0xb4lamx/nestjs-boilerplate-microservice
65.7
Adequate · 21 September 2026
1.4k
lines of production code
TypeScript
with JavaScript
4
measurements over time
What this system is
This system is a NestJS-based microservice that manages user data using a CQRS and event-driven architecture backed by MySQL and EventStore. It exposes functionality through both REST and GraphQL APIs, leveraging Apollo Federation for service composition. The application includes robust infrastructure for local development, CI/CD, and structured logging, with specific handling for file uploads and user lifecycle events.
Features
Add health check endpoint and integrate EventStore and TypeORM
The application now exposes a /healthcheck endpoint that verifies the status of the database and the EventStore microservice. The bootstrapping process has been updated to initialize TypeORM and the EventStore CQRS module using configuration from the shared service, replacing the previous manual microservice connection logic. Additionally, the Swagger documentation setup has been moved to a shared module and now accepts configuration via the config service, while the server now binds to a configurable host and port with sensible defaults.
src · high confidence
Added custom exception classes for file and user errors
The application now includes specific exception classes, FileNotImageException and UserNotFoundException, to handle distinct error scenarios. FileNotImageException extends BadRequestException to manage cases where an uploaded file is not a valid image, while UserNotFoundException extends NotFoundException to signal when a requested user cannot be found. These changes provide more granular error handling for these specific conditions.
src/exceptions · high confidence
Added gRPC microservice setup utility
A new \setupGrpc\ helper function has been added to \src/shared/grpc/setup.ts\ to simplify the configuration of gRPC microservices within the NestJS application. This utility allows developers to connect a microservice by specifying the package name, proto file, and network port, automatically handling the transport setup and starting all microservices.
src/shared/grpc · high confidence
Automated local development environment setup and teardown
New shell scripts (build.sh and cleanup.sh) now automate the lifecycle of the local development environment. build.sh provisions the necessary Docker infrastructure, including creating a dedicated network, persisting data for MySQL and EventStore, deploying an Adminer interface for database management, and building/running the main application container with bind-mounted source code. cleanup.sh provides a corresponding mechanism to stop and remove these containers, networks, and images, with an optional hard mode to purge persistent data directories.
scripts · high confidence
New local development environment setup scripts
The \scripts/dev\ directory now includes a Dockerfile, a \.dockerignore\ file, and an \envVar.sh\ script to streamline local development. The Dockerfile configures a Node.js 16 Alpine container, copying source code, ORM configuration, and pre-built \node\_modules\ to run the development server. The \envVar.sh\ script exports environment variables for connecting to MySQL, EventStore, and Adminer, defining default ports and container names for these services.
scripts/dev · high confidence
Project initialization and tooling overhaul
The repository has been initialized with a new structure, upgrading the target framework to NestJS v10 and switching the linting engine from TSLint to ESLint. This change introduces a new ESLint configuration, a \.env.example\ file for environment variables, and a multi-stage Dockerfile for production builds. Additionally, the project now includes a Jenkinsfile for automated CI/CD pipelines, a Makefile for Docker operations, and configuration files for semantic release and Renovate.
(repo-wide) · high confidence
Behavioural changes
Abstract entity now extends CQRS AggregateRoot and uses standard timestamps
The base entity class in src/common now inherits from NestJS CQRS's AggregateRoot, enabling built-in event sourcing capabilities for entities. Additionally, the database column definitions for created\_at and updated\_at have been simplified to use standard 'timestamp' types instead of 'timestamp without time zone', and the manual DTO transformation logic has been replaced with an abstract toDto method, shifting transformation responsibilities to concrete implementations.
src/common · high confidence
Improved HTTP exception handling and logging
The HTTP exception filter now provides more detailed error responses by including a timestamp in ISO format and exposing the specific error message from the exception's response payload. It also utilizes a dedicated LoggerService for structured logging, distinguishing between internal server errors (logging the stack trace) and other HTTP errors (logging the error response object). Additionally, the filter is now scoped to catch only HttpException instances, and RPC exception filtering remains unchanged.
src/filters · high confidence
Logging interceptor now captures GraphQL resolver performance
The logging interceptor in src/interceptors has been updated to support GraphQL requests in addition to standard HTTP requests. Previously, GraphQL interception logic was commented out; it is now active, allowing the system to log the parent type, field name, and execution time for GraphQL resolvers alongside existing HTTP method and URL logging.
src/interceptors · high confidence
Refactor AbstractDto to use class-transformer decorators
The AbstractDto class has been refactored to use the class-transformer library for property mapping. Instead of manually copying properties from an AbstractEntity in a constructor, the DTO now uses @Exclude() and @Expose() decorators to automatically serialize the id, createdAt, and updatedAt fields. This simplifies the DTO structure and aligns it with the project's new transformation strategy.
src/common/dto · high confidence
Refactor shared services for NestJS v10 compatibility and new configuration support
The shared services have been updated to align with NestJS v10, including refactoring LoggerService to extend NestJS's ConsoleLogger and updating the uuid import to use the standard named export. Environment configuration now defaults to a single .env file instead of environment-specific files, and logging is restricted to the development environment. New configuration getters have been added to support Swagger API documentation settings and Event Store connectivity, while code formatting has been standardized across AWS S3, generator, and logger services.
src/shared/services · high confidence
Swagger configuration now uses addServer instead of addSchemes
The Swagger setup logic in src/shared/swagger/setup.ts has been updated to use the addServer() method for defining the API server URL instead of the deprecated addSchemes() method. This change ensures compatibility with the upgraded @nestjs/swagger library and correctly configures the API documentation endpoint based on the provided scheme configuration.
src/shared/swagger · high confidence
Users module adopts CQRS and event-driven architecture with GraphQL federation
The Users module has been restructured to use a Command Query Responsibility Segregation (CQRS) pattern, routing user creation, updates, and deletions through dedicated command handlers and user retrieval through query handlers. This change introduces an event-driven model where user actions publish domain events (created, updated, deleted, welcomed) to an event store, enabling side effects like a delayed welcome command via sagas. Additionally, the module now exposes user data via a GraphQL API using Apollo Federation, providing specific queries for fetching single or multiple users alongside the existing REST endpoints.
src/modules/users · high confidence
Test coverage
Updated e2e test formatting
The e2e test file (test/app.e2e-spec.ts) has been reformatted to align with the new eslint and prettier-eslint configuration, specifically adjusting indentation and import ordering without changing the test logic.
test · high confidence
Dependencies
Major dependency upgrade to NestJS v10 and Apollo Federation v2
The project has been upgraded from NestJS v6 to v10, bringing significant changes to the core framework, GraphQL integration (Apollo Federation v2), and database layer (TypeORM v0.3). This update also migrates the database driver from \mysql\ to \mysql2\, upgrades the UUID library to v11, and switches the linter from TSLint to ESLint. Additionally, the boilerplate now includes CQRS support via \@nestjs/cqrs\, health checks via \@nestjs/terminus\, and a custom \nestjs-eventstore\ package, while enforcing Node.js \>=16.0.0.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 51 → 66 (+14.3)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 80 → 82 (+1.7)
- Architecture 69 → 69 (+0.0)
- Maturity 86 → 82 (-4.4)
- Readiness 42 → 56 (+13.4)
- Security 76 → 80 (+3.9)
Resolved (51)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 31 more
New (85)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Dependency source pinned to a moving git ref
- Floating npm dependency: nestjs-eventstore
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 65 more
Changes since last survey
- 7 commits — 6 feature/other, 1 fixes
By area
- (repo) — 4 commits
- (root) — 3 commits
Notable commits
- fix: fix(deps): update dependency uuid to v11 [security]
- change: Merge pull request #218 from 0xb4lamx/renovate/npm-uuid-vulnerability
- change: Merge pull request #229 from 0xb4lamx/renovate/npm-typeorm-vulnerability
- change: Merge pull request #232 from 0xb4lamx/renovate/npm-morgan-vulnerability
- change: Merge pull request #249 from 0xb4lamx/renovate/npm-morgan-vulnerability
- change: chore(deps): update dependency morgan to v1.12.0 [security]
- change: chore(deps): update dependency typeorm to v0.3.31 [security]
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
0xb4lamx/nestjs-boilerplate-microservice was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit bda7af7257575fa6ae2b6662af85e6bb855e19e5 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.