link-loom/loom-sdk
42.8
Weak · 21 September 2026
5k
lines of production code
JavaScript
primary language
4
measurements over time
What this system is
Link Loom SDK is a Node.js application backbone designed to orchestrate monoliths, microservices, and workers through a finite state machine-driven runtime. It provides a modular architecture for managing HTTP services with real-time streaming, deterministic worker lifecycles, and a comprehensive event system. The framework standardizes infrastructure integration for databases, storage, and observability while offering built-in utilities for security, data modeling, and dependency injection.
Features
Initial release of Link Loom SDK with runtime orchestration and adapters
This entry introduces the Link Loom SDK, a Node.js runtime foundation that manages application initialization, dependency resolution, and lifecycle via a finite state machine. The SDK exposes core components including the Loom engine, BaseModel, Property, BaseWorker, and specific adapters for Workers and Streams through the main entry point. It also establishes development standards by adding ESLint and Prettier configurations and updates the project documentation to reflect its architecture as an application backbone for monoliths, microservices, and workers.
(repo-wide) · high confidence
Introduction of FunctionsModule for managing cache, timed, and startup functions
A new FunctionsModule has been added to the application's adapter layer to centralize the initialization and lifecycle management of background tasks. This module loads function definitions from the core 'src/functions' cluster and organizes them into three categories: cache, timed, and startup. It handles the dynamic instantiation of these functions, manages scheduled execution intervals for timed tasks using moment.js for time calculations, and ensures startup functions run either immediately or upon a server-loaded event via the event bus. The module also provides structured logging with a specific namespace and error handling to prevent initialization failures from crashing the application.
src/adapters/functions · high confidence
New StreamModule adapter for dynamic stream integration
The application now includes a new StreamModule adapter located at src/adapters/streams/stream.module.js, which enables the dynamic loading and instantiation of stream classes from the src/streams directory. This module is integrated into the main Loom SDK entry point (src/loom.sdk.js) via the \#setupAdapterModules method, allowing the engine to automatically discover, load, and manage stream instances during initialization while providing specific logging and error handling for each stream.
src · high confidence
New modular infrastructure components for database, email, observability, push, and storage
The infrastructure layer now includes dedicated module classes (DatabaseModule, EmailModule, ObservabilityModule, PushModule, StorageModule) that standardize how external services are initialized. Each module reads its configuration from the application's module settings, checks if it is enabled, and dynamically loads the specified default adapter (e.g., from \src/adapters/database/...\) to provide a unified client interface. This change introduces a consistent pattern for enabling, configuring, and accessing infrastructure services across the application.
src/infrastructure · high confidence
New utility modules for security, data modeling, and real-time streaming
The \src/utils\ directory has been populated with a comprehensive suite of new utility classes to support core application capabilities. Security is enhanced with \crypto.util.js\ (AES-256-GCM encryption/decryption and HMAC signing) and \encoder.util.js\ (Base64 and AES-CTR ciphering), while \validator.util.js\ introduces JWT and signed-data verification. Data handling is standardized via \models/base.model.js\ and \models/property.model.js\, which provide a structured way to define entity properties with default types and statuses, supported by \data-types/definition.types.js\. Real-time communication is enabled by \sse.util.js\, which creates Server-Sent Event streams with proper header flushing, and \event.util.js\ for WebSocket topic-based emission. Additional utilities include \performance.util.js\ for tracking CPU/memory metrics, \generator.util.js\ for IDs and JWTs, \search.util.js\ for object/array queries, \io.util.js\ for request/response formatting, \sanitizer.util.js\ for input cleaning, and \lang.utils.js\ for native prototype extensions.
src/utils · high confidence
Architecture
New modular event system architecture with broker, bus, consumer, and producer components
The event handling infrastructure in src/adapters/events has been restructured into four distinct modules: EventBrokerModule manages the WebSocket server setup, BusModule initializes an internal event emitter, EventConsumerModule handles incoming events by connecting to a broker and subscribing to topics, and EventProducerModule manages outgoing events by listening for consumer connections and executing event handlers. Each module follows a consistent pattern with dependency injection, configuration-based enable/disable logic, and structured logging using a specific namespace format.
src/adapters/events · high confidence
Behavioural changes
Core module architecture restructured with new utility and dependency management
The core application structure has been refactored into distinct modules (Console, DataTypes, Dependencies, Settings, Utilities) to improve organization and maintainability. This change introduces a centralized dependency injection system that automatically loads and exposes common libraries (such as Express, Socket.io, and Helmet) to the rest of the application. It also adds new utility modules for performance tracking and Server-Sent Events (SSE) support, while updating the server configuration to use the 'extended' query parser and enforce security headers via Helmet.
src/core · high confidence
HTTP adapter refactored into modular components with SSE and nested route support
The HTTP adapter has been restructured into distinct modules (API, Model, Service) to improve architecture and maintainability. The API module now supports Server-Sent Events (SSE) for streaming responses, allowing real-time data delivery to clients. It also introduces per-route body size limits and supports file uploads via middleware. Additionally, the routing system now handles multi-level (nested) domain paths, enabling more granular URL structures. Model and Service modules are now explicitly loaded and registered, ensuring proper initialization of data types and service instances.
src/adapters/http · high confidence
Introduce deterministic worker lifecycle management with crash-hardened state machine
The worker subsystem now uses a deterministic finite state machine (FSM) to manage worker lifecycles, replacing the previous implicit behavior with explicit states (INACTIVE, ACTIVE\_FOREGROUND, ACTIVE\_BACKGROUND, SUSPENDED, TERMINATING, TERMINATED, CRASHED) and command-driven transitions (spawn, activate, deactivate, suspend, resume, stop, signal). This change prevents crash masking and resource leaks by ensuring that any error during a lifecycle hook immediately transitions the worker to a CRASHED state, while also introducing safe logging wrappers in the base worker to prevent logging failures from interfering with the actual worker logic. The system now provides a robust, observable API for managing worker instances, including automatic performance metric reporting on termination and clear separation between foreground and background activation modes.
src/adapters/workers, src/utils/workers · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 44 → 43 (-1.2)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 57 → 59 (+1.6)
- Architecture 97 → 77 (-20.9)
- Maturity 70 → 71 (+0.4)
- Readiness 16 → 17 (+0.6)
- Security 74 → 79 (+5.3)
Resolved (27)
- #handleMessage (cognitive 17) (src/adapters/workers/worker-thread/threaded-worker.proxy.js)
- #serializerOjectToQueryString (cognitive 17) (src/utils/encoder.util.js)
- Change coupling: email.module.js ↔ observability.module.js (src/infrastructure/email.module.js)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High vulnerability: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- …and 7 more
New (49)
- ClassTooLong: WorkersModule (src/adapters/workers/workers.module.js)
- Documentation: no installation or build instructions (docs/README.md)
- Documentation: written for insiders (docs/core/settings.module.md)
- Documentation: written for insiders (docs/core/utilities.module.md)
- EncoderUtil.#serializerOjectToQueryString (cognitive 17) (src/utils/encoder.util.js)
- Floating npm dependency: body-parser
- Floating npm dependency: colors
- Floating npm dependency: cors
- Floating npm dependency: jsonwebtoken
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 29 more
Changes since last survey
- 3 commits — 1 feature/other, 2 fixes
By area
- (repo) — 1 commit
- (root) — 1 commit
- src/adapters — 1 commit
Notable commits
- fix: Fix: Harden worker lifecycle FSM against crash masking and resource leaks
- fix: Merge pull request #3 from link-loom/fix/worker-lifecycle-hardening
- change: 7.3.53
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
link-loom/loom-sdk was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit ec11dd6dd9297f43b0511c7018825018b957fc0d — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.