Skip to content
CAI
Software that uses CAICheck a score

mercadona/rele

66.3

Adequate · 22 September 2026

1.6k

lines of production code

Python

primary language

6

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Relé is a Python library for managing Google Cloud Pub/Sub subscriptions, providing a CLI and Django/Flask integrations to simplify message consumption. It features automatic subscription discovery, configurable middleware for database and logging contexts, and robust retry policies. The system is designed to streamline worker setup and message handling within Django and Flask applications.

Features

Autodiscovery of subscription modules across app directories

The system now automatically detects subscription modules (files named 'subs' or 'subs.py') within Django app directories. This change introduces a new discovery mechanism in \rele/management/discover.py\ that scans app paths to identify and register these modules, enabling the framework to locate subscriptions regardless of their specific folder structure within an app.

rele/management · high confidence

New contrib middleware package for Flask, Django, and logging

The \rele.contrib\ package now provides a set of ready-to-use middleware components. This includes \FlaskMiddleware\ to manage Flask application contexts during message processing, \DjangoDBMiddleware\ to handle Django database connection lifecycle, and two logging options: \LoggingMiddleware\ for standard Prometheus-compatible metrics and \VerboseLoggingMiddleware\ which includes full message payload details in logs. Additionally, \UnrecoverableMiddleWare\ is available to automatically acknowledge messages that raise specific unrecoverable exceptions.

rele/contrib · high confidence

Behavioural changes

Modernize build tooling and drop Python 3.8/3.9 support

The project has shifted its development and build infrastructure to use \uv\ for dependency management (with \pyproject.toml\ and \uv.lock\ replacing \requirements.txt\ files) and \ruff\ for linting and formatting, replacing the previous \black\ and \isort\ tools. This change also enforces a minimum Python version of 3.10, dropping support for Python 3.8 and 3.9, and updates the Read the Docs configuration to use Python 3.12. Additionally, the public API is now fully typed with strict mypy checks, and releases are automated via release-please and PyPI trusted publishing.

(repo-wide) · high confidence

Relé 1.17.2: CLI, auto-discovery, and Django integration overhaul

This release introduces a new command-line interface (\rele run\) with automatic subscription and settings discovery, allowing users to start workers without manual configuration. It adds support for third-party subscriptions via the \--third-party-subscriptions\ flag and integrates with Django apps by automatically initializing the configuration in \ReleConfig.ready()\. The library now supports class-based subscriptions, configurable retry policies, and message filtering. Additionally, it deprecates the \GC\_CREDENTIALS\ setting in favor of \GC\_CREDENTIALS\_PATH\ and \GC\_PROJECT\_ID\, and updates the version to 1.17.2.

rele · high confidence

Rename runrele command and add showsubscriptions command

The Django management command previously named \runmaruja\ has been removed and replaced with \runrele\, which now starts subscriber threads to consume messages from Relé topics. Additionally, a new \showsubscriptions\ command has been added to list information about Pub/Sub subscriptions registered using Relé, displaying the topic, subscriber name, and associated function in a tabulated format.

rele/management/commands · high confidence

Test coverage

Added comprehensive test coverage for CLI, middleware, and subscription discovery

This change introduces a new test suite in the \tests/\ directory, adding 110 commits of test files to verify core library behaviors. The tests cover the \rele-cli\ command-line interface (including argument parsing for settings and third-party subscriptions), Django management commands (\runrele\, \showsubscriptions\), and various middleware implementations (Flask, Logging, Verbose Logging, and Unrecoverable Exception handling). Additionally, it includes tests for subscription discovery logic, configuration loading, and publisher client interactions, ensuring robust validation of the library's public API and internal components.

tests · high confidence

Dependencies

Migrate to pyproject.toml and adopt uv/hatchling build system

The project has consolidated its configuration and dependencies into a single pyproject.toml file, removing the legacy requirements.txt and requirements\_test.txt files. This change introduces the hatchling build backend and adopts uv for dependency management. The Python runtime requirement is now set to version 3.10 or higher, and the tooling stack has shifted from flake8/tox to ruff for linting and mypy for strict type checking.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 60 → 66 (+6.7)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 99 (+0.4)
  • Architecture 69 → 95 (+26.1)
  • Maturity 53 → 61 (+8.7)
  • Readiness 52 → 56 (+3.5)
  • Security 89 → 85 (-4.0)

Resolved (9)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • LLM evaluation failed
  • Medium IaC: CKV_DOCKER_3 (Dockerfile)
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • Test reliability not included

New (29)

  • Dependency hygiene PARTLY measured — Python dependencies read, no exact pin to grade for currency
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no installation or build instructions (docs/ai/gotchas.md)
  • Documentation: no usage examples (docs/ai/gotchas.md)
  • High CVE: [GHSA redacted] (uv.lock)
  • High CVE: [GHSA redacted] (uv.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Inconsistent parameter naming for message payload and attributes in publish hooks. BaseMiddleware and LoggingMiddleware use 'data' and 'attrs', while VerboseLoggingMiddleware uses 'message_data' and 'message_attributes'.
  • Inconsistent parameter naming for the exception object in failure hooks. Most implementations use 'exception', but UnrecoverableMiddleWare uses 'err'.
  • Job token omits the contents scope its checkout needs
  • Medium CVE: [GHSA redacted] (uv.lock)
  • Medium CVE: PYSEC-2026-3717 (uv.lock)
  • …and 9 more

Changes since last survey

  • 21 commits — 13 feature/other, 8 fixes

By area

  • (root) — 12 commits
  • .github/CODEOWNERS — 1 commit
  • .github/workflows — 1 commit
  • docs/ai — 1 commit
  • rele/init.py — 1 commit
  • rele/client.py — 1 commit
  • rele/config.py — 1 commit
  • rele/discover.py — 1 commit
  • rele/retry_policy.py — 1 commit
  • tests/contrib — 1 commit

Notable commits

  • fix: fix: Subscriber still passed real credentials when using the Pub/Sub emulator (#357)
  • fix: fix: emit the connection-check error log instead of losing it (#330)
  • fix: fix: let an explicit settings path win over autodiscovery (#354)
  • fix: fix: name individual code owners instead of a private team (#350)
  • fix: fix: name the correct hook in the deprecation warning (#344)
  • fix: fix: publish() reports the wrong error when settings has no RELE dict (#343)
  • fix: fix: reject negative backoffs in RetryPolicy (#356)
  • fix: fix: return None from gc_project_id when credentials have no project (#342)
  • change: chore(master): release 1.17.0 (#326)
  • change: chore(master): release 1.17.1 (#329)
  • change: chore(master): release 1.17.2 (#347)
  • change: chore: backfill the 1.17.0 changelog and drop the release-as override (#327)
  • change: chore: release the pending changes as 1.17.0 with v-style tags (#324)
  • change: chore: reset version to last released 1.16.0 (#325)
  • change: ci: publish the coverage badge from Actions and drop codecov (#353)
  • change: ci: run the suite on pushes to master, not only on pull requests (#349)
  • change: docs: credit Aryan Singh K. in AUTHORS.md (#358)
  • change: docs: credit Rajeev Nandan in AUTHORS.md (#348)
  • change: docs: document the release-please pre-release trap (#328)
  • change: test: cover the four public features that had no tests at all (#335)
  • …and 1 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

mercadona/rele was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 7fc1b75b6e8a508cca639b121d87754971f5a4e6 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.