mateodelnorte/sourced
49.9
Weak · 28 September 2026
415
lines of production code
JavaScript
primary language
6
measurements over time
What this system is
This codebase is a small library for building event-sourced entities and immutable value objects, centered on SourcedEntity/Entity and SourcedValue/Value. It supports snapshotting, merging, replaying events, queuing events, and digesting commands, with an authentication example showing how a User entity can grant and revoke access to App value objects. The history is mainly a migration from legacy helper modules to an ES6 class implementation, along with tests and tooling updates, rather than a full application.
Features
Added authentication example for entity-based access control
A new examples/auth folder adds a runnable demo with a User entity and an App value object. The User example provisions a username/password, grants and revokes access to apps, emits provisioned, granted, and revoked events, and records operations through digest. The example script then shows how the same user can be reconstructed from a snapshot, merged from a snapshot, or replayed from events, giving users a concrete pattern for auth-style entity workflows.
examples · medium confidence
Removals
Removed legacy entity and value helper modules
The library deletes the old lib/entity.js and lib/value.js files, eliminating the previous Entity implementation and the value helper that returned Object.freeze(obj). This removes the old code path for entity behavior, including its apply, merge, replay, and snapshot logic, and reduces the library surface by dropping these unused or superseded modules.
lib · medium confidence
Behavioural changes
Entity is now a compatibility proxy over a new ES6 SourcedEntity class
The source code introduces SourcedEntity as an ES6 class that extends EventEmitter and handles snapshot merging, event replay, event queuing, and command digesting, while Entity is provided as a Proxy that creates a SourcedEntity, copies its state into the caller, and calls rehydrate. Using Entity now emits a one-time deprecation warning explaining that the current Entity proxy may later be renamed EntityProxy and that users should either switch to EntityProxy or refactor to class-based usage. The package also exports SourcedEntity, Entity, SourcedValue, and Value, with Value freezing objects.
src · medium confidence
Test coverage
Added test coverage for entity, value, and export behavior; Removed test files for entity and handler support.
Dependencies
Dependency manifest and lockfile refresh
The package manifest was updated from a minimal stub to a full build/test configuration, adding Babel 7.10.3, Jest 26.0.1, ESLint 7.3.0 and related tooling, plus runtime dependencies debug ^4.1.1, lodash.clonedeep ^4.5.0, and lodash.merge ^4.6.2; the previous mocha and should dev dependencies were removed, and a package-lock.json was added to pin the resolved dependency tree. This is primarily a maintenance change to dependency resolution and build/test tooling rather than a user-facing feature.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 54 → 50 (-4.3)
- Rubric changed (rubric-2026.08.20 → rubric-2026.09.16) — scores are not directly comparable.
Lenses
- Code Health 70 → 70 (+0.0)
- Architecture 69 → 69 (+0.0)
- Maturity 48 → 48 (+0.0)
- Readiness 47 → 41 (-5.4)
- Security 75 → 67 (-8.3)
Resolved (53)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 33 more
New (54)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (the committed lockfile is in a format this engine cannot resolve)
- Documentation: no installation or build instructions (README.md)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 34 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
mateodelnorte/sourced was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 27eb5214c15d7ef65d65b330c537968898986ef2 — the exact code this score is about.
- Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-2d9048c36d26.