Skip to content
CAI
Software that uses CAICheck a score

vshulcz/injex

79.4

Strong · 21 September 2026

6.8k

lines of production code

Python

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Injex is a Python dependency injection library that manages object lifecycles and resolves dependencies through a container. It provides core features like scoped and transient object management, automatic registration, and graph validation. The system includes optional integrations for major web frameworks (FastAPI, Django, Flask, etc.) and CLI tools, supported by a comprehensive test suite and benchmarking suite for performance comparison.

Features

Added benchmark suite for dependency injection performance

Added a new \benchmarks/\ directory containing Python scripts and documentation to measure and compare the performance of various Python dependency injection libraries. The suite includes \resolve\_graph.py\ for synchronous resolution, \resolve\_async.py\ for async resolution patterns, and \resolve\_scoped.py\ for per-request scope overhead. The \README.md\ provides instructions for running the benchmarks and presents the latest local results, allowing users to see how Injex and other libraries perform on a typical service-layer graph.

benchmarks · high confidence

Introduce Injex, a Python dependency injection container

Injex is a new dependency injection library for Python, providing a \Container\ for managing object lifecycles (singleton, scoped, transient) and resolving dependencies. The package exposes core classes like \Container\, \Scope\, and \AsyncScope\, along with decorators such as \@injectable\ for automatic registration and \@inject\ for property injection. It supports named dependencies via \Annotated\ types, context data injection, and validation of the dependency graph. The library also includes a CLI tool (\python -m injex check\) for validating container graphs in CI environments, and a testing helper (\overrides\) for temporarily swapping bindings during tests.

injex · high confidence

New framework integrations and CLI injection support

Added optional integrations for FastAPI, aiohttp, Django, Flask, Litestar, Quart, Sanic, and Starlette, each providing thin glue code to open an Injex scope per request and expose it on the request object. Added CLI injection support via the \injex.ext.cli\ module, which provides an \Inject()\ marker and a \wire()\ decorator to inject services into command-line functions. Added a \tasks\ module (\injex.ext.tasks\) with \inject\ and \ainject\ decorators for injecting services into background tasks and handlers across frameworks like Celery, Arq, and aiogram.

injex/ext · high confidence

Behavioural changes

Expanded example suite for Injex

The examples directory now includes a broader set of usage patterns, including clean architecture, CLI injection, configuration injection, cyclic dependency validation, factory-based scoped resources, and FastAPI integration (both standard and async). These examples demonstrate how to wire dependencies, manage resource lifecycles, and integrate Injex with external frameworks.

examples · high confidence

Site refresh: new landing page, article, and SEO infrastructure

The site now features a redesigned landing page (index.html) with updated positioning, performance benchmarks, and use-case descriptions. A new article (why-tiny-python-di.html) explains the rationale for a tiny DI container. A 404 page has been added. SEO and discoverability are improved with a robots.txt, sitemap.xml, and an llms.txt/llms-full.txt context file for AI indexing. The site's visual style is updated via a new styles.css.

site · high confidence

Test coverage

Added tests for async resolution, framework integrations, and CLI injection

Added tests for async resolution, framework integrations, and CLI injection. The new test files cover the async resolution path (including async factories, scoped resources, and lifecycle invariants), the \container.call()\/\acall()\ function injection, CLI injection via \@wire\, and framework integrations for aiohttp, Django, FastAPI, Flask, Litestar, Sanic, and Quart. Additional tests validate error messages, context data, concurrency safety, and edge cases like default values and property injection.

tests · high confidence

Dependencies

Initial project configuration and dependency manifest

The project is now configured for Python packaging and development using pyproject.toml, establishing version 1.9.0 for the 'injex' package. The configuration defines build requirements (setuptools), Python version compatibility (3.10+), and optional dependencies for various web frameworks including FastAPI, Django, Starlette, Litestar, Flask, AIOHTTP, Quart, and Sanic. Development tooling is also specified, including mypy, pytest, ruff, and click, alongside CI and code quality tooling settings.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 78 → 79 (+1.6)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 92 → 95 (+3.1)
  • Architecture 100 → 100 (-0.4)
  • Maturity 68 → 70 (+2.0)
  • Readiness 83 → 84 (+1.2)
  • Security 85 → 85 (+0.4)

Resolved (13)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (11 lines × 2) (injex/container.py)
  • Duplicated block (13 lines × 2) (injex/container.py)
  • Duplicated block (16 lines × 2) (injex/planning.py)
  • Duplicated block (9 lines × 2) (injex/container.py)
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • Test reliability not included
  • The body is clipped mid-sentence inside a code block, so the container-validation section's concrete examples and scope coverage (e.g., async resolution) fall below the clip marker and cannot be confirmed from this excerpt alone. (docs/validation.md)
  • test_async_fuzz._build_resource_graph (cognitive 16) (tests/test_async_fuzz.py)
  • test_flat_creator_fuzz._make_graph (cognitive 28) (tests/test_flat_creator_fuzz.py)
  • test_flat_creator_fuzz._make_graph (cyclomatic 18) (tests/test_flat_creator_fuzz.py)

New (17)

  • Critical CVE: [GHSA redacted] (uv.lock)
  • Dependency hygiene PARTLY measured — Python dependencies read, no exact pin to grade for currency
  • Documentation: no installation or build instructions (README.md)
  • Duplicated block (11 lines × 2) (injex/container.py)
  • Duplicated block (11–14 lines × 2) (injex/container.py)
  • Duplicated block (13 lines × 2) (injex/container.py)
  • Duplicated block (23–24 lines × 2) (injex/container.py)
  • Duplicated block (35–36 lines × 2) (injex/planning.py)
  • High CVE: [GHSA redacted] (uv.lock)
  • Job token omits the contents scope its checkout needs
  • Medium CVE: [GHSA redacted] (uv.lock)
  • Medium CVE: PYSEC-2026-3717 (uv.lock)
  • Medium CVE: PYSEC-2026-3717 (uv.lock)
  • Medium: security finding (details withheld)
  • Near-duplicate member pair (57 shared lines) (injex/container.py)
  • No ADRs found
  • Scattered collaborators

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

vshulcz/injex was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit ba01497d00b233dc97e134791c9246e8139df65d — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.