SAFE-Stack/SAFE-BookStore
52.4
Weak · 23 September 2026
1.3k
lines of production code
F#
primary language
5
measurements over time
What this system is
This system is a modernized web application for managing user wishlists, rebuilt on .NET 8 with a Giraffe/Saturn backend and a Vite/React frontend. It provides user authentication, book management, and persistent storage via Azure services, while replacing legacy components like the SmartMeterHome server and Fable-based client with a cohesive, testable architecture.
Features
New client-side pages for Home, Login, and Wishlist
The application introduces three new client-side pages implemented in F\# using Feliz and Elmish: a Home page that fetches and displays a list of books, a Login page that handles user authentication and form validation, and a Wishlist page that allows authenticated users to view, add, and remove books from their personal list. These pages integrate with existing shared APIs and state management patterns.
src/Client/pages · high confidence
Removals
Removed Fable/Elmish client application files
The client-side application built with Fable and Elmish has been removed from the project. This includes the main application script (app.fsx), the Fable configuration file (fableconfig.json), the HTML entry point (public/index.html), and the .gitignore file. Users will no longer have access to this specific client implementation.
src/msu.SmartMeterHome.Client · high confidence
Removed SmartMeterHome server and dependencies
The SmartMeterHome application, which previously served the client files and provided WebSocket/HTTP endpoints via Suave on port 8085, has been completely removed from the codebase. This deletion includes the server implementation (Server.fs), the entry point (Program.fs), configuration files, and dependency manifests (paket.references/template) for FSharp.Core, Suave, and Kestrel, effectively eliminating the local development server component of the product.
src/msu.SmartMeterHome · high confidence
Behavioural changes
Migrate client to Vite, Tailwind CSS, and DaisyUI
The client application has been rebuilt using Vite as the build tool, replacing the previous Webpack-based setup. Styling has been migrated to Tailwind CSS with the DaisyUI component library, introducing a new visual theme and layout structure. The entry point has been updated to use the \useElmish\ hook for the main application, and the routing/navigation logic has been refactored to use \Feliz.Router\ with a \PageTab\ model for managing Home, Login, and Wishlist states. Additionally, a \NewBook\ component with form validation and error handling has been added to support adding books to the wishlist.
src/Client · high confidence
Migrate server to Giraffe and Saturn with Azure storage integration
The server-side code has been rewritten to use the Giraffe and Saturn web frameworks, replacing the previous stack. This includes a new authentication system using JWT tokens (Authorise.fs) and integration with Azure Table and Blob storage (Azure.fs, Storage.fs) for persisting user wishlists. Additionally, a background job using Quartz has been added to periodically reset the wishlist to default items.
src/Server · high confidence
Migrated build system to .NET 8 and replaced FAKE with a native F\# build script
The project has been upgraded to use the .NET 8 SDK, as specified in the new global.json file. The legacy FAKE build system (build.fsx, build.sh, build.cmd) and associated CI configurations (.travis.yml, appveyor.yml) have been removed and replaced with a modern F\#-based build script (Build.fs) that utilizes the Farmer library for Azure infrastructure-as-code and Vite for client-side bundling. This change simplifies the build process and aligns the project with current .NET standards.
(repo-wide) · high confidence
Updated Paket restore targets to support modern .NET SDK and CLI tooling
The .paket directory has been significantly refactored to modernize the build process. The legacy \paket.targets\ and \PaketRestoreTask.deps.json\ files were removed in favor of an updated \Paket.Restore.targets\ file. This new target file introduces support for the .NET CLI tooling (dotnet paket), adds file hashing for incremental builds, and improves compatibility with newer MSBuild and .NET SDK versions.
.paket · medium confidence
Test coverage
Initial test suite scaffolding for Client, Server, and Shared modules
Added the foundational test infrastructure for the application's three main areas. The Shared module now includes a login validation test case, while the Client and Server modules each have their own test entry points configured with their respective testing frameworks (Fable.Mocha for the client and Expecto for the server). This establishes the structure for future unit and integration tests.
tests · high confidence
Dependencies
Upgrade to .NET 8 and modernize frontend dependencies
The project has been upgraded to target .NET 8.0 across all C\# and F\# projects, replacing the legacy netcoreapp1.1 target. On the client side, the build system has been modernized to use Vite 5.4.6 and React 18.2.0, replacing the older Webpack and Babel-based tooling. Additionally, the backend dependencies have been updated to include modern libraries such as Elmish 4, Fable 4, and Saturn, while removing older packages like Suave and FSharp.Formatting.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 58 → 52 (-5.2)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 100 (+0.0)
- Architecture 100 → 69 (-31.0)
- Maturity 49 → 37 (-12.3)
- Readiness 55 → 60 (+4.9)
- Security 55 → 68 (+12.8)
Resolved (37)
- Dependency hygiene not measured — no packages were read
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: Microsoft.Extensions.Caching.Memory 8.0.0
- High CVE: System.Text.Json 8.0.1
- High CVE: System.Text.Json 8.0.1
- High vulnerability: [GHSA redacted] (package-lock.json)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 17 more
New (36)
- Documentation: no installation or build instructions (README.md)
- Documentation: no licence statement (README.md)
- Documentation: no usage examples (README.md)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High IaC: WD-COMPOSE-0002 (docker-compose.yml)
- High vulnerability: [GHSA redacted] (package-lock.json)
- High: security finding (details withheld)
- …and 16 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
SAFE-Stack/SAFE-BookStore was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 38a1f6dcd1592d566ea19d3c93812b84e20268e1 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.