JasperSui/fastapi-injectable
68.1
Adequate · 22 September 2026
1.9k
lines of production code
Python
primary language
7
measurements over time
What this system is
This system is a Python library that provides dependency injection capabilities for FastAPI applications and various async task frameworks like Celery, Dramatiq, and Temporal. It addresses concurrency challenges by ensuring dependency resources are correctly isolated per event loop, preventing cross-loop hangs and state leakage. The library includes tools for managing dependency lifecycles, test isolation via a pytest plugin, and type checking through a mypy plugin.
Fixes
Fixes cross-loop hangs and adds isolated dependency scopes
This release fixes a critical issue where dependency resources resolved on one event loop were incorrectly served to another, causing silent hangs or "attached to different loop" errors (GitHub \#186). The dependency cache and exit-stack manager are now partitioned by event loop, ensuring resources stay bound to the loop that created them. Additionally, the library introduces \InjectableScope\ and \injectable\_scope()\ to allow users to create isolated dependency lifecycles for specific tasks or contexts, and adds a pytest plugin to automatically reset global state between tests for better isolation.
_src/fastapi\injectable · high confidence
Test coverage
Added integration tests for Celery, Dramatiq, and Temporal interoperability; Expanded test coverage for dependency lifecycle, concurrency, and plugin behavior.
Dependencies
Migrate build tooling from Poetry to uv and expand Python version support
The project has switched its dependency management from Poetry to uv, replacing the poetry.lock with uv.lock and updating the CONTRIBUTING.md and noxfile.py to use uv commands (e.g., uv sync, uv run). This change is accompanied by an expansion of supported Python versions to include 3.13 and 3.14 (including free-threaded builds), reflected in .python-version, .readthedocs.yml, and the noxfile.py test matrix. Additionally, the pre-commit configuration has been simplified by removing several local hooks and updating the default Python version to 3.14, while a new codecov.yml enforces 100% coverage targets for both project and patch changes.
(repo-wide) · high confidence
Migrate dependency management from Poetry to uv and update build backend
The project has switched its dependency management tool from Poetry to uv, replacing the \poetry.lock\ file with a \pyproject.toml\ configured for \hatchling\ as the build backend. This migration updates the project version to 1.6.1, adds support for Python 3.13 and 3.14, and introduces a pytest plugin entry point for test isolation. Development dependencies are now managed via uv's dependency groups, and the configuration includes updated tool settings for ruff, mypy (with a new plugin), and coverage.
(dependencies) · high confidence
Housekeeping
Added example output documentation to worker script
The worker example script now includes a docstring containing sample output logs, illustrating the expected processing flow and cleanup behavior for messages handled by the CountryWorker, Capital, and Mayor components.
example · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 63 → 68 (+5.0)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 97 → 98 (+0.7)
- Architecture 100 → 100 (+0.0)
- Maturity 52 → 57 (+4.8)
- Readiness 65 → 67 (+2.5)
- Security 66 → 80 (+14.3)
Resolved (15)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (24 lines × 2) (src/fastapi_injectable/util.py)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- LLM evaluation failed
- Medium CVE: PYSEC-2026-2132 (uv.lock)
- Medium CVE: PYSEC-2026-2987 (uv.lock)
- No exposed public API
- Off-boarding risk: anonymized user #1
- Test reliability not included
New (30)
- Critical CVE: [GHSA redacted] (uv.lock)
- Dependency hygiene PARTLY measured — Python dependencies read, no exact pin to grade for currency
- Documentation: no installation or build instructions (README.md)
- Documentation: no licence statement (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (24 lines × 2) (src/fastapi_injectable/util.py)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 10 more
Changes since last survey
- 5 commits — 4 feature/other, 1 fixes
By area
- .github/workflows — 3 commits
- (root) — 1 commit
- src/fastapi_injectable — 1 commit
Notable commits
- fix: fix: unwind exit stacks with in-flight exception details so generator dependencies can roll back (#259)
- change: build(deps): bump actions/setup-python from 6 to 7 (#257)
- change: build(deps): bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.2 (#256)
- change: build(deps): bump release-drafter/release-drafter from 7.5.1 to 7.7.0 (#258)
- change: bump: from 1.6.0 to 1.6.1 (#260)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
JasperSui/fastapi-injectable was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 1bc48a109a543bbaafc9717094dd933d7ca29162 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.