localstack-samples/sample-serverless-quiz-app
53.0
Adequate · 21 September 2026
2.2k
lines of production code
JavaScript
with Python
4
measurements over time
What this system is
This system is a serverless quiz application built on AWS, featuring a React frontend and backend logic executed via Lambda functions. It manages quiz creation, timed gameplay, scoring, and leaderboards, with infrastructure provisioned through AWS CDK and supported by LocalStack for local development and testing. The architecture includes DynamoDB for data storage, SQS and SNS for asynchronous processing and notifications, and API Gateway for frontend communication.
Features
Automated API endpoint configuration for local development
A new populate.sh script has been added to the frontend build process to automatically detect and configure the API Gateway endpoint. The script queries the API Gateway (using the lstk CLI) to find the 'QuizAPI' REST API ID and writes the resulting endpoint URL into the .env.local file, defaulting to the localstack endpoint (localhost:4566) if the AWS\_ENDPOINT\_URL environment variable is not set.
frontend/scripts · high confidence
Initial AWS CDK infrastructure for the Quiz application
This change introduces the AWS CDK (Cloud Development Kit) stack definitions that provision the Quiz application's core infrastructure. The \FrontendStack\ provisions an S3 bucket and CloudFront distribution to host the static frontend, while the \QuizAppStack\ provisions the backend services, including DynamoDB tables for quizzes and submissions, an API Gateway REST API, multiple Lambda functions, SQS queues with a dead-letter queue, and SNS topics for alarms. It also includes configuration for SES email verification and tags the resources with an AWS Partner Network ID.
cdk · high confidence
Initial deployment of quiz management and scoring Lambda functions
This change introduces the core backend logic for the quiz application via a set of new AWS Lambda handlers. Users can now create quizzes with human-readable IDs, set visibility (Public/Private), and enable optional timers. The system supports submitting answers, retrieving quiz details and leaderboards, and viewing individual submissions. A dedicated scoring handler processes submissions to calculate scores based on correctness and, if enabled, time taken, while a retry mechanism handles failed database writes via SNS and SQS.
lambdas · high confidence
Initial frontend application shell with multi-page routing
The application now includes a core frontend structure in \frontend/src\ that establishes a navigable user interface. This change introduces a React-based entry point (\App.js\) configured with \react-router-dom\ to handle client-side routing between five distinct views: Home, Quiz, Result, Leaderboard, and Quiz Builder. The visual presentation is defined by a new \App.css\ stylesheet and a custom \@mui/material\ theme with a primary purple color, while the \MainLogo.svg\ asset provides branding. A basic test suite (\App.test.js\) is also included to verify the initial render.
frontend/src · high confidence
Initial frontend public assets and SEO configuration
Added the foundational public assets for the web application, including an HTML entry point with basic SEO metadata (title, description, Open Graph, and Twitter cards), a web app manifest for standalone display and icon configuration, and a robots.txt file to guide search engine indexing.
frontend/public · high confidence
Initial release of the quiz application frontend
This change introduces the complete frontend user interface for the quiz application, adding several new components to \frontend/src/components\. Users can now access a Home page to select or create quizzes, a Quiz Builder to define questions and settings (including timer and visibility), and a Quiz Page that supports timed gameplay, skipping questions, and submitting answers. Additionally, a Result page displays detailed scores and answer history with polling for availability, while a Leaderboard page ranks participants and provides a demo email viewer. The layout is structured with dedicated Main and Quiz layouts, and the Home page includes a QR code for easy sharing.
frontend/src/components · high confidence
New deployment and management scripts for LocalStack infrastructure
The repository now includes a suite of shell and Python scripts in the \bin/\ directory to streamline LocalStack setup and demonstration. \deploy.sh\ provisions the core infrastructure (DynamoDB tables, SQS queues, Lambda functions, IAM roles, and API Gateway) using the \lstk\ CLI. \deploy\_cdk.sh\ provides an alternative deployment path via AWS CDK, handling frontend builds, CDK bootstrapping, and CloudFront invalidation. \ephemeral.sh\ automates the creation of temporary LocalStack instances with specific CORS and extension configurations. \seed.sh\ populates the application with sample quiz data and user submissions via the API, while \update\_policy.py\ allows toggling IAM permissions on Lambda roles to demonstrate IAM enforcement behaviors.
bin · high confidence
Test coverage
Added end-to-end tests for the quiz application; Added infrastructure, chaos, and integration test suites.
Dependencies
Initial dependency manifests for CDK, frontend, and test environments
Added package manifests for the CDK infrastructure, React frontend, and end-to-end testing suites. The CDK environment now depends on aws-cdk v2.171.0 and aws-cdk-local v2.19.0, alongside Python libraries aws-cdk-lib and constructs. The frontend is configured with React 18.3.1, MUI 6.1.3, and react-router-dom 6.27.0. Test environments include pytest, playwright, boto3, and localstack-sdk-python to support local infrastructure testing.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 51 → 53 (+1.9)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 61 → 53 (-8.0)
- Architecture 100 → 100 (+0.0)
- Maturity 67 → 67 (+0.0)
- Readiness 48 → 45 (-3.2)
- Security 43 → 57 (+14.8)
Resolved (70)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (frontend/package-lock.json)
- Critical CVE: [GHSA redacted] (frontend/package-lock.json)
- Critical CVE: [GHSA redacted] (frontend/package-lock.json)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (18 lines × 2) (lambdas/get_quiz/handler.py)
- Duplicated block (9 lines × 2) (lambdas/get_quiz/handler.py)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- …and 50 more
New (124)
- Critical CVE: [GHSA redacted] (frontend/package-lock.json)
- Critical CVE: [GHSA redacted] (frontend/package-lock.json)
- Critical CVE: [GHSA redacted] (frontend/package-lock.json)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (11–12 lines × 2) (lambdas/get_quiz/handler.py)
- Duplicated block (18–19 lines × 2) (lambdas/get_quiz/handler.py)
- FunctionTooLong: HomePage.HomePage (frontend/src/components/HomePage.js)
- FunctionTooLong: LeaderboardPage.LeaderboardPage (frontend/src/components/LeaderboardPage.js)
- FunctionTooLong: QuizBuilder.QuizBuilder (frontend/src/components/QuizBuilder.js)
- FunctionTooLong: QuizPage.QuizPage (frontend/src/components/QuizPage.js)
- FunctionTooLong: ResultPage.ResultPage (frontend/src/components/ResultPage.js)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- …and 104 more
Changes since last survey
- 2 commits — 2 feature/other, 0 fixes
By area
- (repo) — 1 commit
- cdk/app.py — 1 commit
Notable commits
- change: Add AWS PRM partner tag (aws-apn-id)
- change: Merge pull request #39 from localstack-samples/prm-tagging/add-aws-apn-id-tag
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
localstack-samples/sample-serverless-quiz-app was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit f20e26d45758cfa8d8aa514cdd8472de2a29b0a2 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.