaced by a new \EventStore\ module that serves as the main entry point, while a new \register\_postgres\_types\ file handles Postgrex type registration with the Jason library for JSON serialization.

lib · high confidence

Introduce SQL schema initialization and statement generation for PostgreSQL

The \lib/event\_store/sql\ directory now contains the core SQL schema initialization and statement generation logic for PostgreSQL. The \Init\ module defines the DDL statements to create the \streams\, \events\, \stream\_events\, \subscriptions\, and \snapshots\ tables, along with necessary triggers and functions to enforce immutability and handle notifications. The \Reset\ module provides statements to truncate these tables for testing or reset scenarios. The \Statements\ module dynamically generates SQL queries for common operations like inserting events, querying streams, and managing subscriptions using EEx templates. This establishes the foundational database structure and query layer for the event store.

_lib/event\store/sql · high confidence

Introduce Stream and StreamInfo modules for event stream management

Added the \EventStore.Streams.Stream\ and \EventStore.Streams.StreamInfo\ modules to handle core stream operations. The \Stream\ module provides functions for appending, linking, reading, and deleting events, including batched appends, transactional writes, and forward/backward streaming. The \StreamInfo\ module defines the stream metadata structure and validates expected versions, ensuring correct state transitions for stream creation, deletion, and versioning.

_lib/event\store/streams · high confidence

New storage layer for event persistence and subscription management

The \lib/event\_store/storage\ directory now contains a complete set of new modules (Appender, CreateStream, Database, DeleteStream, Initializer, Lock, Reader, Schema, Snapshot, Stream, and Subscription) that implement the backend operations for the event store. This includes batched event appending, stream creation and deletion, database schema management, advisory locking for subscriptions, event reading, and snapshot handling, all interacting with PostgreSQL via Postgrex.

_lib/event\store/storage · high confidence

Runtime configuration storage and URL parsing for Event Store

The library now persists event store configuration at runtime using a GenServer-backed store, allowing the system to track all running event store instances and retrieve their settings. Additionally, a new parser module handles database URL parsing, supporting encoded passwords and query parameters for connection options like SSL and pool size.

_lib/event\store/config · high confidence

Snapshot serialization and management

The Event Store now supports serializing and deserializing snapshot data and metadata using a configurable serializer. This change introduces new modules (\SnapshotData\ and \Snapshotter\) that handle the conversion of snapshot data into a storable format and back, allowing for flexible data handling. Additionally, the system now supports deleting previously recorded snapshots.

_lib/event\store/snapshots · high confidence

Behavioural changes

Database schema migrations for Event Store versions 0.9.0 through 1.3.2

The repository now includes SQL migration scripts for the Event Store database schema, covering versions 0.9.0, 0.10.0, 0.11.0, 0.13.0, 0.14.0, 0.17.0, 1.1.0, 1.2.0, 1.3.0, and 1.3.2. These scripts define the evolution of the event store's internal structure, including the creation of the \schema\_migrations\ table to track versions, the addition of columns like \stream\_version\ and \deleted\_at\, the renaming of columns such as \event\_id\ to \event\_number\, and the introduction of \stream\_events\ and \event\_counter\ tables. The migrations also implement database triggers and functions, such as \notify\_events\ for pub/sub notifications and rules/triggers to enforce immutability of events and stream events, while also updating timestamp columns to use time zones.

priv · high confidence

Extracted SQL statements into EEX templates

The SQL queries for the event store have been extracted from the application code into separate \.sql.eex\ template files within the \lib/event\_store/sql/statements\ directory. This change separates the database logic from the Elixir codebase, making the SQL statements easier to maintain and read. The templates handle dynamic schema quoting and parameter binding for operations such as inserting events, querying streams, and managing subscriptions.

_lib/event\store/sql/statements · high confidence

Introduce structured subscription management with explicit subscriber tracking and state management

The subscription logic is refactored into dedicated modules: \Subscriber\ tracks in-flight events and buffer capacity per connection, \Subscription\ acts as the GenServer coordinating the lifecycle, and \SubscriptionFsm\ manages the state transitions (initial, catching up, subscribed, max capacity). The \SubscriptionState\ struct centralizes tracking of acknowledged and in-flight events. This change introduces a more robust mechanism for acknowledging events by event number or \RecordedEvent\ struct, and manages subscriber connections and disconnections explicitly, improving reliability and state management for event subscriptions.

_lib/event\store/subscriptions · high confidence

Modernized configuration structure and added environment-specific setup files

The application's configuration has been modernized by switching from the legacy \Mix.Config\ to the newer \import Config\ syntax in the main \config/config.exs\ file. Additionally, new environment-specific configuration files have been introduced for benchmarking (\bench\), JSONB storage (\jsonb\), migrations (\migration\), testing (\test\), and text-based IDs (\text\_ids\), each defining distinct database connections, serializers, and retry intervals for those specific scenarios.

config · high confidence

Refactor EventStore mix tasks into generic reusable tasks

The EventStore mix tasks have been refactored into generic tasks that can be used outside of the Mix environment (e.g., with Distillery). The \migrate\ task now uses a database advisory lock to prevent concurrent migrations, and the \migrations\ task (listing status) has been added. Additionally, the \init\ task now checks for an existing initialization state before running the initializer, and the \create\ and \drop\ tasks have been updated to handle schema-specific operations.

_lib/event\store/tasks · high confidence

Split and expand EventStore Mix tasks for multi-store support

The single \event\_store\ Mix task has been separated into distinct, specialized tasks: \event\_store.create\, \event\_store.drop\, \event\_store.init\, \event\_store.migrate\, and \event\_store.migrations\ (to view migration status). Each task now supports the \-e\ (or \--eventstore\) flag to target a specific event store, enabling users to manage multiple event stores in a single application. Additionally, the \event\_store.init\ task is now idempotent, meaning it will do nothing if the events table already exists.

lib/mix/tasks · high confidence

Test coverage

Add storage layer tests for event persistence and subscriptions; Add test support helpers for event store subscriptions and storage; Added comprehensive test coverage for event store core functionality; Added comprehensive tests for event store subscription behaviors; Added manual tests for long-running subscriptions and event store seeding; Added test coverage for stream operations; Added test suite for stream subscription lifecycle; Added tests for notification system resilience and behavior.

Dependencies

Update mix dependencies and raise Elixir requirement to 1.11

The project's dependency manifest (mix.lock) and build configuration (mix.exs) have been updated. Key dependencies such as Postgrex (0.17.4), Jason (1.4.1), and GenStage (1.2.1) are specified with their latest compatible versions. Additionally, the minimum required Elixir version has been raised from 1.2 to 1.11, and development tooling like Dialyxir and ExDoc have been updated to their latest versions.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 67 → 69 (+2.0)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 97 → 99 (+2.0)
  • Architecture 98 → 95 (-3.3)
  • Maturity 62 → 59 (-3.5)
  • Readiness 53 → 61 (+8.2)
  • Security 97 → 95 (-2.5)

Resolved (13)

  • Change coupling: init.ex ↔ migrations.ex (lib/event_store/sql/init.ex)
  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • Duplicated block (7 lines × 4) (lib/mix/tasks/event_store.create.ex)
  • FileTooLong: lib/event_store.ex (lib/event_store.ex)
  • Further orphaned files (smaller)
  • High CVE: [GHSA redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • Orphaned knowledge (lib/event_store/subscriptions/subscription_fsm.ex)
  • Test reliability not included
  • TooManyMethods: SubscriptionFsm (lib/event_store/subscriptions/subscription_fsm.ex)

New (26)

  • Coverage not measured — no coverage collector is wired up
  • Documentation: no contributor guidance (README.md)
  • Documentation: no usage examples (README.md)
  • Dormant codebase
  • Duplicated block (10 lines × 4) (lib/mix/tasks/event_store.create.ex)
  • Duplicated block (6 lines × 2) (lib/event_store/advisory_locks.ex)
  • High CVE: [GHSA redacted] (mix.lock)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Members sharing a duplicated core (4 members, 50+ identical tokens) (lib/mix/tasks/event_store.create.ex)
  • Most significant orphaned file (lib/event_store/subscriptions/subscription_fsm.ex)
  • No dependency advisory monitoring
  • Outdated: dialyxir
  • …and 6 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

commanded/eventstore was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 930f9214cf8ed47e8342e73c9fb364d975140770 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.