Skip to content
CAI
Software that uses CAICheck a score

javierparadadev/python-ddd-skeleton

58.2

Adequate · 22 September 2026

663

lines of production code

Python

primary language

6

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Python-based application scaffold built on Domain-Driven Design and Hexagonal architecture principles. It provides a shared infrastructure layer implementing CQRS and event-sourcing patterns, including command/query buses, logging, and persistence clients for Minio and MongoDB. The codebase also establishes foundational domain models, value objects, and testing utilities to support future feature development.

Features

Added shared domain base classes and error types

Introduced new shared domain abstractions including a BaseObject, Interface, Metadata, and Response base classes, alongside DomainError and UncontrolledError exception types. These provide a common foundation for domain modeling and error handling across the application.

src/contexts/shared/domain · high confidence

Initial project scaffolding and build configuration

The repository was initialized with core project files, including a Dockerfile for containerization, a Makefile defining build, dependency, and test targets, and a .gitignore file to exclude common Python and IDE artifacts. The main application entry point (main.py) and a README describing the DDD/Hexagonal architecture template were also added.

(repo-wide) · high confidence

Introduce CQRS and event-sourcing abstractions with new criteria models

The shared domain layer now includes foundational abstractions for Command, Query, and Event Sourcing patterns. New interfaces and base classes are added for commands (Command, CommandBus, CommandHandler, and CommandNotRegisteredError), queries (Query, QueryBus, QueryHandler, and QueryNotRegisteredError), and domain events (DomainEvent, EventBus, EventSubscriber). Additionally, a new criteria system is introduced, providing models for filtering (Filter, FilterField, FilterOperator, FilterValue), ordering (OrderBy, OrderAttribute, OrderDirection), and pagination (Limit, LimitOffset, UpperLimit), along with a Criteria container and CriteriaQueryMetadata for query results.

src/contexts/shared/domain/criteria · high confidence

Introduces a logging interface for the shared domain

A new Logger interface is added to the shared domain, defining abstract methods for debug, info, warning, error, and critical log levels. This establishes a contract for logging implementations within the application's shared context.

src/contexts/shared/domain/logger · high confidence

Introduces shared infrastructure components for command/query buses, logging, and persistence

Adds new infrastructure implementations including InMemoryCommandBus and InMemoryQueryBus for handling commands and queries, a NativeConsoleLogger for application logging, and persistence layers for Minio and MongoDB (PyMongoRepository, MinioRepository) along with their respective client factories and configuration classes. Additionally, it introduces an EnvManager for environment variable management, a Uuid utility for validation, and parsers for converting dictionary formats to criteria and Mongo queries.

src/contexts/shared/Infrastructure · high confidence

Behavioural changes

Introduces foundational domain model classes

The shared domain layer now includes base classes for domain modeling: an abstract AggregateRoot with a to\_primitives method, a ValueObject base class that stores and exposes a value, and a ValueObjectValidationError exception that provides a consistent error structure with a fixed error ID.

src/contexts/shared/domain/valueobj · medium confidence

Test coverage

Added test utilities for async testing and random word generation

Added new test utilities to the test suite: an async test decorator that runs coroutines in a new event loop, and a WordMother helper class that generates random 10-character lowercase strings. These additions support future test cases by providing reusable testing infrastructure.

tests · high confidence

Dependencies

Updated Python dependencies

The project's Python dependencies have been updated to specific versions: anyio 3.6.2, fastapi 0.109.1, idna 3.7, minio 7.1.13, pymongo 4.6.3, pydantic 1.10.13, sniffio 1.3.0, starlette 0.35.0, and typing\_extensions 4.8.0.

(dependencies) · medium confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 56 → 58 (+2.5)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 98 → 98 (-0.3)
  • Architecture 69 → 69 (+0.0)
  • Maturity 43 → 43 (+0.0)
  • Readiness 70 → 67 (-2.6)
  • Security 60 → 77 (+17.5)

Resolved (22)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (requirements.txt)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: [GHSA redacted] (requirements.txt)
  • Medium IaC: CKV_DOCKER_3 (Dockerfile)
  • No exposed public API
  • …and 2 more

New (45)

  • Critical CVE: [GHSA redacted] (requirements.txt)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (9 lines × 2) (src/contexts/shared/Infrastructure/persistence/minio/MinioClientFactory.py)
  • High CVE: [GHSA redacted] (requirements.txt)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 25 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

javierparadadev/python-ddd-skeleton was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 13634f9edd8b80007652317854ff7b2b91d364bb — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.