synadia-labs/rita
76.9
Strong · 21 September 2026
3k
lines of production code
Go
primary language
4
measurements over time
What this system is
Rita is a Go library for event sourcing that leverages NATS JetStream as its underlying event store. It provides core capabilities for managing event streams, including optimistic concurrency control, state evolution through deciders, and durable side-effect processing via reactors. The system supports flexible data handling through a pluggable serialization framework and type registry, enabling transparent marshaling of various data formats.
Features
Add clock abstraction, ID generators, and protobuf types
This change introduces foundational internal packages: a \clock\ package providing a \Clock\ interface to abstract system time (defaulting to \time.Now\), an \id\ package offering two strategies for generating unique identifiers via UUID and NUID, and an \internal/pb\ package containing the generated Go code and proto definition for a test message type \A\ with helper serialization methods.
clock, id, internal · high confidence
Initial release of Rita, a NATS JetStream-based event sourcing library
Introduces the Rita library, providing an event store backed by NATS JetStream with support for type-registered or binary event serialization, optimistic concurrency control via sequence expectations, and state evolution through Decider and Evolver interfaces. The release includes a Manager for creating and configuring event stores, a Reactor system for durable, side-effect-driven event consumption with configurable backoff and acknowledgment policies, and a Model wrapper for thread-safe state management. It also adds comprehensive test coverage for event appending, replay, reactor binding, and concurrent model evolution.
(repo-wide) · high confidence
Introduce type registry for transparent serialization
The new \types.Registry\ component enables automatic marshaling and unmarshaling of Go structs to and from byte slices using pluggable codecs. It maintains a mapping between type names and struct types, validates that registered types are serializable (e.g., pointer to struct), and supports optional validation via the \Validator\ interface. Users can now register custom types and use the registry to handle serialization logic transparently across the application.
types · high confidence
Introduction of pluggable binary codec implementations
The codec package now provides a unified interface for serializing and deserializing data, featuring four distinct implementations: JSON, Binary, MessagePack, and Protocol Buffers. The Binary codec specifically supports native Go types implementing encoding.BinaryMarshaler/BinaryUnmarshaler as well as raw byte slices, ensuring safe copying during unmarshaling. These codecs are automatically registered in a global map upon initialization, allowing users to select their preferred serialization format by name.
codec · high confidence
New runnable pattern examples for event sourcing and reactive processing
Added a suite of runnable Go examples in the \examples/\ directory that demonstrate core Rita capabilities. The \quickstart\ example shows basic event appending and state reconstruction. \deciders\ illustrates the command-decision pattern with invariant validation and thread-safe model evolution. \optimistic-concurrency\ demonstrates handling sequence conflicts and retries. \projection\ shows continuous state updates using the \Watch\ API. \reactor\ and \reactor-lifecycle\ cover creating, binding, updating, and deleting durable reactors for side-effect processing. Finally, \tenancy\ demonstrates multi-tenant isolation using scoped event store handles.
examples · high confidence
New test utilities for time control, assertions, and NATS server management
The testutil package now provides three new helper components to streamline testing. A deterministic Clock allows tests to control time progression via a configurable unit and supports manual time advancement through a new Add() method. An Is assertion helper simplifies test verification with methods for checking equality, error types, absence of errors, and boolean conditions. Additionally, NATS server management is standardized with functions to start a JetStream-enabled server, with optional support for specifying a custom JetStream domain.
testutil · high confidence
Dependencies
Initial Go module definition for Rita
The project now includes a go.mod file establishing the module as github.com/synadia-labs/rita, targeting Go 1.25.0. This introduces dependencies for NATS connectivity (nats-server v2.12.6, nats.go v1.53.1), JetStream extensions (orbit.go/jetstreamext v0.3.2), serialization (msgpack v5.4.1, protobuf v1.36.12), and utility libraries (uuid, go-cmp, testify).
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 71 → 77 (+6.3)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 93 → 97 (+3.2)
- Architecture 100 → 100 (+0.0)
- Maturity 60 → 62 (+2.2)
- Readiness 78 → 83 (+5.0)
- Security 75 → 98 (+23.2)
Resolved (23)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (go.mod)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (11 lines × 2) (examples/reactor-lifecycle/main.go)
- Duplicated block (12 lines × 2) (eventstore.go)
- Duplicated block (13 lines × 2) (examples/reactor-lifecycle/main.go)
- Duplicated block (14 lines × 2) (examples/projection/main.go)
- Duplicated block (14 lines × 3) (examples/deciders/main.go)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- LLM evaluation failed
- Medium CVE: GO-2025-3955 (go.mod)
- Medium CVE: GO-2026-5024 (go.mod)
- Medium vulnerability: GO-2026-5841 (go.mod)
- No exposed public API
- Off-boarding risk: anonymized user #1
- Test reliability not included
- …and 3 more
New (26)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (13 lines × 2) (eventstore.go)
- Duplicated block (15 lines × 2) (examples/reactor-lifecycle/main.go)
- Duplicated block (15 lines × 2) (examples/reactor-lifecycle/main.go)
- Duplicated block (15–17 lines × 2) (examples/reactor-lifecycle/main.go)
- Duplicated block (15–17 lines × 4) (examples/deciders/main.go)
- Duplicated block (15–18 lines × 5) (examples/deciders/main.go)
- Duplicated block (18–20 lines × 2) (examples/projection/main.go)
- Duplicated block (8 lines × 2) (examples/reactor-lifecycle/main.go)
- Duplicated block (9 lines × 2) (examples/deciders/main.go)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: GO-2025-3955 (go.mod)
- Medium vulnerability: GO-2026-5932 (go.mod)
- Medium: security finding (details withheld)
- Members sharing a duplicated core (4 members, 50+ identical tokens) (examples/deciders/main.go)
- …and 6 more
Changes since last survey
- 1 commits — 1 feature/other, 0 fixes
By area
- (root) — 1 commit
Notable commits
- change: CHORE: dependency updates
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
synadia-labs/rita was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 05ffa420324fc154d6fe23be057f1eb781efdbd0 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.