Skip to content
CAI
Software that uses CAICheck a score

eryzerz/nestjs-ddd

63.4

Adequate · 21 September 2026

2.4k

lines of production code

TypeScript

with JavaScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a NestJS application implementing Domain-Driven Design (DDD) principles, focused on managing products, promotions, and users. It enforces business rules, such as validating promotional codes during order creation, and utilizes safe database migration strategies. The system has been refactored to remove GraphQL infrastructure and unused dependencies, indicating a shift away from GraphQL-based APIs.

Behavioural changes

Database rollback operations changed from destructive to safe

The database migration rollback logic has been updated to use safe deletion statements instead of dropping tables. Specifically, the 'down' methods for the Product and Promo tables now execute 'DELETE FROM' commands rather than 'DROP TABLE', ensuring that the database schema structure is preserved when rolling back migrations.

migration · high confidence

Enforce promo validity period during order creation

The order creation process now validates that the current date falls within the active start and end dates of a promotional code. If the current time is outside the promotion's valid window, the system throws a 'Promo cannot be used for today' error, preventing orders from being created with expired or future promotions.

src/orders · high confidence

Removal of GraphQL and database seeding infrastructure

The application no longer supports GraphQL or database seeding. The GraphQL module has been removed from the NestJS application configuration, and the associated schema file (src/schema.graphql) has been deleted. Additionally, the product factory and seed files used for database seeding have been removed. In the database configuration, the 'synchronize' option has been changed from false to true, and migration-related settings have been removed.

src · high confidence

Removed GraphQL resolvers and decorators from the users module

The user management module no longer exposes GraphQL endpoints for users. The \UserResolver\ class and its associated GraphQL decorators (\@Field\, \@InputType\, \@ObjectType\) have been removed from the codebase. This means that user-related queries and mutations are no longer available through the GraphQL API, effectively decoupling the user domain from the GraphQL layer.

src/users · high confidence

Dependencies

Update project name and remove unused dependencies

The project name in package-lock.json has been changed from 'base-app' to 'nestjs-ddd'. Additionally, several unused dependencies have been removed from package.json and package-lock.json, including @apollo/client, @apollo/federation, @apollo/gateway, apollo-server-express, graphql, graphql-tools, mongodb, typeorm-seeding, and their associated sub-dependencies.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 37 → 63 (+26.8)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 86 → 94 (+7.2)
  • Architecture 100 → 100 (+0.0)
  • Maturity 50 → 56 (+5.5)
  • Readiness 53 → 53 (+0.3)
  • Security 75 → 83 (+8.2)

Resolved (58)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical vulnerability: [GHSA redacted] (package-lock.json)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • …and 38 more

New (97)

  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical vulnerability: [GHSA redacted] (package-lock.json)
  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (the committed lockfile is in a format this engine cannot resolve)
  • Documentation: no architecture or design documentation (README.md)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • …and 77 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

eryzerz/nestjs-ddd was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 16bd1dfc7c1c368dec1b99788c07aeffe365f0f7 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.