Skip to content
CAI
Software that uses CAICheck a score

slashdotdash/conduit

50.0

Adequate · 21 September 2026

2.8k

lines of production code

Elixir

primary language

7

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This is an Elixir-based web application that implements a blog and social networking platform using an event-sourced architecture. It leverages Commanded and EventStore to manage user accounts, articles, comments, and social interactions like favoriting and following. The system exposes a RESTful API for content management and user authentication via JWT tokens, backed by a PostgreSQL database for read-optimized projections.

Features

Add blog feature with article, comment, and author management

Introduces a new blog domain including the ability to publish, favorite, and comment on articles, as well as follow and unfollow authors. The change adds aggregate roots for articles, authors, and comments, along with their respective commands, events, and Ecto projections. It also includes query modules for listing, filtering, and retrieving articles and comments, and a slugger for generating unique article slugs. The blog module serves as the boundary for the blog system, exposing methods to create authors, publish articles, and manage favorites and followers.

lib/conduit/blog · high confidence

Introduce JWT-based authentication with Guardian

Added new authentication logic in lib/conduit/auth, including a password verification module using Bcrypt and a Guardian-based JWT serialization module. Users can now authenticate via email and password, receiving a JWT token for subsequent requests.

lib/conduit/auth · high confidence

Introduces RESTful API endpoints for articles, comments, favorites, and user profiles

The application now exposes a comprehensive set of API endpoints for managing content and user interactions. Users can retrieve, create, and manage articles, including a personalized feed and comment threads. The update also adds support for favoriting/unfavoriting articles, following/unfollowing other users, and viewing user profiles. Authentication is handled via JWT tokens using the Guardian library, with new controllers and views for articles, comments, favorites, profiles, tags, and user sessions. Error handling and JSON serialization are standardized across all endpoints.

_lib/conduit\web · high confidence

Behavioural changes

Added database schema for blog articles, comments, and user interactions

The application's database schema has been extended to support a full-featured blog. New tables have been created for blog articles, authors, comments, and tags, along with supporting tables for user favorites and article feeds. This enables users to create and read blog posts, leave comments, follow other authors, and view personalized content feeds.

priv · high confidence

Added middleware and validators for command uniqueness and validation

Users will now experience stricter validation on commands, with duplicate checks enforced via a new uniqueness middleware and validation rules for string and UUID fields. This ensures that commands are checked for uniqueness constraints before processing, preventing duplicate entries and ensuring data integrity.

lib/conduit/support · high confidence

Introduce command-based user registration and profile management

The accounts context now uses a command-based architecture to handle user registration and updates. Users can register with a username, email, and password, which are validated for uniqueness and format, and passwords are hashed before storage. The system dispatches domain events (e.g., UserRegistered, UsernameChanged) to update a read-optimized user projection, enabling efficient lookups by username or email. This change shifts the accounts module from a simple CRUD interface to an event-sourced model where commands trigger state changes and events, improving consistency and auditability for user data.

lib/conduit/accounts · high confidence

JWT authentication support and code formatting updates

The application now supports JWT-based authentication, evidenced by the import of the ConduitWeb.JWT module in the web layer and the removal of the Conduit module's documentation. Additionally, the codebase has been updated to Commanded and EventStore v1.0.0, and the code has been formatted using \mix format\.

lib · medium confidence

Migrate to Event Sourcing with Commanded and EventStore

The application has been upgraded to use Event Sourcing via Commanded and EventStore, introducing a new event store alongside the existing read store. Configuration files now define settings for the event store, Commanded, and related adapters, and the read store database has been renamed to explicitly distinguish it from the new event store. Additionally, Guardian is configured for authentication, and the Phoenix JSON library is set to Jason.

config · high confidence

Migrated to Commanded for command handling and EventStore for persistence

The application now uses Commanded to manage commands and aggregate state, replacing the previous approach. A new router (Conduit.Router) is introduced to dispatch commands like RegisterUser, PublishArticle, and CommentOnArticle to their respective aggregates (User, Article, Comment, etc.). The application's supervision tree has been updated to include the Commanded application, the EventStore, and specific supervisors for Accounts and Blog contexts. Additionally, the Ecto repository is now explicitly configured to use the Postgres adapter.

lib/conduit · medium confidence

Updated project scaffolding and documentation

The repository was initialized with a new .formatter.exs configuration for Elixir code formatting, a .travis.yml file for CI/CD, and an MIT LICENSE. The README was significantly expanded to include detailed setup instructions for the Conduit application, specifying requirements for Elixir (v1.6+), PostgreSQL, and the Event Store, alongside links to front-end implementations.

(repo-wide) · high confidence

Test coverage

Added integration tests for blog and author features; Added integration tests for user registration and updates; Added unit test for user registration; Added unit tests for article and comment aggregates; Added web controller tests for the application's core features; Formatting updates to error view tests; Refactored test infrastructure to use event store reset and factories.

Dependencies

Upgrade to Phoenix 1.5, Commanded 1.1, and EventStore 1.1

The project dependencies have been updated to use Phoenix 1.5, Commanded 1.1, EventStore 1.1, and Guardian 1.2, alongside various other library upgrades. This update brings modern versions of the core web framework, the CQRS/ES infrastructure, and authentication, ensuring compatibility with Elixir 1.6+ and providing access to the latest features and fixes in these libraries.

(dependencies) · medium confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 51 → 50 (-1.2)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (-0.3)
  • Architecture 100 → 89 (-10.7)
  • Maturity 35 → 35 (+0.0)
  • Readiness 34 → 39 (+5.4)
  • Security 84 → 71 (-13.8)
  • Domain Modelling 100 → 100 (+0.0)
  • Event Sourcing 100 → 100 (+0.0)

Resolved (14)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: [GHSA redacted] (mix.lock)
  • No exposed public API
  • Test reliability not included
  • The prerequisites list (Git/Elixir/PostgreSQL) is a bare dependency requirement and does not mention the Phoenix version needed, which could break installs on newer versions. (README.md)
  • dormant codebase — no living knowledge left to concentrate

New (32)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (5 lines × 2) (lib/conduit/accounts/validators/unique_email.ex)
  • Duplicated block (5 lines × 2) (lib/conduit/blog/queries/feed_articles.ex)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • Leaked secret: signing-key (config/config.exs)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: [GHSA redacted] (mix.lock)
  • No ADRs found
  • No SBOM
  • No artifact signing
  • No build provenance
  • No dependency advisory monitoring
  • Outdated: commanded
  • Outdated: commanded_ecto_projections
  • …and 12 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

slashdotdash/conduit was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 8721f72c75ae702992283e05ac9b992495274458 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.