Skip to content
CAI
Software that uses CAICheck a score

node-ts/bus

53.2

Adequate · 21 September 2026

7k

lines of production code

TypeScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a distributed message bus framework for Node.js that facilitates reliable communication between services. It provides a core abstraction for publishing, subscribing, and handling messages across various transport layers, including RabbitMQ, AWS SQS, and in-memory queues. The system supports complex patterns such as long-running workflows (sagas) with state persistence in MongoDB or PostgreSQL, and offers structured error handling and serialization utilities.

How it got here

2019 — Inversify removal and transport expansion

16 changes.

This period focused on removing the Inversify dependency and refactoring the core bus architecture to be framework-agnostic. Concurrently, the project expanded its capabilities by introducing new transport implementations for RabbitMQ, AWS SQS, and Postgres persistence.

2021–2024 — workflow orchestration and testing infrastructure

10 changes.

This period focused on introducing a comprehensive workflow orchestration subsystem to the core package, enabling long-running business processes with state persistence. The release also expanded the framework's capabilities with a new JSON serializer, an SQS Lambda receiver, and a MongoDB persistence provider, while establishing a shared testing suite for transport adapters.

Features

Add @node-ts/bus-class-serializer package

Introduces a new JSON-based serializer for @node-ts/bus that deserializes messages into strong types using class-transformer. This allows users to maintain object types (such as Date) during serialization and deserialization, providing a preferred alternative to the default serializer that does not support this. The package includes the ClassSerializer implementation, unit tests, and configuration files.

packages/bus-class-serializer · high confidence

Add @node-ts/bus-test package for transport integration testing

The @node-ts/bus-test package has been introduced to provide a common suite of integration tests for transport adapters. It includes helper classes for test messages (commands, events, system messages, poisoned messages) and a \transportTests\ function that validates transport behavior, including message dispatch, system message handling, and retry strategies.

packages/bus-test · high confidence

Add MongoDB persistence provider for workflow state storage

Introduced a new MongoDB-based persistence implementation for the @node-ts/bus framework, allowing users to store and retrieve workflow states in a MongoDB database. The package includes configuration options for the connection string and database name, a MongodbPersistence class that implements the Persistence interface, and integration tests verifying workflow state save, retrieval, and update behaviors. A custom WorkflowStateNotFound error is also provided for cases where a workflow state is not found in the database.

packages/bus-mongodb · high confidence

Add SQS Lambda receiver for serverless message handling

Introduced a new \@node-ts/bus-sqs-lambda\ package that enables applications to receive messages from Amazon SQS events triggered by AWS Lambda. This allows the host application to receive its own messages rather than subscribing directly to the transport, which is useful for local testing or serverless environments where the cloud provider manages message delivery. The change includes the \BusSqsLambdaReceiver\ implementation, its associated tests, and the core \Receiver\ interface in \@node-ts/bus-core\ that supports this pattern.

packages/bus-core/src/receiver, packages/bus-sqs-lambda · high confidence

Add structured logging, DI adapter, and message handling context

The service bus now includes a configurable logging system (defaulting to the \debug\ package) and a \ContainerAdapter\ interface for dependency injection, allowing handlers to be resolved from external IoC containers. Additionally, a \MessageHandlingContext\ is introduced to track the current message and attributes during processing, enabling features like outbox pattern support and context-aware resolution. New error types (\ClassHandlerNotResolved\, \ContainerNotRegistered\, \FailMessageOutsideHandlingContext\, \ReturnMessageOutsideHandlingContext\) provide specific feedback for common misconfigurations and invalid states.

packages/bus-core/src/service-bus · high confidence

Added in-memory persistence implementation for workflow state

Introduced an in-memory persistence provider for the workflow system, allowing workflow state to be stored in memory rather than a durable store. This includes the \InMemoryPersistence\ class and its supporting error types (\PersistenceNotConfigured\, \WorkflowStateNotInitialized\), enabling stateless, ephemeral workflow execution for testing or prototyping. The change also adds a \Persistence\ interface and associated README documentation.

packages/bus-core/src/workflow/persistence · high confidence

Initial implementation of the AWS SQS transport

The SQS transport is now available for use, allowing the bus to send and receive messages via Amazon SQS and SNS. This includes configuration options for queue and topic naming, visibility timeouts, dead-letter queue handling, and automatic resource provisioning. The transport supports message attributes, retry strategies, and integration tests to verify functionality.

packages/bus-sqs/src · high confidence

Introduce MessageSerializer and update JsonSerializer interface

The serialization layer now includes a new MessageSerializer that wraps a base serializer and integrates with the HandlerRegistry to resolve message types during deserialization. The base Serializer interface has been extended with toPlain and toClass methods, and the JsonSerializer implementation has been updated to support these conversions, allowing for more robust type handling during message processing.

packages/bus-core/src/serialization · high confidence

Introduce Postgres persistence implementation for workflow state

Added a new Postgres persistence layer that stores workflow state in a configurable schema and table, with automatic schema and table creation, JSONB storage, and dynamic secondary indexes for message-based lookups. A custom WorkflowStateNotFound error is exported to signal missing states, and integration tests verify the full lifecycle of saving, retrieving, and updating workflow states.

packages/bus-postgres/src · high confidence

Introduce RabbitMQ transport implementation

Added a new RabbitMQ transport implementation for @node-ts/bus, including the main transport class, configuration interface (supporting connection string, max retries, and persistent message flags), and integration tests. This enables users to use RabbitMQ as a message broker for publishing and consuming events and commands within the bus system.

packages/bus-rabbitmq/src · high confidence

Introduce WorkflowRegistry for managing workflow lifecycle and message routing

Added the WorkflowRegistry class and supporting types to the bus-core package, establishing the central component responsible for tracking all managed workflows, mapping incoming messages to specific workflow instances via sticky attributes, and initializing workflow states. This new file structure includes the registry implementation, a handler function type definition, and comprehensive unit tests for workflow initialization and message handling.

packages/bus-core/src/workflow/registry · high confidence

Introduce workflow orchestration support in @node-ts/bus-core

Added a new workflow subsystem to @node-ts/bus-core, enabling long-running business processes (sagas) that coordinate multiple messages and persist state across distributed steps. The change introduces core types (WorkflowState, WorkflowStatus), a configuration API (WorkflowMapper) to map messages to handlers, and error classes for duplicate registrations. It also includes integration and unit tests verifying workflow lifecycle, concurrency safety, and state persistence.

packages/bus-core/src/workflow · high confidence

New domain-specific error classes for the message bus core

The message bus core now exposes three new, specific error types to improve error handling and debugging: \HandlerAlreadyRegistered\ is thrown when attempting to register a duplicate handler name; \HandlerDispatchRejected\ aggregates failures from multiple handlers during message dispatch; and \SystemMessageMissingResolver\ indicates a missing custom resolver for a system message. These classes provide structured error information and helpful context to assist in diagnosing bus-related issues.

packages/bus-core/src/handler/error · high confidence

Removals

Removed ApplicationBootstrap class and its export

The \ApplicationBootstrap\ class, which previously handled bus initialization and handler registration via Inversify dependency injection, has been removed from the codebase. This change eliminates the \application-bootstrap\ module and its associated export, indicating a shift away from the previous bootstrap mechanism for the bus application.

packages/bus-core/src/application-bootstrap · high confidence

Behavioural changes

Introduce typed message attributes and make Message abstract

The Message class is now abstract, requiring subclasses to define $name and $version. A new message-attributes module adds support for typed message attributes, including correlationId, attributes, and stickyAttributes, allowing for structured metadata transmission alongside message payloads.

packages/bus-messages/src · medium confidence

Project infrastructure and tooling updates

The project has migrated its package manager from Yarn to pnpm, evidenced by the addition of pnpm-workspace.yaml and the removal of lerna.json. Configuration files have been updated to support this shift, including a new .prettierrc.js, jest.config.ts, and tsconfig.json (extending @tsconfig/node18). Additionally, a LICENSE file (MIT) and .npmignore were added, while tslint.json was removed.

(repo-wide) · high confidence

Refactored transport interface and replaced in-memory queue implementation

The transport abstraction has been significantly expanded to support more complex messaging scenarios. The \Transport\ interface now includes lifecycle methods (\initialize\, \connect\, \disconnect\, \start\, \stop\, \dispose\) and requires a \CoreDependencies\ setup, allowing transports to interact with the handler registry and logger. The previous \MemoryQueue\ implementation was replaced with a new \InMemoryQueue\ that supports message attributes, dead-letter queue routing, and configurable retry strategies. Additionally, new configuration interfaces (\TransportConfiguration\, \InMemoryQueueConfiguration\) and a \TransportMessage\ wrapper were introduced to standardize how messages and their metadata are handled across different transport implementations.

packages/bus-core/src/transport · high confidence

Removal of Inversify-based workflow data model

The abstract \WorkflowData\ class, which previously relied on Inversify's \@injectable()\ decorator to manage workflow state and concurrency versioning, has been removed. This change eliminates the hard dependency on Inversify for workflow data definitions, simplifying the codebase by stripping out the framework-specific annotations and the associated export structure.

packages/bus-workflow/src/workflow · high confidence

Removal of Inversify-based workflow module

The Inversify-based workflow module and its associated symbols have been removed from the bus-workflow package. This eliminates the hard dependency on Inversify for workflow initialization, simplifying the module's structure by removing the ContainerModule class and related exports.

packages/bus-workflow/src · high confidence

Remove Inversify dependency and restructure core exports

The \bus-module.ts\ and \bus-symbols.ts\ files, which previously provided Inversify-based dependency injection and symbol definitions, have been removed. The \index.ts\ has been updated to remove exports for these files and instead explicitly export new modules including \workflow\, \error\, \container\, \logger\, \retry-strategy\, and \message-handling-context\, reflecting a shift away from the Inversify framework.

packages/bus-core/src · medium confidence

Simplified handler registration and added support for external message types

The handler registration API has been refactored to remove the dependency on Inversify and simplify how handlers are registered with the bus. The \HandlesMessage\ decorator and the \HandlerRegistry\ interface have been replaced with a simpler \register\ method and a new \handlerFor\ helper function. Additionally, the system now supports handling external, non-domain messages (such as AWS S3 events) by allowing custom resolvers and topic identifiers to be registered alongside standard message handlers.

packages/bus-core/src/handler · high confidence

Switched pre-commit hook to use pnpm

The pre-commit hook in .husky has been updated to use pnpm instead of yarn for running the format:precommit script. This change aligns the project's development workflow with the pnpm package manager, ensuring that code formatting checks during commits utilize the correct tooling.

.husky · medium confidence

Test coverage

Added test fixtures for the Postgres bus package; Added test utilities for workflow scenarios; Updated test fixtures and removed Inversify dependency.

Dependencies

Migrate from Yarn to Pnpm and update dependencies

The project has switched its package manager from Yarn to Pnpm, evidenced by the addition of a pnpm-lock.yaml file and the removal of yarn.lock files. This migration is accompanied by significant dependency updates across the monorepo, including upgrading tslib from 1.9.3 to 2.6.2/2.6.3, updating TypeScript to version 5.3.3/5.5.4, and updating various internal packages like @node-ts/bus-core and @node-ts/bus-messages to version 1.x. Additionally, the @node-ts/bus-workflow package has been renamed to @node-ts/bus-mongodb.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 60 → 53 (-6.6)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 93 → 95 (+1.5)
  • Architecture 84 → 55 (-28.8)
  • Maturity 57 → 53 (-4.3)
  • Readiness 56 → 53 (-3.7)
  • Security 54 → 50 (-4.0)

Resolved (26)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Low CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Low CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Low vulnerability: [GHSA redacted] (pnpm-lock.yaml)
  • Low vulnerability: [GHSA redacted] (pnpm-lock.yaml)
  • Medium CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Medium CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Medium CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Medium CVE: [GHSA redacted] (pnpm-lock.yaml)
  • …and 6 more

New (57)

  • BusInstance.dispatchMessageToHandler (cognitive 20) (packages/bus-core/src/service-bus/bus-instance.ts)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Documentation: no installation or build instructions (README.md)
  • End-of-life runtime: Node.js 14
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Low CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Low CVE: [GHSA redacted] (pnpm-lock.yaml)
  • …and 37 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

node-ts/bus was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 62546103926dae05be1eec25f72736077ae9c379 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.