Skip to content
CAI
Software that uses CAICheck a score

fabriziosestito/commanded-spear-adapter

57.8

Adequate · 21 September 2026

1.1k

lines of production code

Elixir

primary language

7

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is an event-sourcing infrastructure library built on Elixir, utilizing the Commanded framework and the Spear library to interact with an EventStoreDB database. It manages the persistence and retrieval of domain events, supporting advanced features like stream prefixing, system event filtering, and snapshot serialization. The codebase includes a comprehensive test suite that automates the management of the EventStoreDB container for reliable integration testing.

Behavioural changes

Migrate event store adapter from Extreme to Spear

The adapter has been renamed and refactored to use the Spear library instead of Extreme. This includes renaming the adapter modules from \extreme\ to \spear\, updating the connection and subscription management to use Spear's API, and adjusting how events are read, filtered, and acknowledged. The change also introduces support for \stream\_prefix\ configuration and adds a \nack\ method for subscription handling.

_lib/commanded/event\store/adapters · high confidence

Refactor event store adapter to support optional stream prefixes and filter system events

The Spear adapter now passes a \stream\_prefix\ to the subscription supervisor, enabling optional prefixing for stream names and snapshot streams. The \stream\_name\ helper is updated to conditionally apply the prefix, and \snapshot\_stream\_name\ is similarly adjusted. Additionally, the adapter now excludes system events from streams using a new \spear\_filter\ helper, and the \stream\_forward\ function uses a \chunk\_size\ parameter instead of \count\, while also mapping events through a stream for efficiency.

_lib/commanded/event\store · medium confidence

Upgrade Elixir and Erlang runtime versions

The project now requires Elixir 1.14.3 and Erlang/OTP 25.2.2, up from Elixir 1.13.1 and OTP 24. This upgrade ensures compatibility with newer versions of the \spear\ library and other dependencies, and may require developers to update their local development environments to match these runtime versions.

(repo-wide) · high confidence

Test coverage

Expanded test coverage for the Spear event store adapter; Refactored test infrastructure to use transient Docker containers for EventStore; Updated test configuration to exclude partition tests.

Dependencies

Update Commanded and Spear dependencies to support EventStoreDB 23.10

The project updates its core dependencies to align with EventStoreDB 23.10 support. Commanded is upgraded to version 1.4 (specifically 1.4.2), and the Spear adapter is updated to version 1.4.0. Additionally, the HTTP client library Httpoison is upgraded to version 2.0.0, and the test framework Mox is updated to 1.1.0. The build tooling is also refreshed, with Credo moving to 1.7.4, Dialyxir to 1.4.3, and ExDoc to 0.31.1. New test dependencies, including excontainers and ex\_check, are added to support transient Docker containers in the test suite.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 57 → 58 (+1.0)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 99 (-0.1)
  • Architecture 69 → 66 (-3.3)
  • Maturity 46 → 42 (-4.0)
  • Readiness 56 → 67 (+11.2)
  • Security 80 → 86 (+6.9)

Resolved (10)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • Duplicated block (10 lines × 2) (lib/commanded/event_store/adapters/spear/mapper.ex)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • No exposed public API
  • Test reliability not included
  • dormant codebase — no living knowledge left to concentrate

New (17)

  • Documentation: no installation or build instructions (README.md)
  • Duplicated block (11 lines × 2) (lib/commanded/event_store/adapters/spear/mapper.ex)
  • HackComment (lib/commanded/event_store/adapters/spear/mapper.ex)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yaml)
  • High: security finding (details withheld)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium: security finding (details withheld)
  • Outdated: commanded
  • Outdated: credo
  • Outdated: dialyxir
  • Outdated: ex_doc
  • Outdated: excontainers
  • Outdated: mox
  • Workflow token permissions not restricted

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

fabriziosestito/commanded-spear-adapter was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit fcf18250f28ce495688ba2257108d9c15e29d8a7 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.