Skip to content
CAI
Software that uses CAICheck a score

kickstarter/event-sourcing-rails-todo-app-demo

61.3

Adequate · 22 September 2026

686

lines of production code

Ruby

primary language

7

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is an educational demonstration of an event-sourced architecture for managing to-do lists and items. It implements a command and reactor pattern where user actions generate domain events that are persisted and processed asynchronously to trigger side effects. The application includes a custom code generation tool to scaffold commands, events, and reactors, supported by a database schema that tracks state changes for the aggregates.

Features

Add custom code generation tool

A new executable script at bin/generate has been added to the project. This Ruby-based tool allows developers to scaffold new Commands, Events, and Reactors by providing a file path, automatically creating the necessary directory structure and populating the files with pre-defined templates for each type.

bin · high confidence

Added database schema for Todo and TodoItem entities

The database now includes tables for managing to-do lists and individual to-do items. Specifically, the schema introduces \todo\_lists\ (with name and timestamps), \todo\_list\_events\ for tracking changes to lists, \todo\_items\ (with name, due date, and completion status), and \todo\_item\_events\ for tracking changes to items. This provides the underlying data structure for the todo list feature.

db · high confidence

Introduce event-sourced architecture for TodoList and TodoItem aggregates

Adds an event-sourcing foundation for managing TodoList and TodoItem entities. The change introduces a base event class (Lib::BaseEvent) that automatically applies state changes to aggregates and dispatches events to registered reactors (both synchronous and asynchronous via Sidekiq). Specific events (Created, NameUpdated) are defined for TodoList and TodoItem, enabling the system to track and replay state changes for these aggregates.

ruby · medium confidence

Introduces a command and reactor pattern for TodoList and TodoItem

The application now uses a command pattern to handle TodoList and TodoItem creation and updates, generating domain events (e.g., \TodoList::Created\, \TodoList::NameUpdated\) which are then dispatched asynchronously via \ReactorJob\ to trigger side effects like sending a getting started email. This introduces a new \Lib::Command\ mixin and \Events::Dispatcher\ to manage the flow from command execution to event processing.

app/models · high confidence

Behavioural changes

Updated project documentation and added license

The repository now includes an MIT license file (MIT-LICENSE) and the README has been replaced with a description of an Event Sourcing demo application for educational purposes, rather than standard setup instructions.

(repo-wide) · high confidence

Test coverage

Added tests for TodoList and TodoItem models

Added new test files for the TodoList and TodoItem models, covering the creation of todo lists and items, as well as updating list names.

test · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 59 → 61 (+2.2)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (+0.0)
  • Architecture 69 → 69 (+0.0)
  • Maturity 58 → 74 (+16.2)
  • Readiness 57 → 62 (+5.6)
  • Security 73 → 71 (-1.5)
  • Accessibility 55 → 54 (-1.0)

Resolved (32)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical vulnerability: [GHSA redacted] (Gemfile.lock)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • …and 12 more

New (35)

  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Critical vulnerability: [GHSA redacted] (Gemfile.lock)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • …and 15 more

Architecture

  • Unchanged — 0 containers · 1 contexts · 0 edges

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

kickstarter/event-sourcing-rails-todo-app-demo was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 43e6d4ec260a22a0e5fcbed06b4f1ae318810a7f — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.