Skip to content
CAI
Software that uses CAICheck a score

link-loom/loom-sdk

42.8

Weak · 21 September 2026

5k

lines of production code

JavaScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Link Loom SDK is a Node.js application backbone designed to orchestrate monoliths, microservices, and workers through a finite state machine-driven runtime. It provides a modular architecture for managing HTTP services with real-time streaming, deterministic worker lifecycles, and a comprehensive event system. The framework standardizes infrastructure integration for databases, storage, and observability while offering built-in utilities for security, data modeling, and dependency injection.

Features

This entry introduces the Link Loom SDK, a Node.js runtime foundation that manages application initialization, dependency resolution, and lifecycle via a finite state machine. The SDK exposes core components including the Loom engine, BaseModel, Property, BaseWorker, and specific adapters for Workers and Streams through the main entry point. It also establishes development standards by adding ESLint and Prettier configurations and updates the project documentation to reflect its architecture as an application backbone for monoliths, microservices, and workers.

(repo-wide) · high confidence

Introduction of FunctionsModule for managing cache, timed, and startup functions

A new FunctionsModule has been added to the application's adapter layer to centralize the initialization and lifecycle management of background tasks. This module loads function definitions from the core 'src/functions' cluster and organizes them into three categories: cache, timed, and startup. It handles the dynamic instantiation of these functions, manages scheduled execution intervals for timed tasks using moment.js for time calculations, and ensures startup functions run either immediately or upon a server-loaded event via the event bus. The module also provides structured logging with a specific namespace and error handling to prevent initialization failures from crashing the application.

src/adapters/functions · high confidence

New StreamModule adapter for dynamic stream integration

The application now includes a new StreamModule adapter located at src/adapters/streams/stream.module.js, which enables the dynamic loading and instantiation of stream classes from the src/streams directory. This module is integrated into the main Loom SDK entry point (src/loom.sdk.js) via the \#setupAdapterModules method, allowing the engine to automatically discover, load, and manage stream instances during initialization while providing specific logging and error handling for each stream.

src · high confidence

New modular infrastructure components for database, email, observability, push, and storage

The infrastructure layer now includes dedicated module classes (DatabaseModule, EmailModule, ObservabilityModule, PushModule, StorageModule) that standardize how external services are initialized. Each module reads its configuration from the application's module settings, checks if it is enabled, and dynamically loads the specified default adapter (e.g., from \src/adapters/database/...\) to provide a unified client interface. This change introduces a consistent pattern for enabling, configuring, and accessing infrastructure services across the application.

src/infrastructure · high confidence

New utility modules for security, data modeling, and real-time streaming

The \src/utils\ directory has been populated with a comprehensive suite of new utility classes to support core application capabilities. Security is enhanced with \crypto.util.js\ (AES-256-GCM encryption/decryption and HMAC signing) and \encoder.util.js\ (Base64 and AES-CTR ciphering), while \validator.util.js\ introduces JWT and signed-data verification. Data handling is standardized via \models/base.model.js\ and \models/property.model.js\, which provide a structured way to define entity properties with default types and statuses, supported by \data-types/definition.types.js\. Real-time communication is enabled by \sse.util.js\, which creates Server-Sent Event streams with proper header flushing, and \event.util.js\ for WebSocket topic-based emission. Additional utilities include \performance.util.js\ for tracking CPU/memory metrics, \generator.util.js\ for IDs and JWTs, \search.util.js\ for object/array queries, \io.util.js\ for request/response formatting, \sanitizer.util.js\ for input cleaning, and \lang.utils.js\ for native prototype extensions.

src/utils · high confidence

Architecture

New modular event system architecture with broker, bus, consumer, and producer components

The event handling infrastructure in src/adapters/events has been restructured into four distinct modules: EventBrokerModule manages the WebSocket server setup, BusModule initializes an internal event emitter, EventConsumerModule handles incoming events by connecting to a broker and subscribing to topics, and EventProducerModule manages outgoing events by listening for consumer connections and executing event handlers. Each module follows a consistent pattern with dependency injection, configuration-based enable/disable logic, and structured logging using a specific namespace format.

src/adapters/events · high confidence

Behavioural changes

Core module architecture restructured with new utility and dependency management

The core application structure has been refactored into distinct modules (Console, DataTypes, Dependencies, Settings, Utilities) to improve organization and maintainability. This change introduces a centralized dependency injection system that automatically loads and exposes common libraries (such as Express, Socket.io, and Helmet) to the rest of the application. It also adds new utility modules for performance tracking and Server-Sent Events (SSE) support, while updating the server configuration to use the 'extended' query parser and enforce security headers via Helmet.

src/core · high confidence

HTTP adapter refactored into modular components with SSE and nested route support

The HTTP adapter has been restructured into distinct modules (API, Model, Service) to improve architecture and maintainability. The API module now supports Server-Sent Events (SSE) for streaming responses, allowing real-time data delivery to clients. It also introduces per-route body size limits and supports file uploads via middleware. Additionally, the routing system now handles multi-level (nested) domain paths, enabling more granular URL structures. Model and Service modules are now explicitly loaded and registered, ensuring proper initialization of data types and service instances.

src/adapters/http · high confidence

Introduce deterministic worker lifecycle management with crash-hardened state machine

The worker subsystem now uses a deterministic finite state machine (FSM) to manage worker lifecycles, replacing the previous implicit behavior with explicit states (INACTIVE, ACTIVE\_FOREGROUND, ACTIVE\_BACKGROUND, SUSPENDED, TERMINATING, TERMINATED, CRASHED) and command-driven transitions (spawn, activate, deactivate, suspend, resume, stop, signal). This change prevents crash masking and resource leaks by ensuring that any error during a lifecycle hook immediately transitions the worker to a CRASHED state, while also introducing safe logging wrappers in the base worker to prevent logging failures from interfering with the actual worker logic. The system now provides a robust, observable API for managing worker instances, including automatic performance metric reporting on termination and clear separation between foreground and background activation modes.

src/adapters/workers, src/utils/workers · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 44 → 43 (-1.2)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 57 → 59 (+1.6)
  • Architecture 97 → 77 (-20.9)
  • Maturity 70 → 71 (+0.4)
  • Readiness 16 → 17 (+0.6)
  • Security 74 → 79 (+5.3)

Resolved (27)

  • #handleMessage (cognitive 17) (src/adapters/workers/worker-thread/threaded-worker.proxy.js)
  • #serializerOjectToQueryString (cognitive 17) (src/utils/encoder.util.js)
  • Change coupling: email.module.js ↔ observability.module.js (src/infrastructure/email.module.js)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High vulnerability: [GHSA redacted] (package-lock.json)
  • Medium CVE: [GHSA redacted] (package-lock.json)
  • …and 7 more

New (49)

  • ClassTooLong: WorkersModule (src/adapters/workers/workers.module.js)
  • Documentation: no installation or build instructions (docs/README.md)
  • Documentation: written for insiders (docs/core/settings.module.md)
  • Documentation: written for insiders (docs/core/utilities.module.md)
  • EncoderUtil.#serializerOjectToQueryString (cognitive 17) (src/utils/encoder.util.js)
  • Floating npm dependency: body-parser
  • Floating npm dependency: colors
  • Floating npm dependency: cors
  • Floating npm dependency: jsonwebtoken
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • …and 29 more

Changes since last survey

  • 3 commits — 1 feature/other, 2 fixes

By area

  • (repo) — 1 commit
  • (root) — 1 commit
  • src/adapters — 1 commit

Notable commits

  • fix: Fix: Harden worker lifecycle FSM against crash masking and resource leaks
  • fix: Merge pull request #3 from link-loom/fix/worker-lifecycle-hardening
  • change: 7.3.53

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

link-loom/loom-sdk was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit ec11dd6dd9297f43b0511c7018825018b957fc0d — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.