gftf2011/clean-node-todolist
53.6
Weak · 21 September 2026
5.6k
lines of production code
TypeScript
with JavaScript
4
measurements over time
What this system is
This system is a backend application that manages users and notes, supporting both REST and GraphQL APIs. It utilizes a layered architecture with distinct controllers, handlers, and repositories, backed by a PostgreSQL database. The codebase includes comprehensive test coverage for both unit and end-to-end scenarios, utilizing test doubles and spies to validate the new service implementations.
Features
Add PostgreSQL initialization scripts for dev and test environments
New shell scripts have been added for the dev and test environments to automatically provision the PostgreSQL database. These scripts create the \users\ and \notes\ tables within their respective schemas, define necessary indexes and clustering, and configure user permissions and ownership, ensuring the database is correctly initialized for both development and testing workflows.
scripts · high confidence
Added Docker Compose configurations for PostgreSQL in dev and test environments
New Docker Compose files and associated Dockerfiles have been added for both the development and test environments. These configurations define a PostgreSQL 14 container, each with specific environment variables, volume mounts for initialization scripts, and port mappings. The development setup allows 10 maximum connections, while the test setup is configured for 1, ensuring appropriate resource allocation for each environment.
docker · high confidence
Introduce GraphQL API alongside REST for note and authentication operations
The application now exposes a GraphQL API via Apollo Server, providing endpoints for authentication (sign-in, sign-up) and note management (create, update, delete, and retrieve notes). This is supported by new adapter classes that bridge the existing REST controllers to the GraphQL resolver pattern, along with an authentication directive that enforces middleware-based authorization on protected fields. The server initialization has been updated to configure and start the Apollo server alongside the existing Express REST routes.
src/main · high confidence
Introduces a structured, layered architecture for handling notes and user operations
The application now uses a clear separation of concerns with dedicated action classes, handlers, and controllers for each operation (create, read, update, delete, and verify). This change introduces a command pattern for actions, a handler layer for business logic, and distinct HTTP and GraphQL controllers that validate input and delegate to the handlers. This structure supports both REST and GraphQL APIs with consistent validation and error handling.
src/app · high confidence
Architecture
Restructured infrastructure layer with new database and repository implementations
The infrastructure layer has been reorganized, moving files from the 'backend' directory to 'src/infra' and updating import paths. New implementations for database connectivity (PostgresConnection, PostgresTransaction) and a circuit-breaker proxy for database queries have been added. Additionally, new repository implementations for 'Note' and 'User' (both remote and local/fake variants) have been introduced, along with factory patterns for repositories and various providers (encryption, decryption, hash, sequencing, token).
src/infra · high confidence
Behavioural changes
Project refactored to root directory with updated test and linting configurations
The project structure has been reorganized by moving configuration files (such as .eslintrc.json, .gitignore, and tsconfig.json) from the 'backend' subdirectory to the repository root. This move is accompanied by updates to the Jest test runner configurations: the unit, integration, and end-to-end test suites now target specific test directories (tests/unit, tests/integration, and tests/e2e respectively) and use updated coverage exclusion patterns. Additionally, the ESLint configuration has been updated to ignore unused variables with an underscore prefix, and the TypeScript build configuration now explicitly excludes the tests directory.
(repo-wide) · high confidence
Removal of generic HTTP contract interfaces
The generic HTTP contract interfaces, specifically \HttpResponse\ and \HttpRequest\, have been removed from the application's contract layer. This eliminates the shared HTTP request and response type definitions that were previously exported from the \backend/src/app/contracts/http\ module, likely as part of a broader refactoring of the backend structure.
backend/src/app/contracts · medium confidence
Removal of in-memory user repository implementation
The in-memory user repository implementation (LocalUserRepositoryFactory and FakeLocalUserRepositoryProduct) has been removed from the backend infrastructure layer. This eliminates the temporary, non-persistent storage mechanism for user data, likely to be replaced by a persistent database-backed repository or a different storage strategy.
backend/src/infra/repositories/user · high confidence
Removal of legacy factory and handler wiring
The backend's legacy factory pattern for user-related operations has been removed. Specifically, the \sign-up.ts\ controller factory, the \create-user\, \find-user-by-email\, and \create-access-token\ handlers, and the \makeBus\ mediator wiring have all been deleted. This eliminates the previous mechanism for instantiating and connecting these specific user management and authentication components.
backend/src/main · high confidence
Removal of repositories index barrel export
The barrel export file at backend/src/infra/repositories/index.ts has been deleted. This removes the consolidated export of the user repository module, meaning consumers must now import from the specific module path rather than the index.
backend/src/infra/repositories · high confidence
Removed authentication controllers and base template
The sign-in, sign-up, and base template controller classes have been removed from the backend. This eliminates the existing user authentication endpoints and the shared controller template that previously handled request validation and error handling for these operations.
backend/src/app/controllers · medium confidence
Test coverage
Added end-to-end and unit tests for note and user management features; Added handler spy implementations for testing; Added test doubles for note and user services; Added unit tests for GraphQL and REST controllers.
Dependencies
Consolidate project dependencies into root package.json
The project's dependency management has been consolidated into a single root package.json, replacing the previous backend/package.json. This change introduces dependencies for GraphQL (@apollo/server, graphql, graphql-scalars) and removes dependencies for RabbitMQ (amqplib), email (nodemailer), and browser automation (puppeteer), while updating test tooling (jest, ts-jest) and dev dependencies.
(dependencies) · medium confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 62 → 54 (-8.6)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 93 → 89 (-3.9)
- Architecture 100 → 75 (-24.7)
- Maturity 61 → 61 (+0.0)
- Readiness 51 → 37 (-13.2)
- Security 68 → 71 (+2.5)
Resolved (23)
- Coverage not included — suite not readable by the collector
- Critical IaC: DS-0031 (docker/dev/images/postgres/Dockerfile)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium IaC: CKV_DOCKER_3 (docker/dev/images/postgres/Dockerfile)
- No exposed public API
- Scanner failed to run — not a clean result
- Secret: generic-api-key (backend/env/dev/.env)
- …and 3 more
New (38)
- Critical IaC: DS-0031 (docker/dev/images/postgres/Dockerfile)
- Critical IaC: DS-0031 (docker/dev/images/postgres/Dockerfile)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no committed lockfile, so no resolved version to grade)
- End-of-life runtime: Node.js 18
- High interface indirection
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 18 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
gftf2011/clean-node-todolist was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit fc21408378c2542c13d6f11d5a103d236055102d — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.