hookdeck/supahooks
39.4
Weak · 21 September 2026
1.8k
lines of production code
TypeScript
primary language
4
measurements over time
What this system is
This system is a Supabase-integrated web application designed to manage webhooks via the Hookdeck service. It provides user authentication and a dashboard for registering, viewing, and testing webhook subscriptions. The platform handles event publishing, delivery tracking, and local development configuration.
Features
Add Hookdeck integration for webhook management and event publishing
Added new utility functions to manage webhook subscriptions, retrieve events and delivery attempts, and publish webhook events via the Hookdeck SDK. The implementation includes creating and listing webhook connections, fetching event details, and publishing events with custom headers and authentication. Additionally, a helper function was added to generate secure webhook secrets and strip internal headers from incoming requests.
src/utils · high confidence
Add Supabase authentication and webhook management dashboard
The application now requires Supabase authentication, introducing login, signup, and email confirmation flows. Once authenticated, users can access a dashboard to register, view, and delete webhooks. The dashboard includes an interactive JSON editor for testing webhooks and an events table that displays delivery attempts and response statuses. The default landing page has been replaced with a redirect to the login page.
src/app · high confidence
Add Supabase client, types, and middleware for authentication and account management
The application now integrates Supabase for user authentication and account management. A new Supabase client is provided for both browser and server-side rendering, enabling session management via Next.js middleware that redirects authenticated users from login/signup pages to the dashboard and redirects unauthenticated users to login. Additionally, a helper function automatically creates a user's account record in the database if it does not exist, storing a generated webhook secret. TypeScript types for the database schema (accounts, products, webhooks) are also added to support these features.
src/utils/supabase · high confidence
Automated local development setup for Supabase webhooks
A new script (script/setup.ts) has been added to automate the configuration of local development environments. This script configures a Hookdeck connection for the 'product-change-webhook' and generates a final Supabase schema file by replacing template placeholders with environment-specific values.
script · high confidence
Behavioural changes
Initial Supabase database schema and configuration
The Supabase environment is initialized with a new database schema defining \accounts\, \products\, and \webhooks\ tables, along with row-level security policies and grants. An email template for user invitation is also added to support authentication flows.
supabase · medium confidence
Dependencies
Updated project dependencies and tooling
The project name was changed to 'supahooks' and the package-lock was updated to reflect a series of dependency upgrades. Key updates include Next.js and eslint-config-next to 14.2.15, ESLint to v9, and @types/node to v22. New dependencies added are @hookdeck/sdk, @supabase/ssr, dayjs, react-icons, and zod. Dev dependencies were also updated to include hookdeck-cli and supabase, while tailwindcss was bumped to 3.4.16.
(dependencies) · medium confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 40 → 39 (-0.5)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 78 → 80 (+2.0)
- Architecture 100 → 97 (-3.1)
- Maturity 50 → 45 (-4.8)
- Readiness 20 → 22 (+2.0)
- Security 71 → 74 (+3.1)
- Accessibility 47 → 47 (-0.1)
Resolved (30)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Low CVE: [GHSA redacted] (package-lock.json)
- Low CVE: [GHSA redacted] (package-lock.json)
- Low vulnerability: [GHSA redacted] (package-lock.json)
- …and 10 more
New (45)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical vulnerability: [GHSA redacted] (package-lock.json)
- Documentation: no installation or build instructions (README.md)
- Documentation: no licence statement (README.md)
- Documentation: no usage examples (README.md)
- FunctionTooLong: events-table.EventsTable (src/app/components/dashboard/events-table.tsx)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 25 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
hookdeck/supahooks was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 26372d507121e762c21bec5a3f2811c4265f50c2 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.