bitloops/ddd-hexagonal-cqrs-es-eda
54.6
Adequate · 21 September 2026
9.7k
lines of production code
TypeScript
primary language
4
measurements over time
What this system is
This system is a modern, full-stack application for managing tasks, built with a NestJS backend and a React frontend. It provides secure user authentication via Keycloak and supports real-time updates through Server-Sent Events. The architecture includes a Go-based telemetry consumer for observability and a comprehensive test suite for frontend state management.
Features
Backend development environment and tooling
The backend directory now includes a full set of configuration and infrastructure files to support local development and containerized workflows. A Dockerfile defines a multi-stage build using Node.js 24.18.1 and pnpm, while a \frontend-development.docker-compose.yml\ file orchestrates the backend alongside PostgreSQL, NATS, Keycloak, and observability services (Prometheus, Grafana, Jaeger). A \server-development.docker-compose.yml\ provides a lighter stack for frontend development. The backend is configured with TypeScript (\tsconfig.json\), ESLint, Prettier, and NestJS (\nest-cli.json\) settings. Additionally, a \swagger.json\ file exposes the OpenAPI 3.0.0 specification for the REST API, and a \.template-env\ file provides default environment variables for OIDC and database connections.
backend · high confidence
Frontend build and configuration scaffolding
The frontend area now includes the foundational build and configuration files required to run the application. This includes a Dockerfile for containerizing the React/Vite app, an Nginx configuration for serving the static assets and handling health checks, and TypeScript configuration files (tsconfig) for the application and node environments. Additionally, an ESLint configuration is added for code quality, and an OpenAPI TypeScript configuration is provided to generate the API client. The Vite build configuration is also established to support React development.
frontend · high confidence
Implement user authentication and real-time todo updates via SSE
The backend now enforces OIDC-based authentication using a Keycloak identity provider, securing all REST and SSE endpoints with an \OidcAuthGuard\. The API module configures the necessary infrastructure (Postgres, Jetstream/NATS, and tracing). A new \TodoSSEController\ establishes Server-Sent Events (SSE) streams, allowing clients to subscribe to real-time todo events (added, completed, deleted, modified). The system processes integration events (e.g., \TodoAddedIntegrationEvent\) via dedicated handlers that broadcast updates to subscribed clients. Additionally, an outbox pattern is implemented in the IAM context to reliably publish user registration and email change events.
backend/src · high confidence
Introduce Go-based telemetry consumer for NATS, Prometheus, and Jaeger
Added a new telemetry consumer service written in Go that subscribes to NATS JetStream streams containing observability data. The service processes incoming trace and metric events, routing traces to a Jaeger endpoint and pushing counters (for commands, queries, domain/integration events, and controllers) to a Prometheus Pushgateway. The implementation includes the main entry point, NATS connection logic, and dedicated modules for metrics and tracing, along with a Dockerfile for containerization.
telemetry-consumer · high confidence
Major frontend refactor introducing a new API client and event bus
The frontend application has been refactored to use a new, auto-generated API client built with @hey-api/openapi-ts, which provides typed methods for all backend endpoints (auth, todos, SSE) and includes a robust HTTP client with interceptors and serialization utilities. Additionally, a global event bus has been introduced to manage application-wide events such as authentication changes, toast notifications, and server-sent state updates, decoupling the UI components from direct API calls and centralizing state synchronization.
frontend/src · high confidence
Behavioural changes
Added default Grafana configuration file
A new configuration file for Grafana has been added, setting the default admin username to 'admin' with a placeholder password, and disabling user sign-up by default.
grafana · low confidence
Modernized architecture with Keycloak IAM, PostgreSQL, and updated dependencies
The project has been modernized to use Keycloak for authentication (OpenID Connect Authorization Code Flow with PKCE) and PostgreSQL as the sole application database, replacing previous MongoDB and local credential-based auth. The backend now uses NestJS 11, Fastify 5, and the \ddd-tactical-core-boilerplate\ package, while the frontend utilizes Vite 7, Redux Toolkit, and React 19.2. The repository also includes updated documentation, Kubernetes manifests, and a pnpm workspace configuration.
(repo-wide) · high confidence
Test coverage
Added frontend test suite for todo state and mapping
Added a new test suite in the frontend to verify the Redux reducer's handling of todo state transitions and the anti-corruption layer that maps backend events to UI actions. The suite includes Cucumber scenarios for the todo reducer (covering initialization, adding, deleting, completing, and modifying todos) and unit tests for the TodoMapper, ensuring that backend fields like \completed\ are correctly translated to the frontend's \isCompleted\ and that lifecycle events are properly transformed.
_frontend/tests, frontend/tests/features/step\definitions · high confidence
Dependencies
Updated frontend and backend dependencies
The frontend and backend package.json files have been updated with new dependencies, including React 19.2.8, NestJS 11.1.28, and Fastify 5.11.0. The telemetry consumer's Go dependencies have also been updated, specifically bumping golang.org/x/crypto to v0.52.0 and google.golang.org/protobuf to v1.33.0.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 57 → 55 (-2.2)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 80 → 80 (+0.5)
- Architecture 100 → 80 (-19.7)
- Maturity 67 → 67 (+0.7)
- Readiness 44 → 44 (-0.9)
- Security 63 → 61 (-2.3)
- Accessibility 63 → 60 (-2.2)
Resolved (22)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Further orphaned files (smaller)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- LLM evaluation failed
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Medium CVE: GO-2025-3955 (telemetry-consumer/go.mod)
- Medium vulnerability: GO-2026-5841 (telemetry-consumer/go.mod)
- Medium vulnerability: GO-2026-5932 (telemetry-consumer/go.mod)
- No exposed public API
- …and 2 more
New (387)
- Deprecated module: go.opentelemetry.io/otel/exporters/jaeger
- FunctionTooLong: client.createClient (frontend/src/api/client/client.ts)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High IaC: WD-COMPOSE-0002 (docker-compose.yml)
- High IaC: WD-COMPOSE-0002 (docker-compose.yml)
- High IaC: WD-COMPOSE-0002 (docker-compose.yml)
- High IaC: WD-COMPOSE-0002 (docker-compose.yml)
- High IaC: WD-COMPOSE-0002 (docker-compose.yml)
- High IaC: WD-COMPOSE-0002 (docker-compose.yml)
- High IaC: WD-K8S-0002 (k8s/secret-bl-keycloak-secret.yaml)
- High IaC: WD-K8S-0002 (k8s/secret-bl-postgres-secret.yaml)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 367 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
bitloops/ddd-hexagonal-cqrs-es-eda was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit c05b2dee2ea5d74c8ad2e39d658317fd67aff988 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.