mpanaryin/job_scope
44.7
Weak · 20 September 2026
5k
lines of production code
Python
primary language
4
measurements over time
What this system is
This system is a backend application infrastructure focused on operational robustness, featuring a FastAPI service backed by PostgreSQL and Redis. It implements a comprehensive observability stack using ELK for centralized logging and Prometheus/Grafana for metrics monitoring. The architecture supports asynchronous database operations, background task processing via Celery, and secure JWT-based authentication with token revocation capabilities.
Features
Added directory structure printing utility
A new Python script, \tools/print\structure.py\, has been added to the repository. This tool allows users to print a formatted tree view of a directory structure, filtering out common non-essential files and directories (such as \\\pycache\\_\, \.git\, and \venv\) and optionally limiting the depth of displayed folders like \alembic\ or \media\. It can be run from the command line to visualize the project layout.
tools · high confidence
New centralized logging, metrics, and infrastructure organization
The \infra\ directory now houses the complete operational stack, consolidating services previously scattered in the project root. This change introduces a full ELK-based logging pipeline (Filebeat, Logstash, Elasticsearch, Kibana) that collects and parses application, Nginx, and PostgreSQL logs, including specific handling for Celery tasks and error notifications via Telegram. Additionally, a Prometheus and Grafana stack is added to monitor system, FastAPI, Nginx, and PostgreSQL metrics, with pre-configured dashboards for each. The Nginx configuration has been updated to expose internal metrics endpoints (\/\_\_internal\metrics\\_\, \/stub\_status\) and standardize log paths, while Redis and PostgreSQL configurations are now explicitly managed within this infrastructure layer.
infra · high confidence
Behavioural changes
Database migration system and authentication infrastructure overhaul
The backend now uses Alembic for database schema management, introducing initial migrations for the users and vacancies tables (including a subsequent migration to add an updated\_at column) and configuring the environment to support PostgreSQL-specific features like JSONB. Concurrently, the authentication system has been restructured to support token revocation via Redis storage and allows JWT signing to be configured via an algorithm setting (defaulting to ES256 in the codebase), replacing previous hardcoded or simpler implementations.
backend · high confidence
Log directory structure reorganized for infrastructure components
The logging directory structure has been updated to separate logs by infrastructure component. New placeholder directories have been created for FastAPI, Nginx, and PostgreSQL logs, aligning with the new organizational scheme where logs are stored in the root logs directory and partitioned by service.
logs · medium confidence
Static assets relocated to project root
Static files, including CSS stylesheets and JavaScript libraries, have been moved from the backend source directory to a dedicated static folder at the project root. This structural change separates static content from the application code, preparing the layout for external serving by nginx rather than the FastAPI backend.
static · high confidence
Dependencies
Updated backend dependencies to support PostgreSQL, async database drivers, and observability tools
The backend requirements have been expanded to include async PostgreSQL drivers (asyncpg, psycopg), Alembic for database migrations, Elasticsearch and aiohttp clients, Celery and Redis for background tasks, Prometheus instrumentation, and updated testing libraries (pytest, httpx). The aiosqlite dependency remains present but is now accompanied by the necessary stack to support PostgreSQL and enhanced logging/monitoring capabilities.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 49 → 45 (-4.4)
- Rubric changed (rubric-2026.08.17 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 99 → 100 (+0.2)
- Architecture 100 → 79 (-20.6)
- Maturity 78 → 67 (-10.8)
- Readiness 17 → 21 (+3.7)
- Security 95 → 75 (-19.9)
- Domain Modelling 100 → 100 (+0.0)
- Accessibility 62 → 53 (-8.7)
Resolved (16)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — no supported dependency manifest was read
- Duplicated block (14–16 lines × 2) (backend/src/crud/base.py)
- Low IaC: DS-0026 (infra/elk/filebeat/Dockerfile)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- No exposed public API
- Test reliability not included
- early-stage repository — too little history to judge knowledge freshness
- git history depth insufficient
- git history depth insufficient
- single-maintainer — knowledge-concentration (bus factor) risk
New (50)
- Banned license: psycopg
- Documentation: no usage examples (README.md)
- Duplicated block (14 lines × 2) (backend/src/crud/base.py)
- High CVE: [GHSA redacted] (backend/requirements.txt)
- High IaC: WD-COMPOSE-0002 (docker-compose.test.yml)
- High vulnerability: [GHSA redacted] (backend/requirements.txt)
- Low IaC: WD-COMPOSE-0002 (docker-compose.dev.yml)
- Low IaC: WD-COMPOSE-0002 (docker-compose.dev.yml)
- Low IaC: WD-COMPOSE-0002 (docker-compose.dev.yml)
- Low IaC: WD-COMPOSE-0002 (docker-compose.dev.yml)
- Low IaC: WD-COMPOSE-0002 (docker-compose.dev.yml)
- Low IaC: WD-COMPOSE-0002 (docker-compose.dev.yml)
- Low IaC: WD-COMPOSE-0002 (docker-compose.dev.yml)
- Low IaC: WD-COMPOSE-0002 (docker-compose.dev.yml)
- Low IaC: WD-COMPOSE-0002 (docker-compose.dev.yml)
- Low IaC: WD-COMPOSE-0002 (docker-compose.dev.yml)
- Low IaC: WD-COMPOSE-0002 (docker-compose.dev.yml)
- Low IaC: WD-COMPOSE-0002 (docker-compose.dev.yml)
- Low IaC: WD-COMPOSE-0002 (docker-compose.dev.yml)
- Low IaC: WD-COMPOSE-0002 (docker-compose.dev.yml)
- …and 30 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
mpanaryin/job_scope was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit dfcc24357b41f4ec602415c9e4dba8664a1a69ee — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.