Skip to content
CAI
Software that uses CAICheck a score

synadia-labs/rita

76.9

Strong · 21 September 2026

3k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Rita is a Go library for event sourcing that leverages NATS JetStream as its underlying event store. It provides core capabilities for managing event streams, including optimistic concurrency control, state evolution through deciders, and durable side-effect processing via reactors. The system supports flexible data handling through a pluggable serialization framework and type registry, enabling transparent marshaling of various data formats.

Features

Add clock abstraction, ID generators, and protobuf types

This change introduces foundational internal packages: a \clock\ package providing a \Clock\ interface to abstract system time (defaulting to \time.Now\), an \id\ package offering two strategies for generating unique identifiers via UUID and NUID, and an \internal/pb\ package containing the generated Go code and proto definition for a test message type \A\ with helper serialization methods.

clock, id, internal · high confidence

Initial release of Rita, a NATS JetStream-based event sourcing library

Introduces the Rita library, providing an event store backed by NATS JetStream with support for type-registered or binary event serialization, optimistic concurrency control via sequence expectations, and state evolution through Decider and Evolver interfaces. The release includes a Manager for creating and configuring event stores, a Reactor system for durable, side-effect-driven event consumption with configurable backoff and acknowledgment policies, and a Model wrapper for thread-safe state management. It also adds comprehensive test coverage for event appending, replay, reactor binding, and concurrent model evolution.

(repo-wide) · high confidence

Introduce type registry for transparent serialization

The new \types.Registry\ component enables automatic marshaling and unmarshaling of Go structs to and from byte slices using pluggable codecs. It maintains a mapping between type names and struct types, validates that registered types are serializable (e.g., pointer to struct), and supports optional validation via the \Validator\ interface. Users can now register custom types and use the registry to handle serialization logic transparently across the application.

types · high confidence

Introduction of pluggable binary codec implementations

The codec package now provides a unified interface for serializing and deserializing data, featuring four distinct implementations: JSON, Binary, MessagePack, and Protocol Buffers. The Binary codec specifically supports native Go types implementing encoding.BinaryMarshaler/BinaryUnmarshaler as well as raw byte slices, ensuring safe copying during unmarshaling. These codecs are automatically registered in a global map upon initialization, allowing users to select their preferred serialization format by name.

codec · high confidence

New runnable pattern examples for event sourcing and reactive processing

Added a suite of runnable Go examples in the \examples/\ directory that demonstrate core Rita capabilities. The \quickstart\ example shows basic event appending and state reconstruction. \deciders\ illustrates the command-decision pattern with invariant validation and thread-safe model evolution. \optimistic-concurrency\ demonstrates handling sequence conflicts and retries. \projection\ shows continuous state updates using the \Watch\ API. \reactor\ and \reactor-lifecycle\ cover creating, binding, updating, and deleting durable reactors for side-effect processing. Finally, \tenancy\ demonstrates multi-tenant isolation using scoped event store handles.

examples · high confidence

New test utilities for time control, assertions, and NATS server management

The testutil package now provides three new helper components to streamline testing. A deterministic Clock allows tests to control time progression via a configurable unit and supports manual time advancement through a new Add() method. An Is assertion helper simplifies test verification with methods for checking equality, error types, absence of errors, and boolean conditions. Additionally, NATS server management is standardized with functions to start a JetStream-enabled server, with optional support for specifying a custom JetStream domain.

testutil · high confidence

Dependencies

Initial Go module definition for Rita

The project now includes a go.mod file establishing the module as github.com/synadia-labs/rita, targeting Go 1.25.0. This introduces dependencies for NATS connectivity (nats-server v2.12.6, nats.go v1.53.1), JetStream extensions (orbit.go/jetstreamext v0.3.2), serialization (msgpack v5.4.1, protobuf v1.36.12), and utility libraries (uuid, go-cmp, testify).

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 71 → 77 (+6.3)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 93 → 97 (+3.2)
  • Architecture 100 → 100 (+0.0)
  • Maturity 60 → 62 (+2.2)
  • Readiness 78 → 83 (+5.0)
  • Security 75 → 98 (+23.2)

Resolved (23)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (11 lines × 2) (examples/reactor-lifecycle/main.go)
  • Duplicated block (12 lines × 2) (eventstore.go)
  • Duplicated block (13 lines × 2) (examples/reactor-lifecycle/main.go)
  • Duplicated block (14 lines × 2) (examples/projection/main.go)
  • Duplicated block (14 lines × 3) (examples/deciders/main.go)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • LLM evaluation failed
  • Medium CVE: GO-2025-3955 (go.mod)
  • Medium CVE: GO-2026-5024 (go.mod)
  • Medium vulnerability: GO-2026-5841 (go.mod)
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • Test reliability not included
  • …and 3 more

New (26)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (13 lines × 2) (eventstore.go)
  • Duplicated block (15 lines × 2) (examples/reactor-lifecycle/main.go)
  • Duplicated block (15 lines × 2) (examples/reactor-lifecycle/main.go)
  • Duplicated block (15–17 lines × 2) (examples/reactor-lifecycle/main.go)
  • Duplicated block (15–17 lines × 4) (examples/deciders/main.go)
  • Duplicated block (15–18 lines × 5) (examples/deciders/main.go)
  • Duplicated block (18–20 lines × 2) (examples/projection/main.go)
  • Duplicated block (8 lines × 2) (examples/reactor-lifecycle/main.go)
  • Duplicated block (9 lines × 2) (examples/deciders/main.go)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: GO-2025-3955 (go.mod)
  • Medium vulnerability: GO-2026-5932 (go.mod)
  • Medium: security finding (details withheld)
  • Members sharing a duplicated core (4 members, 50+ identical tokens) (examples/deciders/main.go)
  • …and 6 more

Changes since last survey

  • 1 commits — 1 feature/other, 0 fixes

By area

  • (root) — 1 commit

Notable commits

  • change: CHORE: dependency updates

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

synadia-labs/rita was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 05ffa420324fc154d6fe23be057f1eb781efdbd0 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.