Skip to content
CAI
Software that uses CAICheck a score

snatalenko/node-cqrs

68.1

Adequate · 21 September 2026

9.5k

lines of production code

TypeScript

with JavaScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

node-cqrs is a TypeScript CQRS and Event Sourcing framework for Node.js that provides core abstractions for aggregates, sagas, and projections. It supports distributed architectures through optional integrations with MongoDB, Redis, and RabbitMQ for durable storage, locking, and messaging. The system also includes specialized modules for running CPU-intensive projections in worker threads and persisting data via SQLite, alongside in-memory implementations for testing.

How it got here

2015–2025 — TypeScript rewrite and infrastructure expansion

17 changes.

The project was rewritten from JavaScript to TypeScript, introducing a comprehensive CQRS framework with base classes for aggregates, sagas, and projections. This period also saw the addition of diverse storage and messaging adapters, including in-memory, SQLite, and RabbitMQ implementations, alongside extensive unit and integration testing.

2026 — Worker threads and storage backends

16 changes.

This period focused on introducing worker-thread projections to offload CPU-intensive work and expanding the project's storage capabilities with new MongoDB, Redis, and SQLite integrations. Comprehensive unit and integration tests were added to validate the new threading mechanisms, distributed locking features, and database connectors. The release also included an expanded example suite and a rebuilt Jekyll-based documentation site.

Features

Add MongoDB-backed event storage and persistent views

Introduces a new MongoDB integration for node-cqrs, providing \MongoEventStorage\ for durable event sourcing with optimistic concurrency control (throwing \ConcurrencyError\ on conflicts) and \MongoObjectView\/\AbstractMongoObjectProjection\ for persistent read models. The module includes \MongoViewLocker\ and \MongoEventLocker\ to manage distributed locking for schema migrations and event processing, along with \MongoObjectStorage\ for key-value document storage with version-based retries. Configuration is handled via \mongoDbFactory\ and \viewModelMongoDbFactory\ container keys, with automatic exit cleanup for database connections.

src/mongodb · high confidence

Added utility functions for SQLite event ID handling

New utility functions have been added to the SQLite module to support event storage: \bufferToGuid\ converts a Buffer to a hex string, \guid\ converts a string identifier to a Buffer for BLOB storage, and \getEventId\ generates or retrieves an event ID, using MD5 hashing of the event content if no ID is assigned. These utilities are exported via the utils index file.

src/sqlite/utils · high confidence

Custom changelog generation and obsolete tag cleanup scripts

The repository now includes a custom changelog generation script (scripts/changelog) that replaces the previous ESLint preset, allowing users to generate release notes based on commit tags (e.g., Features, Fixes, Security) using Handlebars templates. Additionally, a new script (scripts/cleanup\_obsolete\_tags.sh) has been added to automatically identify and remove superseded pre-release tags (alpha, beta, rc) when a higher-priority tag (such as a release or RC) is published, keeping the remote tag history clean.

scripts · high confidence

Expanded example suite with new storage backends, browser support, and saga patterns

The examples directory has been significantly expanded to demonstrate a wider range of capabilities. New examples include browser-based smoke tests (\examples/browser\), MongoDB-backed event storage and view projections (\examples/mongodb-eventstore\, \examples/mongodb-views\), Redis-backed projections (\examples/redis\), and SQLite-backed projections (\examples/sqlite\). Saga orchestration is now covered with both simple (\examples/sagas-simple\) and overlapping multi-saga scenarios (\examples/sagas-overlaps\), alongside a new OpenTelemetry tracing example (\examples/telemetry\). The suite also provides CommonJS (\examples/user-domain-cjs\) and framework-free (\examples/user-domain-framework-free\) implementations, as well as a worker-thread projection example (\examples/workers-projection\).

examples · high confidence

Experimental Redis-backed projection views with distributed locking

The \src/redis\ module introduces a new experimental capability for \node-cqrs\ projections to persist state in Redis, enabling projections to survive process restarts and share state across multiple instances. This includes \AbstractRedisProjection\ for defining projections, \RedisView\ for managing view state, and \RedisObjectStorage\ for standalone key-value storage with optimistic concurrency control. To coordinate distributed operations, the module provides \RedisViewLocker\ (preventing concurrent projection rebuilds) and \RedisEventLocker\ (preventing duplicate event processing), both using Redis keys with TTLs and Lua scripts for atomic state transitions. The module also adds \AbstractRedisAccessor\ to manage Redis client lifecycle and connection initialization safely.

src/redis · high confidence

Initial release of the TypeScript CQRS framework

The library has been rewritten from JavaScript to TypeScript, introducing a complete set of base classes for defining Aggregates, Projections, and Sagas, along with supporting infrastructure such as the EventStore, EventDispatcher, and DI container builder. This release adds support for OpenTelemetry tracing, configurable concurrency error handling (including an 'ignore' option), and automatic event ID generation via a dispatch pipeline processor. The legacy JavaScript implementations have been removed in favor of the new typed architecture.

src · high confidence

Introduce RabbitMQ transport for cross-process command and event delivery

This change adds a new RabbitMQ integration to node-cqrs, enabling commands and events to be published and subscribed to via a RabbitMQ broker instead of in-memory buses. It introduces \RabbitMqGateway\ for managing connections and subscriptions, \RabbitMqEventBus\ for fanout event distribution (with optional durable queues and single-active-consumer support), and \RabbitMqCommandBus\ for point-to-point command delivery. The implementation supports configuration for exchange names, queue durability, handler timeouts, concurrent processing limits, dead-letter queues, and message TTLs, and includes automatic reconnection and graceful shutdown handling.

src/rabbitmq · high confidence

Introduce async SQLite worker for non-blocking database queries

This change adds a new \sqlite-workers\ module that offloads SQLite read operations to a background Node.js worker thread, preventing main-thread blocking. It provides a \SqliteWorkerProxy\ class that exposes asynchronous \all\, \get\, and \run\ methods, as well as a \prepare\ method for reusable statement handles via \AsyncSqliteStatement\. The implementation uses Comlink for inter-process communication and supports two database initialization modes: opening a standard read-only database file via \dbLocation\ with optional PRAGMAs, or using a custom factory function via \dbFactoryLocation\ for advanced setup. Shared worker utility functions for creating and managing worker threads have been moved to \src/shared/worker-utils\ to support this architecture.

src/sqlite-workers · high confidence

Introduce in-memory infrastructure components for testing and development

This change adds a new set of in-memory implementations for core infrastructure interfaces, including \InMemoryEventStorage\, \InMemoryMessageBus\, \InMemorySnapshotStorage\, \InMemoryView\, and \InMemoryLock\. These components provide lightweight, transient storage and messaging capabilities that reset on application restart, making them suitable for unit tests, integration tests, and local development environments without requiring external database or message broker dependencies. The \InMemoryEventStorage\ supports event querying, concurrency error handling, and OpenTelemetry tracing, while the \InMemoryMessageBus\ handles command and event dispatching with optional queue support.

src/in-memory · high confidence

Introduce worker-thread projections for CPU-intensive workloads

Added a new \src/workers\ module that allows projections to run their event handlers and view logic inside a Node.js worker thread, keeping the main thread responsive. The \AbstractWorkerProjection\ base class and \WorkerProxyProjection\ handle the threading and remote procedure calls via Comlink, while the restore phase now batches events to reduce overhead. This enables users to offload heavy projection work to separate threads while maintaining the same view API.

src/workers · high confidence

New Jekyll-based documentation site with dark mode and structured navigation

The documentation site has been rebuilt using Jekyll, introducing a new layout that includes a responsive header with a dark/light theme toggle, a sidebar with grouped navigation (primary pages, modules, and resources), and automatic table-of-contents generation. The site now supports SEO metadata, Open Graph tags, and links to GitHub source files and examples, providing a more structured and accessible reading experience for the node-cqrs documentation.

.jekyll · high confidence

New SQLite-backed event storage and projection views

This change introduces a new \src/sqlite\ module providing durable, SQLite-based storage for the CQRS event stream and read-model views. Users can now register \SqliteEventStorage\ to persist events locally (primarily for development and testing) and use \AbstractSqliteObjectProjection\ or \AbstractSqliteView\ to build SQLite-backed read models with automatic schema versioning, restore locking, and last-processed-event tracking. The implementation supports both synchronous and asynchronous database initialization via \viewModelSqliteDb\ or \viewModelSqliteDbFactory\, and includes built-in concurrency checks and event locking to ensure data integrity during projection updates.

src/sqlite · high confidence

New utility library for locking, cloning, and validation

The \src/utils\ module has been expanded with a suite of new utilities to support core infrastructure. A new \Lock\ class and \LockLease\ provide named and global locking with support for the \using\ keyword (via \Symbol.dispose\), while a \Deferred\ class enables manual promise resolution. Object handling is improved with a \clone\ function that falls back to JSON serialization when \structuredClone\ is unavailable, and a \MapAssertable\ class that supports lazy factory initialization and automatic cleanup via usage counters. Validation and introspection are standardized through a comprehensive \assert\ module (covering types like strings, arrays, and domain-specific interfaces like \IMessage\), alongside utilities for extracting error details, identifying class names, and discovering message handler names on observer instances.

src/utils · high confidence

Behavioural changes

Introduce worker projection interfaces for batched restoration and proxy extensibility

New TypeScript interfaces are added to define the contract for worker-side projections and their proxy counterparts. IWorkerProjection now includes a \_projectBatch method to deliver events in batches during the restoring phase, optimizing performance by reducing Comlink roundtrips, and exposes getLastProjectedEvent to retrieve the last projected event. Additionally, IProxyProjection and its associated type definitions allow for extending the WorkerProxyProjection via a custom proxy type factory, enabling more flexible worker instantiation patterns.

src/workers/interfaces · high confidence

New CQRS interface contracts and concurrency control options

This release introduces a comprehensive set of TypeScript interfaces for the CQRS architecture, defining core contracts for Aggregates, Sagas, Commands, Events, and Projections. A key behavioral addition is the support for an 'ignore' option in concurrency error handling, allowing aggregates to force-dispatch immediately on conflict rather than retrying. The interfaces also formalize the event dispatch pipeline with origin-based routing, introduce OpenTelemetry span metadata for tracing, and expose projection restore promises on the DI container to manage async initialization.

src/interfaces · high confidence

Optimized next-cycle scheduling for improved performance

The in-memory utility for deferring execution to the next event loop cycle now uses setImmediate in Node.js environments instead of setTimeout, falling back to setTimeout only in browsers. This change reduces performance overhead when scheduling asynchronous operations, resulting in faster event processing for users relying on the in-memory storage layer.

src/in-memory/utils · high confidence

Project renamed to node-cqrs with Apache-2.0 license and modernized build tooling

The project has been renamed from cqrs-framework to node-cqrs, and the license has been changed to Apache-2.0. The build system now supports ESM, CJS, and browser bundles, with TypeScript targets updated to ES2022. ESLint configuration has been migrated from the legacy .eslintrc format to the new flat config (eslint.config.mjs), and the test runner is now Jest. Documentation has been restructured with a new CONTRIBUTING.md, and symlinks (AGENTS.md, CLAUDE.md) point to it. The package now requires Node.js 16+.

(repo-wide) · high confidence

Test coverage

Added Jest unit tests for core CQRS components; Added integration tests for MongoDB-backed storage and locking components; Added integration tests for Redis locking and object storage; Added integration tests for SqliteView performance and correctness; Added integration tests for worker projection proxy behavior; Added test fixtures for worker projection integration testing; Added unit tests for MongoDB event storage and exit cleanup; Added unit tests for RabbitMQ bus configuration and gateway behavior; Added unit tests for Redis-backed projection components; Added unit tests for SQLite event sourcing components; Added unit tests for SQLite worker proxy and runner; Added unit tests for in-memory infrastructure components; Added unit tests for utility functions; Integration tests for RabbitMQ messaging components; Removed legacy JavaScript EventStore tests and added TypeScript test configuration.

Dependencies

Initial release of node-cqrs toolkit with multi-format builds and optional adapters

The project is introduced as 'node-cqrs' (v1.2.1), a TypeScript CQRS/Event Sourcing toolkit for Node.js 16+. It provides ESM, CJS, and browser builds with specific entry points for core functionality, workers, RabbitMQ, SQLite, Redis, and MongoDB. The package includes runtime dependencies for async utilities and DI, while dev dependencies cover testing (Jest), linting (ESLint), and build tools (Rollup, TypeScript). Optional peer dependencies allow users to integrate OpenTelemetry, RabbitMQ, SQLite, Comlink, Redis, and MongoDB as needed.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 62 → 68 (+5.9)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 96 → 94 (-2.1)
  • Architecture 89 → 95 (+5.8)
  • Maturity 62 → 67 (+5.3)
  • Readiness 53 → 58 (+5.7)
  • Security 67 → 83 (+16.0)
  • Accessibility 82 → 82 (+0.0)

Resolved (24)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • LLM evaluation failed
  • Low CVE: [GHSA redacted] (package-lock.json)
  • Medium CVE: [GHSA redacted] (package-lock.json)
  • Medium CVE: [GHSA redacted] (package-lock.json)
  • …and 4 more

New (46)

  • AggregateCommandHandler.execute (cognitive 21) (src/AggregateCommandHandler.ts)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Dependency advisory scan runs only on code events
  • Documentation: no installation or build instructions (README.md)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 26 more

Changes since last survey

  • 8 commits — 7 feature/other, 1 fixes

By area

  • (root) — 5 commits
  • (repo) — 1 commit
  • src/rabbitmq — 1 commit
  • src/workers — 1 commit

Notable commits

  • fix: Fix: Avoid logging error on intentional worker termination
  • change: 1.2.0
  • change: 1.2.0-beta.2
  • change: 1.2.1
  • change: Build: Use Jekyll to build documentation from README's
  • change: Chore: Improve log output on rabbitmq message handler timeout
  • change: Create CNAME
  • change: Merge branch 'beta'

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

snatalenko/node-cqrs was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 6dbb502623202a70f28bf6f95204d24aef674b85 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.