alexleboucher/docker-express-postgres-boilerplate
61.1
Adequate · 21 September 2026
1.6k
lines of production code
TypeScript
with JavaScript
4
measurements over time
What this system is
Features
Initial project scaffolding and configuration
The repository is initialized with essential configuration files including a Dockerfile, docker-compose.yml, and .env.example for environment setup. TypeScript is configured via tsconfig.json and tsconfig.build.json, and ESLint is set up with a flat config (eslint.config.mjs) for code quality. Testing is configured with jest.config.ts, and the project includes a Code of Conduct and Contributing guidelines to support community involvement.
(repo-wide) · high confidence
Introduce domain models, repository interfaces, and use cases for user management
Added new domain models for User and RequestUser, along with the corresponding repository interface (IUserRepository) and service interfaces (IAuthenticator, IEncryptor) to support user registration and authentication workflows. The CreateUserUseCase was introduced to handle user creation, including email and username uniqueness checks, password hashing, and timestamp management, establishing the core structure for user-related business logic.
src/domain · medium confidence
Introduces core infrastructure abstractions and utilities
The core module now includes new foundational types and interfaces to support the application's architecture. This includes a Result type for handling success/failure states, interfaces for logging (ILogger), time (ITime), and use cases (IUseCase), as well as utility functions for environment variable access (env.ts) and a branded type system (brand.ts) for type safety.
src/core · high confidence
Behavioural changes
Added concrete implementations for logging, encryption, and time services
The application now includes concrete, injectable implementations for core infrastructure concerns. A console-based logger (ConsoleLogger) and a no-op logger (BrokenLogger) are provided to satisfy the ILogger interface, enabling flexible logging behavior for production and testing. For security, a BcryptEncryptor is introduced to handle password hashing and comparison using the bcryptjs library. Additionally, a SystemTime class is added to provide the current timestamp via the ITime interface. These changes support a cleaner architecture by decoupling these services, allowing them to be swapped or mocked more easily throughout the codebase.
src/infra/logger, src/infra/security, src/infra/time · high confidence
Migrate Express routing to a structured, dependency-injected router hierarchy
The application's routing layer has been refactored from a flat or controllet-based structure into a modular, dependency-injected hierarchy. A new \BaseRouter\ abstract class and specific router implementations (\ApiRouter\, \AuthRouter\, \HealthRouter\, \UsersRouter\) now manage route registration using standard Express \Router\ instances. Each router is injected with its corresponding request handler via InversifyJS, replacing the previous \inversify-express-utils\ controllets. This change improves separation of concerns by delegating route setup to individual router classes, each responsible for a specific domain (auth, health, users) and wired together in the root \ApiRouter\.
src/app/routers · high confidence
Migrate database layer from TypeORM to Drizzle
The database infrastructure has been refactored to use Drizzle ORM instead of TypeORM. This introduces a new configuration file for Drizzle, a database connection class implementing the IDatabase interface, a user table schema definition, a migration script creating the 'user' table, and a UserRepository implementation using Drizzle's query API. The change affects how database connections are managed, how schemas are defined, and how data is persisted and retrieved.
src/infra/database · high confidence
Migrate to a clean architecture with explicit request handlers and middleware
The application has been refactored to use a clean architecture pattern, replacing the previous inversify-express-utils controllets with standard Express routers and middlewares. This introduces a new request handler layer (src/app/request-handlers) that explicitly maps HTTP requests to domain use cases, and dedicated middlewares (src/app/middlewares) for authentication, current user resolution, and error handling. Users will experience the same API surface but with improved internal structure and separation of concerns.
src/app/middlewares, src/app/request-handlers · high confidence
Refactored app initialization and error handling
The application entry point (src/app) now uses a new HttpError class to standardize HTTP error responses, and the server setup has been refactored to use Inversify for dependency injection, replacing previous patterns. The server creation logic in src/app/server.ts now explicitly wires up middleware and routers via the DI container, and the app entry point (src/app/index.ts) initializes the container and starts the server.
src/app · medium confidence
Restructures the application's dependency injection container
The dependency injection setup in src/container has been refactored to use a new ContainerBuilder pattern. This change organizes the registration of core services, middlewares, routers, request handlers, and use cases into distinct, modular files, improving maintainability and separation of concerns within the container setup.
src/container · high confidence
Switch ID generation to use Node.js built-in crypto
The UUID generator in the infrastructure layer has been updated to use the built-in Node.js 'crypto' module (specifically 'randomUUID') instead of an external 'uuid' package. This change simplifies the dependency tree by removing the 'uuid' package in favor of the standard library, while maintaining the same 'IIDGenerator' interface for the ID generation capability.
src/infra/id-generator · high confidence
Switched authentication from session-based to JWT-based tokens
The application now uses JSON Web Tokens (JWT) for authentication instead of server-side sessions. The new implementation includes a JwtAuthenticator that issues and verifies JWTs, alongside new use cases (GetCurrentUserUseCase, LoginUseCase) that interact with this token-based flow. Users will now receive and present JWTs for authentication, changing how the system validates user identity.
src/domain/use-cases/auth, src/infra/auth · high confidence
Fixes
Fix TypeScript augmentation for Express Request
A new global type definition file (src/types/global.d.ts) was added to properly augment the Express Request interface with a user property. This resolves a ts-node issue related to augmented types, ensuring that TypeScript correctly recognizes the user property on the request object during development and type-checking.
src/types · low confidence
Test coverage
Added test helper utilities for integration testing; Added unit and end-to-end tests for core application components.
Dependencies
Updated project dependencies and tooling versions
The project's \package.json\ and \yarn.lock\ have been updated to use newer versions of key dependencies and dev dependencies. Notable updates include Express 5.2.1, Inversify 8.1.1, TypeScript 6.0.3, ESLint 10.6.0, and Jest 30.4.2, alongside various other library upgrades.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 62 → 61 (-1.4)
- Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 95 → 97 (+2.4)
- Architecture 100 → 88 (-12.2)
- Maturity 66 → 69 (+2.8)
- Readiness 47 → 44 (-2.1)
- Security 73 → 76 (+3.0)
Resolved (26)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Low CVE: [GHSA redacted] (yarn.lock)
- …and 6 more
New (56)
- Documentation: no contributor guidance (README.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 36 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
alexleboucher/docker-express-postgres-boilerplate was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 422d3e659814e468cb0d1cd8389e5ca34f03e22a — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.