Skip to content
CAI
Software that uses CAICheck a score

JasperSui/fastapi-injectable

68.1

Adequate · 22 September 2026

1.9k

lines of production code

Python

primary language

7

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Python library that provides dependency injection capabilities for FastAPI applications and various async task frameworks like Celery, Dramatiq, and Temporal. It addresses concurrency challenges by ensuring dependency resources are correctly isolated per event loop, preventing cross-loop hangs and state leakage. The library includes tools for managing dependency lifecycles, test isolation via a pytest plugin, and type checking through a mypy plugin.

Fixes

Fixes cross-loop hangs and adds isolated dependency scopes

This release fixes a critical issue where dependency resources resolved on one event loop were incorrectly served to another, causing silent hangs or "attached to different loop" errors (GitHub \#186). The dependency cache and exit-stack manager are now partitioned by event loop, ensuring resources stay bound to the loop that created them. Additionally, the library introduces \InjectableScope\ and \injectable\_scope()\ to allow users to create isolated dependency lifecycles for specific tasks or contexts, and adds a pytest plugin to automatically reset global state between tests for better isolation.

_src/fastapi\injectable · high confidence

Test coverage

Added integration tests for Celery, Dramatiq, and Temporal interoperability; Expanded test coverage for dependency lifecycle, concurrency, and plugin behavior.

Dependencies

Migrate build tooling from Poetry to uv and expand Python version support

The project has switched its dependency management from Poetry to uv, replacing the poetry.lock with uv.lock and updating the CONTRIBUTING.md and noxfile.py to use uv commands (e.g., uv sync, uv run). This change is accompanied by an expansion of supported Python versions to include 3.13 and 3.14 (including free-threaded builds), reflected in .python-version, .readthedocs.yml, and the noxfile.py test matrix. Additionally, the pre-commit configuration has been simplified by removing several local hooks and updating the default Python version to 3.14, while a new codecov.yml enforces 100% coverage targets for both project and patch changes.

(repo-wide) · high confidence

Migrate dependency management from Poetry to uv and update build backend

The project has switched its dependency management tool from Poetry to uv, replacing the \poetry.lock\ file with a \pyproject.toml\ configured for \hatchling\ as the build backend. This migration updates the project version to 1.6.1, adds support for Python 3.13 and 3.14, and introduces a pytest plugin entry point for test isolation. Development dependencies are now managed via uv's dependency groups, and the configuration includes updated tool settings for ruff, mypy (with a new plugin), and coverage.

(dependencies) · high confidence

Housekeeping

Added example output documentation to worker script

The worker example script now includes a docstring containing sample output logs, illustrating the expected processing flow and cleanup behavior for messages handled by the CountryWorker, Capital, and Mayor components.

example · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 63 → 68 (+5.0)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 97 → 98 (+0.7)
  • Architecture 100 → 100 (+0.0)
  • Maturity 52 → 57 (+4.8)
  • Readiness 65 → 67 (+2.5)
  • Security 66 → 80 (+14.3)

Resolved (15)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (24 lines × 2) (src/fastapi_injectable/util.py)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • LLM evaluation failed
  • Medium CVE: PYSEC-2026-2132 (uv.lock)
  • Medium CVE: PYSEC-2026-2987 (uv.lock)
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • Test reliability not included

New (30)

  • Critical CVE: [GHSA redacted] (uv.lock)
  • Dependency hygiene PARTLY measured — Python dependencies read, no exact pin to grade for currency
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no licence statement (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (24 lines × 2) (src/fastapi_injectable/util.py)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 10 more

Changes since last survey

  • 5 commits — 4 feature/other, 1 fixes

By area

  • .github/workflows — 3 commits
  • (root) — 1 commit
  • src/fastapi_injectable — 1 commit

Notable commits

  • fix: fix: unwind exit stacks with in-flight exception details so generator dependencies can roll back (#259)
  • change: build(deps): bump actions/setup-python from 6 to 7 (#257)
  • change: build(deps): bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.2 (#256)
  • change: build(deps): bump release-drafter/release-drafter from 7.5.1 to 7.7.0 (#258)
  • change: bump: from 1.6.0 to 1.6.1 (#260)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

JasperSui/fastapi-injectable was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 1bc48a109a543bbaafc9717094dd933d7ca29162 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.