Skip to content
CAI
Software that uses CAICheck a score

CuatroElixir/spear

60.8

Adequate · 21 September 2026

7.3k

lines of production code

Elixir

primary language

8

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is an Elixir client library for EventStoreDB, designed to facilitate communication with the database via gRPC and HTTP/2. It provides core capabilities for managing connections with automatic reconnection and keep-alive, as well as reading and writing events through streams with server-side filtering. Additionally, it supports persistent subscriptions for event consumption and offers administrative APIs for cluster operations, user management, and access control.

Features

Initial project scaffolding and configuration

The repository has been initialized with standard Elixir project configuration files, including \.formatter.exs\ for code formatting, \.credo.exs\ for static analysis, and \.gitignore\ for build artifacts. Development and testing workflows are supported by a \docker-compose.yml\ file that provisions an EventStoreDB instance and an Elixir app container, alongside an \.iex.exs\ script for convenient local connection setup. The project also includes a \CHANGELOG.md\ following the Keep a Changelog format, a \LICENSE\ (Apache 2.0), and \coveralls.json\ for test coverage reporting.

(repo-wide) · high confidence

Initial release of the Spear EventStoreDB client library

Introduces Spear, a new Elixir client for EventStoreDB 20+ built on the mint HTTP/2 library. The library provides a \Spear.Connection\ GenServer for managing connections and a \Spear.Client\ module for simplified, connection-less API calls. Key capabilities include reading and writing events via streams (supporting the \:all\ stream and server-side filters), persistent subscriptions with ack/nack handling, and APIs for users, gossip, operations, and monitoring. The implementation uses gRPC for communication and \gpb\ for protobuf decoding, exposing both high-level \Spear.Event\ structs and raw \Spear.Records\ for advanced use cases.

lib · high confidence

Initial release of the Spear EventStoreDB client library

Introduces the Spear library, an Elixir client for EventStoreDB. This release provides core capabilities including connection management with automatic reconnection and keep-alive, event reading and streaming with server-side filtering, event appending with batch support and idempotency, and persistent subscriptions with ack/nack handling. It also includes administrative APIs for managing access control lists (ACLs), cluster info, users, and operations, along with a client macro for simplified module-based connections.

lib/spear · high confidence

Introduces Spear.Reading.Stream for event stream processing

Adds the Spear.Reading.Stream module, which implements a new mechanism for reading events from EventStore streams. This component handles chunked reading, buffering, and continuous unfolding of events, including logic to terminate the stream when a chunk is smaller than requested or when non-event responses are encountered. It supports configuration options such as stream name, starting position, chunk size, direction, and filtering, providing the underlying infrastructure for stream-based event consumption.

lib/spear/reading · high confidence

Behavioural changes

Add persistent subscription info and settings structs

The library now includes \Spear.PersistentSubscription.Info\ and \Spear.PersistentSubscription.Settings\ structs to represent persistent subscription details and configuration. The \Info\ struct captures connection metrics, status, and buffer statistics returned by \Spear.get\_persistent\_subscription\_info/4\, while the \Settings\ struct defines creation and update parameters such as consumer strategies, buffer sizes, and timeouts, mapping them to the underlying EventStoreDB protocol records.

_lib/spear/persistent\subscription · high confidence

Connection configuration and keep-alive timer implementation

The connection layer now includes a dedicated configuration module that validates settings and introduces keep-alive functionality, allowing users to configure \:keep\_alive\_interval\ and \:keep\_alive\_timeout\ to manage connection health. Additionally, TCP NodeDelay is enabled by default via transport options to reduce latency for small request/response messages exchanged with EventStoreDB.

lib/spear/connection · high confidence

EventStoreDB test environment configuration and certificate generation

The EventStoreDB test setup now includes a pinned configuration for version 23.10.x (the last open-source release) and a script to generate throwaway SSL certificates for testing. The configuration enables external TCP and HTTP ports, runs all projections, and specifies certificate paths, while the new gen-certs.sh script automates the creation of a CA and node certificate in PKCS\#1 format to ensure compatibility with the test container.

eventstoredb · high confidence

Migrate configuration to environment-specific files

The application configuration has been restructured to use environment-specific files (dev, test, prod) instead of a single monolithic config. The main config file now imports the appropriate environment file based on the Mix environment. The test configuration now explicitly defines connection strings and TLS certificate paths for the EventStoreDB client, ensuring tests run against a local instance with proper TLS settings.

config · high confidence

Test coverage

Added test fixtures for client setup and version compatibility; Added tests for connection configuration validation and keep-alive timer behavior; Added unit tests for gRPC error handling; Initial test suite for Spear core modules; Initial test suite for Spear library.

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 38 → 61 (+22.6)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 97 → 99 (+2.2)
  • Architecture 100 → 98 (-1.7)
  • Maturity 55 → 55 (+0.0)
  • Readiness 18 → 50 (+31.2)
  • Security 37 → 76 (+39.2)

Resolved (35)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • Duplicated block (10 lines × 2) (lib/spear/persistent_subscription/settings.ex)
  • Duplicated block (11 lines × 2) (lib/spear.ex)
  • Duplicated block (16 lines × 2) (lib/spear.ex)
  • Duplicated block (9 lines × 2) (lib/spear.ex)
  • FileTooLong: spear/client.ex (lib/spear/client.ex)
  • High CVE: [GHSA redacted] (mix.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 15 more

New (44)

  • Documentation: no architecture or design documentation (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (12 lines × 2) (lib/spear.ex)
  • Duplicated block (13 lines × 2) (lib/spear/persistent_subscription/settings.ex)
  • Duplicated block (17–18 lines × 2) (lib/spear.ex)
  • Duplicated block (9 lines × 2) (lib/spear.ex)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 24 more

Changes since last survey

  • 5 commits — 5 feature/other, 0 fixes

By area

  • .github/workflows — 2 commits
  • (root) — 1 commit
  • eventstoredb/certs — 1 commit
  • lib/spear — 1 commit

Notable commits

  • change: Add Dialyzer to CI
  • change: Add changelog notes for v1.5.0
  • change: CI: Create releases with gh and grant contents write
  • change: CI: Remove Slack notification in publish job
  • change: Rework/update CI

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

CuatroElixir/spear was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 2f5476ae73b35e5a2192eda88aefcf71198a7bfe — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.