Skip to content
CAI
Software that uses CAICheck a score

Evyweb/ioctopus

64.1

Adequate · 21 September 2026

461

lines of production code

TypeScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is an Inversion of Control (IoC) container for JavaScript and TypeScript that manages dependency injection. It provides a typed registry to bind classes, functions, and higher-order functions with support for singleton, transient, and scoped lifetimes. The library enforces strict type safety and validation for dependency bindings, resolving circular dependencies and managing module loading.

Features

Introduce container, module, and type system for dependency injection

Added a new dependency injection container with support for singleton, transient, and scoped lifetimes, along with module loading/unloading. The container now supports binding classes, functions, and higher-order functions with optional dependencies (arrays or objects). A new type system enforces registry-based type safety for bindings and resolves circular dependencies with clear error messages. The previous app entry points (app.ts, hello.ts) were removed as the library's core API is now exposed via src/index.ts.

src · high confidence

Behavioural changes

Improved type safety and validation for dependency bindings

The library now enforces stricter type safety for dependency bindings, particularly for classes, functions, and higher-order functions. This includes improved validation of dependency keys and types, ensuring that the types provided during binding match what is expected. Additionally, the changelog and README have been updated to reflect these changes, and the test configuration has been adjusted to include source files for coverage while excluding type definition files.

(repo-wide) · low confidence

Test coverage

Added comprehensive test coverage for the dependency injection container

Added 23 new and updated test files in the \specs\ directory to verify the container's behavior. These tests cover core container operations such as binding values, functions, classes, and higher-order functions, as well as module loading/unloading and scope management (singleton, transient, scoped). The tests validate dependency resolution, error handling for missing bindings, and the correct behavior of the typed registry and currying features.

specs · high confidence

Dependencies

Update project identity and dev dependencies

The package name and repository have been updated from @evyweb/node-script-template to @evyweb/ioctopus, with the description changed to reflect an IoC container for JavaScript and TypeScript. The project version has been bumped to 1.4.1, and dev dependencies including @types/node, @vitest/coverage-v8, tsup, typescript, and vitest have been updated to newer versions.

(dependencies) · medium confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 62 → 64 (+2.6)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 97 → 95 (-2.4)
  • Architecture 69 → 69 (+0.0)
  • Maturity 52 → 55 (+3.1)
  • Readiness 60 → 68 (+7.5)
  • Security 76 → 79 (+3.0)

Resolved (17)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low vulnerability: [GHSA redacted] (package-lock.json)
  • No exposed public API
  • Small-team knowledge concentration
  • Test reliability not included

New (46)

  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (the committed lockfile resolved no direct production dependency)
  • Documentation: no architecture or design documentation (README.md)
  • Documentation: no usage examples (README.md)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low vulnerability: [GHSA redacted] (package-lock.json)
  • Medium CVE: [GHSA redacted] (package-lock.json)
  • Medium: security finding (details withheld)
  • No assertions: should allow dependency arrays stored in typed variables (specs/registry.spec.ts)
  • …and 26 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

Evyweb/ioctopus was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit fd12d232c62ff1b741c99be3855d05bbbc0eb9b5 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.