Skip to content
CAI
Software that uses CAICheck a score

ivanpaulovich/event-sourcing-jambo

40.7

Weak · 21 September 2026

2k

lines of production code

C#

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a .NET-based microservices architecture for managing blog content, comprising Auth, Producer, and Consumer services. The Producer service handles content creation and updates via a CQRS pattern, publishing domain events to Kafka. The Consumer service subscribes to these events to maintain MongoDB read models, while the Auth service manages user authentication with JWT tokens.

Features

Initial release of Auth and Producer microservices with MongoDB and Kafka integration

This change introduces the foundational structure for the Auth and Producer domains. The Auth service provides a login endpoint that issues JWT tokens, configured via \appsettings.json\ and supporting Docker-based local development with MongoDB and Kafka. The Producer service implements command handlers for managing Blogs and Posts (create, update, enable/disable, publish, comment) using a CQRS pattern with MediatR. It includes read models for querying blogs and posts from MongoDB and publishes domain events to a Kafka topic via a \Bus\ implementation, all wired together with Autofac dependency injection.

setup, source/Auth, source/Producer · high confidence

Introduce consumer application with domain event handlers and MongoDB persistence

The consumer application is introduced, featuring domain event handlers for Blog and Post lifecycle events (creation, updates, enable/disable/publish/hidden states) that update read models in a MongoDB-backed repository layer. The infrastructure layer provides a MongoContext and typed repositories (read/write for blogs and posts) wired via Autofac modules, while a Kafka-based Bus subscriber consumes domain events and dispatches them through MediatR. A new Jambo.Domain layer defines the aggregate roots, domain events, and exception types, with unit tests added for value object validation.

source/Shared · high confidence

Dependencies

Initial project structure and dependency configuration for Auth, Consumer, and Producer services

The repository introduces the foundational .csproj files for the Auth, Consumer, and Producer domains, each defining their respective application and infrastructure layers. These project files establish the build configuration (targeting .NET Standard 2.0 or .NET Core 2.0) and declare key dependencies including MediatR, Autofac, MongoDB.Driver, Confluent.Kafka, and Swashbuckle. The shared Jambo.Domain project is also added, along with a corresponding unit test project, setting the stage for the application's modular architecture.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 43 → 41 (-2.3)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 58 → 58 (-0.1)
  • Architecture 90 → 90 (+0.0)
  • Maturity 46 → 46 (+0.0)
  • Readiness 28 → 23 (-5.1)
  • Security 66 → 66 (+0.1)
  • Domain Modelling 68 → 71 (+2.2)

Resolved (28)

  • Bounded contexts not declared
  • Change coupling: BlogsController.cs ↔ PostsController.cs (source/Producer/Jambo.Producer.UI/Controllers/BlogsController.cs)
  • High CVE: Microsoft.AspNetCore.Identity 2.0.0
  • High CVE: Microsoft.AspNetCore.Identity 2.0.0
  • High CVE: Microsoft.AspNetCore.Server.Kestrel.Core 2.0.0
  • High CVE: Microsoft.AspNetCore.Server.Kestrel.Core 2.0.0
  • High CVE: System.Net.Security 4.0.0
  • High CVE: System.Net.Security 4.0.0
  • High CVE: System.Net.Security 4.3.0
  • High CVE: System.Net.Security 4.3.0
  • High CVE: System.Security.Cryptography.Xml 4.4.0
  • High CVE: System.Security.Cryptography.Xml 4.4.0
  • Medium CVE: Microsoft.AspNetCore.All 2.0.0
  • Medium CVE: Microsoft.AspNetCore.All 2.0.0
  • Medium CVE: Microsoft.AspNetCore.Server.Kestrel.Core 2.0.0
  • Medium CVE: Microsoft.AspNetCore.Server.Kestrel.Core 2.0.0
  • Medium CVE: Microsoft.AspNetCore.Server.Kestrel.Transport.Libuv 2.0.0
  • Medium CVE: System.Data.SqlClient 4.4.0
  • Medium CVE: System.Net.Security 4.0.0
  • Medium CVE: System.Net.Security 4.0.0
  • …and 8 more

New (25)

  • Documentation: no usage examples (README.md)
  • Duplicated block (5 lines × 2) (source/Producer/Jambo.Producer.Application/CommandHandlers/Blogs/DisableBlogCommandHandler.cs)
  • Duplicated block (6 lines × 5) (source/Producer/Jambo.Producer.Application/CommandHandlers/Posts/DisablePostCommandHandler.cs)
  • Duplicated block (8 lines × 2) (source/Producer/Jambo.Producer.Application/CommandHandlers/Posts/CreateCommentCommandHandler.cs)
  • End-of-life runtime: .NET netcoreapp2.0
  • High CVE: Microsoft.AspNetCore.Identity 2.0.0
  • High CVE: System.Net.Security 4.0.0
  • High CVE: System.Net.Security 4.3.0
  • High CVE: System.Security.Cryptography.Xml 4.4.0
  • High IaC: WD-COMPOSE-0002 (setup/docker-compose.yml)
  • High IaC: WD-COMPOSE-0002 (setup/docker-compose.yml)
  • High IaC: WD-DOCKER-0013 (source/Auth/Jambo.Auth.UI/Dockerfile)
  • High IaC: WD-DOCKER-0013 (source/Consumer/Jambo.Consumer.UI/Dockerfile)
  • High IaC: WD-DOCKER-0013 (source/Producer/Jambo.Producer.UI/Dockerfile)
  • Leaked secret: signing-key (source/Auth/Jambo.Auth.UI/appsettings.json)
  • Leaked secret: signing-key (source/Producer/Jambo.Producer.UI/appsettings.json)
  • Medium IaC: WD-DOCKER-0003 (source/Auth/Jambo.Auth.UI/Dockerfile)
  • Medium IaC: WD-DOCKER-0003 (source/Consumer/Jambo.Consumer.UI/Dockerfile)
  • Medium IaC: WD-DOCKER-0003 (source/Producer/Jambo.Producer.UI/Dockerfile)
  • The command handler for creating a post is located in the Blogs namespace (Jambo.Producer.Application.CommandHandlers.Blogs) but handles a Post command, whereas other post-related handlers are in the Posts namespace. This suggests a misplaced namespace or a naming inconsistency where the handler belongs in the Posts module.
  • …and 5 more

API surface

  • Unchanged — 16 HTTP endpoints

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

ivanpaulovich/event-sourcing-jambo was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 15ac2de003dead45ca25fc673f08aa7b7168350a — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.