EduardoPires/EquinoxProject
46.7
Weak · 28 September 2026
2.3k
lines of production code
C#
primary language
7
measurements over time
What this system is
This system is a customer management application built on .NET 9 that implements an event-sourced architecture using SQL for persistence. It provides capabilities for registering, updating, and removing customers, while tracking their history through a normalized event timeline. The platform secures access via ASP.NET Core Identity with JWT authentication and enforces architectural integrity through automated tests.
How it got here
2016 — .NET 9 migration and event sourcing implementation
9 changes.
The project was upgraded to .NET 9.0, replacing MediatR and AutoMapper with NetDevPack and custom mapping solutions. This period focused on implementing a SQL-based event sourcing infrastructure, including new contexts, repositories, and database migrations for persisting customer data and domain events.
2017–2024 — Modernization and identity integration
7 changes.
The project underwent extensive modernization by migrating to .NET 9 and adopting minimal API hosting, while refactoring data access and dependency injection patterns. Concurrently, a complete identity subsystem was implemented, introducing JWT authentication, role-based authorization, and ASP.NET Core Identity for user management. The codebase was further stabilized with dedicated EF Core configurations and architecture tests to enforce structural integrity.
Features
Added ASP.NET Core Identity for user authentication and authorization
The application now includes a complete user identity system, enabling users to register new accounts, log in with local credentials, and log out. This change introduces ASP.NET Core Identity with Razor Pages for the account management UI (Login, Register, Logout) and controllers for customer management protected by role-based authorization. It also sets up the underlying database schema via Entity Framework Core migrations for users, roles, and claims, and configures dependency injection and database contexts to support these identity features.
src/Equinox.UI.Web · high confidence
Initial database schema for Customers and StoredEvent tables
The application now includes the initial Entity Framework Core migrations to create the 'Customers' and 'StoredEvent' database tables. The 'Customers' table stores user identity information including Name, Email, and BirthDate, while the 'StoredEvent' table supports the event sourcing architecture by persisting event data, aggregate IDs, and timestamps. These migrations establish the foundational data structure required for the application's domain models.
src/Equinox.Infra.Data/Migrations · high confidence
Introduce customer history tracking and event-sourced normalizers
The application now exposes a customer history feature that aggregates past events into a readable timeline. This is implemented via new \CustomerHistory\ and \CustomerHistoryData\ classes in the \EventSourcedNormalizers\ namespace, which deserialize stored events and map them to user-friendly actions (Registered, Updated, Removed). The \CustomerAppService\ now includes a \GetAllHistory\ method that retrieves these normalized history records from the event store, and the \ICustomerAppService\ interface has been updated to expose this capability to consumers.
src/Equinox.Application · high confidence
Introduction of SQL-based event sourcing and customer repository
The data access layer now includes a new \CustomerRepository\ for managing customer entities and a new \EventStoreSqlRepository\ implementing \IEventStoreRepository\ to persist and retrieve domain events using SQL. The customer repository utilizes \AsNoTracking()\ for read operations to improve performance, while the event store repository provides methods to store and fetch events by aggregate ID.
src/Equinox.Infra.Data/Repository · high confidence
Introduction of SQL-based event store implementation
A new SqlEventStore class has been added to the EventSourcing infrastructure, providing a concrete implementation of the IEventStore interface that persists domain events to a SQL database. This component handles event serialization using Newtonsoft.Json to support complex object inheritance and stores events via the underlying IEventStoreRepository, while also capturing user identity information for audit purposes.
src/Equinox.Infra.Data/EventSourcing · high confidence
New identity infrastructure with JWT authentication and role-based authorization
This update introduces a complete identity subsystem for the application, adding JWT-based authentication and role-based access control. It includes configuration for ASP.NET Core Identity with Entity Framework Core migrations (supporting both SQLite for development and SQL Server for production), a builder pattern for generating JWT tokens, and custom authorization filters that enforce claim-based permissions. The change also adds models for user login/registration, user responses, and extensions to extract user claims from the principal.
src/Equinox.Infra.CrossCutting.Identity · high confidence
Behavioural changes
1 commit (0 fixes) modifying sql
A change to existing behaviour in sql — 1 commit, 1 file.
sql · low confidence · unverified
Customer domain model and command handling refactored to NetDevPack
The customer management logic in the domain layer has been rewritten to use the NetDevPack framework. This introduces a new Customer entity and associated command handlers for registering, updating, and removing customers, replacing the previous implementation. The change includes new validation rules (via FluentValidation) ensuring email uniqueness and age requirements, and implements event-driven notifications for customer lifecycle changes using NetDevPack's mediator pattern.
src/Equinox.Domain · high confidence
Introduce separate EF Core entity configuration classes for Customer and StoredEvent
The data access layer now uses dedicated configuration classes (CustomerMap and StoredEventMap) implementing IEntityTypeConfiguration to define how the Customer and StoredEvent domain models map to the database. This refactors the mapping logic out of the main context, explicitly configuring column names (such as mapping Timestamp to CreationDate and MessageType to Action) and data types (varchar(100)) for these entities, aligning the codebase with EF Core 2.0 best practices for organized entity configuration.
src/Equinox.Infra.Data/Mappings · high confidence
Introduction of EF Core data contexts with domain event handling
The application now uses Entity Framework Core for data access, introducing \EquinoxContext\ for general domain data and \EventStoreSqlContext\ for event storage. \EquinoxContext\ implements the Unit of Work pattern and automatically publishes domain events before saving changes, ensuring consistency between state and event logs. String columns are globally configured as \varchar(100)\, and query tracking is disabled by default for performance.
src/Equinox.Infra.Data/Context · high confidence
Migrate API to .NET 6 minimal hosting model
The Equinox API has been upgraded to .NET 6, replacing the previous startup pattern with the minimal hosting model (Program.cs). This change introduces a new configuration structure using extension methods (ApiConfig, DatabaseConfig, SwaggerConfig, DependencyInjectionConfig) to register services and middleware. The application now uses ASP.NET Core Identity endpoints via MapIdentityApi, configures Swagger with JWT Bearer security, and excludes specific Identity endpoints from the Swagger UI. The Dockerfile has been updated to use .NET 6.0 base images, and configuration files (appsettings) have been restructured to support environment-specific settings for Development, Staging, and Testing.
src/Equinox.Services.Api · high confidence
Project migrated to .NET 9.0 with simplified dependencies
The Equinox Project has been upgraded to .NET 9.0, requiring developers to install the .NET SDK 9.0 as specified in the new AGENTS.md setup guide. This release replaces the MediatR library with NetDevPack.SimpleMediator for CQRS handling and removes AutoMapper in favor of custom mapping extensions. The solution structure remains consistent, organizing the code into Presentation, Services, Application, Domain, and Infrastructure layers, while adding architecture tests via NetArchTest.Rules.
(repo-wide) · high confidence
Replaces MediatR with NetDevPack for in-memory event bus
The InMemoryBus implementation now uses NetDevPack's mediator and messaging abstractions instead of the previous MediatR-based approach. This change updates the underlying infrastructure for publishing domain events and sending commands, relying on NetDevPack's interfaces for handling these cross-cutting concerns within the application bus.
src/Equinox.Infra.CrossCutting.Bus · high confidence
Replaces MediatR with NetDevPack.SimpleMediator for dependency injection
The application's dependency injection configuration has been updated to use NetDevPack.SimpleMediator instead of the previous MediatR library. This change modifies how the domain bus and mediator patterns are wired up, specifically registering the IMediator and IMediatorHandler interfaces with the InMemoryBus implementation, and updating the registration of command and event handlers to align with the new mediator's interface contracts.
src/Equinox.Infra.CrossCutting.IoC · high confidence
Test coverage
Added architecture tests to enforce code structure rules
Added a new suite of architecture tests in the \Equinox.Tests.Architecture\ project that use NetArchTest to verify coding standards. These tests ensure that the domain layer remains independent of application and infrastructure layers, that repository classes utilize dependency injection via constructor parameters, that base classes are abstract, and that interfaces follow the 'I' prefix convention. The suite also includes support helpers to aggregate project assemblies and format test output.
tests · high confidence
Dependencies
Upgrade to .NET 9 and update core dependencies
The project has been migrated to the .NET 9 runtime, updating the target framework across all application and test projects. This change includes upgrading Microsoft.AspNetCore and EntityFrameworkCore packages to version 9.0.3, updating Swashbuckle to 8.1.0, and refreshing supporting libraries such as FluentValidation (11.11.0), NetDevPack (8.0.2), and Azure.Identity (1.13.2).
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 50 → 47 (-2.9)
- Rubric changed (rubric-2026.08.20 → rubric-2026.09.16) — scores are not directly comparable.
Lenses
- Code Health 61 → 61 (+0.0)
- Architecture 81 → 81 (+0.0)
- Maturity 55 → 55 (+0.0)
- Readiness 42 → 40 (-1.6)
- Security 52 → 49 (-2.5)
- Domain Modelling 61 → 48 (-12.8)
- Accessibility 65 → 65 (+0.0)
Resolved (18)
- Bounded contexts not declared
- High CVE: System.Security.Cryptography.Xml 9.0.3
- High CVE: System.Security.Cryptography.Xml 9.0.3
- High CVE: System.Security.Cryptography.Xml 9.0.3
- High CVE: System.Security.Cryptography.Xml 9.0.3
- High CVE: System.Security.Cryptography.Xml 9.0.3
- High CVE: System.Security.Cryptography.Xml 9.0.3
- High CVE: System.Security.Cryptography.Xml 9.0.3
- High CVE: System.Security.Cryptography.Xml 9.0.3
- LLM evaluation failed
- Medium IaC: CKV_DOCKER_3 (src/Equinox.Services.Api/Dockerfile)
- Medium IaC: CKV_DOCKER_3 (src/Equinox.UI.Web/Dockerfile)
- No exposed public API
- Secret: generic-api-key (src/Equinox.Services.Api/appsettings.Development.json)
- Secret: generic-api-key (src/Equinox.Services.Api/appsettings.Staging.json)
- Secret: generic-api-key (src/Equinox.Services.Api/appsettings.Testing.json)
- dormant codebase — no living knowledge left to concentrate
- redundant comment (src/Equinox.Domain/Events/CustomerEventHandler.cs)
New (18)
- Documentation: no contributor guidance (README.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- End-of-life runtime: .NET net9.0
- High CVE: System.Security.Cryptography.Xml 9.0.3
- High secret: WD-SECRET-0002 (src/Equinox.Services.Api/appsettings.Development.json)
- High secret: WD-SECRET-0002 (src/Equinox.Services.Api/appsettings.Staging.json)
- High secret: WD-SECRET-0002 (src/Equinox.Services.Api/appsettings.Testing.json)
- Leaked secret: high-entropy-secret (src/Equinox.Services.Api/appsettings.Staging.json)
- Leaked secret: high-entropy-secret (src/Equinox.Services.Api/appsettings.Testing.json)
- Medium IaC: WD-DOCKER-0003 (src/Equinox.Services.Api/Dockerfile)
- Medium IaC: WD-DOCKER-0003 (src/Equinox.Services.Api/Dockerfile)
- Medium IaC: WD-DOCKER-0003 (src/Equinox.UI.Web/Dockerfile)
- Medium IaC: WD-DOCKER-0003 (src/Equinox.UI.Web/Dockerfile)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- No dependency advisory monitoring
API surface
- Unchanged — 16 HTTP endpoints
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
EduardoPires/EquinoxProject was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit fde9a953eb31a31217e1c9d35b385b73adb5e1d3 — the exact code this score is about.
- Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-2d9048c36d26.