Skip to content
CAI
Software that uses CAICheck a score

alan2207/bulletproof-react

58.2

Adequate · 28 September 2026

17.7k

lines of production code

TypeScript

with JavaScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Add Next.js app with server-side rendering and E2E tests

The Next.js application is introduced, providing a server-side rendered (SSR) implementation of the app. This includes page components for the dashboard, discussions, and user profiles that utilize React Query's hydration boundaries for data fetching. The app features a dashboard layout with navigation, an admin guard for user management, and end-to-end tests using Playwright to verify authentication, profile updates, and discussion/comment CRUD operations.

apps/nextjs-app · high confidence

Add React Vite application with E2E tests and component generators

The React Vite application is introduced in the \apps/react-vite\ directory, providing a complete frontend setup including routing, state management, and UI components. The change adds end-to-end tests using Playwright to verify user flows such as authentication, profile updates, and discussion management. It also includes a Plop-based generator for scaffolding new components. Configuration files for ESLint, Prettier, Storybook, and VS Code are added to standardize code quality and development environment setup.

apps/react-vite · high confidence

Add authentication forms and discussion management UI for Next.js apps

Added login and registration form components for both the Next.js app and pages directories, enabling users to authenticate. Additionally, introduced a full set of components and API hooks for creating, viewing, updating, and deleting discussions, including list views, detail views, and admin-restricted update/delete actions.

apps/nextjs-app/src/features/auth, apps/nextjs-pages/src/features/auth, apps/nextjs-pages/src/features/discussions · high confidence

Add comment, team, and user management features

The React Vite app now includes full CRUD capabilities for comments, users, and teams. Users can create, read, and delete comments on discussions, with infinite scroll pagination and real-time list updates. Users can update their own profile information (name, email, bio) and administrators can delete users. Additionally, the app provides a list view for teams. These changes introduce new UI components and API hooks for managing these core entities.

apps/react-vite/src/features/comments, apps/react-vite/src/features/teams, apps/react-vite/src/features/users · high confidence

Add full CRUD operations for discussions

The discussions feature now supports creating, reading, updating, and deleting discussions. This includes API hooks for each operation (create, read single, read list with pagination, update, delete) and corresponding React components (CreateDiscussion, DiscussionView, DiscussionsList, UpdateDiscussion, DeleteDiscussion) that integrate with TanStack Query for state management and form handling.

apps/react-vite/src/features/discussions · high confidence

Add user and comment management features to Next.js apps

This change introduces new API hooks and UI components for managing users and comments across both the Next.js App Router and Pages Router applications. For users, it adds the ability to list, delete, and update profiles (including email, name, and bio). For comments, it adds the ability to create, list (with infinite scroll), and delete comments on discussions. These features are implemented using @tanstack/react-query for data fetching and mutations, with corresponding React components for the UI.

(repo-wide) · high confidence

Behavioural changes

Add pre-commit hook to lint staged files across apps

A new pre-commit hook has been added to the .husky directory. This hook automatically runs lint-staged for three specific application directories: apps/nextjs-app, apps/nextjs-pages, and apps/react-vite. This ensures that code changes in these folders are linted before being committed.

.husky · high confidence

Removed default Create React App boilerplate files

The default Create React App entry point (src/index.tsx), root component (src/App.tsx), associated styles (src/App.css, src/index.css), and utility files (src/reportWebVitals.ts, src/setupTests.ts, src/react-app-env.d.ts) have been removed from the source directory. This clears the way for a new application structure, as indicated by the accompanying migration to a modern React stack and shadcn UI components.

src · high confidence

Removed default React App template files

The default public template files, specifically index.html and manifest.json, have been removed from the public directory. This indicates a shift away from the standard Create React App structure, likely as part of a migration to a modern stack or custom build configuration.

public · medium confidence

Dependencies

Migrate to modern stack with Next.js and Vite apps

The project has been restructured into a monorepo containing three distinct application implementations: Next.js (using both App and Pages routers), and a Vite-based React app. Each app directory (apps/nextjs-app, apps/nextjs-pages, apps/react-vite) now includes its own package.json and yarn.lock, establishing independent dependency graphs and build configurations for modern tooling like Vite, Storybook, and Playwright, while the root package.json has been simplified to orchestrate the workspace.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 41 → 58 (+17.2)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.16) — scores are not directly comparable.

Lenses

  • Code Health 70 → 88 (+18.3)
  • Architecture 88 (new)
  • Maturity 74 → 65 (-9.5)
  • Readiness 21 → 47 (+26.4)
  • Security 51 → 61 (+9.5)
  • Accessibility 70 (new)
  • Performance 100 (new)

Resolved (77)

  • Critical CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • Critical CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • Critical CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • Critical CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • Critical CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • Critical CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • Critical CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • Critical CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • Critical CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • Critical CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • Critical CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • Critical CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • Dimension evaluation failed
  • High CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • High CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • High CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • High CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • High CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • High CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • High CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • …and 57 more

New (181)

  • Change coupling: create-comment.tsx ↔ update-profile.tsx (apps/react-vite/src/features/comments/components/create-comment.tsx)
  • Change coupling: router.tsx ↔ register-form.tsx (apps/react-vite/src/app/router.tsx)
  • Change-coupling hub: create-discussion.tsx → landing.tsx, create-comment.tsx, delete-discussion.tsx, update-discussion.tsx, update-profile.tsx (apps/react-vite/src/features/discussions/components/create-discussion.tsx)
  • Change-coupling hub: update-discussion.tsx → create-comment.tsx, delete-discussion.tsx, update-profile.tsx (apps/react-vite/src/features/discussions/components/update-discussion.tsx)
  • Coverage not measured — JavaScript/TypeScript suite
  • Critical CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • Critical CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • Critical CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • Critical CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • Critical CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • Critical CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • Critical CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • Critical CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • Critical vulnerability: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • Critical vulnerability: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • Documentation: no usage examples (docs/testing.md)
  • FunctionTooLong: dashboard-layout.DashboardLayout (apps/react-vite/src/components/layouts/dashboard-layout.tsx)
  • FunctionTooLong: dashboard-layout.Layout (apps/nextjs-app/src/app/app/_components/dashboard-layout.tsx)
  • FunctionTooLong: dashboard-layout.Layout (apps/nextjs-pages/src/components/layouts/dashboard-layout.tsx)
  • High CVE: [GHSA redacted] (apps/nextjs-app/yarn.lock)
  • …and 161 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

alan2207/bulletproof-react was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 9506629ed003a561c6627735480cce4994244bb4 — the exact code this score is about.
  • Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-24a00d372a4b.