eryzerz/nestjs-ddd
63.4
Adequate · 21 September 2026
2.4k
lines of production code
TypeScript
with JavaScript
4
measurements over time
What this system is
This system is a NestJS application implementing Domain-Driven Design (DDD) principles, focused on managing products, promotions, and users. It enforces business rules, such as validating promotional codes during order creation, and utilizes safe database migration strategies. The system has been refactored to remove GraphQL infrastructure and unused dependencies, indicating a shift away from GraphQL-based APIs.
Behavioural changes
Database rollback operations changed from destructive to safe
The database migration rollback logic has been updated to use safe deletion statements instead of dropping tables. Specifically, the 'down' methods for the Product and Promo tables now execute 'DELETE FROM' commands rather than 'DROP TABLE', ensuring that the database schema structure is preserved when rolling back migrations.
migration · high confidence
Enforce promo validity period during order creation
The order creation process now validates that the current date falls within the active start and end dates of a promotional code. If the current time is outside the promotion's valid window, the system throws a 'Promo cannot be used for today' error, preventing orders from being created with expired or future promotions.
src/orders · high confidence
Removal of GraphQL and database seeding infrastructure
The application no longer supports GraphQL or database seeding. The GraphQL module has been removed from the NestJS application configuration, and the associated schema file (src/schema.graphql) has been deleted. Additionally, the product factory and seed files used for database seeding have been removed. In the database configuration, the 'synchronize' option has been changed from false to true, and migration-related settings have been removed.
src · high confidence
Removed GraphQL resolvers and decorators from the users module
The user management module no longer exposes GraphQL endpoints for users. The \UserResolver\ class and its associated GraphQL decorators (\@Field\, \@InputType\, \@ObjectType\) have been removed from the codebase. This means that user-related queries and mutations are no longer available through the GraphQL API, effectively decoupling the user domain from the GraphQL layer.
src/users · high confidence
Dependencies
Update project name and remove unused dependencies
The project name in package-lock.json has been changed from 'base-app' to 'nestjs-ddd'. Additionally, several unused dependencies have been removed from package.json and package-lock.json, including @apollo/client, @apollo/federation, @apollo/gateway, apollo-server-express, graphql, graphql-tools, mongodb, typeorm-seeding, and their associated sub-dependencies.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 37 → 63 (+26.8)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 86 → 94 (+7.2)
- Architecture 100 → 100 (+0.0)
- Maturity 50 → 56 (+5.5)
- Readiness 53 → 53 (+0.3)
- Security 75 → 83 (+8.2)
Resolved (58)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical vulnerability: [GHSA redacted] (package-lock.json)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 38 more
New (97)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical vulnerability: [GHSA redacted] (package-lock.json)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (the committed lockfile is in a format this engine cannot resolve)
- Documentation: no architecture or design documentation (README.md)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 77 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
eryzerz/nestjs-ddd was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 16bd1dfc7c1c368dec1b99788c07aeffe365f0f7 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.