Skip to content
CAI
Software that uses CAICheck a score

fjogeleit/prometheus-messenger-middleware

62.1

Adequate · 21 September 2026

198

lines of production code

PHP

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a middleware component for the Symfony Messenger framework that integrates with Prometheus to expose metrics about message bus activity. It dynamically identifies message buses and exposes relevant labels to Prometheus, handling both standard and error states. The implementation has been modernized to support recent versions of Symfony Messenger and the Prometheus client library, with an emphasis on clean, testable code.

Behavioural changes

Refactor to use BusNameStamp for dynamic bus names and introduce default label providers

The middleware now extracts the message bus name from the envelope's BusNameStamp instead of relying on a constructor-injected string, allowing dynamic bus identification. Default implementations for label and error label value providers are introduced, and the middleware now uses these providers to extract label values from the envelope, simplifying the internal logic and removing the need for manual default value construction.

src · medium confidence

Updated PHPUnit configuration and added Docker Compose setup

The project now includes a docker-compose.yaml file to simplify running the application and tests via Docker, alongside a .gitignore update to exclude composer.lock. Additionally, the phpunit.xml configuration has been updated to use the PHPUnit 9.3 schema and modernized coverage settings, reflecting a shift in the testing environment.

(repo-wide) · medium confidence

Updated namespace and improved error messaging for invalid names

The exception class was moved from the Prometheus namespace to the PrometheusMiddleware namespace. Additionally, the error message for invalid names was updated to include both the BusName and MetricName values, and the code was adjusted to maintain compatibility with older versions of the promphp library by checking for the presence of specific constants.

src/Exception · medium confidence

Test coverage

Updated test suite to use new namespace and middleware

The test suite has been updated to reflect the new \PrometheusMiddleware\ namespace, replacing the previous \Prometheus\\Messenger\ namespace across all test files. Additionally, the tests now include the \AddBusNameStampMiddleware\ in the message bus configuration, and assertions have been updated to expect \message\ as a label key instead of \command\.

tests · high confidence

Dependencies

Update Prometheus client and allow Symfony Messenger 6 and 7

The project's Prometheus client library has been updated from 'endclothing/prometheus\_client\_php' to 'promphp/prometheus\_client\_php' (version 2.0), requiring a corresponding namespace change from 'Prometheus\\Messenger' to 'PrometheusMiddleware'. Additionally, the Symfony Messenger dependency has been expanded to support versions 6 and 7 alongside the existing 5.x support, and the minimum required PHP version has been raised to 7.2.5.

(dependencies) · medium confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 54 → 62 (+7.8)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (+0.0)
  • Architecture 69 → 69 (+0.0)
  • Maturity 55 → 55 (+0.0)
  • Readiness 60 → 59 (-1.0)
  • Security 45 → 78 (+33.0)

Resolved (14)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • Test reliability not included
  • early-stage repository — too few commits for a meaningful bus factor
  • early-stage repository — too little history to judge knowledge freshness
  • git history depth insufficient
  • git history depth insufficient

New (12)

  • Dependency hygiene PARTLY measured — Composer dependencies read, no committed lock to grade for currency
  • Documentation: no installation or build instructions (README.md)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yaml)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yaml)
  • Medium: security finding (details withheld)
  • No dependency advisory monitoring

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

fjogeleit/prometheus-messenger-middleware was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit a50309b64316fb425c5656c05644bac2c4ae9e24 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.