Skip to content
CAI
Software that uses CAICheck a score

ever-co/ever-api-starter-kit

51.0

Adequate · 21 September 2026

1.6k

lines of production code

TypeScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Added TypeORM database configuration for PostgreSQL

A new \orm-config.ts\ file has been added to configure the TypeORM data source. This configuration sets up a PostgreSQL connection using environment variables for credentials and host, with support for SSL/TLS connections via a base64-encoded CA certificate. It enables automatic migration execution and file-based query logging.

src · high confidence

Centralized export of core entity classes

A new barrel file at src/core/entities/index.ts has been added to centralize the export of core entity classes, specifically Base and Employee, making them easily accessible from a single entry point.

src/core · medium confidence

Behavioural changes

Enforced commit message linting and pre-commit formatting

Developers will now have their commit messages validated against linting rules via commitlint, and staged files will be automatically formatted using pretty-quick before each commit. This ensures consistent commit history and code style.

.husky · high confidence

Update GraphQLPubSub type in employee resolver

The employee resolver now uses the GraphQLPubSub type from the @ptc-org/nestjs-query-graphql package instead of the generic PubSub from graphql-subscriptions. This change aligns the employee module with the updated NestJS Query GraphQL integration, ensuring consistent pub/sub handling for GraphQL subscriptions.

src/modules/employee · medium confidence

Dependencies

Upgrade to NestJS 11 and Express 5, plus add TypeORM migration scripts

The project has been upgraded to NestJS 11 (including @nestjs/core, @nestjs/common, @nestjs/graphql, etc.) and Express 5, alongside updates to other dependencies like TypeORM, GraphQL, and various utility packages. Additionally, new npm scripts have been added to the project configuration to support TypeORM database migrations (create, generate, run, and rollback), enabling users to manage their database schema changes directly through the command line.

(dependencies) · medium confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 51 → 51 (-0.3)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 94 → 85 (-9.2)
  • Architecture 89 → 89 (-0.5)
  • Maturity 88 → 88 (+0.0)
  • Readiness 34 → 31 (-2.7)
  • Security 40 → 47 (+6.7)
  • Domain Modelling 100 → 100 (+0.0)

Resolved (120)

  • Build action pinned to a mutable branch
  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical IaC: DS-0031 (.deploy/api/Dockerfile)
  • Critical vulnerability: [GHSA redacted] (yarn.lock)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • …and 100 more

New (302)

  • Assertions commented out: should return "Hello World!" (src/app.controller.spec.ts)
  • Base-context workflow trigger runs with an unscoped token
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical IaC: DS-0031 (.deploy/api/Dockerfile)
  • Critical IaC: DS-0031 (.deploy/api/Dockerfile)
  • Critical IaC: DS-0031 (.deploy/api/Dockerfile)
  • Critical IaC: DS-0031 (.deploy/api/Dockerfile)
  • Critical IaC: DS-0031 (.deploy/api/Dockerfile)
  • Critical IaC: DS-0031 (.deploy/api/Dockerfile)
  • Critical IaC: DS-0031 (.deploy/api/Dockerfile)
  • Critical IaC: DS-0031 (.deploy/api/Dockerfile)
  • Critical IaC: DS-0031 (.deploy/api/Dockerfile)
  • …and 282 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

ever-co/ever-api-starter-kit was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 2856985de63773188d8b5ba9252a29ec52b69a3d — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.