Skip to content
CAI
Software that uses CAICheck a score

cecric/hexapinod

50.6

Adequate · 21 September 2026

4.3k

lines of production code

TypeScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Hexapinod is a TypeScript-based Node.js framework that provides a hexagonal architecture skeleton for building scalable applications. It integrates TypeORM for database interactions, Express for HTTP routing, and Socket.IO for real-time WebSocket communication. The system includes middleware for centralized error handling and JWT authentication, alongside a service manager for dynamic component loading and event-driven architecture.

Features

Add CLI wrapper for TypeORM commands

The application now includes a CLI wrapper for TypeORM, allowing users to execute database operations such as migrations, schema synchronization, and entity generation directly through the command line interface. This change introduces a new \typeorm\ command that proxies TypeORM CLI commands, enabling seamless integration with the framework's configuration and path handling.

src/application/cli · high confidence

Add MySQL database manager with connection pooling

A new DBManager class has been introduced in the MySQL manager module, providing both synchronous and asynchronous access to MySQL connection pools. This change enables the application to manage database connections more efficiently by reusing existing connections, reducing the overhead of establishing new connections for each request. The implementation includes error handling for common database issues like connection loss and too many connections, and integrates with the existing logger for monitoring.

src/dependencies/mysql-manager · high confidence

Add TypeORM integration to the framework

Introduced a new \TypeOrmWrapper\ class that extends the existing \OrmWrapper\ to provide TypeORM support within the framework. This change adds an initialization step that loads database configurations and manages connections, along with a \getRepository\ method that returns the appropriate repository for a given entity model, enabling the framework to interact with TypeORM-based data access layers.

src/dependencies/typeorm-wrapper · high confidence

Add TypeORM support to the framework

The framework now includes an abstract \OrmWrapper\ class that provides an initialization step and a \getRepository\ method, enabling the integration of external Object-Relational Mappers (ORMs) such as TypeORM. This change introduces a new layer for database interactions, allowing services to retrieve repository instances through a standardized interface.

src/dependencies/hexapinod-framework/model · high confidence

Add configuration reader for loading and templating JSON config files

A new ConfigurationReader singleton has been introduced to load JSON configuration files from a specified directory. The reader supports environment variable templating, allowing configuration values to be dynamically replaced using a \{{process.env.VARIABLE}}\ syntax. It also automatically converts string values of 'true' or 'false' into boolean types. This component is now available for use in managing application settings.

src/dependencies/configuration-reader · high confidence

Add example model classes for standard and TypeORM-based entities

The models directory now includes two new example entity classes: a basic \Example\ model extending the framework's base \Model\ without an ORM, and an \ExampleOrm\ class that integrates with TypeORM using decorators like \@TypeORM.Entity()\ and \@TypeORM.Column()\. These serve as reference implementations for defining data models in both plain and database-mapped contexts.

src/core/example/models · high confidence

Added API call wrapper and WebSocket server implementation

The API layer now includes an \apiCallWrapper\ utility that automatically catches and forwards exceptions from API call handlers, ensuring consistent error handling. Additionally, a new \WSServer\ class has been introduced to manage WebSocket connections using Socket.io, supporting room-based subscriptions and disconnections, while the main \ApplicationServer\ integrates this WebSocket server alongside existing HTTP route and middleware configurations.

src/application/api · high confidence

Added JWT authentication middleware

A new JWT authentication middleware has been introduced to the API REST layer. It validates incoming requests by verifying JSON Web Tokens, extracting user information, and attaching the authenticated user to the request session. If validation fails or the token is invalid, an AccessDeniedException is thrown.

src/application/api/rest/middlewares/example · high confidence

Added TypeORM integration and repository examples in infrastructure

The infrastructure layer now includes a new TypeORM-based repository implementation (exampleorm.typeorm.repo.ts) alongside the existing standard repository (example.repo.ts). This adds support for TypeORM as a database access mechanism, providing an alternative to the previous approach. Additionally, a test repository (test/example.repo.ts) has been added to demonstrate in-memory testing capabilities, and README files have been added to explain the repository structure and usage.

src/infrastructure · high confidence

Added example API routes for OpenAPI and JWT authentication

Introduced new example endpoints to demonstrate API documentation and authentication flows. The \example.routes.ts\ file adds public and protected GET endpoints (\/example\, \/second-example\, \/protected-path/example\) annotated with JSDoc comments for OpenAPI and APIDocJS documentation. The \jwtauth.routes.ts\ file implements JWT-based authentication with \/authorize\ and \/refresh\ POST endpoints, enabling token generation and refresh capabilities for the example application.

src/application/api/rest/routes/example · medium confidence

Added example event listeners for authentication and WebSocket communication

The \src/core/example/eventslisteners\ directory now includes new example event listeners: \AuthentificationListener\ handles login attempts and successful authentication events, while \WebSocketsListener\ manages WebSocket connections, disconnections, and message broadcasting to sockets, rooms, and all connected clients. These additions provide concrete examples of how to implement event listeners for authentication and real-time communication features.

src/core/example/eventslisteners · high confidence

Added example service and validator schema

The src/core/example/services directory now includes a README.md explaining how to create and load services dynamically, and a new validator folder containing an example AJV schema (example.schema.ts) that validates email and date formats.

src/core/example/services · high confidence

Added example use cases demonstrating framework integration

Added example use cases that demonstrate how to implement and integrate with the framework's core features. The new \ExampleUsecases\ class provides reference implementations for using the validator service, event dispatching, repository access, and sub-process launching. Additionally, \AuthentificationUsecases\ and \ExampleTestUsecases\ are introduced to showcase authentication flows and testing patterns using the \ServiceManager\ and \EventsManager\. A README is also added to explain the structure and conventions for writing use cases.

src/core/example/usecases · high confidence

Added subprocess use case for service execution

A new SubProcessUsecases class was added to handle subprocess operations. This component listens for 'launch' messages, retrieves a service by path, and executes it in a subprocess environment, with error handling and logging integrated via the framework's logger and service manager.

src/core/hexapinod/usecases · medium confidence

Automatic REST route discovery and registration

The application now automatically discovers and registers REST route modules by scanning the routes directory for files ending in .routes.ts or .routes.js. This eliminates the need for manual route registration, as each matching file is dynamically imported and its default export is attached to the Express router.

src/application/api/rest/routes · high confidence

Initial release of Hexapinod framework with ESM support and TypeORM integration

The Hexapinod framework is introduced as a TypeScript-based, hexagonal architecture skeleton for Node.js applications. This release enables ES Modules (ESM) by switching the TypeScript configuration from CommonJS to ESM, allowing modern module resolution. It also integrates TypeORM for database interactions and provides a preconfigured project structure including CLI commands for server and subprocess management, along with API documentation generation via OpenAPI and APIDocJS.

(repo-wide) · high confidence

Introduce ServiceManager for managing and initializing framework services

The framework now includes a ServiceManager that automatically discovers, loads, and initializes services from the core bundles. This new component manages the lifecycle of services, handling their instantiation, initialization, and persistent caching. It supports both persistent and transient service modes and provides a unified interface for retrieving service instances by name.

src/dependencies/hexapinod-framework/service-manager · high confidence

Introduce core event handling and use-case base classes

The framework now includes a new event management system, introducing a singleton \EventsManager\ that automatically discovers and registers event listeners from core bundles, supporting both synchronous and asynchronous dispatch. Additionally, a base \UseCases\ class has been added to serve as a common interface for all use-case implementations.

src/dependencies/hexapinod-framework/events · medium confidence

Introduce new structured logging utility

A new LoggerTool class has been added to handle application logging, featuring distinct methods for error, warn, info, and success log levels. The implementation supports structured logging by serializing objects using the 'flatted' library to handle circular references, and applies colorized output via 'chalk' for better readability in the console.

src/dependencies/logger · high confidence

New exception classes for HTTP error handling

Added new exception classes for the hexapinod module, including AccessDeniedException, GenericException, InvalidAccessException, InvalidParametersException, NoContentException, and NotFoundException. These classes extend the standard Error class and are intended to be used by the Express middleware to return specific HTTP status codes (401, 500, 403, 400, 204, and 404 respectively).

src/core/hexapinod/exceptions · high confidence

New interface contracts for user and example repositories

The \src/core/example/interfaces\ directory now contains new interface definitions that establish contracts for the application's data access layer. Specifically, \models/user.interface.ts\ introduces the \IUser\ interface, which defines methods for managing user identity, email, and password. Additionally, \repositories/example.interface.ts\ and \repositories/exampleorm.interface.ts\ define the \IExample\ and \IExampleOrm\ repository interfaces, both extending the base \IRepository\ contract to specify asynchronous retrieval of \Example\ and \ExampleOrm\ entities, respectively.

src/core/example/interfaces · high confidence

New service architecture for repositories and validation

The framework introduces a new service structure in src/core/hexapinod/services, adding an OrmRepositoriesService for TypeORM integration and a RepositoriesService for native repository loading. Additionally, a ValidatorService is added to handle schema-based validation using AJV, allowing the system to validate data against defined schemas across bundles.

src/core/hexapinod/services · high confidence

Behavioural changes

Add centralized error handling middleware for the REST API

A new error middleware has been introduced to standardize how the API handles exceptions. It catches specific custom exceptions (such as InvalidAccess, NotFound, and AccessDenied) and returns appropriate HTTP status codes (400, 401, 403, 404, 500) along with structured error responses. For non-production environments, the middleware also includes stack traces in the response, while all errors are logged via the application logger.

src/application/api/rest/middlewares · medium confidence

Test coverage

Added initial test coverage for example use cases and utility functions

Added new test files in the application layer to verify the behavior of example use cases (specifically the test validator and database repository actions) and a basic 'Hello World' utility function, ensuring these components return expected results.

src/application/tests · high confidence

Dependencies

Initial release of Hexapinod framework with TypeScript, Express, and Socket.IO support

The project introduces a new Node.js/TypeScript framework skeleton called Hexapinod, featuring Express for HTTP, Socket.IO for websockets, TypeORM for database access, and Redis for session/state management. It includes development tools like ESLint, Mocha, and Typedoc, and specifies a minimum Node.js version of 14.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 51 → 51 (-0.8)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 58 → 59 (+0.6)
  • Architecture 100 → 92 (-8.1)
  • Maturity 55 → 51 (-4.4)
  • Readiness 36 → 39 (+3.1)
  • Security 75 → 79 (+4.0)

Resolved (56)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • …and 36 more

New (102)

  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • EventsManagerTool.readPath (cognitive 19) (src/dependencies/hexapinod-framework/events/eventsmanager.ts)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • …and 82 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

cecric/hexapinod was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit bdc74deedc99479ea92e545a1254ef92a47c9132 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.