Skip to content
CAI
Software that uses CAICheck a score

GaloyMoney/es-entity

75.1

Strong · 21 September 2026

25.1k

lines of production code

Rust

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Rust-based event sourcing framework designed to persist entities to PostgreSQL with automated repository generation. It provides core capabilities for managing entity lifecycles, including optimistic concurrency control, batch isolation with savepoints, and GDPR-compliant data deletion via forgettable payloads. The library also supports rich audit trails through thread-local event context propagation and ensures reliability with idempotency guards and retry logic for concurrent modifications.

Features

Batch isolation and commit hooks for atomic operations

The \src/operation\ module now provides \BatchIsolation\ methods (\run\_isolated\ and \run\_bisected\) that allow processing a batch of items within a single transaction while isolating each item's failure using savepoints. It also introduces a commit hook system (\CommitHook\) that lets users register pre-commit, post-commit, and rollback callbacks to execute side effects like event publishing or cache updates, with support for hook ordering, merging, and re-entrant registration.

src/operation · high confidence

Initial CI pipeline configuration for es-entity

This change introduces the foundational CI infrastructure for the es-entity project, establishing a Concourse pipeline that automates code checking, testing, and release processes. The pipeline leverages Nix for reproducible builds and integrates with Galoy's shared CI assets via vendir to standardize task definitions. Key capabilities include automated checks using \nix flake check\, test execution via \cargo nextest\, and a complete release workflow that publishes to crates.io and creates GitHub releases, with built-in retry logic for stability. Additionally, a self-bootstrapping fuzzing job is configured to run nightly, persisting its corpus to Google Cloud Storage and triggering Zenduty alerts on crashes, ensuring continuous security testing without manual seed management.

ci · high confidence

Initial CI/CD pipeline tasks for release automation

This change introduces the initial set of CI/CD tasks required to build, version, and release the Calaserver project. The new scripts automate the end-to-end release process: prep-docker-build-env.sh prepares the build environment with version and commit metadata; build-release.sh compiles the Rust binary for Linux and macOS targets; publish-to-crates.sh publishes the es-entity and es-entity-macros crates to crates.io; bump-image-digest.sh and open-charts-pr.sh handle updating Helm chart values and creating pull requests for container image updates; and set-dev-version.sh and update-repo.sh manage version bumps for development and release cycles respectively.

ci/tasks · high confidence

Initial release of the es-entity event-sourcing library

This entry introduces the core \src\ module of the \es-entity\ crate, providing a Rust library for persisting event-sourced entities to PostgreSQL. It establishes the foundational types and modules for the system, including centralized database type aliases (\db.rs\), error handling with constraint violation parsing (\error.rs\), and the event management infrastructure (\events.rs\) for tracking persisted and new events. The release adds support for GDPR-compliant data deletion via the \Forgettable\<T\>\ wrapper (\forgettable.rs\), idempotency guards to prevent duplicate event processing (\idempotent.rs\), and utilities for nested entity operations (\nested.rs\). It also includes a \OneTimeExecutor\ for trace-context annotation of SQL statements (\one\_time\_executor.rs\), cursor-based pagination structures (\pagination.rs\), and the \es\_query!\ macro infrastructure for type-safe entity hydration (\query.rs\ and \macros.rs\).

src · high confidence

Introduce thread-local event context with lazy async propagation

A new context module provides a thread-local system for attaching metadata (such as request IDs, user IDs, or audit info) to events as they are persisted. The \EventContext\ struct manages a stack of contexts within a single thread, while \ContextData\ offers an immutable, thread-safe snapshot for transferring context across async boundaries or threads. To optimize performance, context seeding in async tasks is now lazy: the \with\_event\_context\ wrapper defers the creation of context stack entries until the context is actually observed during a poll, avoiding unnecessary allocations for polls that do not access the context. Additionally, the module integrates with OpenTelemetry via the \tracing-context\ feature, automatically injecting trace IDs and span information into event context when available.

src/context · high confidence

Introduce unified clock abstraction with manual time control and global access

The \src/clock\ module now provides a unified time abstraction that supports both real-time and manual (test) clocks via \ClockHandle\. Users can create manual clocks for deterministic testing, where time only advances via explicit \ClockController\ calls like \advance()\ and \advance\_to\_next\_wake()\. A new \sleep\_coalesce()\ method allows housekeeping tasks to coalesce wake-ups during large time jumps, preventing excessive processing. Additionally, a global \Clock\ singleton is available for easy access to time operations, with support for installing a manual clock globally for testing purposes.

src/clock · high confidence

New event sourcing macro library with context propagation and retry logic

The \es-entity-macros\ crate introduces a suite of procedural macros for event-sourced entities. The \\#\[derive(EsEntity)\]\ macro generates the \EsEntity\ trait implementation, supporting nested child entities and automatic event field detection. The \\#\[derive(EsEvent)\]\ macro adds GDPR-compliant forgettable payload support, allowing sensitive data to be extracted and cleared from event variants. A new \\#\[es\_event\_context\]\ attribute macro automatically captures function arguments into an event context for audit trails, handling both synchronous and asynchronous execution contexts. Additionally, the \\#\[retry\_on\_concurrent\_modification\]\ attribute implements exponential backoff retry logic for handling concurrent modification errors, and the \IndexCatalog\ component parses SQL migration files to optimize \list\_for\_filters\ queries by matching against physical composite indexes.

es-entity-macros/src · high confidence

Repository initialization with Nix-based development environment and documentation

The repository is initialized with a comprehensive Nix flake configuration that replaces Docker Compose with \nix process-compose\ for managing development dependencies like PostgreSQL, enabling reproducible local setups without Docker. The project includes a new Event Sourcing Entity Framework for Rust (\es-entity\), featuring derive macros for automatic repository generation, optimistic concurrency control, and idempotent operations. Development tooling is established with \bacon.toml\ for hot-reloading, \deny.toml\ for license and dependency auditing, and \CLAUDE.md\ for AI-assisted development guidance. Documentation is added via a new mdBook structure, a detailed README with usage examples, and a SECURITY.md policy. The build system includes a \build.rs\ script to ensure proc-macro code regenerates when database migrations change, and the project enforces safe Rust with \\#!\[forbid(unsafe\_code)\]\.

(repo-wide) · high confidence

Repository macro generates new internal code generation modules

The \es-entity-macros/src/repo\ directory now contains a set of new Rust source files (e.g., \begin.rs\, \combo\_cursor.rs\, \create\_all\_fn.rs\, \create\_fn.rs\, \delete\_fn.rs\, \error\_classifier.rs\, \error\_types.rs\, \events\_write.rs\, \find\_all\_fn.rs\) that implement the code generation logic for the repository derive macro. These modules handle the emission of repository methods for operations like create, delete, and find, as well as internal structures for cursor handling, error classification, and event persistence.

es-entity-macros/src/repo · high confidence

Behavioural changes

New macro configuration options for scoped repositories, soft deletes, and post-operation hooks

The \es-entity-macros\ derive macro now supports configuring repository behavior via new attributes. Users can define multi-column scopes using \id(scope)\ or \scope\ attributes on columns, with compile-time validation ensuring distinct types and variant names. Soft deletion is configurable via \delete = "soft"\ or \delete = "soft\_without\_queries"\ to toggle inclusion of deleted rows in queries. Additionally, \post\_persist\_hook\ and \post\_hydrate\_hook\ attributes allow specifying methods to run after entity persistence and hydration, respectively, with optional custom error types.

es-entity-macros/src/repo/options · high confidence

Support for GDPR-compliant data deletion via forgettable payloads

The \es\_query!\ macro now accepts a \forgettable\_tbl\ parameter, enabling the inclusion of forgettable payload data in query results to support GDPR-compliant data deletion. When this parameter is provided, the generated SQL performs a \LEFT JOIN\ on the specified table to retrieve the payload as \forgettable\_payload?\, and a compile-time assertion ensures the parameter is present if the event type contains \Forgettable\<T\>\ fields. Additionally, the macro now strips table aliases from \ORDER BY\ columns to ensure correct sorting behavior.

es-entity-macros/src/query · high confidence

Vendored CI tasks updated from shared repository

The CI vendor tasks in ci/vendor/tasks have been replaced with new versions synced from the galoy-concourse-shared repository. This update introduces a new fuzzing task (fuzz.sh) that supports cargo-fuzz with corpus management and seed merging, updates the release preparation script (prep-release-src.sh) to use git-cliff for changelog generation and bump2version for semver bumping, and refreshes the test and code-check tasks (test-integration.sh, test-bats.sh, check-code.sh) to run within a Nix environment using Podman for dependencies. The helpers.sh script now sets specific CARGO\_HOME and CARGO\_TARGET\_DIR paths, and the with-nix-cache.sh wrapper has been updated to improve Nix binary cache management and fetch retry logic.

ci/vendor/tasks · high confidence

Test coverage

Added database migration fixtures for testing repository features; Added fuzzing targets for event hydration and constraint parsing; Added micro-benchmarks for event-context performance; Added test entity definitions for event-sourced domain models; Comprehensive integration test coverage for core framework capabilities.

Dependencies

Initial release of es-entity 0.13.1-dev with Rust 2024 edition and updated dependencies

This change introduces the initial codebase for the es-entity Event Sourcing Entity Framework, setting the project version to 0.13.1-dev and adopting the Rust 2024 edition. It establishes the core library and proc-macro crate with a dependency stack that includes async-graphql 8.0.0-rc.5, sqlx 0.8, tokio 1.52, and uuid 1.23 (with v7 support), alongside optional features for tracing, GraphQL, and event context. A dedicated fuzzing workspace is also added to support automated fuzz targets for constraint parsing and event hydration.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 69 → 75 (+5.7)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 93 → 90 (-3.7)
  • Architecture 98 → 100 (+1.8)
  • Maturity 65 → 65 (-0.3)
  • Readiness 76 → 80 (+4.0)
  • Security 61 → 78 (+17.0)
  • Domain Modelling 100 → 100 (+0.0)
  • Event Sourcing 100 (new)

Resolved (21)

  • Build action pinned to a mutable branch
  • Change coupling: list_for_filters_fn.rs ↔ list_for_fn.rs (es-entity-macros/src/repo/list_for_filters_fn.rs)
  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High vulnerability: [GHSA redacted] (Cargo.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium advisory (unsound): RUSTSEC-2026-0097 (Cargo.lock)
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • Test reliability not included
  • …and 1 more

New (137)

  • ClassTooLong: ErrorTypes (es-entity-macros/src/repo/error_types.rs)
  • ClassTooLong: ListForFiltersFn (es-entity-macros/src/repo/list_for_filters_fn.rs)
  • Columns::validate_scope (cognitive 19) (es-entity-macros/src/repo/options/columns.rs)
  • CommitHooks::execute_pre (cognitive 20) (src/operation/hooks.rs)
  • Dependency advisory scan runs only on code events
  • Dependency hygiene PARTLY measured — Cargo dependencies read, dependency currency not (crates.io unreachable)
  • Documentation: no architecture or design documentation (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicate intent for installing/configuring manual clock controllers. Both Clock and ClockHandle expose methods to install a manual controller, with identical naming patterns (install_manual vs manual) and optional start time variants (_at). This creates confusion about which entry point to use.
  • Duplicate intent for sleep operations across Clock and ClockHandle. Both types expose identical sleep and sleep_coalesce methods with the same signatures and return types, leading to ambiguity in which type should be used for scheduling sleeps.
  • Duplicated block (10 lines × 2) (es-entity-macros/src/repo/error_types.rs)
  • Duplicated block (10 lines × 2) (es-entity-macros/src/repo/events_write.rs)
  • Duplicated block (10 lines × 3) (es-entity-macros/src/repo/error_types.rs)
  • Duplicated block (10 lines × 8) (es-entity-macros/src/repo/error_types.rs)
  • Duplicated block (11 lines × 2) (es-entity-macros/src/repo/error_types.rs)
  • Duplicated block (11 lines × 4) (es-entity-macros/src/repo/error_types.rs)
  • Duplicated block (12 lines × 2) (es-entity-macros/src/repo/error_types.rs)
  • Duplicated block (12 lines × 4) (es-entity-macros/src/repo/find_all_fn.rs)
  • Duplicated block (13 lines × 2) (es-entity-macros/src/repo/create_all_fn.rs)
  • …and 117 more

Changes since last survey

  • 102 commits — 92 feature/other, 10 fixes

By area

  • (root) — 64 commits
  • es-entity-macros/src — 21 commits
  • src/operation — 7 commits
  • book/src — 3 commits
  • ci/vendor — 3 commits
  • ci/vendir.lock.yml — 2 commits
  • ci/fuzz.sh — 1 commit
  • fuzz/fuzz_targets — 1 commit

Notable commits

  • fix: chore(ci): re-vendor for fuzz_job path fix (#21) (#194)
  • fix: chore(deps): all-dependencies group (syn 3) + darling 0.24 to fix the build (#180)
  • fix: ci: fix release script
  • fix: fix(macros): classify FK/CHECK/exclusion violations as ConstraintViolation (#184)
  • fix: fix(macros): specialize list_for_filters on any equality index prefix (#185)
  • fix: fix(pagination)!: gate PaginatedQueryRet construction and take (#229)
  • fix: fix(repo): classify duplicate-id create violations deterministically (#198)
  • fix: fix: exercise load_n multi-entity path in fuzz_event_hydration (Bugbot #189) (#190)
  • fix: fix: load_n(_,0) returns all entities & ManualClock::now() panics on huge advance() (#187)
  • fix: fix: remove panic paths from event persistence and last_persisted (#172)
  • change: chore(ci): bump vendir (ci) to galoy-concourse-shared 26b38b4
  • change: chore(deps): bump event-listener to 5.4.2 to patch RUSTSEC-2026-0221 (#171)
  • change: chore(deps): bump rustls-webpki 0.103.9 -> 0.103.13 (#176)
  • change: chore(deps): bump the all-dependencies group with 2 updates (#219)
  • change: chore(deps): bump the all-dependencies group with 3 updates (#202)
  • change: chore(deps): bump the all-dependencies group with 4 updates (#225)
  • change: chore(deps): bump uuid from 1.24.0 to 1.24.1 in the all-dependencies group (#211)
  • change: ci(dev): set version to 0.11.11-dev
  • change: ci(dev): set version to 0.11.12-dev
  • change: ci(dev): set version to 0.11.13-dev
  • …and 82 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

GaloyMoney/es-entity was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 9011ae277e07822a50ad1ec281d6f4c23ec9ef7b — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.