Skip to content
CAI
Software that uses CAICheck a score

Evyweb/simple-ddd-toolkit

65.2

Adequate · 21 September 2026

447

lines of production code

TypeScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Behavioural changes

Async event dispatch and new event retrieval for aggregates

The Aggregate base class now supports asynchronous, non-blocking dispatch of domain events via a new \dispatchEventsAsync\ method, which uses \setImmediate\ to avoid blocking the main thread. The synchronous \dispatchEvents\ method has been updated to be \async\ and now accepts an \EventBusPort\ interface instead of a concrete \EventBus\ class, improving testability. Additionally, a \getEvents\ method has been added to retrieve a snapshot of pending domain events.

src/aggregate · medium confidence

Enforce immutability and simplify UUID creation

The base ValueObject now uses a recursive deep-freeze mechanism to ensure all nested data structures are immutable, and equality checks are performed via a new reflective comparison method. For UUIDs, the API is simplified: the static create method now accepts an explicit value and isNew flag, removing the previous separation between create (auto-generate) and createFrom (manual) methods, and the dependency on Node's crypto module is removed.

src/valueObject · high confidence

Introduce middleware pipeline and async dispatch capabilities for the event bus

The event bus now supports a middleware chain, allowing cross-cutting concerns like logging to be applied around event handling. The \EventBus\ class now uses a \use\ method to register \IEventMiddleware\ implementations, such as the new \EventLoggingMiddleware\ which logs event details. Additionally, the bus now provides \dispatchEvents\ for synchronous batch processing and \dispatchEventsAsync\ for fire-and-forget asynchronous processing, improving consistency and performance for multiple events.

src/eventBus · high confidence

Merged Command and Query buses into a unified bus

The separate CommandBus and QueryBus implementations have been removed, consolidating the two into a single, unified bus. This change simplifies the registration of commands and queries, removing the previous separation between command and query handling mechanisms.

src/commandBus · high confidence

Migrate to Biome and update TypeScript configuration

The project has migrated its code quality and formatting tooling from ESLint/other formatters to Biome, introducing a new biome.json configuration file that enforces import organization, linting, and formatting rules (including a 120-character line width). Additionally, the TypeScript configuration (tsconfig.json) has been updated to target ES2022, enable declaration generation, and adjust module resolution and strictness settings to align with the new tooling and modern standards.

(repo-wide) · high confidence

Refactor error class structure and formatting

The error handling classes in the src/errors directory have been refactored. The abstract property errorName on CustomError has been replaced with \_\_TAG, and the isDomainError and isTechnicalError methods have been implemented in the DomainError and TechnicalError subclasses to distinguish between domain and technical errors. Additionally, the code formatting has been updated to use 4-space indentation.

src/errors · medium confidence

Refactored domain event structure to use abstract class with payload and metadata

The domain event system has been refactored to use an abstract \DomainEvent\ class that implements a \Message\ interface, replacing the previous interface-based approach. This change introduces dedicated \Payload\ and \Metadata\ types, allowing domain events to carry structured data and arbitrary metadata. The \DomainEvent\ class now encapsulates \eventId\, \occurredOn\, \payload\, and \metadata\ properties, providing a more robust foundation for event handling and metadata autocompletion.

src/domainEvent · medium confidence

Removal of unused command interfaces

The \ICommand\ and \ICommandHandler\ interfaces have been removed from the codebase. This eliminates the optional response pattern for commands, simplifying the command structure by removing these specific interface definitions.

src/command · high confidence

Removed command and query middleware interfaces and logging implementation

The command and query middleware interfaces (CommandMiddleware, QueryMiddleware) and the CommandLoggingMiddleware implementation have been removed from the codebase. This eliminates the previous middleware execution chain for commands and queries, meaning logging and potential side-effects from these middleware layers will no longer occur.

src/middleware · high confidence

Removed generic query interfaces

The generic interfaces IQuery, IQueryHandler, and IResponse have been removed from the codebase. This eliminates the shared abstractions for query types, handlers, and responses, likely as part of a broader simplification of the command/query pattern implementation.

src/query · high confidence

Restricts Entity setter to protected access

The set method on the Entity class is now protected, meaning it can only be called from within the class or its subclasses, preventing external code from directly modifying entity state via the set method.

src/entity · high confidence

Restructured module exports and simplified interfaces

The public API surface has been reorganized: command and query buses are now exported from the new 'bus' directory, with separate exports for commands, queries, and their respective handlers. Middleware and logging utilities have been consolidated under the 'bus' and 'domainEvent' paths. Additionally, the IUseCase interface's execute method now explicitly returns a Promise\<void\>, clarifying its asynchronous nature.

src · medium confidence

Unified message bus with middleware support and typed message contracts

The message bus has been refactored to support both commands and queries through a single, unified Bus class. This change introduces a shared Message type with a \_\_TAG identifier, allowing the bus to route messages to their respective handlers. Additionally, the architecture now supports a middleware pipeline, enabling cross-cutting concerns like logging to be applied to both command and query execution flows.

src/bus · high confidence

Fixes

Refactor Result type to use discriminated unions with explicit accessors

The Result class now uses a discriminated union (success/failure) with a \\_tag\ property to track state, replacing the previous approach of storing separate \\_value\ and \\_error\ fields. This change introduces explicit \getValue()\ and \getError()\ methods to safely access the result's content, ensuring that accessing the wrong state (e.g., getting a value from a failure) throws an error rather than returning undefined. The \isOk()\ and \isFail()\ type guards have also been updated to check the \\_tag\ property.

src/result · high confidence

Test coverage

Added comprehensive test coverage for the command and query bus implementations; Added tests for value object equality and immutability; Removed obsolete test files for the command bus; Removed test infrastructure for command handlers; Update error class tests to use \_\_TAG property; Updated Result spec to use new getter methods; Updated aggregate and UUID test suite; Updated entity test suite with new imports and formatting; Updated use case test to use new command structure.

Dependencies

Updated project dependencies and tooling configuration

The project's package manifests have been updated to version 0.21.1, with the lock file reflecting upgrades to TypeScript (5.3.3→5.8.3), Vitest (1.3.1→3.1.2), @changesets/cli, and @types/node. A new dev dependency, @biomejs/biome, has been added alongside @vitest/coverage-v8 and rimraf, while the configuration now specifies 'dist/' as the published files and sets the npm registry access to public.

(dependencies) · medium confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 62 → 65 (+2.9)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 97 (-1.8)
  • Architecture 69 → 69 (+0.0)
  • Maturity 54 → 57 (+2.8)
  • Readiness 61 → 71 (+10.3)
  • Security 73 → 74 (+1.5)

Resolved (21)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low CVE: [GHSA redacted] (package-lock.json)
  • No exposed public API
  • Test reliability not included
  • The document begins with a two-line warning about unreleased production readiness, then an installation block, and features as checkboxes before any content on Value Object or Entity appears. The outlined sections 'Value Object' and 'Entity' are present in the Features outline but not yet shown. (README.md)
  • no production source files with tracked history to analyse
  • …and 1 more

New (25)

  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (the committed lockfile resolved no direct production dependency)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low CVE: [GHSA redacted] (package-lock.json)
  • …and 5 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

Evyweb/simple-ddd-toolkit was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 17cc3e20b8a8e5dbbf8332ba5fb8de3b8459cf8c — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.