quix-labs/flash
53.3
Weak · 21 September 2026
2.4k
lines of production code
Go
with TypeScript
4
measurements over time
What this system is
Features
Add PostgreSQL WAL logical replication driver
A new \wal\_logical\ driver is introduced to enable real-time database change tracking via PostgreSQL's logical replication. The implementation manages PostgreSQL replication slots and publications to stream Insert, Update, and Delete events to the application. It supports filtering events using configurable conditions and field selection, and includes a test suite to verify the driver's behavior against a PostgreSQL container configured for logical replication.
_drivers/wal\logical · high confidence
Introduce PostgreSQL trigger driver for database event listening
Added a new PostgreSQL trigger driver that listens for database events via PostgreSQL triggers and pg\_notify. The driver manages trigger lifecycle (create/drop) and parses incoming notifications to emit Flash events, supporting INSERT, UPDATE, and DELETE operations with optional condition-based filtering and soft-delete handling. Includes a basic test case for the driver.
drivers/trigger · high confidence
Introduce WAL-based database change tracking with driver architecture
The library now supports tracking real-time PostgreSQL changes via a new WAL (Write-Ahead Log) driver, enabling features like listening to specific columns and using logical replication. This is achieved through a new \Driver\ interface and \Client\ implementation that manages listeners and operations, alongside updated documentation and a \Makefile\ for testing. The change also includes a \docker-compose.yaml\ update to enable logical replication for the PostgreSQL service.
(repo-wide) · high confidence
New example applications for the Flash library
Added five new example applications in the \_examples directory to demonstrate various usage patterns of the Flash library. These include debug\_trace and trigger\_insert for basic insert operations, specific\_fields for filtering by columns, trigger\_all for handling all event types, parallel\_callback for concurrent processing, and development for profiling and complex listener configurations.
_\examples · high confidence
Removals
Removed client package and PostgreSQL trigger management code
The client package has been removed from the codebase. This includes the Client struct and its methods for connecting to PostgreSQL, as well as the Listener struct and its associated logic for managing database event triggers. Specifically, the files client.go, listeners.go, and queries.go, which contained the implementation for initializing and cleaning up database triggers for insert, update, delete, and truncate events, have all been deleted.
client · high confidence
Dependencies
Updated project dependencies and added new Go module files
Added new Go module files for the trigger and wal\_logical drivers, specifying dependencies on github.com/lib/pq, github.com/jackc/pgx/v5, and github.com/jackc/pglogrepl. Updated the root go.mod to include testcontainers-go and its dependencies, and upgraded golang.org/x/crypto to v0.22.0.
(dependencies) · medium confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 50 → 53 (+3.3)
- Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 95 (-5.4)
- Architecture 100 → 97 (-2.8)
- Maturity 45 → 45 (+0.0)
- Readiness 39 → 43 (+4.8)
- Security 54 → 65 (+11.2)
Resolved (22)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (drivers/wal_logical/go.mod)
- Critical CVE: [GHSA redacted] (drivers/wal_logical/go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (go.mod)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: GO-2024-2598 (drivers/trigger/go.mod)
- Medium CVE: GO-2026-5024 (drivers/trigger/go.mod)
- Medium CVE: GO-2026-5970 (drivers/wal_logical/go.mod)
- Medium vulnerability: GO-2026-5841 (go.mod)
- No exposed public API
- Test reliability not included
- The Quickstart link points to './installation' but no installation/doc exists, so readers cannot find step-by-step setup guidance. (docs/guide/what-is-flash.md)
- The VPTeamPage template loads data from './team.data' which never appears in the visible docs, so member names are hard-coded rather than coming from the team data source. (docs/team.md)
- …and 2 more
New (47)
- Critical CVE: [GHSA redacted] (drivers/wal_logical/go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (drivers/wal_logical/go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Documentation: no installation or build instructions (README.md)
- Duplicated block (11 lines × 2) (driver_testcase.go)
- Duplicated block (9 lines × 2) (drivers/trigger/queries.go)
- High CVE: [GHSA redacted] (go.mod)
- High IaC: WD-COMPOSE-0002 (docker-compose.yaml)
- High IaC: WD-COMPOSE-0002 (docker-compose.yaml)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: GO-2024-2598 (drivers/trigger/go.mod)
- Medium CVE: GO-2026-5024 (drivers/trigger/go.mod)
- Medium CVE: GO-2026-5970 (drivers/wal_logical/go.mod)
- Medium vulnerability: GO-2026-5841 (go.mod)
- …and 27 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
quix-labs/flash was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit e455efdc694e9c275d153ae0c8e8ef7d1375953c — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.