Skip to content
CAI
Software that uses CAICheck a score

gonzaloplaza/express-ts-ddd

59.3

Adequate · 21 September 2026

946

lines of production code

TypeScript

with JavaScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This is a Node.js backend service that manages user activities through a RESTful API. It handles user authentication and authorization via AWS Cognito, using JWTs to secure endpoints. The system persists activity data using a PostgreSQL database managed by Prisma ORM, and includes comprehensive testing and logging infrastructure.

Features

Added Prisma ORM configuration and Activity model

The application now includes a Prisma ORM setup, defining a PostgreSQL data source and a new 'Activity' model with fields for id, type, content, and creation timestamp. This introduces a new database schema and ORM layer for managing activity data.

prisma · high confidence

Added activity management and Cognito-based authentication to the API

The API now supports creating and retrieving activities, backed by a new Prisma ORM persistence layer. Additionally, the API introduces a full authentication and authorization flow using AWS Cognito. Users can now authenticate via a new /auth endpoint, which validates credentials against Cognito and returns an access token. Subsequent requests to the /api/v1/activities endpoints are protected by a JWT-based authorizer middleware that validates the Cognito token, ensuring only authorized users can access activity data.

src/api · high confidence

Behavioural changes

Configuration structure expanded to support testing and Cognito

The application's configuration system has been updated to include a dedicated test environment, allowing for isolated testing setups. Additionally, Cognito authentication settings (USER\_POOL\_ID, CLIENT\_ID, REGION) have been added to the configuration schema for all environments, enabling the application to connect to AWS Cognito for authentication.

config · high confidence

Refactored shared infrastructure with new logging and error handling

The shared infrastructure layer was restructured to introduce a new \ILogger\ interface and a \ServerLogger\ implementation backed by Winston and Morgan, replacing the previous logging approach. Error handling was consolidated into a new \ErrorMiddleware\ class in \src/shared/infrastructure/express\, which manages 404, client, custom, and global errors, replacing the old middleware-based error handling. The \Kernel\ class was removed, and the dependency injection container was updated to register the new logger, error middleware, and other services like Prisma and Cognito authentication.

src/shared · medium confidence

Updated Docker configuration and service routing

The Docker setup for the application has been restructured to use separate Dockerfiles for Nginx and Node.js, with the Node container based on Alpine Linux. The Nginx configuration was updated to proxy requests to the Node application on port 3000 instead of the previous port 5000. Additionally, the supervisor configuration was modified to remove the Nginx process from the container, relying instead on the separate Nginx container, and the Node.js command was adjusted to point to the correct build output directory.

etc · high confidence

Updated startup sequence to expose environment and log level configuration

The application startup process in bin/index.ts has been updated to resolve the Server and Configuration dependencies from the container. This change modifies the startup sequence to explicitly log the NODE\_ENV and APP\_LOG\_LEVEL from the configuration, providing users with clearer visibility into the active environment and logging settings during initialization.

bin · medium confidence

Upgraded Node.js runtime to version 18 and updated build output directory

The Dockerfile base image has been upgraded from Node.js 14/16 to Node.js 18-alpine, and the build process now utilizes a multi-stage build to compile TypeScript into the /app/dist directory. This change improves security by moving to a newer, supported Node.js version and aligns the production container build with the updated TypeScript configuration.

(repo-wide) · high confidence

Test coverage

Added comprehensive test coverage for the API and shared infrastructure

Added unit tests for the Cognito authentication flow, including the CognitoClient, CognitoAuthorizer, and CognitoJwtVerifier. Added tests for the core application services (CreateActivity, GetActivities, Authentication, HealthCheck) and their corresponding Express controllers. Added tests for shared infrastructure components, including the Server, Router, ErrorMiddleware, RequestValidator, and ServerLogger. Added test fixtures and mocks for Prisma, Winston, and JWT generation to support these new tests.

tests · high confidence

Dependencies

Updated project dependencies and tooling

The project's dependencies have been updated to newer versions, including Express, Jest, and TypeScript, while also adding new packages such as Prisma, Winston, and JSON Web Token libraries. This update also introduces new test scripts and configuration for Jest and Prisma, enhancing the development and testing capabilities of the application.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 59 → 59 (+0.3)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 100 (+0.8)
  • Architecture 69 → 69 (+0.0)
  • Maturity 50 → 50 (+0.0)
  • Readiness 57 → 60 (+3.6)
  • Security 69 → 73 (+4.0)

Resolved (45)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical vulnerability: [GHSA redacted] (yarn.lock)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • …and 25 more

New (69)

  • Critical CVE: [GHSA redacted] (yarn.lock)
  • Critical vulnerability: [GHSA redacted] (yarn.lock)
  • Documentation: no architecture or design documentation (README.md)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • …and 49 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

gonzaloplaza/express-ts-ddd was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 0de3752d9c5bce62691bcd5fbd721cd02df9603b — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.