Skip to content
CAI
Software that uses CAICheck a score

daangn/ventyd

64.0

Adequate · 21 September 2026

4k

lines of production code

TypeScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Ventyd is an event sourcing library for TypeScript that manages entity state through immutable event logs and pluggable persistence adapters. It supports multiple schema validation libraries, including Zod, Valibot, and TypeBox, to ensure type-safe domain modeling and event validation. The system provides built-in support for event versioning, snapshotting, and CQRS patterns via a repository interface that abstracts storage backends like Prisma, MongoDB, and SQLite.

Features

Initial release of Ventyd event sourcing library

The library introduces core event sourcing capabilities, including the \Entity\ class for managing state through event logs, \createRepository\ for persistence with adapter and plugin support, and \defineSchema\/\defineReducer\ for type-safe domain modeling. It provides official schema providers for Valibot, Zod, ArkType, and TypeBox (including legacy v0 support), all unified via the Standard Schema V1 specification, and adds features like event versioning, snapshot support, and custom ID generation.

src · high confidence

Introduce Prisma adapter with event versioning and snapshot support

The Prisma adapter now supports event versioning and automatic snapshotting. It stores events with a version number and can save a snapshot of the entity state every N events (configurable via \snapshotEvery\), writing the snapshot in the same transaction as the events and view update to ensure consistency. The adapter manages three distinct tables: events, snapshots, and views, providing methods to retrieve events by entity and version, fetch the latest snapshot, and commit new events along with the corresponding view update.

src/adapter · high confidence

Introduces core type definitions for the event sourcing library

This change establishes the foundational TypeScript types for the Ventyd event sourcing system. It defines the \Adapter\ interface for pluggable persistence backends (supporting databases like Prisma or Drizzle, as well as in-memory stores) and the \Repository\ interface for entity persistence and retrieval. The \Entity\ and \EntityConstructor\ types model the lifecycle of entities, including creation, loading from state or events, and the new \UNSAFE\_mutable\ option for loading mutable entities from pre-computed state. A \ReadonlyEntity\ type is introduced to enforce immutability on loaded entities by stripping mutation methods, ensuring CQRS compliance. Additionally, the \Schema\ and \SchemaInput\ types provide a library-agnostic way to define entity structures and validate events/states, while \Plugin\ types allow for composable side effects like analytics or notifications after event commits.

src/types · high confidence

Behavioural changes

1 commit (0 fixes) modifying .yarn

A change to existing behaviour in .yarn — 1 commit, 1 file.

.yarn · low confidence · unverified

Docs generation script now skips execution when build output is missing

The \scripts/generate-docs.ts\ script has been updated to gracefully handle cases where the expected documentation build output (\docs/build/client/llms\) is not present. Instead of failing with an error, the script now detects the missing directory, logs a warning message instructing the user to run \npm run build:docs\, and exits cleanly. This prevents build failures when the embedded documentation source has not yet been generated.

scripts · high confidence

Test coverage

Added entity test fixtures for multiple schema libraries; Added test infrastructure for adapter backends and schema providers.

Dependencies

Introduce multi-schema support and documentation site

The package now exports separate entry points for multiple schema libraries (standard, valibot, typebox, typebox0, zod, arktype) and the Prisma adapter, allowing users to import only the validation logic they need. The build tooling has switched from bunchee to tsdown, and the project has upgraded to Yarn 4.18.0. Additionally, a new documentation site has been added under the docs directory, built with React Router, Fumadocs, and Tailwind CSS.

(dependencies) · high confidence

Housekeeping

Ventyd 1.20.4 release with production guide documentation

This release updates the package to version 1.20.4. The primary change is the addition of a production guide to the documentation, as indicated in the changelog. The repository configuration has also been updated to use Yarn 4.18.0 with global hardlinks, and the build system is configured via tsdown to output ESM and CJS formats for various schema integrations (Valibot, Zod, ArkType, TypeBox) and the Prisma adapter.

(repo-wide) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 61 → 64 (+2.6)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 97 (-1.9)
  • Architecture 98 → 93 (-5.0)
  • Maturity 60 → 56 (-3.4)
  • Readiness 53 → 61 (+8.2)
  • Security 57 → 69 (+11.9)

Resolved (29)

  • Change coupling: Entity.ts ↔ defineSchema.ts (src/Entity.ts)
  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High vulnerability: [GHSA redacted] (yarn.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 9 more

New (48)

  • Coverage not measured — JavaScript/TypeScript suite
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Documentation: no architecture or design documentation (README.md)
  • Entity.Entity (cognitive 16) (src/Entity.ts)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High: security finding (details withheld)
  • …and 28 more

Changes since last survey

  • 1 commits — 1 feature/other, 0 fixes

By area

  • (root) — 1 commit

Notable commits

  • change: chore: upgrade Yarn to 4.18.0 and enable global hardlinks (#102)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

daangn/ventyd was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit d232eb505a8ba05ab66446bb7924f3b73e872729 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.