fmcarrero/nest-js-products-api
57.8
Adequate · 21 September 2026
522
lines of production code
TypeScript
with JavaScript
4
measurements over time
What this system is
This is a Node.js-based backend service built with NestJS, designed to manage product data via a RESTful API. It handles product creation and retrieval using MongoDB, with strict validation ensuring prices are positive. The system includes comprehensive end-to-end testing and containerized deployment support.
Features
Added Docker support and project licensing
The project now includes a Dockerfile for containerized builds using Node.js 10, along with a corresponding .dockerignore file. Environment configuration files (development.env, test.env) are added to support local and testing setups with MongoDB connection details. Additionally, an MIT LICENSE file has been added to clarify the project's licensing terms.
(repo-wide) · high confidence
Behavioural changes
Adopt Optional return types for repository operations
Repository methods (create, get, delete, update) now return Optional\<Product\> instead of Product, allowing callers to handle missing or null results explicitly rather than relying on undefined or exceptions. The Product domain class now validates that price is greater than zero, throwing a specific exception if not. The HTTP exception filter was updated to catch and handle this new business exception, returning a 400 status code. The product controller was changed to accept a new ProductCommand DTO for input, and the application layer was updated to use a ProductFactory for creating Product instances from commands.
src/infrastructure · high confidence
App initialization and global exception handling updated
The application entry point (main.ts) now initializes the NestJS app using a new static factory method on the AppModule, and registers a global HTTP exception filter to handle errors consistently across the application.
src · medium confidence
Test coverage
Added e2e test for products endpoint
Added an end-to-end test for the products API, including a JSON fixture and a NestJS-based test that spins up a MongoDB container to verify the POST /products/ endpoint returns a 201 status and the correct price. Removed the previous generic app.e2e-spec.ts test.
test · high confidence
Dependencies
Update project dependencies and test configuration
The project's dependency tree has been updated, adding new packages such as JSONStream, any-promise, bl, buffer-alloc, byline, and default-gateway to the lockfile. Additionally, the package.json has been updated to include the 'dotenv' and 'typescript-optional' libraries, while 'testcontainers' has been added as a development dependency. The test scripts have also been modified to include the DEBUG environment variable for testcontainers and additional Jest flags for handling open handles.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 58 → 58 (+0.0)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 94 → 93 (-1.3)
- Architecture 57 → 55 (-1.4)
- Maturity 61 → 61 (+0.0)
- Readiness 49 → 51 (+1.8)
- Security 73 → 81 (+7.4)
Resolved (63)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical vulnerability: [GHSA redacted] (package-lock.json)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 43 more
New (98)
- Coverage not measured — JavaScript/TypeScript suite
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical vulnerability: [GHSA redacted] (package-lock.json)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (the committed lockfile is in a format this engine cannot resolve)
- Documentation: no installation or build instructions (README.md)
- Documentation: no licence statement (README.md)
- Documentation: no usage examples (README.md)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 78 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
fmcarrero/nest-js-products-api was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit c809e70c8efec173509cbed726993f0afb01528c — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.