Skip to content
CAI
Software that uses CAICheck a score

nestjs/nest

56.8

Adequate · 28 September 2026

61.6k

lines of production code

TypeScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the NestJS framework, a progressive Node.js framework for building efficient, reliable, and scalable server-side applications. It provides a modular architecture with built-in support for HTTP (Express/Fastify), microservices (gRPC, Kafka, MQTT, etc.), and WebSockets, alongside features like dependency injection, validation, and security. The codebase includes extensive integration tests and utilities for common patterns such as file streaming, GraphQL, and database connectivity.

How it got here

2017–2018 — Monorepo restructuring and ESM migration

133 changes.

The project underwent a major architectural shift by splitting into a Lerna monorepo with distinct packages for core, common, and platform adapters, while simultaneously migrating the codebase and samples to ES modules. This period focused on stabilizing the new modular structure through comprehensive integration and unit testing across all supported transports and decorators.

2019–2021 — Microservices and GraphQL expansion

73 changes.

This period focused on significantly expanding the framework's microservices capabilities, introducing structured client management, standardized serialization/deserialization, and public context classes for various transports like Kafka and NATS. It also added robust support for GraphQL Federation and Code-First approaches, alongside new features for file streaming, host-based routing, and enhanced lifecycle hook testing.

2022–2026 — Core infrastructure and security enhancements

57 changes.

This period focused on strengthening the framework's core by introducing a configurable module builder, a dependency graph inspector, and a built-in REPL for debugging. It also added significant security features, including native CSRF protection, security headers, and adapter-agnostic cookie handling, while expanding file upload capabilities for Fastify.

Features

Add Cats integration sample with request-scoped services and subscriptions

The cats integration sample now includes a complete GraphQL implementation featuring a request-scoped service option, a custom guard, and real-time subscriptions. Users can now explore how to configure services with \Scope.REQUEST\ via the module's \enableRequestScope\ factory, apply guards to resolvers, and handle live updates using \graphql-subscriptions\ with a \PubSub\ instance.

integration/graphql-schema-first/src/cats · high confidence

Add Date scalar for GraphQL integration

The integration tests now include a custom Date scalar implementation that serializes date values to timestamps for client responses and parses incoming integer values back to Date objects, enabling proper handling of date types in the GraphQL schema-first integration tests.

integration/graphql-schema-first/src/common · high confidence

Add ESM-based NestJS sample with Webpack HMR support

The sample/08-webpack directory now provides a NestJS application example using ES modules (importing .js extensions) and includes Webpack Hot Module Replacement (HMR) configuration in the bootstrap entry point, allowing for faster development feedback loops.

sample/08-webpack · high confidence

Add GraphQL Code-First integration sample application

A new sample application has been added to the integration/graphql-code-first directory, demonstrating how to set up a NestJS application using the GraphQL Code-First approach with the Apollo driver. The app includes an AppModule that configures GraphQL with an auto-generated schema file and a main entry point that starts the server on port 3000 with global validation pipes.

integration/graphql-code-first/src · high confidence

Add GraphQL Federation Code-First sample with Posts and Users subgraphs

A new code-first GraphQL Federation sample has been added, demonstrating a federated architecture with two subgraphs: a Posts application (listening on port 3003) and a Users application (listening on port 3002). The Posts subgraph exposes Post and User types, using Apollo Federation 2 directives (such as @key and @extends) to share the User entity across subgraphs, while the Users subgraph owns the canonical User definition and provides a resolveReference implementation to support entity resolution. The sample is built with NestJS and @nestjs/graphql, includes unit tests for resolvers and services, and uses ESM module syntax.

sample/31-graphql-federation-code-first/posts-application · high confidence

Add GraphQL Federation schema-first sample application

Introduces a new sample demonstrating a GraphQL Federation architecture using the schema-first approach. The sample consists of two microservices: a posts application and a users application. The posts service exposes Post entities and extends the User type to resolve user references, while the users service owns the User type and provides a reference resolver. Both services are configured with the Apollo Federation driver to enable cross-service type composition.

sample/31-graphql-federation-code-first/gateway, sample/32-graphql-federation-schema-first/gateway, sample/32-graphql-federation-schema-first/posts-application · high confidence

Add GraphQL-Prisma sample with Better-SQLite3 support

This change introduces a new sample application (sample/22-graphql-prisma) that demonstrates integrating NestJS GraphQL with Prisma. The sample configures the Apollo driver for GraphQL, defines a Post schema with queries, mutations, and subscriptions, and implements a Prisma service using the Better-SQLite3 adapter for local database operations.

sample/22-graphql-prisma · high confidence

Add NestJS class-transformer serializer sample

A new sample application (sample/21-serializer) demonstrates how to use the class-transformer library with NestJS to control serialization output. The example shows how to exclude sensitive fields like passwords, expose computed properties such as a full name, and transform nested objects (e.g., extracting a role name) using decorators like @Exclude, @Expose, and @Transform within a controller response.

sample/21-serializer · high confidence

Add NestJS event emitter sample application

A new sample application demonstrating the NestJS event emitter pattern has been added to the samples directory. This example includes a complete module structure with an orders service that emits an 'order.created' event upon creating an order, and a corresponding listener that handles the event. The sample illustrates how to configure the EventEmitterModule, define event classes, and wire up controllers, services, and listeners within a NestJS application.

sample/30-event-emitter · high confidence

Add NestJS sample demonstrating dynamic module context selection

The sample/18-context directory now includes a new NestJS example that demonstrates how to select and access providers from a dynamic module within the application context. The sample defines a MyDynamicModule that registers a provider with a configurable value, imports it into AppModule, and uses app.select() in main.ts to retrieve the provider's value at runtime, illustrating the usage of dynamic modules with the application context API.

sample/18-context · high confidence

Add REPL integration test application

A new NestJS application has been added to the \integration/repl\ directory to serve as an integration test environment for the REPL feature. This application bootstraps a long-lived module (\LongLivingAppModule\) that imports a \DatabaseModule\ to maintain a persistent connection, alongside a \UsersModule\ providing standard CRUD endpoints. The entry point (\repl.ts\) uses the core \repl()\ function to expose an interactive shell for testing, configured with a \tsconfig.json\ that maps local packages for development.

integration/repl · high confidence

Add Server-Sent Events (SSE) sample with ESM support

The sample/28-sse directory now provides a working example of Server-Sent Events, featuring an endpoint that emits a 'hello: world' message every second and an HTML page that displays these updates in real-time. The sample has been migrated to ESM (using .js imports and import.meta.url) and includes a main entry point that uses top-level await and enables forceCloseConnections to ensure clean restarts.

sample/28-sse · high confidence

Add WebSocket gateway sample application

A new sample application demonstrating WebSocket communication has been added to the \sample/16-gateways-ws\ directory. This sample includes an \EventsGateway\ that listens on port 8080 and handles 'events' messages, integrated into the NestJS application via a dedicated module and a custom WebSocket adapter in the bootstrap process.

sample/16-gateways-ws · high confidence

Add cache sample with HTTP cache interceptor

The sample/20-cache location now includes a complete demonstration of caching in NestJS. It features an AppModule that registers the cache-manager, an AppController that uses the CacheInterceptor and simulates a delay to prove caching works, and a custom HttpCacheInterceptor that extends the base interceptor to cache only GET requests based on the request URL. The sample also includes unit tests for both the controller and the custom interceptor to verify this behavior.

sample/20-cache · high confidence

Add hello-world integration sample with controller, service, and validation

The integration/hello-world/src/hello directory now includes a complete sample application demonstrating core NestJS capabilities. This includes a HelloController that exposes endpoints for synchronous, asynchronous, and stream-based greetings, utilizes the @Header() decorator to set response headers, and implements a custom parameter pipe (UserByIdPipe) for argument transformation. Additionally, a TestDto is provided to showcase class-validator decorators for input validation, and the module structure wires these components together for integration testing.

integration/hello-world/src/hello · high confidence

Add host-based routing and tenant extraction support

The integration test suite now includes a new host module that demonstrates multi-tenant routing capabilities. Users can now configure controllers to respond to specific hostnames (e.g., \:tenant.example.com\) using the \host\ option in the \@Controller\ decorator. The \@HostParam\ decorator allows extracting the tenant identifier from the request host, enabling logic that varies based on the incoming domain. This change adds the necessary controller, service, and pipe implementations to validate this feature within the hello-world integration tests.

integration/hello-world/src/host · high confidence

Add integration test suite for multi-host routing

Added a new integration test module under \integration/hello-world/src/host-array\ that demonstrates and validates the framework's ability to route requests based on an array of host patterns. This new area includes a controller configured with multiple host constraints (\:tenant.example1.com\, \:tenant.example2.com\), a service, and supporting utilities like a custom pipe and DTOs to verify that host-based routing correctly extracts and passes tenant identifiers through various endpoint types (standard, async, and streaming).

integration/hello-world/src/host-array · high confidence

Add public exception filter interfaces for HTTP, RPC, and WebSockets

The \packages/common/interfaces/exceptions\ module now exposes the core interfaces required to implement custom exception filters across all transport layers. Developers can now define custom filters for standard HTTP requests (\ExceptionFilter\), microservice RPC calls (\RpcExceptionFilter\), and WebSocket connections (\WsExceptionFilter\), along with their corresponding metadata interfaces (\ExceptionFilterMetadata\, \RpcExceptionFilterMetadata\) to support the framework's internal filter resolution and registration mechanisms.

packages/common/interfaces/exceptions · high confidence

Add sample demonstrating queue-based audio transcoding with Bull

The 26-queues sample now provides a working example of integrating NestJS with Bull for background job processing. It includes an AudioController that exposes a POST /audio/transcode endpoint to enqueue jobs, an AudioProcessor that handles the 'transcode' job type by logging start, data, and completion states, and the necessary module configurations to connect to a Redis instance. Comprehensive unit tests are included to verify the controller's queue interaction and the processor's logging behavior.

sample/26-queues · high confidence

Add sample for @nestjs/serve-static with ESM support

A new sample application (sample/24-serve-static) demonstrates how to use the @nestjs/serve-static module. The sample is written in ESM, uses a global API prefix, and configures the static file server to exclude specific paths (e.g., /api/{\*test}) and disable fallthrough.

sample/24-serve-static · high confidence

Added Kafka concurrency integration demo with explicit partitioning

The integration tests for microservices now include a new Kafka concurrency scenario that demonstrates concurrent consumption across three partitions. This setup uses a custom partitioner to route messages to specific partitions based on headers and implements a synchronization mechanism where the consumer waits for a signal before returning the result, allowing for controlled testing of concurrent message processing.

integration/microservices/src/kafka-concurrent · high confidence

Added empty NestJS module for core injectables

A new NestJS module, CoreInjectablesModule, has been introduced in the integration/injector area. Currently, it is an empty module with no providers, exports, or imports, serving as a structural placeholder for future core injectable registrations.

integration/injector/src/core-injectables · high confidence

Added gRPC service definitions for orders and common types

New Protocol Buffers definitions have been added to the \grpc-advanced/proto\ directory, establishing the contract for the orders microservice. This includes common type definitions for items and shipments, an Order message structure, and an OrderService exposing RPC methods for finding orders and various streaming synchronization patterns (bidirectional, server-streaming, and client-streaming).

integration/microservices/src/grpc-advanced/proto · high confidence

Built-in CSRF protection and security headers

NestJS now includes built-in cross-site request forgery (CSRF) protection and security headers, removing the need for external middleware like Helmet. The new \app.enableCsrfProtection()\ method validates requests using \Sec-Fetch-Site\ and \Origin\ headers, rejecting cross-site requests unless they are safe methods, same-origin, or explicitly trusted/excluded. The \app.useSecurityHeaders()\ method automatically applies a suite of security headers (including Content-Security-Policy, Strict-Transport-Security, and X-Frame-Options) with defaults matching Helmet 8, while allowing customization and per-route overrides. These features are integrated via a shared request hook to ensure headers are set even on rejected requests.

integration/security, packages/core/security · high confidence

NestJS now includes native support for reading and writing cookies without relying on external middleware like cookie-parser. The framework provides @Cookies() and @SignedCookies() decorators to access request cookies, with the latter supporting HMAC-SHA256 signature verification and secret rotation. For responses, the HttpAdapter exposes setCookie() and clearCookie() methods, allowing users to configure attributes such as httpOnly, secure, sameSite, and maxAge directly. This change removes the dependency on third-party cookie parsing libraries for standard use cases and ensures consistent behavior across Express and Fastify adapters.

integration/cookies, packages/core/helpers/cookies · high confidence

Core decorators now support injection scopes, host filtering, and API versioning

The core decorators in \@nestjs/common\ have been updated to support advanced configuration options. The \@Controller()\ decorator now accepts a \ControllerOptions\ object, allowing you to specify \scope\ (for dependency injection lifetime), \host\ (to restrict routes to specific request hosts), and \version\ (for API versioning). Similarly, the \@Injectable()\ decorator now accepts \InjectableOptions\ to define injection scopes. The \@Version()\ decorator has been added to set endpoint versions, and the \@Catch()\ decorator now supports \Abstract\ types for exception filtering. Additionally, new utility decorators \applyDecorators()\ and \Bind()\ have been introduced to help compose and apply multiple decorators programmatically.

packages/common/decorators/core · high confidence

Expanded microservices error handling with specific exception classes

The microservices module now exposes a comprehensive set of specific exception classes to improve error diagnosis for users. New public API exceptions include CorruptedPacketLengthException, EmptyResponseException, IncompleteMessageTimeoutException, MaxPacketLengthExceededException, MaxSendBufferSizeExceededException, and NetSocketClosedException for TCP transport issues. gRPC-specific errors are now distinct: InvalidGrpcDecoratorException, InvalidGrpcPackageException, InvalidGrpcServiceException, InvalidProtoDefinitionException, and two new exceptions for package definition validation (InvalidGrpcPackageDefinitionMissingPackageDefinitionException and InvalidGrpcPackageDefinitionMutexException). Additionally, InvalidJSONFormatException, InvalidKafkaClientTopicException, InvalidMessageException, and InvalidTcpDataReceptionException provide clearer context for JSON parsing, Kafka consumer, general message, and TCP data reception failures respectively.

packages/microservices/errors · high confidence

Expose INQUIRER token for transient injection

The injector now provides a dedicated INQUIRER token (defined as a string constant) that can be injected into transient-scoped services. This allows components to identify their immediate caller within the dependency graph, supporting patterns where a service needs to know which other service requested its instantiation.

packages/core/injector/inquirer · high confidence

Fastify file upload interceptors backed by @fastify/multipart

The Fastify platform adapter now supports file uploads using the @fastify/multipart library, providing interceptors such as FileInterceptor, FilesInterceptor, FileFieldsInterceptor, NoFilesInterceptor, and the new FileStreamInterceptor. This integration allows users to upload files to Fastify applications with behavior and API parity to the existing Express (multer) implementation, including support for disk storage, file size limits, and field validation.

integration/file-upload · high confidence

HTTP exceptions now support error chaining and custom error codes

The \HttpException\ class and all its built-in subclasses (such as \BadRequestException\, \NotFoundException\, and \InternalServerErrorException\) now accept an optional \HttpExceptionOptions\ object. This allows developers to attach an underlying \cause\ for error chaining (following the Node.js v16.9.0+ standard) and to specify a custom \errorCode\ string that is included in the JSON response body. Additionally, the base \HttpException\ now inherits from \IntrinsicException\ to prevent default logging of intrinsic errors, and the response body structure is standardized to include the \errorCode\ when provided.

packages/common/exceptions · high confidence

Initial release of the @nestjs/common package structure

The \@nestjs/common\ package is now available as a distinct, standalone module within the framework. This change introduces the foundational public API, including core decorators (\@Controller\, \@Injectable\), lifecycle hook interfaces (\OnModuleInit\, \OnApplicationShutdown\, etc.), and essential interfaces for providers and HTTP handling. It also establishes the internal constant definitions and metadata keys used by the framework's core logic, separating these common utilities from the main \@nestjs/core\ package.

packages/common · high confidence

Initial release of the @nestjs/platform-express package

The \@nestjs/platform-express\ package is now available as a standalone, officially supported module for integrating NestJS with the Express.js HTTP adapter. This new package exposes the Express adapter, associated interfaces, and Multer support via its entry point (\index.ts\), allowing users to explicitly install and configure Express as their underlying HTTP server. The package is structured with its own TypeScript build configuration (\tsconfig.build.json\) that references the \common\ and \core\ packages, ensuring it is built as a distinct unit within the monorepo.

packages/platform-express · high confidence

Inspector integration adds API versioning and request-scoped lifecycle tests

The inspector integration now includes controllers for API versioning (v1 and v2) and a suite of modules designed to test complex NestJS lifecycle behaviors. Specifically, it introduces a request-scoped guard, service, and interceptor in the circular-hello module to verify instantiation counters, alongside a durable service and context-id strategy in the durable module to test tenant-based request isolation. These additions allow the integration suite to validate request-scoped injection, circular module dependencies, and durable context strategies.

integration/inspector · high confidence

Integration test suite for TCP over TLS microservices

Added a new integration test scenario under \integration/microservices/src/tcp-tls\ that validates TCP communication secured with TLS. The change introduces an application module and controller demonstrating three client configuration patterns (useFactory, useClass, and custom proxy) alongside message patterns for summing, streaming, error handling, and event notifications. A self-signed CA certificate and private key are included to facilitate local TLS verification within the test environment.

integration/microservices/src/tcp-tls · high confidence

Introduce ClientsModule for managing microservice client connections

A new ClientsModule has been added to the microservices package, providing a structured way to register and manage client proxies within the NestJS dependency injection container. Users can now configure clients synchronously via register() or asynchronously via registerAsync(), supporting factory patterns and external imports. The module automatically handles lifecycle management by attaching an onApplicationShutdown hook to each client proxy, ensuring connections are closed gracefully when the application shuts down. It also supports marking the module as global and exporting providers for use across other modules.

packages/microservices/module · high confidence

Introduce ClientsModule interface definitions

Added the TypeScript interface definitions for the new ClientsModule, including types for client providers (ClientProvider, ClientProviderOptions), module configuration options (ClientsModuleOptions), and asynchronous factory options (ClientsModuleOptionsFactory, ClientsProviderAsyncOptions). These interfaces define the shape of the configuration passed to the module, supporting both synchronous and asynchronous client setup via factories or classes, and allow for global module registration.

packages/microservices/module/interfaces · high confidence

Introduce ExpressAdapter as the primary HTTP adapter for Express platform

The Express platform now uses a dedicated \ExpressAdapter\ class (located in \packages/platform-express/adapters/express-adapter.ts\) to manage HTTP interactions, replacing previous inline or less structured adapter implementations. This adapter centralizes core HTTP behaviors including request/response handling, streamable file support, error and not-found handler registration with global prefix normalization, and lifecycle hooks (onRequest/onResponse). It also introduces raw body support, versioning filters, and graceful shutdown mechanisms, providing a more robust and consistent foundation for Express-based NestJS applications.

packages/platform-express/adapters · high confidence

Introduce Fastify platform adapter with multipart and route configuration support

The \@nestjs/platform-fastify\ package is now available, providing a first-class HTTP adapter for Fastify. This release adds the \FastifyAdapter\ and \NestFastifyApplication\ interfaces, enabling users to run Nest applications on the Fastify engine. It includes built-in support for file uploads via the \MultipartModule\ and interceptors (such as \FileInterceptor\ and \FileStreamInterceptor\), as well as decorators for configuring Fastify-specific route properties like \RouteConfig\, \RouteConstraints\, and \RouteSchema\.

packages/platform-fastify · high confidence

Introduce Global module decorator and refine Module decorator implementation

The \packages/common/decorators/modules\ area now includes a new \Global\ decorator, allowing users to mark modules as global-scoped so their exported providers are available across the entire application without explicit re-importing. The existing \Module\ decorator has been updated to validate configuration keys via \validateModuleKeys\ and now uses \Object.hasOwn\ for safer property iteration when defining metadata, ensuring more robust module configuration handling.

packages/common/decorators/modules · high confidence

Introduce SerializeOptions decorator for serializer configuration

A new SerializeOptions decorator is now available in the common serializer decorators package, allowing users to attach configuration options to classes or methods. This decorator accepts either ClassSerializerContextOptions or StandardSchemaSerializerContextOptions, enabling flexible control over how objects are serialized using either the existing class-based serializer or the newly introduced standard schema serializer.

packages/common/serializer/decorators · high confidence

Introduce StreamableFile class for streaming file responses

A new \StreamableFile\ class has been added to the \packages/common/file-stream\ package, providing a standardized way to handle streaming file responses in NestJS applications. This class accepts either a \Uint8Array\ buffer or a Node.js \Readable\ stream, automatically calculating the content length when a buffer is provided. It exposes configurable headers (such as content type and disposition) and allows users to set custom error handlers and loggers, ensuring robust error management during file streaming operations.

packages/common/file-stream · high confidence

Introduce configurable module builder utility

A new \ConfigurableModuleBuilder\ class has been added to \packages/common/module-utils\ to help developers create dynamic, configurable modules with less boilerplate. This utility allows you to define custom static methods (like \forRoot\ or \register\), configure async options factories, and apply extra module definition options (such as making a module global) through a fluent API. The package also exports necessary interfaces and constants to support this pattern, streamlining the creation of reusable module structures.

packages/common/module-utils · high confidence

Introduce configurable module interfaces for async options and dynamic module construction

Added new TypeScript interfaces in the module-utils package to support configurable NestJS modules. The \ConfigurableModuleAsyncOptions\ interface defines the structure for asynchronous module configuration, including support for \useClass\, \useFactory\, and a new \provideInjectionTokensFrom\ property that allows passing options to nested async modules. The \ConfigurableModuleCls\ interface provides the type definition for the configurable module class blueprint, while \ConfigurableModuleHost\ serves as the base interface for module classes to inherit from, exposing tokens and type helpers for options and async configurations.

packages/common/module-utils/interfaces · high confidence

Introduce dedicated @nestjs/platform-ws package

A new standalone package, @nestjs/platform-ws, has been added to provide a WebSocket adapter based on the 'ws' library. This allows users to use WebSockets without pulling in the Express or Fastify HTTP server dependencies. The package includes a WsAdapter that supports mounting multiple WebSocket servers on different paths, allows for a custom message parser via constructor options, and ensures that handler errors are logged rather than silently discarding messages or tearing down the connection stream.

packages/platform-ws · high confidence

Introduce interactive REPL for NestJS applications

Adds a new \repl()\ function in \packages/core/repl\ that bootstraps a NestJS application context and launches an interactive command-line interface. This feature allows developers to inspect and interact with the application's dependency injection container, modules, and providers directly. It includes built-in commands such as \help\, \get\, \resolve\, \select\, \debug\, and \methods\, along with auto-complete support for registered tokens and modules. The implementation uses a dedicated \ReplContext\ to manage the scope and native functions, and ensures graceful shutdown of the application when the REPL session exits.

packages/core/repl · high confidence

Introduce pluggable opaque key factories for module identification

The core injector now supports multiple strategies for generating unique module keys via the new \ModuleOpaqueKeyFactory\ interface and its implementations. Users can choose between the new \ByReferenceModuleOpaqueKeyFactory\, which uses a fast random or shallow hashing approach, and the existing \DeepHashedModuleOpaqueKeyFactory\, which performs deep serialization of dynamic metadata. This change allows for better performance tuning in scenarios with large or complex dynamic module configurations by selecting the appropriate key generation algorithm.

packages/core/injector/opaque-key-factory · high confidence

Introduce public interfaces for external validation and transformation libraries

The \packages/common/interfaces/external\ directory now exposes explicit TypeScript interfaces for the \class-transformer\, \class-validator\, CORS, and HTTPS configurations. This includes \ClassTransformOptions\, \ValidatorOptions\, \ValidationError\, and their corresponding package contracts (\TransformerPackage\, \ValidatorPackage\), alongside \CorsOptions\ and \HttpsOptions\. These definitions provide a stable, documented public API for users configuring validation pipes, class transformation, and server security options, ensuring type safety and clarity when interacting with these external dependencies.

packages/common/interfaces/external · high confidence

Introduces explicit deserializers for incoming requests, responses, and transport-specific payloads

The \packages/microservices/deserializers\ module now exposes a set of new deserializer classes that standardize how incoming microservice messages are interpreted. \IncomingRequestDeserializer\ and \IncomingResponseDeserializer\ provide base logic to detect whether a payload is an external message or an internal Nest packet, mapping them into standardized \IncomingRequest\ and \IncomingResponse\ schemas. Transport-specific implementations, including \KafkaRequestDeserializer\, \KafkaResponseDeserializer\, \NatsRequestJSONDeserializer\, and \NatsResponseJSONDeserializer\, extend these bases to handle protocol-specific details such as Kafka headers (correlation IDs, error flags) and NATS JSON decoding. An \IdentityDeserializer\ is also provided for passthrough scenarios. These changes are exported via a new \index.ts\ barrel file, making these components available as public APIs for users to configure or extend within their microservice transports.

packages/microservices/deserializers · high confidence

Introduces public context classes for microservice transports

The microservices package now exposes a set of public context classes (BaseRpcContext, KafkaContext, MqttContext, NatsContext, RedisContext, RmqContext, and TcpContext) under the ctx-host module. These classes provide structured access to transport-specific details such as message payloads, channel/subject names, consumer/producer references, and attached metadata, allowing users to inspect and interact with the underlying communication context within their handlers.

packages/microservices/ctx-host · high confidence

Introduces public type definitions for external microservice transporters

The \packages/microservices/external\ directory now exposes a set of TypeScript interfaces that mirror the configuration options of the underlying transport libraries, making them available as part of the public API. This includes \KafkaConfig\ and related types for Kafka, \IORedisOptions\ for Redis (ioredis), \ChannelOptions\ for gRPC, \MqttClientOptions\ for MQTT, \NatsCodec\ for NATS, and \RmqUrl\/\AmqpConnectionManagerSocketOptions\ for RabbitMQ. Users can now import these types directly to ensure their configuration objects are strictly typed against the specific requirements of each broker.

packages/microservices/external · high confidence

Introduction of AbstractHttpAdapter base class

The core HTTP adapter layer now includes an \AbstractHttpAdapter\ class that implements the \HttpServer\ contract. This base class provides default implementations for common HTTP methods (GET, POST, etc.) and utility functions like cookie handling, while delegating framework-specific logic to the underlying instance. It serves as the foundation for platform-specific adapters like Express and Fastify, ensuring consistent behavior across different HTTP servers.

packages/core/adapters · high confidence

Introduction of WebSocketAdapter interface for custom WebSocket drivers

A new \WebSocketAdapter\ interface has been added to the common package, defining the contract for custom WebSocket drivers. This interface specifies methods for creating server instances, binding client connect and disconnect events, handling incoming messages with optional acknowledgment support, and closing connections. This change enables users to implement and inject their own WebSocket transport mechanisms rather than relying on a default implementation.

packages/common/interfaces/websockets · high confidence

Microservices package restructured with new event status enums and constants

The \@nestjs/microservices\ package has been reorganized, introducing a new \events/\ directory that exports standardized status enums (e.g., \KafkaStatus\, \RmqStatus\, \MqttStatus\) and event type maps for all supported transports. Additionally, transport-specific defaults (such as \TCP\_DEFAULT\_PORT\, \RMQ\_DEFAULT\_QUEUE\, and \KAFKA\_DEFAULT\_BROKER\) and metadata keys have been centralized in a new \constants.ts\ file, and the main \index.ts\ now explicitly re-exports these new event modules alongside existing client, decorator, and server components.

packages/microservices · high confidence

Mongoose sample now supports full CRUD operations

The Mongoose sample application has been updated to include a complete Create, Read, Update, and Delete (CRUD) workflow for managing cat records. In addition to the existing create, find all, and find one endpoints, the sample now exposes update and delete routes, allowing users to modify and remove existing documents. The implementation uses the \@nestjs/mongoose\ decorators for schema definition and \HydratedDocument\ for type safety, with corresponding unit tests verifying the new service and controller behaviors.

sample/06-mongoose · high confidence

NestJS core package restructured with new public API surface and security features

The \@nestjs/core\ package has been reorganized, introducing a new \ApplicationConfig\ class to centralize global settings such as prefix options, versioning, and route conflict policies. This update adds built-in support for CSRF protection and security headers, configurable via \NestApplicationOptions\, and introduces a \PreRequestHook\ mechanism for executing logic before guards. The public API is now explicitly defined through \index.ts\, exposing core components like \NestFactory\, \NestApplication\, and \NestApplicationContext\, while internal implementation details are isolated in \internal.ts\. Additionally, the package includes new interfaces for module definitions and overrides, and a \MetadataScanner\ with caching for improved performance.

packages/core · high confidence

New Discovery module for decorator-based metadata scanning

A new \DiscoveryModule\ and \DiscoveryService\ have been added to the core package, enabling applications to discover providers and controllers based on custom metadata keys. This feature introduces a \createDecorator\ factory that generates discoverable decorators, automatically registering decorated classes in a metadata collection. The \DiscoveryService\ exposes \getProviders\ and \getControllers\ methods to retrieve instance wrappers filtered by these metadata keys or by a specific list of included modules, facilitating advanced plugin and extension patterns.

packages/core/discovery · high confidence

New Fastify sample application with ESM and modern patterns

A new Fastify-based sample application has been added to demonstrate the framework integration. The sample uses ES modules (ESM) with \.js\ extensions in imports, reflecting the migration to ESM. It showcases key NestJS features including a Cats resource with validation via \class-validator\, role-based access control using a custom \RolesGuard\ and \SetMetadata\, and global interceptors for logging and response transformation. The entry point uses top-level await for bootstrapping, and unit tests are included for the controller and service.

sample/10-fastify · high confidence

New Graph Inspector for Dependency Graph Visualization

The core package now includes a Graph Inspector that serializes the application's dependency graph into a structured JSON format. This feature introduces a \SerializedGraph\ class and a \GraphInspector\ service that capture modules, classes, edges, and entrypoints, enabling external tools to visualize the dependency structure. The implementation includes a \DeterministicUuidRegistry\ to generate consistent identifiers for graph nodes and edges, ensuring stable output across runs. It also supports partial graph inspection for error scenarios and provides a \NoopGraphInspector\ for environments where inspection is disabled.

packages/core/inspector · high confidence

New GraphQL Code-First sample with custom directives and plugins

The sample/23-graphql-code-first location now provides a complete GraphQL code-first example that demonstrates advanced NestJS GraphQL capabilities. It includes a custom 'upper' directive that transforms field values to uppercase, a complexity plugin that rejects queries exceeding a complexity threshold of 20, a logging plugin, and a custom Date scalar. The sample also showcases input validation via class-validator decorators on DTOs and implements full CRUD operations with subscriptions.

sample/23-graphql-code-first · high confidence

New HTTP adapter interfaces for cookies, CSRF, security headers, and redirects

The \packages/common/interfaces/http\ module now exposes a set of new TypeScript interfaces that define the contract for built-in HTTP security and response features. This includes \CookieSerializeOptions\ and \CookiesOptions\ for the new adapter-agnostic cookie support, \CsrfProtectionOptions\ for Fetch-Metadata-based CSRF protection, and \SecurityHeadersOptions\ for configuring standard security headers (CSP, HSTS, etc.). Additionally, \HttpRedirectResponse\ standardizes redirect responses, \HttpExceptionBody\ adds an optional \errorCode\ field, and \HttpServer\ is expanded with methods for security hooks and cookie management. These interfaces provide the type definitions required for the new application-level security and response capabilities.

packages/common/interfaces/http · high confidence

New HTTP status codes and request method enums added

The \packages/common/enums\ module now includes expanded enumerations for HTTP interactions. The \HttpStatus\ enum has been updated to include new status codes such as EARLYHINTS (103), MISDIRECTED (421), FAILED\_DEPENDENCY (424), and PRECONDITION\_REQUIRED (428), alongside several others. Additionally, the \RequestMethod\ enum now supports WebDAV methods (PROPFIND, PROPPATCH, MKCOL, COPY, MOVE, LOCK, UNLOCK) and the QUERY method. The \RouteParamtypes\ enum has also been extended to include parameters for RAW\_BODY, ACK, COOKIES, and SIGNED\_COOKIES, enabling more granular route parameter injection.

packages/common/enums · high confidence

New MQTT integration controllers for testing and demonstration

Added \mqtt-broadcast.controller.ts\ and \mqtt.controller.ts\ to the integration microservices area. These controllers provide concrete implementations for testing MQTT transport features, including broadcast patterns, streaming, concurrent requests, wildcard topic matching, shared wildcards, and record builders with QoS settings.

integration/microservices/src/mqtt · high confidence

New Multer file-interceptor utilities for Express platform

The \packages/platform-express/multer/interceptors\ directory now provides a set of ready-to-use NestJS interceptors for handling file uploads via Multer. Specifically, \AnyFilesInterceptor\, \FileFieldsInterceptor\, \FileInterceptor\, \FilesInterceptor\, and \NoFilesInterceptor\ have been added. These interceptors wrap the corresponding Multer methods (\any\, \fields\, \single\, \array\, \none\) and integrate with the existing \MulterModuleOptions\ via dependency injection, allowing developers to easily handle single files, multiple files, specific file fields, or reject file uploads entirely within their Express-based controllers.

packages/platform-express/multer/interceptors · high confidence

New RPC and gRPC exception filters and exception classes

This change introduces a new exception handling layer for microservices. It adds a \BaseRpcExceptionFilter\ that standardizes how RPC exceptions are caught and serialized, ensuring unknown errors return a consistent \{ status: 'error', message: ... }\ payload. It also introduces a \GrpcExceptionFilter\ specifically for gRPC services, which maps \GrpcException\ instances to gRPC status codes and serializes generic \RpcException\s into the appropriate gRPC response format. Additionally, new exception classes are provided: \RpcException\ for general RPC errors, \GrpcException\ (with specific subclasses like \GrpcNotFoundException\, \GrpcInternalException\, etc.) for gRPC-specific errors, and \KafkaRetriableException\ to signal transient Kafka errors that should trigger retries. These components are exported from \packages/microservices/exceptions\ to be used by the microservices package.

packages/microservices/exceptions · high confidence

New RPC parameter extraction factory

A new RpcParamsFactory has been introduced to handle the extraction of RPC parameters from incoming arguments. This factory supports extracting the payload (with optional property extraction), context, and gRPC call objects, mapping them via the RpcParamtype enum.

packages/microservices/factories · high confidence

New Reflector service with strongly-typed decorators

The \packages/core/services\ module now exports a new \Reflector\ class that provides a strongly-typed alternative to NestJS's standard \@SetMetadata\ decorator. This service allows developers to create custom decorators with optional value transformation and supports retrieving metadata from single or multiple targets, including merging results from a set of targets. The implementation is exposed via a new \index.ts\ barrel file.

packages/core/services · high confidence

New Standard Schema serializer and ClassSerializerInterceptor improvements

The serializer module now includes a new StandardSchemaSerializerInterceptor that validates and transforms responses using the Standard Schema specification (StandardSchemaV1), allowing users to define schemas for serialization via @SerializeOptions or default interceptor options. The existing ClassSerializerInterceptor has been enhanced to support default options passed via its constructor, allowing global serialization configuration, and now properly ignores StreamableFile responses to prevent serialization errors on file streams. Additionally, the module exports updated interfaces and constants to support these new capabilities.

packages/common/serializer · high confidence

New TypeScript interfaces for Express Multer configuration

The Express platform now exposes dedicated TypeScript interfaces (\MulterOptions\, \MulterLimits\, \MulterField\, \MulterModuleOptions\, \MulterOptionsFactory\, and \MulterModuleAsyncOptions\) in the \packages/platform-express/multer/interfaces\ directory. These definitions provide structured, type-safe configuration options for file uploads, including support for dynamic options via factories and async module setup, improving developer experience when configuring the Multer module.

packages/platform-express/multer/interfaces · high confidence

New TypeScript interfaces for module configuration and providers

The \packages/common/interfaces/modules\ directory now exposes a comprehensive set of TypeScript interfaces that define the structure of NestJS modules and dependency injection. This includes \DynamicModule\ for configuring global-scoped modules, \ModuleMetadata\ detailing imports, controllers, providers, and exports, and specific provider types (\ClassProvider\, \ValueProvider\, \FactoryProvider\, \ExistingProvider\) that support advanced features like request-scoped durability (\durable\ flag), factory injection with optional dependencies, and provider aliasing via \useExisting\. These interfaces also formalize \ForwardReference\ for circular dependencies and \InjectionToken\ types, providing strict typing for module definitions and provider configurations.

packages/common/interfaces/modules · high confidence

New advanced gRPC controller for integration testing

Added a new \AdvancedGrpcController\ in the \grpc-advanced\ integration module to serve as a comprehensive test harness for gRPC capabilities. This controller exposes HTTP endpoints that proxy requests to a gRPC client and implements various gRPC service methods, including unary, server-side streaming, client-side streaming, and bidirectional streaming. It also demonstrates handling of gRPC metadata, such as setting response headers like \Set-Cookie\, providing a concrete example of advanced gRPC interactions for integration testing purposes.

integration/microservices/src/grpc-advanced · high confidence

New benchmarking tool and refactored build system

Developers can now run performance benchmarks against Express, Fastify, and NestJS (with both adapters) using a new CLI tool in tools/benchmarks that leverages autocannon. The build tooling (Gulp) has been migrated from JavaScript to TypeScript, enabling better maintainability and supporting multi-application samples with Node.js version checks.

tools · high confidence

New built-in pipes and standard schema validation support

The \packages/common/pipes\ module now includes a comprehensive set of new built-in pipes: \DefaultValuePipe\ for providing fallback values, \ParseArrayPipe\ for splitting and validating string inputs into typed arrays, \ParseBoolPipe\ for boolean coercion, \ParseDatePipe\ for date parsing with defaults, \ParseEnumPipe\ for enum validation, \ParseFloatPipe\ and \ParseIntPipe\ for numeric parsing, and \ParseUUIDPipe\ for UUID validation (including v3, v4, v5, and v7). Additionally, a \StandardSchemaValidationPipe\ has been added to support the Standard Schema spec for validation, and the \ValidationPipe\ has been updated to support custom validator/transformer packages, error formatting options, and improved primitive transformation.

packages/common/pipes · high confidence

New configurable integration module for external service connections

This change introduces a new \integration/module-utils\ package that provides a configurable NestJS module for connecting to external services. The module accepts configuration options including a required \url\ and an optional \secure\ flag, and is registered as a global module by default. It leverages the \ConfigurableModuleBuilder\ pattern to allow flexible initialization via a \forRoot\ method, enabling consumers to easily integrate external integrations into their application with strict TypeScript support and strict null checks.

integration/module-utils · high confidence

New development and testing scripts for reliable local setup

Added a set of new scripts to streamline the local development environment. A cross-platform wrapper (docker-compose.js) ensures Docker Compose commands work regardless of whether the host has V1 or V2 installed. New shell scripts (prepare.sh, run-integration.sh, test.sh) automate the build, container startup, and test execution workflows. Additionally, a wait-for-rabbitmq.js utility ensures integration tests only run after RabbitMQ is ready, and an update-samples.sh script simplifies dependency updates for sample projects.

scripts · high confidence

New file upload sample demonstrating validation with ParseFilePipeBuilder

A new sample application (29-file-upload) has been added to demonstrate file upload handling in NestJS. It showcases the use of FileInterceptor for handling multipart file uploads and illustrates how to implement file validation using ParseFilePipeBuilder, including examples for both passing and failing validation scenarios based on file type (jpeg vs jpg). The sample also includes a basic DTO for request body data and uses ESM module syntax.

sample/29-file-upload · high confidence

New hybrid HTTP/gRPC sample application

Added a new sample application in sample/04-grpc that demonstrates a hybrid NestJS setup running both HTTP and gRPC servers. The sample includes a Hero service with standard and streaming RPC methods, configured via a gRPC client module and a proto definition, and bootstrapped using ESM syntax with dynamic imports.

sample/04-grpc · high confidence

New microservice configuration and hook interfaces

This change introduces four new public interfaces in the common microservices package to support advanced microservice configuration. Users can now configure hybrid microservices to inherit application configuration via \NestHybridApplicationOptions.inheritAppConfig\ and defer initialization with \NestHybridApplicationOptions.deferInitialization\. A new \PreRequestHook\ interface allows registering global hooks that execute before guards, enabling context setup (e.g., AsyncLocalStorage) for downstream enhancers. Additionally, \ITransportServer\ exposes the shape of the transport server for better autocomplete, and \NestMicroserviceOptions\ is now explicitly defined as an alias for \NestApplicationContextOptions\.

packages/common/interfaces/microservices · high confidence

New microservices client proxy implementations and factory

This change introduces the concrete client proxy classes for all supported transport protocols (gRPC, Kafka, MQTT, NATS, Redis, RabbitMQ, and TCP) within the \packages/microservices/client\ directory, along with a \ClientProxyFactory\ to instantiate them. Each client implements the \ClientProxy\ base class, providing standardized connection management, serialization/deserialization, and status event emission (e.g., CONNECTED, DISCONNECTED, RECONNECTING) specific to its underlying broker or protocol. The factory centralizes the creation logic, mapping \Transport\ enum values to the appropriate client implementation, allowing users to configure microservices clients via a unified options interface.

packages/microservices/client · high confidence

New microservices decorators for client, context, and pattern handling

The \packages/microservices/decorators\ module now exposes a comprehensive set of decorators to configure microservice interactions. The \@Client\ decorator attaches \ClientProxy\ instances to class properties, while \@Ctx\ and \@Payload\ serve as parameter decorators for extracting RPC context and message payloads, with \@Payload\ supporting property extraction and validation pipes. Message and event handling is standardized via \@MessagePattern\ and \@EventPattern\, which now support optional transport selection and extra metadata, and include specific gRPC helpers like \@GrpcMethod\, \@GrpcStreamMethod\, and \@GrpcStreamCall\ to register service handlers. Additionally, \@GrpcService\ is provided as an alias for the standard \@Controller\ to define gRPC services.

packages/microservices/decorators · high confidence

New microservices enums for transport, Kafka, gRPC, and RPC parameter types

The microservices package now exposes a dedicated set of enums to standardize configuration and error handling across different communication patterns. Users can now reference \Transport\ for supported protocols (TCP, Redis, NATS, MQTT, gRPC, RMQ, Kafka), \KafkaHeaders\ for detailed Kafka message metadata (including framework-specific headers like \NEST\_ERR\ and \NEST\_IS\_DISPOSED\), and \GrpcStatus\ for standard gRPC status codes. Additionally, \RpcParamtype\ defines parameter types for RPC and WebSocket contexts, and \PatternHandler\ distinguishes between message and event patterns. These enums are exported via the \packages/microservices/enums\ module.

packages/microservices/enums · high confidence

New microservices sample with hybrid HTTP/TCP setup and custom strategies

The sample/03-microservices directory now provides a complete, runnable example of a NestJS hybrid application that serves both HTTP and TCP microservice endpoints. It demonstrates how to register a TCP client via ClientsModule, handle messages with @MessagePattern, and manage errors using a custom RpcExceptionFilter and LoggingInterceptor. The sample also includes a custom NatsStrategy to show how to extend the microservices transport layer, and is updated to use ES modules with ESM imports (.js extensions) and async bootstrap patterns.

sample/03-microservices · high confidence

New microservices utility functions for pattern transformation and RPC parameter decoration

The microservices package now includes new utility modules to handle RPC-specific concerns. The \transform-pattern.utils.ts\ module provides a \transformPatternToRoute\ function that safely converts complex object patterns into string routes, featuring configurable recursion depth and key limits to prevent stack overflows or excessive memory usage. Additionally, \param.utils.ts\ introduces \createRpcParamDecorator\ and \createPipesRpcParamDecorator\, which enable the use of NestJS parameter decorators (such as \@MessagePattern\ arguments) with support for pipes and JSON schema validation options, aligning RPC parameter handling with the broader framework's decorator ecosystem.

packages/microservices/utils · high confidence

New public API interfaces for NestJS core capabilities

The \packages/common/interfaces\ directory now exposes a comprehensive set of TypeScript interfaces and types that define the public API for core NestJS features. This includes \INestApplicationContext\ and \NestApplicationContextOptions\ for application lifecycle and configuration (e.g., \abortOnError\, \preview\, \instrument\), \INestApplication\ and \NestApplicationOptions\ for HTTP-specific settings (e.g., \cors\, \rawBody\, \forceCloseConnections\, \routeConflictPolicy\, \cookies\), and \INestMicroservice\ for microservice contexts (e.g., \registerPreRequestHook\, \status\, \unwrap\). Additionally, it introduces interfaces for dependency injection scopes (\Scope\, \ScopeOptions\), API versioning (\VersionOptions\, \VersioningOptions\), router behavior (\RouteConflictPolicy\, \RouteResolutionStrategy\), and security features like CSRF and security headers. These interfaces provide the type definitions and options objects required to configure and interact with the framework's advanced features.

packages/common/interfaces · high confidence

New public API interfaces for execution context, arguments, and pipes

This change introduces a set of new TypeScript interfaces in the common package that define the public API for NestJS's core execution features. Specifically, it adds \ArgumentsHost\ (with context switching for HTTP, WebSocket, and RPC), \ExecutionContext\ (extending \ArgumentsHost\ to expose handler and controller details), \NestInterceptor\ and \CallHandler\ for interceptor implementation, \CanActivate\ for guards, and \PipeTransform\ along with \ArgumentMetadata\ for parameter validation. These interfaces standardize how developers interact with the request pipeline, guards, interceptors, and pipes, providing explicit types for argument metadata including support for standard schemas.

packages/common/interfaces/features · high confidence

New public interfaces for microservices configuration, serialization, and client proxies

This change introduces a comprehensive set of new TypeScript interfaces in the \packages/microservices/interfaces\ package to standardize and expose the public API for microservice communication. Users can now explicitly define custom serializers and deserializers via the new \Serializer\ and \Deserializer\ interfaces, which support async operations. Configuration for all supported transports (gRPC, Kafka, MQTT, NATS, Redis, TCP, RabbitMQ) is now strictly typed through \MicroserviceOptions\ and specific option interfaces (e.g., \GrpcOptions\, \KafkaOptions\), exposing granular settings like keepalive, buffer sizes, and TLS options. Additionally, new interfaces such as \ClientGrpc\, \ClientKafkaProxy\, and \CustomTransportStrategy\ provide clear contracts for interacting with gRPC services, managing Kafka consumer/producer instances, and implementing custom transport strategies, while \MessageHandler\ and \RequestContext\ define the structure for handling incoming messages and accessing RPC context.

packages/microservices/interfaces · high confidence

New record builders for MQTT, NATS, and RabbitMQ microservices

Added new \record-builders\ module that provides builder classes for creating structured records in microservice communication. The module exports \MqttRecordBuilder\ (supporting QoS, retain, duplicate flags, and MQTT 5.0 properties), \NatsRecordBuilder\ (supporting custom headers), and \RmqRecordBuilder\ (supporting RabbitMQ-specific options like expiration, persistence, delivery mode, and headers). These builders allow developers to construct typed records with protocol-specific metadata before sending messages.

packages/microservices/record-builders · high confidence

New router interface contracts for route resolution and conflict handling

The router module now exposes a set of new internal interfaces that formalize how routes are resolved, registered, and validated. \ResolvedRoute\ and \RoutePathMetadata\ define the structure of final route descriptions, including composed paths, host/version constraints, and handler chains. \Resolver\ standardizes the contract for walking the controller graph and registering routes on the HTTP adapter, supporting deferred registration via \RouteResolutionOptions\. \RouteConflict\ and \ConflictKind\ introduce explicit types for detecting and distinguishing between duplicate and shadowed route overlaps, enabling better diagnostics. Additional interfaces like \ExceptionsFilter\, \ExcludeRouteMetadata\, and \IRouteParamsFactory\ provide structured contracts for exception handling, route exclusion, and parameter resolution.

packages/core/router/interfaces · high confidence

New samples for Zod validation and Valibot serialization

Added two new sample applications demonstrating request validation and response serialization using the Standard Schema protocol. The \35-zod-validation\ sample shows how to use Zod schemas with \StandardSchemaValidationPipe\ to validate incoming request bodies, while the \36-valibot-serializer\ sample demonstrates using Valibot schemas with \StandardSchemaSerializerInterceptor\ to transform and filter outgoing responses.

sample/35-zod-validation, sample/36-valibot-serializer · high confidence

New serializer implementations for Kafka, MQTT, NATS, and RMQ

The \packages/microservices/serializers\ module now includes dedicated serializer classes for Kafka, MQTT, NATS, and RabbitMQ (RMQ), along with an IdentitySerializer and a central index for exports. These serializers handle protocol-specific formatting: Kafka requests are encoded with JSON stringification for objects and preserved keys/headers; MQTT packets are serialized to JSON strings, extracting data from MqttRecord instances; NATS records are built with headers and stringified data; and RMQ packets preserve options from RmqRecord instances. This change standardizes how microservice messages are prepared for transmission across different transport layers.

packages/microservices/serializers · high confidence

New utility functions for configurable module options and provider injection

This change introduces two new utility functions in the module-utils package to support configurable module patterns. The \generateOptionsInjectionToken\ function creates unique injection tokens for module options using a random string generator, ensuring isolation between different module instances. The \getInjectionProviders\ function recursively resolves all necessary providers for a given set of injection tokens, handling optional factory dependencies and preventing circular loops or duplication. These utilities are exported via a new index file, providing a clean API for internal module configuration logic.

packages/common/module-utils/utils · high confidence

Repository initialized with foundational configuration and documentation

The repository is established with essential infrastructure files, including a Lerna monorepo setup (version 12.1.0), commit linting rules, and code formatting configurations for Prettier and oxlint. It also includes a Vitest test configuration, a Gulp build file, and comprehensive project documentation such as the README (in English, Chinese, Japanese, and Korean), Contributing guidelines, Code of Conduct, and Security policy.

(repo-wide) · high confidence

Support for property-based dependency injection in the integration injector

The integration injector now supports injecting dependencies directly into class properties using the @Inject decorator. This allows services to receive dependencies via property injection rather than constructor injection, supporting both string tokens and Symbol-based tokens for dependency resolution.

integration/injector/src/properties · high confidence

Support for raw body access in Express body parsers

The platform now allows users to access the raw request body when using body parsers. A new utility function configures the body parser to attach the raw buffer to the request object (via the \rawBody\ property) when the \rawBody\ option is enabled, enabling middleware or handlers to inspect the unprocessed payload alongside the parsed data.

packages/platform-express/adapters/utils · high confidence

Removals

Removal of Nest core framework and Socket.IO integration

The entire \src/nest\ directory has been deleted, removing the application's custom Nest-like framework implementation and its Socket.IO integration. This change eliminates the core dependency injection system (NestContainer, NestInjector, NestInstanceLoader), the module and route scanning logic, the Express-based router builder, and the decorators used to define modules, components, and routes. It also removes the Socket.IO gateway infrastructure, including the SocketModule, SocketsContainer, and the SocketGateway decorator, effectively stripping the application of its server-side framework and real-time communication capabilities.

src/nest · high confidence

Removal of legacy application bootstrap and user management modules

The application's previous entry point and configuration structure have been removed, including the Express-based application class, configuration setup for logging and body parsing, and the MongoDB connection logic. Additionally, the entire user management module has been deleted, removing the REST API route for retrieving users, the service layer for database queries, the WebSocket gateway for real-time connections, and the module definitions that wired these components together.

src/app, src/app/modules/users · high confidence

Architecture

New microservices server architecture with transport-specific implementations

The microservices server layer has been restructured into a modular, transport-specific architecture. A new \ServerFactory\ now dynamically instantiates the appropriate server class based on the configured transport (TCP, Redis, NATS, MQTT, RabbitMQ, Kafka, or gRPC). Each transport has its own dedicated server class (e.g., \ServerKafka\, \ServerRMQ\, \ServerGrpc\) that handles connection management, event binding, and message processing specific to that protocol. The base \Server\ class provides common functionality like serialization, deserialization, and pattern matching, while individual server implementations extend it to handle transport-specific features such as gRPC service loading, Kafka consumer groups, or RabbitMQ channel management. This change improves code organization, maintainability, and allows for better isolation of transport-specific logic.

packages/microservices/server · high confidence

Behavioural changes

Add option to suppress logging during lazy module loading

The LazyModuleLoader now accepts a \logger\ option in its load method. When set to \false\, the loader temporarily replaces the instance logger with a silent logger during the module loading process and restores the original logger afterward, preventing log output for that specific lazy load operation.

packages/core/injector/lazy-module-loader · high confidence

Cats sample application migrated to ESM and modernized

The 01-cats-app sample has been updated to use ES modules (ESM) with .js extensions in imports, and the bootstrap entry point now uses top-level await. The application wiring now includes a CoreModule that registers global interceptors (TransformInterceptor and LoggingInterceptor) alongside the CatsModule, and the main entry point applies a global ValidationPipe. Role-based access control is demonstrated via a RolesGuard and Roles decorator on the create endpoint, and unit tests have been added for the CatsController and CatsService.

sample/01-cats-app · high confidence

Dependency injection container and injector refactored into modular components

The core dependency injection system has been restructured into distinct, specialized classes to improve maintainability and clarity. The \NestContainer\ now delegates module compilation to a new \ModuleCompiler\ and manages module registration via \NestContainer\. Instance resolution logic has been extracted into \AbstractInstanceResolver\, which provides \find\ and \resolvePerContext\ methods for handling static and context-specific lookups. A new \InstanceLinksHost\ manages the mapping between injection tokens and their corresponding \InstanceWrapper\ references, simplifying lookup logic in \ModuleRef\. The \InstanceWrapper\ class has been enhanced to support context-aware instance storage via \ContextId\ and \HostComponentInfo\, enabling better isolation for request and transient scopes. Additionally, a \SettlementSignal\ class is introduced to manage asynchronous provider resolution and detect circular dependencies. These changes refine how the framework manages provider lifecycles, scopes, and dependency graph integrity.

packages/core/injector · high confidence

Dynamic Modules sample rewritten with configurable ID generation

The dynamic modules sample (sample/25-dynamic-modules) has been rewritten to demonstrate how to create a configurable, reusable module using NestJS dynamic modules. The new structure introduces an IdGeneratorModule that accepts a 'prefix' option via a static register() method, allowing consumers like UsersModule and OrdersModule to inject distinct ID prefixes ('usr\' and 'ord\'). This change shifts the sample from a static module structure to one that showcases dynamic configuration and dependency injection patterns, with all source files converted to ES modules and the bootstrap process updated to use top-level await.

sample/25-dynamic-modules · high confidence

Enhanced error messages with actionable solutions and improved diagnostics

The error reporting system in the core package has been significantly improved to provide better developer experience. Unknown dependency errors now include specific potential solutions, such as checking for incorrect 'import type' usage or verifying module imports. Invalid module creation errors now display the received value's type and name, and circular dependency errors now list the full scope of involved modules. Additionally, a new exception handling infrastructure (ExceptionHandler and ExceptionsZone) ensures errors are logged and logs are flushed before process teardown.

packages/core/errors · high confidence

HTTP decorator module restructured with new capabilities

The HTTP decorator module has been reorganized into a dedicated location, introducing several new features and behavioral updates. A new @Header() decorator allows setting response headers directly on controller methods, while the @Redirect() decorator enables explicit URL redirections with optional status codes. The @Sse() decorator now supports an options object to specify custom HTTP methods (defaulting to GET), and a new @SseSignal() parameter decorator injects an AbortSignal for managing Server-Sent Events lifecycle. The core routing decorators (@Get, @Post, etc.) have been expanded to support additional HTTP methods including SEARCH, QUERY, and WebDAV methods (PROPFIND, PROPPATCH, MKCOL, COPY, MOVE, LOCK, UNLOCK). The parameter decorator system has been enhanced with a new options interface supporting schema validation and pipe configuration, and the @Response() decorator now accepts a passthrough option to control response handling behavior.

packages/common/decorators/http · high confidence

Improved file-upload error handling and options merging

File uploads now provide more precise error responses: multer and busboy errors are mapped by their error codes rather than fragile message strings, ensuring consistent HTTP status codes (400 or 413) and including the specific field name in the error message when available. Additionally, when both global module options and local interceptor options define limits, they are now merged key-by-key instead of the local settings overriding the global ones entirely, preventing accidental loss of other limit constraints.

packages/platform-express/multer/multer · high confidence

Interceptors now support AsyncLocalStorage context propagation

The interceptor execution flow has been refactored to correctly inherit the asynchronous execution context (such as AsyncLocalStorage) when invoking handlers. By wrapping the handler invocation in \AsyncResource.bind\ and eagerly resolving the next promise within that bound scope, the framework ensures that async context is preserved throughout the interceptor chain, preventing context loss that could occur if the async operation were deferred to a later subscription phase.

packages/core/interceptors · high confidence

Introduce explicit TypeScript interfaces for StreamableFile and handler responses

The file-stream module now exposes dedicated TypeScript interfaces to improve type safety and documentation for streaming capabilities. \StreamableFileOptions\ is introduced to explicitly define the options for the \StreamableFile\ class, notably allowing the \disposition\ header to accept either a string or an array of strings. Additionally, a new \StreamableHandlerResponse\ interface is provided to type the underlying HTTP response object, exposing properties like \destroyed\, \headersSent\, \statusCode\, and methods \send\ and \end\. These interfaces are re-exported from a new \interfaces\ barrel file.

packages/common/file-stream/interfaces · high confidence

Introduce explicit pipe execution infrastructure

The core pipe execution logic has been restructured into dedicated modules: \PipesContextCreator\ now handles the resolution of global and scoped pipes using the \iterare\ library, \PipesConsumer\ manages the sequential application of transforms, and \ParamsTokenFactory\ provides explicit string mapping for route parameter types. This change establishes a clearer separation of concerns for how pipes are collected, instantiated, and applied to request data.

packages/core/pipes · high confidence

Introduce internal core module factory and registration

The internal core module is now structured with a dedicated factory class that registers essential providers (such as ExternalContextCreator, ModulesContainer, HttpAdapterHost, LazyModuleLoader, and SerializedGraph) using factory functions, and an internal module that exports core utilities like Reflector and request/inquirer providers. This change centralizes the wiring of these internal dependencies and ensures they are available globally within the application context.

packages/core/injector/internal-core-module · high confidence

Introduce new file upload validation pipeline with ParseFilePipe and validators

The file upload handling in the common package has been refactored to use a new \ParseFilePipe\ and \ParseFilePipeBuilder\ instead of the previous implementation. This change introduces a dedicated \FileTypeValidator\ that validates files by inspecting magic numbers (via the \file-type\ package) rather than relying solely on the client-provided MIME type, providing more robust security against spoofed file types. The validator supports advanced options such as \fallbackToMimetype\ (to fall back to client MIME if magic number detection fails), \overrideMimeType\ (to replace the client MIME with the detected one), and \skipMagicNumbersValidation\. A new \MaxFileSizeValidator\ is also included, allowing size checks with customizable error messages. Users can now compose validation rules using the builder pattern or pass custom validators implementing the \FileValidator\ interface to the \ParseFilePipe\.

packages/common/pipes/file · high confidence

Introduce request-scoped provider for the REQUEST token

The router request module now exports a dedicated \requestProvider\ that binds the \REQUEST\ token with \Scope.REQUEST\. This ensures that any component injecting the \REQUEST\ token receives a new instance per HTTP request, enabling request-scoped middleware and services to access request-specific data without retaining state across requests.

packages/core/router/request · high confidence

Introduce strict TypeScript interfaces for NestExpressApplication and body parsers

This change extracts and defines explicit TypeScript interfaces for the Express platform, including \NestExpressApplication\, \NestExpressBodyParserOptions\, and \ServeStaticOptions\. For users, this means improved type safety and IntelliSense when configuring the Express adapter, particularly for \useBodyParser\ which now enforces specific option types per parser (json, urlencoded, text, raw) and excludes the reserved \verify\ option. The \NestExpressApplication\ interface now clearly exposes methods like \setLocal\, \useStaticAssets\, and \enableCors\ with precise signatures, replacing previous loose or implicit typing.

packages/platform-express/interfaces · high confidence

JWT authentication sample migrated to ESM and native NestJS guards

The 19-auth-jwt sample has been rewritten to use ES modules (ESM) and native NestJS authentication mechanisms, removing the previous dependency on the Passport library. The application now uses a custom AuthGuard and JwtService to handle token verification and user payload injection, with the entry point updated to use top-level await for bootstrapping. This change provides a modern, framework-native example of implementing JWT-based authentication without external middleware.

sample/19-auth-jwt · high confidence

Lifecycle hooks are now executed in dependency hierarchy order

The execution of lifecycle hooks (OnModuleInit, OnModuleDestroy, OnApplicationBootstrap, OnApplicationShutdown, and the new BeforeApplicationShutdown) has been refactored to respect the application's dependency hierarchy. Instances are now grouped by their hierarchy level and invoked in a specific order (ascending for initialization, descending for destruction), ensuring that dependencies are initialized before dependents and destroyed in the reverse order. This change also introduces the BeforeApplicationShutdown hook, which runs prior to the standard OnApplicationShutdown hook, and improves shutdown reliability by using Promise.allSettled to ensure the shutdown process continues even if individual hook implementations reject.

packages/core/hooks · high confidence

Migrate GraphQL integration sample to ESM and dynamic schema loading

The GraphQL schema-first integration sample has been updated to use ES modules (ESM), evidenced by the use of \import.meta.dirname\ in module configurations and \.js\ extensions in imports. The application now dynamically loads GraphQL schema files using glob patterns (\\\/\*.graphql\) via the Apollo driver, replacing static or path-specific schema definitions. This change affects how the NestJS application bootstraps and resolves schema files, requiring Node.js ESM support and updating the module structure to support asynchronous configuration patterns.

integration/graphql-schema-first/src · high confidence

Migrate Husky to v9 with updated hook scripts

The project has upgraded Husky from version 8 to version 9, replacing the previous hook implementation with new scripts for commit messages and pre-commit stages. The \commit-msg\ hook now uses \npx --no-install commitlint --edit $1\ to validate commit messages, while the \pre-commit\ hook runs \npx lint-staged\ to manage staged file linting. This change ensures compatibility with the latest Husky version and standardizes the execution of linting and commit validation tasks.

.husky · high confidence

Migrate MVC sample to ESM and externalize static assets

The MVC sample application has been updated to use ES modules (ESM), evidenced by the use of \import.meta.url\ and \.js\ extensions in imports. The project structure has changed to move the \public\ and \views\ directories outside of the \src\ folder, with \main.ts\ now explicitly configuring static asset and view paths relative to the compiled output directory. Additionally, the bootstrap logic in \main.ts\ now uses top-level await.

sample/15-mvc · high confidence

Migrate sample to ESM and Fastify adapter

The 17-mvc-fastify sample has been updated to use ES modules (import/export syntax) and the @nestjs/platform-fastify adapter. The application now bootstraps using an async bootstrap function with an explicit await, configures Handlebars as the view engine, and serves static assets from a public directory, reflecting a shift from CommonJS to modern module standards.

sample/17-mvc-fastify · high confidence

Mongoose sample now uses ESM and explicit await for bootstrap

The sample application has been migrated to ECMAScript Modules (ESM), evidenced by the .js extensions on all local imports and the use of top-level await in main.ts. This ensures the module loader correctly resolves dependencies and that the NestJS application bootstrap process is fully awaited before the script exits, aligning the sample with modern Node.js module standards.

sample/14-mongoose-base · high confidence

Multer module now generates unique IDs to support nested options

The Multer module has been updated to inject a unique identifier (MULTER\_MODULE\_ID) into the dependency injection container for every registration. This change resolves issues where nested or multiple file-upload configurations could conflict, ensuring that each instance of the module is distinctly identified and options are correctly isolated.

packages/platform-express/multer · high confidence

New RPC execution context and exception handling infrastructure

The microservices module now includes a dedicated context layer for RPC handlers, introducing \RpcContextCreator\ to manage the execution pipeline (guards, pipes, interceptors, and pre-request hooks) and \ExceptionFiltersContext\ to handle errors via \RpcExceptionsHandler\. A new \RpcProxy\ wraps handler calls to catch synchronous and asynchronous errors, while \RequestContextHost\ provides a standardized way to access the RPC pattern, data, and underlying transport context within handlers. This refactors how RPC requests are processed and errors are reported, moving away from the previous implicit context handling.

packages/microservices/context · high confidence

New Swagger sample with typed responses and ESM support

The 11-swagger sample has been updated to demonstrate real-world usage by implementing typed responses (e.g., returning the \Cat\ entity directly) and migrating to ES modules (ESM) with \.js\ extensions in imports. The sample now includes unit tests for the controller and service, uses \class-validator\ for DTOs, and configures Swagger with Bearer authentication and specific API property examples.

sample/11-swagger · high confidence

New internal helper utilities for provider classification and debug mode

This change introduces three new internal helper files within the injector helpers directory. The \provider-classifier.ts\ file adds type-guard functions (\isClassProvider\, \isValueProvider\, \isFactoryProvider\) to reliably identify provider types, replacing previous type assertions. The \is-debug-mode.util.ts\ file provides a shared helper to check for the \NEST\_DEBUG\ environment variable. Additionally, a \SilentLogger\ class is added to suppress all logging output, including a new \fatal\ level, which can be used to disable logging in specific contexts.

packages/core/injector/helpers · high confidence

New topology tree for cycle-safe dependency traversal

The injector now uses a dedicated TopologyTree and TreeNode implementation to map module dependencies. This change introduces cycle detection during tree construction to prevent infinite loops and allows for safe depth calculation, ensuring that the dependency graph is traversed correctly even when circular references exist.

packages/core/injector/topology-tree · high confidence

New utility functions for route exclusion and path flattening

The router utilities now include \isRouteExcluded\ to determine if a route should be skipped based on metadata and request method, and \flattenRoutePaths\ to normalize and combine nested route paths into a flat list of module-path pairs. These utilities are exported from the core router utils package to support internal routing logic.

packages/core/router/utils · high confidence

REPL native functions are split into individual modules with added descriptions and formatting

The REPL native functions (debug, get, help, methods, resolve, select) have been refactored from a monolithic structure into separate, dedicated files within the native-functions directory, improving code organization and maintainability. The 'debug' function now includes a detailed description in its definition and outputs a newline before printing module information for better readability. The 'help' function has been updated to display these descriptions alongside function names, providing users with clearer guidance on available commands. Additionally, internal implementation details like the nativeFunctions storage have been optimized using Maps for better performance.

packages/core/repl/native-functions · high confidence

Recipes integration now uses GraphQL Code-First with real-time subscriptions

The recipes integration has been migrated to a GraphQL Code-First approach, defining the schema via decorators on the \Recipe\ model, \NewRecipeInput\, and \RecipesArgs\ DTOs. The \RecipesResolver\ exposes queries for listing and fetching recipes, mutations for adding and removing them, and a \recipeAdded\ subscription that uses \graphql-subscriptions\ to notify clients in real time. The module registers a custom \DateScalar\ for handling date serialization, an \UnauthorizedFilter\ for consistent error handling, and an \AuthGuard\ to enforce authentication on specific queries.

integration/graphql-code-first/src/recipes · high confidence

Redefine middleware configuration interfaces to support route exclusion

The middleware configuration interfaces have been restructured to explicitly support excluding specific routes from middleware application. The \MiddlewareConfigProxy\ interface now includes an \exclude\ method, allowing users to specify paths or route info objects that should bypass the current middleware. Additionally, the \RouteInfo\ interface has been updated to include an optional \version\ field, enabling version-specific route matching within middleware configurations. These changes provide finer control over middleware application scope.

packages/common/interfaces/middleware · high confidence

Refactor core helpers into a modular structure

The \packages/core/helpers\ directory has been reorganized into a modular structure, introducing dedicated files for specific concerns such as \Barrier\ for synchronizing async operations, \ContextIdFactory\ for managing execution context identifiers, and \ExecutionContextHost\ for handling request context switching. This change also extracts \HttpAdapterHost\ to expose the listening stream and initialization state, and introduces \ExternalContextCreator\ to centralize the creation of guarded, intercepted, and piped handler contexts. Additionally, new utilities like \RouterMethodFactory\ for HTTP method mapping and \SafeInstanceDecorator\ for robust instance decoration have been added to improve reliability and performance.

packages/core/helpers · high confidence

Refactored exception classes to use centralized message templates

The exception classes in \packages/core/errors/exceptions\ have been refactored to derive their error messages from centralized template functions (e.g., \UNKNOWN\_DEPENDENCIES\_MESSAGE\, \INVALID\_MODULE\_MESSAGE\) rather than hardcoded strings. This change ensures that error messages now consistently include contextual details such as the received value type, module names, and specific dependency tokens, providing clearer diagnostics for configuration errors.

packages/core/errors/exceptions · high confidence

Refactored exception handling into modular filter contexts and handlers

The exception handling logic in the core package has been restructured into distinct, reusable components: \BaseExceptionFilter\ (handling standard HTTP and unknown errors), \ExceptionsHandler\ (managing custom filters for internal contexts), \ExternalExceptionFilter\ (logging and rethrowing for external contexts), and their respective context creators (\BaseExceptionFilterContext\, \ExternalExceptionFilterContext\). This change separates the concerns of filter instantiation, metadata selection, and error response generation, allowing for more granular control over how exceptions are caught and processed in both internal and external request flows.

packages/core/exceptions · high confidence

Refactored guard execution into dedicated consumer and context creator classes

The guard handling logic in the core package has been reorganized into two new classes: \GuardsConsumer\ and \GuardsContextCreator\. \GuardsConsumer\ now centralizes the execution of \CanActivate\ guards, supporting synchronous, Promise, and RxJS Observable return types via a new \tryActivate\ method. \GuardsContextCreator\ manages the instantiation and retrieval of guard instances from the container, handling both global and request-scoped guards. This change introduces a clearer separation of concerns for how guards are created and executed within the application context.

packages/core/guards · high confidence

Refactored logging system with structured params and enhanced ConsoleLogger options

The logging infrastructure in \packages/common/services\ has been refactored to support structured logging and more granular control over output. The \ConsoleLogger\ now accepts a \structuredParams\ option (enabled by default) to treat plain objects passed as arguments as metadata rather than separate log messages, with a \flattenParams\ option to control JSON nesting. Output formatting is now configurable via \ConsoleLoggerOptions\, including \compact\ mode for single-line object display, \maxArrayLength\ and \maxStringLength\ limits, and \sorted\ keys. The \Logger\ service wraps these methods with a buffer mechanism for performance, and the \ConsoleLogger\ supports a \forceConsole\ option to bypass \process.stdout\ buffering in test environments.

packages/common/services · high confidence

Refactored logging utilities and added 'fatal' log level support

The logging utility functions have been extracted into dedicated modules (filter-log-levels, is-log-level-enabled, is-log-level) to improve code organization. A new 'fatal' log level has been introduced, expanding the available logging severity options. The isLogLevelEnabled function has been optimized to use a single-pass check instead of sorting, and the system now supports parsing log level filters via strings (e.g., '\>warn' or 'error,log').

packages/common/services/utils · high confidence

Refactored middleware execution and routing logic

The middleware system has been refactored to improve execution order and route matching. The \MiddlewareBuilder\ now uses a \ConfigProxy\ to handle route exclusions and applies middleware configurations based on module dependency distance, ensuring global middleware runs first. Route matching logic has been updated to correctly handle overlapping routes, versioned routes, and global prefixes, while the \RouteInfoPathExtractor\ ensures paths are correctly resolved against the global prefix and versioning configuration. Additionally, the \MiddlewareContainer\ now properly manages middleware instance wrappers with scope and durability metadata.

packages/core/middleware · high confidence

Refactored shared utilities into a modular utils package

The shared utility functions previously scattered across the codebase have been consolidated into a new, modular \packages/common/utils\ directory. This change introduces dedicated files for specific concerns, including \load-package.util.ts\ for safer dependency loading, \cli-colors.util.ts\ for terminal output, \strip-proto-keys.util.ts\ for security against prototype pollution, and \shared.utils.ts\ for common type guards and path normalization. This restructuring improves code organization and maintainability for internal framework components.

packages/common/utils · high confidence

Refactors microservices transport helpers and adds gRPC package definition validation

The microservices transport layer has been refactored to improve stability and configurability. TCP and JSON socket handling now uses an abstract base class to prevent stack overflows during pipelined message processing and enforces memory limits to bound peer buffer usage. Kafka support includes a new reply partition assigner that preserves previous assignments to ensure replies are routed correctly, a parser that can preserve binary payloads without UTF-8 encoding, and a dedicated logger helper. Additionally, gRPC helpers now validate that exactly one of 'protoPath' or 'packageDefinition' is provided, preventing ambiguous configuration.

packages/microservices/helpers · high confidence

Removal of legacy NestJS server entry point

The legacy server entry point (src/server.ts) has been removed. This file previously initialized the NestJS application using a custom NestRunner, and its deletion indicates that the application startup process has been refactored or migrated to a different entry mechanism.

src · high confidence

Router module restructured into dedicated package with legacy route conversion and conflict detection

The router logic has been extracted into a new \packages/core/router\ module, introducing a \LegacyRouteConverter\ that automatically migrates deprecated wildcard syntax (like \\\ and \(.\)\) to the new \path-to-regexp\ format while logging warnings, and a \RouteConflictDetector\ that identifies overlapping routes and enforces specificity ordering to ensure predictable request handling.

packages/core/router · high confidence

Samples now use Vitest for testing and ESM modules

The sample applications have been updated to use the Vitest test runner instead of Jest, with new \vitest.config.mts\ and \vitest.config.e2e.mts\ files added to each sample directory. Additionally, the samples have been migrated to use ES modules (ESM) as indicated by the \nodenext\ module resolution in \tsconfig.json\ and the \.js\ extensions in test imports. E2E tests have been added or updated for multiple samples including cats-app, gateways, microservices, grpc, sql-typeorm, mongoose, sequelize, fastify, and swagger.

sample · high confidence

Socket.IO adapter deduplicates disconnect listeners and prevents handler errors from breaking message streams

The Socket.IO platform adapter now ensures that only a single disconnect listener is registered per socket, even when multiple gateways bind handlers to the same connection, preventing duplicate disconnect events. Additionally, message handlers that throw errors no longer tear down the underlying event stream; errors are logged and subsequent messages on the same event continue to be processed and acknowledged normally.

packages/platform-socket.io · high confidence

Updated GraphQL schema-first sample with owner resolution and custom directives

The schema-first GraphQL sample now demonstrates resolving nested fields using the @ResolveField decorator, allowing a Cat entity to fetch its associated Owner via a dedicated CatOwnerResolver. The sample also includes a custom upper-case directive transformer that modifies schema fields, a logging plugin for request lifecycle monitoring, and a custom Date scalar. Additionally, the module configuration has been updated to use the ApolloDriver, and unit tests have been added for the resolvers and services to verify the new owner resolution and validation logic.

sample/12-graphql-schema-first · high confidence

Updated MongoDB TypeORM sample to use ESM and modern NestJS patterns

The sample/13-mongo-typeorm application has been migrated to ES modules (ESM), with all source files now using .js extensions in imports and top-level await in main.ts. The photo entity now uses TypeORM's ObjectIdColumn for MongoDB \_id fields, and the service layer explicitly injects a MongoRepository. Unit tests for the controller and service have been added using Vitest, and the bootstrap process now logs the application URL upon startup.

sample/13-mongo-typeorm · high confidence

Updated Sequelize sample to use ESM and explicit MySQL configuration

The sample/07-sequelize directory has been migrated to ES modules (ESM), evidenced by the .js extensions in all import statements and the top-level await in main.ts. The application now explicitly configures the Sequelize connection to use the MySQL dialect on host 127.0.0.1, replacing any previous implicit or different database settings. Additionally, the sample includes updated unit tests for the Users controller and service, utilizing the vi mocking library.

sample/07-sequelize · high confidence

Updated TypeORM sample to use ESM, auto-loading entities, and explicit host configuration

The sample application has been refactored to use ES modules (importing .js extensions) and modernized TypeORM configuration. The database connection now explicitly sets the host to 127.0.0.1 and enables autoLoadEntities, simplifying entity registration. Additionally, the bootstrap process in main.ts now uses top-level await, and the user controller ensures ID parameters are parsed as integers for findOne operations.

sample/05-sql-typeorm · high confidence

Updated WebSocket gateway sample with ESM and Redis adapter scaffolding

The 02-gateways sample has been migrated to ES modules (ESM), updating file extensions to .js and using top-level await in main.ts. The EventsGateway now uses Socket.IO decorators and exposes 'events' and 'identity' handlers. A new RedisIoAdapter class is provided to demonstrate how to integrate Redis for horizontal scaling, though it is commented out by default in main.ts. Unit and e2e tests have been added to verify gateway behavior.

sample/02-gateways · high confidence

WebSockets package restructured into modular ESM layout

The \@nestjs/websockets\ package has been reorganized from a flat structure into a modular directory layout (e.g., \adapters/\, \context/\, \decorators/\, \exceptions/\, \factories/\, \interfaces/\) with explicit ESM exports. This change introduces the \@Ack()\ decorator for manual acknowledgement handling, updates the \BaseWsExceptionFilter\ to support a \cause\ object in error payloads for better error context, and refactors the internal context creation and exception handling logic to align with the new modular architecture.

packages/websockets · high confidence

Test coverage

Add Mongoose integration test suite; Add NATS microservice integration tests with record builder and broadcast support; Add Redis-based microservice integration controllers; Add integration test fixtures for multi-package gRPC and streaming scenarios; Add integration test for NestApplication.getUrl; Add integration test for graceful shutdown behavior; Add integration test infrastructure for microservices transports; Add integration tests for error handling scenarios; Add integration tests for lazy module dependency resolution; Add integration tests for middleware and versioning interactions; Add integration tests for optional dependency default assignments; Add integration tests for request-scoped, transient, and durable providers; Add self-injection provider modules for integration testing; Added CORS integration test application; Added E2E tests for file upload functionality; Added TypeORM integration test for photo management; Added comprehensive e2e integration tests for the hello-world application; Added comprehensive tests for TopologyTree and TreeNode classes; Added comprehensive unit tests for JsonSocket microservice communication; Added dynamic module integration test fixture; Added e2e tests for HTTP QUERY method lifecycle; Added e2e tests for lifecycle hook execution order and shutdown signals; Added e2e tests for the context sample application; Added e2e tests for the serializer sample; Added end-to-end test for JWT authentication flow; Added end-to-end tests for API versioning strategies; Added end-to-end tests for Express CORS configuration; Added end-to-end tests for Express app.locals integration; Added end-to-end tests for Mongoose integration options; Added end-to-end tests for NestApplication.getUrl(); Added end-to-end tests for NestJS application listen behavior; Added end-to-end tests for Server-Sent Events on Express and Fastify; Added end-to-end tests for TypeORM integration scenarios; Added end-to-end tests for WebSocket gateways; Added end-to-end tests for file streaming capabilities; Added end-to-end tests for graceful shutdown behavior; Added end-to-end tests for lazy module imports; Added end-to-end tests for raw body handling in Express and Fastify adapters; Added end-to-end tests for the REPL functionality; Added end-to-end tests for the cache sample application; Added end-to-end tests for the dynamic modules sample; Added end-to-end tests for the graph inspector; Added individual test suites for HTTP exception classes; Added integration test fixture for NestJS application listen behavior; Added integration test for circular property injection in ESM; Added integration test for circular structures in dynamic modules; Added integration test setup for the injector module; Added integration test suite for auto-mocking capabilities; Added integration tests for DI scopes and durable providers; Added integration tests for NestJS dependency injection scenarios; Added integration tests for auto-mocking capabilities; Added integration tests for circular dependency injection in ESM; Added integration tests for decorator-based discovery; Added integration tests for multiple provider resolution; Added test coverage for StreamableFile; Added test coverage for the core graph inspector utilities; Added test data for special characters in TCP microservice messages; Added test utility files for mocking and string manipulation; Added tests for ConfigurableModuleBuilder; Added tests for LazyModuleLoader behavior; Added tests for Observable response lifecycle on client disconnect; Added tests for RpcParamsFactory; Added tests for built-in cookie handling and signing; Added tests for flattenRoutePaths utility; Added tests for getBodyParserOptions utility; Added tests for getInjectionProviders utility; Added tests for microservices pattern transformation utility; Added tests for transient scope injection via ModuleRef.create; Added unit tests for ClientsModule registration; Added unit tests for Express adapter error handling and middleware registration; Added unit tests for GuardsConsumer and GuardsContextCreator; Added unit tests for InterceptorsConsumer and InterceptorsContextCreator; Added unit tests for InternalCoreModuleFactory; Added unit tests for MulterModule configuration and error transformation logic; Added unit tests for REPL utility functions and context components; Added unit tests for class and standard-schema serializer interceptors; Added unit tests for common decorators; Added unit tests for common pipes and validation; Added unit tests for common utility functions; Added unit tests for core application configuration and security features; Added unit tests for core error handling and messaging; Added unit tests for core exception handling components; Added unit tests for core lifecycle hooks; Added unit tests for core pipe infrastructure; Added unit tests for discovery service and meta-host collection; Added unit tests for file validation pipes and validators; Added unit tests for microservices client implementations; Added unit tests for microservices context classes; Added unit tests for microservices context handling; Added unit tests for microservices core components; Added unit tests for microservices exception handling; Added unit tests for microservices helper utilities; Added unit tests for multer file-interceptor variants; Added unit tests for provider classifier and silent logger utilities; Added unit tests for the Reflector service; Added unit tests for the core injector subsystem; Added unit tests for the logger service and log-level utilities; Added unit tests for the middleware module components; Expanded end-to-end test coverage for microservices transports; Expanded integration test coverage for the dependency injector; Initial release of the @nestjs/testing package; Integration test for Express app.locals exposure; Integration test suite for Kafka microservice messaging patterns; Integration test suite for global prefix middleware behavior; Integration tests for RabbitMQ fanout and topic exchanges; Integration tests for application shutdown hooks; Integration tests for body parser configuration limits; Integration tests for global prefix exclusion and middleware behavior; Integration tests for module override functionality migrated to Vitest; Integration tests for raw body handling in Express and Fastify adapters; Integration tests for request and transient scoped providers; New GraphQL Code-First integration test suite with strict TypeScript configuration; New Server-Sent Events (SSE) integration test suite; New integration test app for file streaming capabilities; New integration test application for microservices clients; New integration tests for WebSocket manual acknowledgments and request-scoped gateways; New integration tests for route conflict policies and specificity resolution.

Dependencies

Routine dependency updates across 53 manifests

This release updates dependencies across 53 manifests, including bumping @nestjs/core to v11.1.11, upgrading the typescript-eslint monorepo to v8.34.1, and updating @commitlint/cli to v19.2.0. It also includes various patch and minor version updates for development tools and libraries such as prettier, mongoose, and socket.io to keep the project's toolchain current.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 57.

Lenses

  • Code Health 88
  • Architecture 56
  • Maturity 68
  • Readiness 46
  • Security 73
  • Domain Modelling 100

Changes since last survey

  • 300 commits — 157 feature/other, 143 fixes

By area

  • (root) — 85 commits
  • sample/31-graphql-federation-code-first — 39 commits
  • packages/microservices — 36 commits
  • (repo) — 26 commits
  • packages/core — 26 commits
  • packages/common — 18 commits
  • .github/workflows — 6 commits
  • sample/34-hmr-esm — 6 commits
  • tools/benchmarks — 6 commits
  • sample/25-dynamic-modules — 5 commits
  • packages/platform-express — 4 commits
  • packages/platform-fastify — 4 commits
  • packages/platform-ws — 4 commits
  • sample/35-zod-validation — 4 commits
  • integration/docker-compose.yml — 3 commits
  • integration/hello-world — 3 commits
  • sample/11-swagger — 3 commits
  • integration/nest-application — 2 commits
  • integration/scopes — 2 commits
  • packages/platform-socket.io — 2 commits

Notable commits

  • fix: Fix: merge multer limits key-by-key instead of overriding it wholesale (#17818)
  • fix: Revert "feat(core): add support for array of global prefixes (#17713)" (#17845)
  • fix: fix(common): Support numeric string values in ParseEnumPipe (#17668)
  • fix: fix(common): apply the ParseDatePipe default to every missing value (#17827)
  • fix: fix(common): collapse duplicate internal slashes in normalizePath (#17710)
  • fix: fix(common): invoke proto-key stripping hook via this in transform (#17761)
  • fix: fix(common): mark parse date pipe options as optional (#17780)
  • fix: fix(common): reject non-numeric items in ParseArrayPipe with items Number (#17876)
  • fix: fix(common): reject null file input in parse-file pipe
  • fix: fix(common): serialize errorCode in built-in exception responses
  • fix: fix(common): support object path segments in issue messages (#17690)
  • fix: fix(common): treat empty string as array input in ParseArrayPipe (#17702)
  • fix: fix(common): validate UUID v3 variant (#17655)
  • fix: fix(common): validate uuid version and variant when no version is set (#17738)
  • fix: fix(core): Serialize errorCode for plain HttpException responses
  • fix: fix(core): avoid treating error instances with statusCode as http errors (#17709)
  • fix: fix(core): circular durable providers issue #17562
  • fix: fix(core): clean up repeated shutdown signal listeners (#17625)
  • fix: fix(core): correctly discover value providers in discovery service
  • fix: fix(core): detect circular dependencies across more than two providers (#17871)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

nestjs/nest was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit b58554ea5857445841674963211e4f3f41b0a3a4 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d00c643c3f66.