ivan-borovets/fastapi-clean-example
68.9
Adequate · 22 September 2026
3.2k
lines of production code
Python
primary language
7
measurements over time
What this system is
This system is a Python-based web application framework that provides user and account management capabilities, including authentication, session handling, and role-based access control. It exposes a RESTful HTTP API for user lifecycle management and administrative operations, backed by a structured domain layer with database persistence. The project is fully bootstrapped with modern tooling, including dependency injection, automated migrations, and comprehensive test coverage.
Features
Add script to generate dependency graph for Dishka container
A new Python script, \scripts/dishka/plot\_dependencies\_data.py\, has been added to generate a dependency graph of the application's DI container in D2 format, allowing users to visualize the container's structure.
scripts/dishka · high confidence
Added Makefile helper scripts for environment, Docker, and migration workflows
New shell scripts have been added to the scripts/makefile directory to streamline common development tasks. docker\_env.sh and local\_env.sh automatically generate .env files for Docker and local environments respectively, sourcing from env.example and .secrets. docker\_prune.sh provides a safe way to clean up unused Docker resources. migration.sh automates the creation and application of Alembic migrations using a dedicated Docker compose project. pip\_audit.sh runs security audits on Python dependencies. pycache\_del.sh removes Python cache files, and slotscheck.sh validates Python module imports. These scripts are called by the Makefile to simplify setup, deployment, and maintenance.
scripts/makefile · high confidence
Introduce HTTP inbound layer for account and user management
The application now exposes HTTP endpoints for account management (sign up, log in, log out, change password) and user management (create, list, activate, deactivate, grant/revoke admin, set password). These are wired into the \/api/v1\ router and protected by a new \AuthCookieMiddleware\ that manages session cookies. The inbound handlers delegate to new outbound handlers and adapters (e.g., \SqlaUserTxStorage\, \SqlaUserReader\, \BcryptPasswordHasher\) that implement the core domain logic and data access.
src/app/inbound, src/app/outbound · high confidence
Introduce core user management commands and authorization
The application now includes a complete set of commands for managing users, including creating, activating, deactivating, and changing the password of users, as well as granting and revoking admin privileges. These commands enforce role-based access control, ensuring that only authorized users (such as admins or super admins) can perform these actions. The implementation introduces a new authorization framework with permission checks, role hierarchies, and context-based access control. Additionally, query support for listing users with pagination and sorting is added, along with value objects for usernames, passwords, and UTC datetimes.
src/app/core · high confidence
Project scaffolding and tooling setup
The project is now fully bootstrapped with a complete development environment. This includes a Dockerfile configured for Python 3.13 and the \uv\ package manager, a comprehensive \.gitignore\ and \.dockerignore\, a \Makefile\ for managing services, tests, and migrations, and a \.pre-commit-config.yaml\ to enforce code quality with tools like \ruff\ and \mypy\. Additionally, configuration files for \alembic\ and environment variables are provided to support database migrations and application configuration.
(repo-wide) · high confidence
Behavioural changes
Added empty \_\_init\_\_.py for src/app
An empty \_\init\\_.py file was added to the src/app directory, marking it as a Python package.
src/app · low confidence
Centralized configuration and dependency injection setup for the application
The application's startup and configuration have been reorganized into a dedicated \src/app/main\ package. This introduces a structured configuration system using \pydantic\_settings\ to load environment variables for app, database, JWT, and session settings. Additionally, the entry point (\run.py\) and setup routines (\setup.py\) now initialize the \dishka\ dependency injection container, wiring up core services, outbound adapters, and HTTP middlewares.
src/app/main · high confidence
Test coverage
Added integration and unit tests for account, user management, and system health
Added comprehensive test coverage for the application's core features. Integration tests verify the account lifecycle (sign-up, log-in, log-out, password change) and user management (create, list, activate/deactivate, grant/revoke admin roles, set password) with proper authentication and authorization checks. A new migration validation test ensures Alembic migrations can be applied and rolled back without errors. Additionally, sanity tests confirm the health and liveness probes function correctly, and unit tests cover the authorization permission system.
tests · high confidence
Dependencies
Migrate project configuration to pyproject.toml and update dependencies
The project's build and dependency management has been consolidated into a new pyproject.toml file, replacing previous configuration methods. This includes defining the project metadata, specifying Python 3.13 as the required version, and listing all production and development dependencies with pinned versions (e.g., FastAPI 0.136.1, SQLAlchemy 2.0.49). Additionally, tooling configurations for coverage, mypy, pytest, ruff, and import-linter are now managed within this single file, standardizing the project's development environment.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 69 → 69 (+0.0)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 99 (-0.2)
- Architecture 100 → 86 (-13.9)
- Maturity 81 → 73 (-8.3)
- Readiness 51 → 56 (+4.5)
- Security 80 → 88 (+8.0)
Resolved (17)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (18 lines × 2) (src/app/core/commands/activate_user.py)
- Duplicated block (18 lines × 2) (src/app/core/commands/grant_admin.py)
- High CVE: [GHSA redacted] (uv.lock)
- High CVE: [GHSA redacted] (uv.lock)
- High CVE: [GHSA redacted] (uv.lock)
- High vulnerability: [GHSA redacted] (uv.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: [GHSA redacted] (uv.lock)
- Medium CVE: [GHSA redacted] (uv.lock)
- Medium IaC: CKV_DOCKER_2 (Dockerfile)
- No exposed public API
- Small-team knowledge concentration
- Test reliability not included
New (30)
- Banned license: psycopg
- Critical CVE: [GHSA redacted] (uv.lock)
- Documentation: no installation or build instructions (README.md)
- Documentation: no project overview (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (17 lines × 4) (src/app/core/commands/activate_user.py)
- Duplicated block (28 lines × 2) (src/app/core/commands/activate_user.py)
- Duplicated block (28 lines × 2) (src/app/core/commands/grant_admin.py)
- Duplicated block (6 lines × 2) (src/app/core/commands/create_user.py)
- Duplicated block (9 lines × 2) (src/app/outbound/adapters/sqla_transaction_manager.py)
- High CVE: [GHSA redacted] (uv.lock)
- High CVE: [GHSA redacted] (uv.lock)
- High CVE: [GHSA redacted] (uv.lock)
- High CVE: [GHSA redacted] (uv.lock)
- High CVE: [GHSA redacted] (uv.lock)
- High vulnerability: [GHSA redacted] (uv.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: [GHSA redacted] (uv.lock)
- …and 10 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
ivan-borovets/fastapi-clean-example was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 927172311ec272ee3894619d91008a1b3403bc75 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.