patchlevel/event-sourcing-bundle
63.2
Adequate · 21 September 2026
2.6k
lines of production code
PHP
primary language
4
measurements over time
What this system is
This system is a Symfony bundle that integrates the Patchlevel event-sourcing library, providing infrastructure for command and query handling, aggregate management, and event storage. It automates service registration through compiler passes and offers deep integration with the Symfony ecosystem, including profiler collectors, database connection factories, and request listeners for subscription management. The codebase focuses on bridging event-sourcing patterns with modern Symfony features while maintaining robust testing and static analysis tooling.
How it got here
2021 — Symfony 6+ and Event Sourcing 3.0+ integration
6 changes.
The project underwent a major architectural overhaul to support Event Sourcing 3.0+ and Symfony 6.4/7/8, introducing a new dependency injection layer with automated compiler passes for handlers and repositories. This period also included the addition of query bus support via Symfony Messenger, a shift to PHPStan for static analysis, and comprehensive test coverage for the new integration components.
2022–2024 — Symfony integration and tooling
7 changes.
This period focused on deepening Symfony integration by adding Web Profiler collectors for event sourcing visibility and implementing request listeners for automatic subscription management. It also introduced a standardized Doctrine DBAL connection factory and added documentation scripts to keep code examples synchronized with the source.
2025–2026 — Symfony integration and test coverage
5 changes.
This period focused on integrating Symfony Command Bus infrastructure, including message handling and parameter resolution, while adding comprehensive unit tests for request listeners, normalizers, and the command bus. It also addressed a critical data loss bug in the deprecated store migration command by ensuring buffered messages are correctly persisted.
Features
Add Doctrine DBAL connection factory with DSN scheme mapping
A new DbalConnectionFactory class has been introduced to standardize how database connections are established from connection URLs. It leverages Doctrine's DsnParser with a predefined scheme-to-driver mapping (covering databases like MySQL, PostgreSQL, SQLite, and SQL Server) to automatically resolve the correct driver, simplifying connection configuration for users.
src/Doctrine · high confidence
Add Symfony Command Bus integration
Introduces Symfony-specific implementations for the command bus infrastructure: SymfonyCommandBus wraps Symfony Messenger's HandlerFailedException to unwrap the root cause for clearer error reporting, and SymfonyParameterResolver resolves command handler arguments by fetching them from the service container using a method-name-based prefix.
src/CommandBus · high confidence
Add query bus support and register compiler passes
The bundle now includes a \SymfonyQueryBus\ implementation that delegates query dispatching to Symfony Messenger, enabling users to execute queries via the event sourcing query bus. Additionally, the main bundle class has been updated to register several compiler passes (including \QueryHandlerCompilerPass\, \CommandHandlerCompilerPass\, and others) with specific priorities to ensure proper service resolution and configuration during container compilation.
src · high confidence
Added scripts to extract and inject PHP code examples in documentation
Two new executable scripts, \bin/docs-extract-php-code\ and \bin/docs-inject-php-code\, have been added to the \bin\ directory to manage PHP code snippets within Markdown documentation. The extraction script scans Markdown files in the \docs\ directory, identifies fenced code blocks tagged as \php\, and writes the code content into separate \.php\ files in a \docs\_php\ directory. The injection script reverses this process by reading those extracted PHP files and replacing the corresponding code blocks in the original Markdown files, ensuring that the documentation always reflects the latest code examples.
bin · high confidence
New Symfony Web Profiler integration for Event Sourcing
A new collector has been added to the Symfony Web Profiler, providing visibility into the event-sourcing layer directly in the developer toolbar and profiler interface. Users can now see a count of published messages, defined aggregates, and events in the toolbar, and access detailed tables within the profiler panel that list message names, headers, and event/aggregator class names. This includes a custom SVG icon for the toolbar and specific styling to highlight class names in the profiler view.
src/Resources · high confidence
New request listeners for automatic subscription setup and file-change rebuilds
Two new Symfony kernel request listeners have been added to the \RequestListener\ directory to automate subscription lifecycle management during web requests. \AutoSetupListener\ automatically sets up subscriptions that are in the 'New' status on the main request, while \SubscriptionRebuildAfterFileChangeListener\ detects changes to subscriber file modification times and triggers a rebuild (remove, setup, boot) for affected subscriptions. Both listeners support an \excludeUrl\ configuration to skip processing for specific routes, such as internal Symfony URLs or health checks.
src/RequestListener · high confidence
Symfony Profiler integration for Event Sourcing
A new data collector has been added to the Symfony Profiler, allowing users to inspect event-sourcing details directly in the web debug toolbar. This includes viewing the list of dispatched messages with their event classes and headers, as well as listing registered aggregate roots and event types. The implementation uses a decorator event bus to capture messages during request handling without altering the core event dispatching logic.
src/DataCollector · high confidence
Behavioural changes
Add factory classes and reset listener for Symfony container compatibility
To support static dumping of the Symfony container, this change introduces factory classes for components with value-object dependencies (GapResolverMessageLoaderFactory) and a static in-memory subscription store (StaticInMemorySubscriptionStoreFactory). Additionally, a ResetServicesListener is added to reset services on worker running events, ensuring compatibility with Symfony 8.1's ResetInterface requirements.
src/Subscription · high confidence
Deprecated store migration command with message buffering fix
The \event-sourcing:store:migrate\ command in \src/Command/StoreMigrateCommand.php\ is now deprecated (since v3.15.0) and will be removed in v4.0.0; users should migrate to the command provided by the \patchlevel/event-sourcing\ package. This command migrates events from one store to another using configurable translators and a buffer size (default 1,000). A behavioral fix ensures that any remaining messages in the buffer after the main loop are correctly saved to the new store, preventing data loss when the total message count is not an exact multiple of the buffer size.
src/Command · high confidence
Major event-sourcing architecture overhaul with new compiler passes and Symfony integration
The dependency injection layer has been completely rewritten to support the event-sourcing 3.0+ architecture. This introduces a suite of new compiler passes (CommandHandler, QueryHandler, Repository, Hydrator, SubscriberGuard, etc.) that automate service registration for aggregate handlers, repositories, and subscribers based on metadata. The bundle now supports multiple event bus types (default, Symfony Messenger, PSR-14) and provides a Symfony-specific event bus implementation. Configuration has been expanded to support stream stores, in-memory stores, subscription engine options (retry strategies, gap detection, auto-setup), and cryptographic features. New normalizers for Symfony UIDs and DatePoint types are included, along with an AggregateRootId value resolver for controllers.
src/DependencyInjection · high confidence
Shift to PHPStan for static analysis and update testing tooling
The project has replaced Psalm with PHPStan as its primary static analysis tool, removing the psalm.xml configuration and adding a PHPStan baseline to manage existing issues. The Makefile has been updated to reflect this change, removing the psalm target and adding targets for PHPStan and mutation testing via Infection. Additionally, the PHPUnit configuration has been modernized to use a cache directory and source filtering, and the coding standards configuration now includes the tests directory in its scope.
(repo-wide) · high confidence
Test coverage
Added test fixtures for event-sourcing bundle components; Added unit tests for EventSourcingCollector; Added unit tests for RequestListener components; Added unit tests for Symfony integration components; Added unit tests for SymfonyCommandBus; Added unit tests for normalizers and type guesser.
Dependencies
Major dependency upgrade to Symfony 6.4/7/8 and Event Sourcing 3.19
This release performs a significant dependency overhaul, dropping support for PHP 7.4 and 8.0/8.1 in favor of PHP 8.2–8.5. The core \patchlevel/event-sourcing\ library is upgraded to version 3.19.1, and the bundle now requires Symfony 6.4, 7.0, or 8.0 components (replacing the previous 4.4/5.1 constraints). Development tooling has also been updated, including PHPUnit to 11.5.45, PHPStan to 2.1.32, and Infection to 0.32.0, while adding new suggested packages for admin UI and static analysis integration.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 64 → 63 (-0.5)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 93 → 95 (+1.2)
- Architecture 96 → 90 (-6.1)
- Maturity 58 → 53 (-5.3)
- Readiness 69 → 67 (-2.5)
- Security 57 → 71 (+14.0)
- Accessibility 74 (new)
Resolved (27)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 7 more
New (69)
- ClassTooLong: PatchlevelEventSourcingExtension (src/DependencyInjection/PatchlevelEventSourcingExtension.php)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 49 more
Changes since last survey
- 17 commits — 17 feature/other, 0 fixes
By area
- (root) — 15 commits
- (repo) — 1 commit
- .github/workflows — 1 commit
Notable commits
- change: Improve docs deployement to minimise CI times. * on versioned branches only trigger deploy if a changed landed in the docs * on release always trigger deploy
- change: Lock file maintenance
- change: Lock file maintenance
- change: Lock file maintenance
- change: Lock file maintenance
- change: Lock file maintenance
- change: Lock file maintenance
- change: Lock file maintenance
- change: Lock file maintenance
- change: Lock file maintenance
- change: Lock file maintenance
- change: Lock file maintenance
- change: Lock file maintenance
- change: Lock file maintenance
- change: Lock file maintenance
- change: Lock file maintenance
- change: Merge pull request #335 from patchlevel/improve-deploy
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
patchlevel/event-sourcing-bundle was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 986123969f609be37df89ecbc9b54f63af9390f2 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.