Skip to content
CAI
Software that uses CAICheck a score

u8slvn/sutoppu

67.0

Adequate · 21 September 2026

236

lines of production code

Python

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Python library implementing the Specification design pattern, providing a base class for defining and combining domain-specific business rules using logical operators. It includes comprehensive test coverage and is configured with Poetry for dependency management and static type checking.

Features

Introduce Sutoppu Specification pattern implementation

Added the 'sutoppu' package, a Python library implementing the Specification pattern. The library provides a base 'Specification' class that automatically handles error reporting via a metaclass decorator, allowing users to define domain-specific business rules that can be combined using logical operators (AND, OR, NOT) and evaluated against candidate objects.

src · high confidence

Test coverage

Added test suite for the specification pattern implementation

Added comprehensive tests for the specification pattern, including validation that the Specification base class enforces the is\_satisfied\_by method, and verifies the behavior of logical operators (AND, OR, NOT) and chained specifications. Additionally, tests confirm that error reports are generated correctly for failed specifications and that the error state resets after two uses.

tests · high confidence

Dependencies

Migrate project configuration to Poetry and update dependencies

The project has migrated its build and dependency management from a previous system to Poetry, introducing a new \pyproject.toml\ and \poetry.lock\ file. This includes adding \mypy\ as a development dependency for static type checking, updating test dependencies like \pytest\ and \tox\, and specifying Python version support (3.8.1+). The lockfile also records specific versions for packages such as \coverage\, \exceptiongroup\, and \filelock\, ensuring reproducible builds.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 66 → 67 (+1.2)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (+0.0)
  • Architecture 69 → 69 (+0.0)
  • Maturity 59 → 59 (+0.0)
  • Readiness 63 → 67 (+3.8)
  • Security 88 → 92 (+3.3)

Resolved (10)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: [GHSA redacted] (poetry.lock)
  • Medium CVE: [GHSA redacted] (poetry.lock)
  • Medium CVE: [GHSA redacted] (poetry.lock)
  • No exposed public API
  • Test reliability not included
  • single-maintainer — knowledge-concentration (bus factor) risk

New (14)

  • Dependency hygiene PARTLY measured — Python dependencies read, no exact pin to grade for currency
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: [GHSA redacted] (poetry.lock)
  • Medium CVE: [GHSA redacted] (poetry.lock)
  • Medium CVE: [GHSA redacted] (poetry.lock)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No dependency advisory monitoring
  • Workflow token permissions not restricted

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

u8slvn/sutoppu was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit f28be0e3b7e3b29622e4d8bb396a284290924a7a — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.