Skip to content
CAI
Software that uses CAICheck a score

takagiy/validated-extendable.js

60.3

Adequate · 21 September 2026

150

lines of production code

TypeScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a JavaScript library called validated-extendable that provides factory functions for creating classes with built-in Zod schema validation. It offers two modes: immutable instances for static data and mutable instances backed by proxies that re-validate state on every property change. The library aims to reduce boilerplate by allowing developers to define extendable classes that automatically enforce schema constraints and support round-trip validation.

Features

Introduce Validated and ValidatedMutable class constructors with Zod integration

This change introduces two new factory functions, \Validated\ and \ValidatedMutable\, which create class constructors that validate input data against a Zod schema. \Validated\ returns immutable instances, while \ValidatedMutable\ returns instances backed by a Proxy that re-validates the entire object state on every property mutation. Both constructors expose a \schema\ property for direct access to the underlying Zod schema and a \z()\ method that returns a Zod type capable of transforming and validating instances back into the class structure. An optional \wrapValue\ option allows wrapping the validated data in a \{ value }\ object, which is automatically applied for primitive types or when explicitly requested.

src · high confidence

Test coverage

Added test coverage for Validated and ValidatedMutable classes

Added a new test suite in test/index.ts that validates the behavior of the Validated and ValidatedMutable class factories. The tests cover basic instantiation, property access, method invocation, and error handling for invalid inputs. They also verify the functionality of the wrapValue option, which exposes the underlying validated object via a .value property, and confirm that the .z() static method correctly parses and validates input data.

test · high confidence

Dependencies

Initial release of validated-extendable v7.3.0

This entry introduces the validated-extendable library (version 7.3.0), a tool for defining classes that extend Zod schemas to reduce boilerplate. The package is configured for dual CommonJS and ESM support via explicit exports, uses SWC for bundling, and lists Zod as a peer dependency.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 56 → 60 (+4.3)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 (new)
  • Architecture 69 → 69 (+0.0)
  • Maturity 59 → 59 (+0.0)
  • Readiness 46 → 53 (+7.4)
  • Security 64 → 70 (+6.2)

Resolved (22)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Medium CVE: [GHSA redacted] (pnpm-lock.yaml)
  • No exposed public API
  • …and 2 more

New (27)

  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Documentation: no installation or build instructions (README.md)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 7 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

takagiy/validated-extendable.js was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 63da702ae3db44cd7303dc5f4f0f297f749f39d6 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.