Skip to content
CAI
Software that uses CAICheck a score

fmcarrero/nest-js-products-api

57.8

Adequate · 21 September 2026

522

lines of production code

TypeScript

with JavaScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This is a Node.js-based backend service built with NestJS, designed to manage product data via a RESTful API. It handles product creation and retrieval using MongoDB, with strict validation ensuring prices are positive. The system includes comprehensive end-to-end testing and containerized deployment support.

Features

Added Docker support and project licensing

The project now includes a Dockerfile for containerized builds using Node.js 10, along with a corresponding .dockerignore file. Environment configuration files (development.env, test.env) are added to support local and testing setups with MongoDB connection details. Additionally, an MIT LICENSE file has been added to clarify the project's licensing terms.

(repo-wide) · high confidence

Behavioural changes

Adopt Optional return types for repository operations

Repository methods (create, get, delete, update) now return Optional\<Product\> instead of Product, allowing callers to handle missing or null results explicitly rather than relying on undefined or exceptions. The Product domain class now validates that price is greater than zero, throwing a specific exception if not. The HTTP exception filter was updated to catch and handle this new business exception, returning a 400 status code. The product controller was changed to accept a new ProductCommand DTO for input, and the application layer was updated to use a ProductFactory for creating Product instances from commands.

src/infrastructure · high confidence

App initialization and global exception handling updated

The application entry point (main.ts) now initializes the NestJS app using a new static factory method on the AppModule, and registers a global HTTP exception filter to handle errors consistently across the application.

src · medium confidence

Test coverage

Added e2e test for products endpoint

Added an end-to-end test for the products API, including a JSON fixture and a NestJS-based test that spins up a MongoDB container to verify the POST /products/ endpoint returns a 201 status and the correct price. Removed the previous generic app.e2e-spec.ts test.

test · high confidence

Dependencies

Update project dependencies and test configuration

The project's dependency tree has been updated, adding new packages such as JSONStream, any-promise, bl, buffer-alloc, byline, and default-gateway to the lockfile. Additionally, the package.json has been updated to include the 'dotenv' and 'typescript-optional' libraries, while 'testcontainers' has been added as a development dependency. The test scripts have also been modified to include the DEBUG environment variable for testcontainers and additional Jest flags for handling open handles.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 58 → 58 (+0.0)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 94 → 93 (-1.3)
  • Architecture 57 → 55 (-1.4)
  • Maturity 61 → 61 (+0.0)
  • Readiness 49 → 51 (+1.8)
  • Security 73 → 81 (+7.4)

Resolved (63)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical vulnerability: [GHSA redacted] (package-lock.json)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • …and 43 more

New (98)

  • Coverage not measured — JavaScript/TypeScript suite
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical vulnerability: [GHSA redacted] (package-lock.json)
  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (the committed lockfile is in a format this engine cannot resolve)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no licence statement (README.md)
  • Documentation: no usage examples (README.md)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • …and 78 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

fmcarrero/nest-js-products-api was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit c809e70c8efec173509cbed726993f0afb01528c — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.