Skip to content
CAI
Software that uses CAICheck a score

wso2/product-integrator-si

39.6

Weak · 22 September 2026

1.4k

lines of production code

Java

primary language

6

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a streaming data integration and processing platform, centered around the WSO2 Streaming Integrator and Siddhi engine. It provides the core runtime environment, including startup scripts, OSGi configuration, and Docker deployment support. The system enables real-time event processing through various connectors (Kafka, HTTP, GCS, Micro Integrator) and offers comprehensive performance benchmarking and OSGi-based integration testing capabilities.

How it got here

2014–2017 — Distribution assembly and test infrastructure

8 changes.

This period focused on assembling the WSO2 Streaming Integrator product distribution, including utility scripts, OSGi configuration, and sample applications. It also established the foundational infrastructure for integration testing, introducing a Kubernetes-based test framework and a results collection service.

2018–2019 — Performance testing and integration samples

14 changes.

This period focused on expanding the project's testing and demonstration capabilities by introducing a comprehensive performance testing suite, including throughput measurement extensions and TCP benchmark clients. Additionally, the codebase was enriched with new sample applications for integrating with Kafka, Google Cloud Storage, and Micro Integrator, alongside infrastructure updates like Dockerfiles and startup scripts.

2020–2022 — OSGi test distribution and monitoring

8 changes.

This period focused on establishing a complete OSGi-based test distribution for WSO2 Streaming Integrator, including startup scripts, configuration files, and integration tests. It also introduced Grafana dashboard templates for monitoring metrics and packaged the distribution with legal policy pages and Docker support.

Features

Add Dockerfile for WSO2 Streaming Integrator

A new Dockerfile has been added to the WSO2 Streaming Integrator distribution, establishing a Docker image based on the wso2/streaming-integrator:latest base image. The build process copies Siddhi files into the /home/wso2carbon/wso2si/wso2/server/deployment/siddhi-files directory, enabling containerized deployment of the streaming integrator.

modules/distribution/carbon-home/resources/dockerfiles, modules/distribution/src/docker-distribution · high confidence

Add Grafana dashboard templates for WSO2 Streaming Integrator metrics

Added a collection of new Grafana dashboard JSON files and a configuration README for monitoring WSO2 Streaming Integrator metrics via Prometheus. The new dashboards cover general Siddhi statistics (overall, server, query, aggregation, and sink metrics), as well as specific source and sink statistics for CDC and File connectors, enabling users to visualize performance and operational data in Grafana.

_modules/osgi-tests/test-distribution/carbon-home/resources, modules/osgi-tests/test-distribution/src/policies/public/js/libs/font-wso2\1.0.0 · high confidence

Add Kafka consumer sample client

A new sample client for consuming Kafka messages has been added to the WSO2 Stream Processor. The Java implementation initializes a Siddhi application that subscribes to specified Kafka topics, processes the incoming data streams, and logs the output. This sample demonstrates how to configure Kafka source parameters such as bootstrap servers, topics, partitions, and threading options within a Siddhi application.

modules/samples/sample-clients/kafka-consumer/src · high confidence

Add Kafka sample for event processing

A new sample application, HelloKafka.siddhi, has been added to demonstrate consuming events from a Kafka topic and publishing them to another. The sample processes sweet production data, calculating batch totals and generating alerts for low production batches, with a corresponding kafka\_sample.txt file providing test data.

modules/samples/artifacts/WorkingWithKafka · high confidence

Add TCP performance sample clients

A new TCP client sample has been added to the performance module, providing two Java programs for testing: a high-throughput benchmark client that sends one million events in batches, and a store-test client that sends a single boolean event. The build configuration and logging setup are included to support running these clients against a WSO2 Stream Processor instance.

modules/performance/sample-clients · high confidence

The distribution module now includes dedicated pages for the privacy policy, cookie policy, and a policies landing page. Users can now access these legal documents directly from the application, with the landing page providing links to the individual policy pages.

modules/distribution/src/policies/pages · high confidence

Add throughput performance measurement extension

A new \throughput\ extension is introduced for the Siddhi execution engine, enabling users to measure stream processor performance by calculating throughput, latency, or both. The extension accepts parameters for timestamp, metric type, window size, and ID, and writes the resulting performance metrics to CSV files.

modules/performance/extension/siddhi-execution-performance/component · high confidence

Added GCS sink sample for publishing events to Google Cloud Storage

A new Siddhi application named 'GCSSinkSample' has been added to demonstrate how to publish events to a Google Cloud Storage (GCS) bucket. This sample consumes HTTP events and uses the siddhi-io-gcs sink extension to aggregate and commit objects to a GCS bucket, providing a complete example including prerequisites, execution steps, and a curl-based test command.

modules/samples/artifacts/PublishEventsToGooglCloudStorage · high confidence

Added HTTP and HTTPS server sample clients

A new sample HTTP/HTTPS server has been added to the WSO2 Stream Integration distribution. This sample provides a ready-to-use Java application that starts an HTTP server on port 8080 and an HTTPS server (using a default keystore) to receive and log incoming events, serving as a reference implementation for integrating with WSO2 Stream Integration.

modules/samples/sample-clients/http-server · high confidence

Added HTTP request-response sample

A new sample Siddhi application has been added to demonstrate how to configure WSO2 Streaming Integrator to send production events via HTTP transport, receive the server's response, and process it. The sample includes the necessary stream definitions and query logic, along with updated documentation and a fix to use 0.0.0.0 for the HTTP server binding.

modules/samples/artifacts/HttpRequestResponseSample · high confidence

Added Kafka producer sample client

A new sample client for the Kafka producer has been added to the WSO2 Stream Integrator. The \KafkaClient\ and \EventSendingUtil\ classes provide a test client that connects to a Kafka broker, configures a Siddhi app to send events to a specified topic, and supports sending events in JSON, XML, text, or binary formats. Users can use this sample to understand how to produce events to Kafka using the Siddhi runtime.

modules/samples/sample-clients/kafka-producer/src · high confidence

Added Kubernetes integration test framework and test results service

The distribution module now includes a new integration test module that supports running integration tests on Kubernetes. This includes a test results service for collecting and displaying test outcomes, alongside the necessary Maven POM files and Python requirements for the Kubernetes infrastructure automation scripts.

(dependencies) · high confidence

Added OSGi launch configuration for Carbon server

A new launch.properties file has been added to configure the OSGi framework for the Carbon server. This includes enabling the OSGi console, setting the bundle parent to 'framework', and configuring system package exports and boot delegation for specific Sun and WSO2 Carbon security packages.

modules/distribution/carbon-home/conf/osgi · high confidence

Added OSGi test distribution configuration files

Added new configuration files for the WSO2 Streaming Integrator test distribution, including OSGi launch properties, server deployment settings, logging (log4j2), and Netty transport configurations. These files define server ports, data receiver/agent settings, and transport properties for the test environment.

modules/osgi-tests/test-distribution/carbon-home/conf · high confidence

Added OSGi test distribution packaging and policy pages for WSO2 Streaming Integrator

The WSO2 Streaming Integrator test distribution now includes a complete package assembly (bin.xml) that bundles the product, kernel, and extensions into a zip archive, along with a Dockerfile for containerized deployment. Additionally, the distribution now ships with a policies section containing HTML templates for the Privacy Policy, Cookie Policy, and a policies index page, all styled with a dedicated CSS file and logo, ensuring users have access to legal and compliance documentation out of the box.

modules/osgi-tests/test-distribution/src · high confidence

Added TCP Benchmark artifacts for performance testing

New Siddhi application artifacts have been added to the performance testing suite. These include a base filter benchmark, simple passthrough, and time-windowed (large and small) processing flows. Additionally, persistence benchmarks for insert and update operations against SQL Server, MySQL, and Oracle databases have been introduced, alongside partitioning, pattern matching, and throughput-based processing scenarios.

modules/performance/artifacts · high confidence

Added WSO2 font library for icon rendering

The WSO2 font library (version 1.0.0) has been added to the policies public assets. This includes the CSS styles for the 'font-wso2' font-face, a minified CSS file, and the SVG font file. This enables the use of WSO2-specific icons and UI elements across the policies interface.

_modules/distribution/src/policies/public/js/libs/font-wso2\1.0.0 · high confidence

Added Windows and Unix startup scripts for the OSGi test distribution

New startup scripts (carbon.bat and carbon.sh) have been added to the OSGi test distribution's runtime directory. These scripts handle environment variable setup, classpath configuration, and command-line argument parsing for starting, stopping, and debugging the WSO2 Carbon server. The Windows batch file includes logic to detect the Java version and apply appropriate JVM arguments, such as --add-opens for Java 11 and higher, ensuring compatibility across different Java versions.

modules/distribution/carbon-home/runtime, modules/osgi-tests/test-distribution/carbon-home/runtime · high confidence

Added extension installer scripts for Windows and Unix

New shell scripts (extension-installer.bat and extension-installer.sh) have been added to the distribution module. These scripts allow users to install extensions by resolving the CARBON\_HOME directory and invoking the extension-installer tool located in the wso2/tools/extension-installer/bin directory.

modules/distribution/src/scripts · high confidence

Added new utility scripts for Carbon tools

New shell and batch scripts have been added to the distribution's bin directory to support various Carbon tools, including ciphertool, icf-provider, jartobundle, osgi-lib, and server startup. These scripts handle environment variable checks, path resolution, and execution of Java-based tools such as CipherToolInitializer and CarbonToolExecutor, enabling users to run these utilities directly from the command line.

modules/distribution/carbon-home/bin · high confidence

Added sample Siddhi application for testing

A new sample Siddhi application named 'TestSiddhiApp' has been added to the distribution, defining a stream processing flow that reads from an in-memory source and inserts data into a destination stream. This serves as a reference implementation for Siddhi-based stream processing within the product.

modules/distribution/carbon-home/deployment/siddhi-files · high confidence

Added startup and utility scripts for the test distribution

New shell and batch scripts are added to the test distribution's bin directory to support the runtime environment. This includes server launch scripts (server.sh/bat) that initialize jars and start the worker, as well as utility scripts for ciphertool, ICF provider, JAR-to-bundle conversion, and OSGI library deployment. A version.txt file is also added to the bin directory.

modules/osgi-tests/test-distribution/carbon-home/bin · high confidence

Added styling and branding assets for the public policies page

The public policies page now includes a dedicated CSS stylesheet that defines the visual appearance of the page, including the header, main content area, and typography for headings and paragraphs. Additionally, the WSO2 logo SVG asset has been added to support the page's branding.

modules/distribution/src/policies/public · high confidence

Initial WSO2 Streaming Integrator distribution assembly

The product distribution is now assembled using a new \bin.xml\ and \filter.properties\ configuration, defining the structure of the WSO2 Streaming Integrator package. This includes copying the Carbon kernel, configuration files, scripts, and sample data into the final zip archive, while excluding unnecessary files like IDE configurations and temporary build artifacts.

modules/distribution/src/assembly · high confidence

New sample for connecting Streaming Integrator to Micro Integrator via gRPC

Added a new sample demonstrating how to trigger a sequence in Micro Integrator from Streaming Integrator using the gRPC protocol. The update includes the Siddhi application file (HelloMi.siddhi) which defines the data streams and query logic, along with the required XML configuration files (grpcInboundEndpoint.xml and inSeq.xml) to establish the gRPC connection between the two components.

modules/samples/artifacts/ConnectToMicroIntegratorFromSI · high confidence

Behavioural changes

6 commits (0 fixes) modifying modules/distribution/carbon-home/resources/security

A change to existing behaviour in modules/distribution/carbon-home/resources/security — 6 commits, 2 files.

modules/distribution/carbon-home/resources/security · medium confidence · unverified

Test coverage

Added OSGi integration tests for Streaming Integrator; Added OSGi test configuration files for WSO2 Streaming Integrator; Added OSGi test resources for Siddhi applications; Added test-results-service and Kubernetes integration test framework.

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 49 → 40 (-9.2)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 94 → 96 (+1.8)
  • Architecture 100 → 91 (-9.1)
  • Maturity 47 → 47 (+0.0)
  • Readiness 31 → 24 (-6.5)
  • Security 71 → 72 (+0.8)
  • Accessibility 40 (new)

Resolved (17)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (modules/performance/extension/siddhi-execution-performance/component/src/main/java/org/wso2/extension/siddhi/execution/throughput/CalculatePerformanceStreamProcessorExtension.java)
  • Duplicated block (10 lines × 2) (modules/performance/extension/siddhi-execution-performance/component/src/main/java/org/wso2/extension/siddhi/execution/throughput/util/filewriting/BothFileWriting.java)
  • Duplicated block (14 lines × 2) (modules/performance/extension/siddhi-execution-performance/component/src/main/java/org/wso2/extension/siddhi/execution/throughput/CalculatePerformanceStreamProcessorExtension.java)
  • Duplicated block (7 lines × 2) (modules/performance/extension/siddhi-execution-performance/component/src/main/java/org/wso2/extension/siddhi/execution/throughput/util/filewriting/BothFileWriting.java)
  • EventSendingUtil.publishEvents (cognitive 27) (modules/samples/sample-clients/kafka-producer/src/main/java/org/wso2/si/sample/kafka/client/EventSendingUtil.java)
  • KafkaClient.main (cognitive 30) (modules/samples/sample-clients/kafka-producer/src/main/java/org/wso2/si/sample/kafka/client/KafkaClient.java)
  • KafkaClient.main (cyclomatic 25) (modules/samples/sample-clients/kafka-producer/src/main/java/org/wso2/si/sample/kafka/client/KafkaClient.java)
  • LLM evaluation failed
  • Medium IaC: CKV_DOCKER_2 (modules/distribution/src/docker-distribution/filtered/Dockerfile)
  • Medium IaC: CKV_DOCKER_3 (modules/distribution/carbon-home/resources/dockerfiles/Dockerfile)
  • Medium IaC: CKV_DOCKER_7 (modules/distribution/carbon-home/resources/dockerfiles/Dockerfile)
  • Medium: security finding (details withheld)
  • No exposed public API
  • Test reliability not included
  • dormant codebase — no living knowledge left to concentrate

New (58)

  • Critical IaC: KSV-0045 (modules/kubenetes/00-prereqs.yaml)
  • Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no licence statement (docs/api/latest.md)
  • Duplicated block (14 lines × 2) (modules/performance/extension/siddhi-execution-performance/component/src/main/java/org/wso2/extension/siddhi/execution/throughput/CalculatePerformanceStreamProcessorExtension.java)
  • Duplicated block (15 lines × 2) (modules/performance/extension/siddhi-execution-performance/component/src/main/java/org/wso2/extension/siddhi/execution/throughput/CalculatePerformanceStreamProcessorExtension.java)
  • Duplicated block (15–16 lines × 2) (modules/performance/extension/siddhi-execution-performance/component/src/main/java/org/wso2/extension/siddhi/execution/throughput/util/filewriting/BothFileWriting.java)
  • Duplicated block (6 lines × 2) (modules/performance/extension/siddhi-execution-performance/component/src/main/java/org/wso2/extension/siddhi/execution/throughput/util/filewriting/BothFileWriting.java)
  • FixmeComment (modules/integration/tests-kubernetes-integration/src/test/resources/infrastructure-automation/kargo/contrib/inventory_builder/inventory.py)
  • High IaC: KSV-0056 (modules/kubenetes/00-prereqs.yaml)
  • High secret: WD-SECRET-0004 (modules/distribution/carbon-home/resources/security/wso2carbon.jks)
  • Leaked secret: hardcoded-credential (modules/distribution/carbon-home/runtime/server/carbon.bat)
  • Leaked secret: hardcoded-credential (modules/distribution/carbon-home/runtime/server/carbon.sh)
  • Leaked secret: private-key-store (modules/distribution/carbon-home/resources/security/wso2carbon.jks)
  • Medium IaC: CKV2_K8S_6 (modules/kubenetes/01-siddhi-operator.yaml)
  • Medium IaC: CKV_K8S_10 (modules/kubenetes/01-siddhi-operator.yaml)
  • Medium IaC: CKV_K8S_11 (modules/kubenetes/01-siddhi-operator.yaml)
  • Medium IaC: CKV_K8S_12 (modules/kubenetes/01-siddhi-operator.yaml)
  • Medium IaC: CKV_K8S_13 (modules/kubenetes/01-siddhi-operator.yaml)
  • Medium IaC: CKV_K8S_20 (modules/kubenetes/01-siddhi-operator.yaml)
  • …and 38 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

wso2/product-integrator-si was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit ce42dcf94fd20e563e791158274552500ce39ed1 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.